Spyware / Malware / Virus Removal
XP Total Security 2011 taken over my computer
17 min read
slvrthunder
Topic Starter
XP Total Security 2011 pop-ups that keep coming and it won't allow me to open Internet Explorer. I am posting this from my laptop(a different computer). I have run a scan from Super AntiSpyware that didn't help. I have Malwarebytes' Anti-Malware but it will not open. McAfee is currently scanning.
I am running Windows xp and have the Service Pack 3.
JonTom
Hello slvrthunder and
My name is JonTom
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOTKIT" entries
Please post the DDS logs and the GMER log in your next reply.
If you are still unable to run the scans after running rKill just let me know
My name is JonTom
- Malware Logs can sometimes take a lot of time to research and interpret.
- Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
- Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
- Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
- PLEASE NOTE: If you do not reply after 5 days your thread will be closed.
You will need to download the required tools using your laptop and then transfer them to the infected machine. If you use a flash drive for the transfer, please run the following tool first to reduce the chances of cross infection:I am posting this from my laptop
- Please download Flash Disinfector
- Click here to download Flash Disinfector and save the file (called Flash_Disinfector.exe) to your desktop.
- Double click on the Flash_Disinfector.exe icon to run the program and follow any prompts that may appear.
- The program may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so if prompted.
- Wait until Flash disinfector has finished scanning and then exit the program.
- Reboot your computer.
Lets begin with rKill and see if it allows us to run some system scans.
- rkill
- Please download rkill (Courtesy of Bleepingcomputer.com).
- There are 5 different versions of this tool. If one of them will not run, please try the next one in the list.
- Note: Vista and Windows 7 Users must right click and select "Run as Administrator" to run the tool.
- Note: You only need to get one of the tools to run, not all of them.
1. rkill.exe
2. rkill.com
3. rkill.scr
4. WiNlOgOn.exe
5. uSeRiNiT.exe
Note: You will likely see a message from this rogue telling you the file is infected. Ignore the message. Leave the message OPEN, do not close the message.
Run rkill repeatedly until it's able to do it's job. This may take a few tries.
You'll be able to tell rkill has done it's job when your desktop (explorer.exe) cycles off and then on again.
- Please perform the following scan
- Please download DDS from here and save it to your desktop.
- Disable any script blocking protection (How to Disable your Security Programs)
- Double click on the DDS icon to run the tool (may take up to 3 minutes to run).
- When done, DDS.txt will open.
- After a few moments, attach.txt will open in a second window.
- Save both reports to your desktop.
- Please post the contents of the DDS.txt and Attach.txt logs in your next reply.
- Please scan your system with GMER
[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
- Extract the contents of the zipped file to desktop.
- Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent.
- If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
- In the right panel, you will see several boxes that have been checked. Uncheck the following …
- IAT/EAT
- Drives/Partition other than Systemdrive (typically C:\)
- Show All (don't miss this one)
- Then click the Scan button & wait for it to finish.
- Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
- Save it where you can easily find it, such as your desktop, and post it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOTKIT" entries
Please post the DDS logs and the GMER log in your next reply.
If you are still unable to run the scans after running rKill just let me know
slvrthunder
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 10:58:54.06 on Fri 04/01/2011
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1547 [GMT -4:00]
.
AV: Spy Sweeper with AntiVirus *Disabled/Updated* {B3891867-7230-459B-9987-E7CCFA7A7D1D}
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\vsnpstd.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Location Finder\LocationFinder.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\j2 Messenger 4.2\J2GTray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
E:\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn4\yt.dll
BHO: {089fd14d-132b-48fc-8861-0048ae113215} - c:\program files\siteadvisor\6253\SiteAdv.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20101124091320.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: AIM Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\program files\aim toolbar\aimtb.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn4\YTSingleInstance.dll
BHO: {fdd3b846-8d59-4ffb-8758-209b6ad74acc} - c:\program files\microsoft money\system\mnyviewer.dll
TB: McAfee SiteAdvisor: {0bf43445-2f28-4351-9252-17fe6e806aa0} - c:\program files\siteadvisor\6253\SiteAdv.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn4\yt.dll
TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
EB: &Yahoo! Messenger: {4528bbe0-4e08-11d5-ad55-00010333d0ad} - c:\progra~1\yahoo!\common\yhexbmesus.dll
EB: MoneySide: {9404901d-06da-4b23-a0ee-3ea4f64ec9b3} - c:\program files\microsoft money\system\mnyviewer.dll
uRun: [Microsoft Location Finder] "c:\program files\microsoft location finder\LocationFinder.exe"
uRun: [SUPERAntiSpyware] "c:\program files\superantispyware\SUPERAntiSpyware.exe"
uRun: [EasyLinkAdvisor] "c:\program files\linksys easylink advisor\LinksysAgent.exe" /startup
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\user\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [Microsoft Works Update Detection] "c:\program files\common files\microsoft shared\works shared\WkUFind.exe"
mRun: [UpdReg] c:\windows\Updreg.exe
mRun: [AHQInit] "c:\program files\creative\sblive\program\AHQInit.exe"
mRun: [AdaptecDirectCD] "c:\program files\roxio\easy cd creator 5\directcd\DirectCD.exe"
mRun: [Lexmark X5100 Series] "c:\program files\lexmark x5100 series\lxbabmgr.exe"
mRun: [DIGStream] "c:\program files\digstream\digstream.exe"
mRun: [DIGServices] "c:\program files\espnruntime\DIGServices.exe" /brand=ESPN /priority=0 /poll=24
mRun: [MimBoot] c:\progra~1\musicm~1\musicm~1\mimboot.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [SiteAdvisor] "c:\program files\siteadvisor\6172\SiteAdv.exe"
mRun: [j2 4.2] "c:\program files\j2 messenger 4.2\J2GDllCmd.exe" /R
mRun: [BlackBerryAutoUpdate] c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe /background
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [AppleSyncNotifier] "c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe"
mRun: [snpstd] c:\windows\vsnpstd.exe
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\j242~1.lnk - c:\program files\j2 messenger 4.2\J2GTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~2.lnk - c:\program files\microsoft office\office\OSA9.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\common files\microsoft shared\works shared\wkcalrem.exe
IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: &Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: Yahoo! &Dictionary - file:///c:\program files\yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\yahoo!\Common/ycsms.htm
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim95\aim.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {301DA1EE-F65C-4188-A417-9E915CC8FBFA} - c:\program files\microsoft money\system\mnyviewer.dll
Trusted Zone: musicmatch.com\online
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://dcode.support.microsoft.com/dcode/ActiveX/MSDcode.cab
DPF: {0F2AAAE3-7E9E-4B64-AB5D-1CA24C6ACB9C} - hxxp://notes.belf.wnyric.org/dwa85W.cab
DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/3/9/8/398422c0-8d3e-40e1-a617-af65a72a0465/LegitCheckControl.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1005.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1150326369750
DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - hxxp://www.nick.com/common/groove/gx/GrooveAX28.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} - hxxp://notes.belf.wnyric.org/dwa7W.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - c:\program files\siteadvisor\6253\SiteAdv.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: WRNotifier - WRLogonNTF.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Notification Packages = scecli scecli scecli scecli scecli scecli
mASetup: {A509B1FF-37FF-4bFF-8CFF-4F3A747040FF} - c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,launchinfsectionex c:\program files\internet explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2010-7-15 386840]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2010-7-15 84072]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2006-10-10 5632]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2007-2-27 32256]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-7-15 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-7-15 271480]
R2 McProxy;McAfee Proxy Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-7-15 271480]
R2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2010-7-15 171168]
R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2010-7-15 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\common files\mcafee\systemcore\mfevtps.exe [2010-7-15 141792]
R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files\webroot\spy sweeper\SpySweeper.exe [2007-10-15 3567928]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-7-15 55840]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2010-7-15 152960]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-7-15 313288]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2010-7-15 88544]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2006-2-16 4096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2010-7-15 52104]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2010-7-15 88544]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-7-15 84264]
S3 PortlUSB;PortlUSB;c:\windows\system32\drivers\SiriusUSB.sys [2008-7-29 7552]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-1-8 24652]
.
=============== Created Last 30 ================
.
2011-03-31 00:17:49 331776 –sha-w- c:\docume~1\user\locals~1\applic~1\isf.exe
2011-03-14 16:17:08 ——– d—–w- c:\program files\common files\Software Update Utility
2011-03-08 21:38:37 ——– d—–w- c:\program files\iPod
2011-03-08 21:38:33 ——– d—–w- c:\docume~1\alluse~1\applic~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-03-08 21:20:06 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2011-03-08 21:20:06 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2011-03-08 21:20:06 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2011-03-08 21:20:06 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2011-03-08 21:20:06 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2011-03-08 21:20:06 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2011-03-08 21:20:06 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2011-03-08 21:08:13 ——– d—–w- c:\program files\Bonjour
2011-03-03 08:08:32 ——– d—–w- c:\windows\system32\XPSViewer
2011-03-03 08:07:49 89088 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-03-03 08:06:56 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2011-03-03 08:06:56 597504 ——w- c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2011-03-03 08:06:56 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2011-03-03 08:06:56 575488 ——w- c:\windows\system32\xpsshhdr.dll
2011-03-03 08:06:56 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2011-03-03 08:06:56 1676288 ——w- c:\windows\system32\xpssvcs.dll
2011-03-03 08:06:56 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2011-03-03 08:06:56 117760 ——w- c:\windows\system32\prntvpt.dll
2011-03-03 08:06:55 ——– d—–w- C:\dbb74f8f171e24df2830baee
.
==================== Find3M ====================
.
2011-02-18 21:36:58 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll
2011-02-09 13:53:52 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-02 07:58:35 2067456 —-a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09:02 290048 —-a-w- c:\windows\system32\atmfd.dll
2005-06-26 15:17:11 774144 —-a-w- c:\program files\RngInterstitial.dll
2004-03-25 00:10:31 338800 —-a-w- c:\program files\efxsetup.exe
2004-03-13 14:00:05 723870 —-a-w- c:\program files\yahtzee.exe
.
============= FINISH: 11:01:09.76 ===============
slvrthunder
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 10/22/2002 2:53:47 PM
System Uptime: 3/31/2011 9:35:55 PM (14 hours ago)
.
Motherboard: Dell Computer Corp. | |
Processor: Intel® Pentium® 4 CPU 2.00GHz | Microprocessor | 1999/400mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 74 GiB total, 39.03 GiB free.
D: is CDROM ()
E: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP1217: 3/13/2011 6:58:45 AM - System Checkpoint
RP1218: 3/14/2011 8:12:44 AM - System Checkpoint
RP1219: 3/15/2011 11:49:19 AM - System Checkpoint
RP1220: 3/16/2011 3:00:23 AM - Software Distribution Service 3.0
RP1221: 3/17/2011 3:23:12 AM - System Checkpoint
RP1222: 3/18/2011 3:34:42 AM - System Checkpoint
RP1223: 3/19/2011 4:34:42 AM - System Checkpoint
RP1224: 3/20/2011 5:34:42 AM - System Checkpoint
RP1225: 3/21/2011 6:34:43 AM - System Checkpoint
RP1226: 3/22/2011 7:34:42 AM - System Checkpoint
RP1227: 3/23/2011 8:34:33 AM - System Checkpoint
RP1228: 3/24/2011 9:34:32 AM - System Checkpoint
RP1229: 3/25/2011 3:00:21 AM - Software Distribution Service 3.0
RP1230: 3/26/2011 3:34:32 AM - System Checkpoint
RP1231: 3/27/2011 4:34:32 AM - System Checkpoint
RP1232: 3/28/2011 5:34:32 AM - System Checkpoint
RP1233: 3/29/2011 6:00:35 AM - System Checkpoint
RP1234: 3/30/2011 7:00:40 AM - System Checkpoint
RP1235: 3/31/2011 7:08:53 AM - System Checkpoint
RP1236: 4/1/2011 7:40:17 AM - System Checkpoint
.
==== Installed Programs ======================
.
3D Groove Playback Engine
Ad-aware 6 Professional
Adobe Acrobat 4.0
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop 6.0
Adobe Reader 9.4.2
Adobe Shockwave Player
Adobe SVG Viewer
AIM 7
AIM Toolbar
AOL Instant Messenger
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Display Driver
BlackBerry Desktop Software 5.0.1
BlackBerry Device Software Updater
Bonjour
Canon PIXMA iP5000
Canon Utilities Easy-PhotoPrint
Classic PhoneTools
Compatibility Pack for the 2007 Office system
Critical Update for Windows Media Player 11 (KB959772)
CutePDF Writer 2.8
Dell Digital Jukebox Driver
Dell Modem-On-Hold
Dell Picture Studio - Dell Image Expert
Dell Solution Center
Digital Line Detect
Digital Photo Navigator 1.5
Download Updater (AOL LLC)
Drivers Install For Linksys Easylink Advisor
Easy CD Creator 5 Basic
ESPN RunTime
File Extension Finder
Finale Reader 2011
Full Tilt Poker
GE 98063 EasyCam
GNU Solfege 3.16.4
Google Chrome
Google Toolbar for Internet Explorer
Help and Support Customization
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
Intel® PRO Ethernet Adapter and Software
Intel® PROSet II
InterActual Player
InterVideo WinDVD
iTunes
j2 Messenger 4.2
Java Auto Updater
Java™ 6 Update 22
Lexmark X5100 Series
LimeWire 5.5.8
Linksys EasyLink Advisor 1.6 (0032)
Malwarebytes' Anti-Malware
McAfee SecurityCenter
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Encarta Encyclopedia Standard 2002
Microsoft Excel 2000 SR-1
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Location Finder
Microsoft Money 2002
Microsoft Money 2002 System Pack
Microsoft National Language Support Downlevel APIs
Microsoft Outlook 2000 SR-1
Microsoft Picture It! Photo 2002
Microsoft PowerPoint 2000 SR-1
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Word 2000 SR-1
Microsoft Word 2002
Microsoft Works 2002 Setup Launcher
Microsoft Works 6.0
Microsoft Works Suite Add-in for Microsoft Word
Microsoft XML Parser
MobileMe Control Panel
Modem Helper
Move Media Player
MSN Music Assistant
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB973686)
Musicmatch® Jukebox
Musicnotes Software Suite 1.4.6
My Sirius Studio
NEF Codec
Nero Suite
Paint Shop Pro 7
PCFriendly
Picasa 3
PowerDirector Express
PowerDVD
PowerProducer
PowerTeacher Gradebook
QuickTime
RealPlayer
Rhapsody Player Engine
Safari
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
ServiceProvider
Shockwave
Skype Toolbars
Skype™ 5.1
Solero Music Viewer 8.0.29.370
Sound Blaster Live! Value
Spy Sweeper
SUPERAntiSpyware Free Edition
TWC Client ActiveX Controls
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB968220)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
URGE
VideoLAN VLC media player 0.8.1
Viewpoint Media Player
WebFldrs XP
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
Works Suite OS Pack
Works Synchronization
Yahoo! extras
Yahoo! Software Update
Yahoo! Toolbar
Yahtzee 1.1.6
.
==== Event Viewer Messages From Past Week ========
.
4/1/2011 12:39:57 AM, error: Service Control Manager [7031] - The McShield service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
3/31/2011 1:36:06 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service McNaiAnn with arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}
3/31/2011 1:34:59 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips intelppm IPSec mfehidk mfetdi2k MRxSmb NetBIOS NetBT RasAcd Rdbss SASDIFSV SASKUTIL Tcpip
3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning.
3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The McShield service depends on the McAfee Validation Trust Protection Service service which failed to start because of the following error: The dependency service or group failed to start.
3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The McAfee Validation Trust Protection Service service depends on the McAfee Inc. mfehidk service which failed to start because of the following error: A device attached to the system is not functioning.
3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The McAfee Proxy Service service depends on the McAfee Firewall Core Service service which failed to start because of the following error: The dependency service or group failed to start.
3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The McAfee Personal Firewall Service service depends on the McAfee Firewall Core Service service which failed to start because of the following error: The dependency service or group failed to start.
3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The McAfee Network Agent service depends on the McAfee Firewall Core Service service which failed to start because of the following error: The dependency service or group failed to start.
3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The McAfee Firewall Core Service service depends on the McAfee Validation Trust Protection Service service which failed to start because of the following error: The dependency service or group failed to start.
3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The McAfee Anti-Spam Service service depends on the McAfee Firewall Core Service service which failed to start because of the following error: The dependency service or group failed to start.
3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBT service which failed to start because of the following error: A device attached to the system is not functioning.
3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
3/31/2011 1:34:23 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
3/30/2011 10:08:15 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the HTTP SSL service to connect.
3/30/2011 10:08:15 PM, error: Service Control Manager [7000] - The HTTP SSL service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
3/30/2011 10:06:03 PM, error: Service Control Manager [7000] - The Webroot Spy Sweeper Engine service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
3/30/2011 10:06:02 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Webroot Spy Sweeper Engine service to connect.
.
==== End Of File ===========================
slvrthunder
GMER 1.0.15.15570 - http://www.gmer.net
Rootkit scan 2011-04-01 17:04:33
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST380021A rev.3.75
Running: gmer.exe; Driver: C:\DOCUME~1\User\LOCALS~1\Temp\awtyapob.sys
—- System - GMER 1.0.15 —-
SSDT 8A9242C8 ZwAllocateVirtualMemory
SSDT 8A963400 ZwCreateKey
SSDT 8A9632A0 ZwCreateProcess
SSDT 8A961020 ZwCreateProcessEx
SSDT 8A999450 ZwCreateThread
SSDT 8A924D48 ZwDeleteKey
SSDT 8A95D020 ZwDeleteValueKey
SSDT 8A924340 ZwQueueApcThread
SSDT 8A91B460 ZwReadVirtualMemory
SSDT 8A99B6D8 ZwRenameKey
SSDT 8A924430 ZwSetContextThread
SSDT 8A978668 ZwSetInformationKey
SSDT 8A9628B0 ZwSetInformationProcess
SSDT 8A999360 ZwSetInformationThread
SSDT 8A941138 ZwSetValueKey
SSDT 8A962838 ZwSuspendProcess
SSDT 8A9243B8 ZwSuspendThread
SSDT 8A9610D0 ZwTerminateProcess
SSDT 8A9993D8 ZwTerminateThread
SSDT 8A91B4D8 ZwWriteVirtualMemory
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xF786D16E]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenKey [0xF786D0CC]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xF786D0A4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xF786D0B8]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetSecurityObject [0xF786D144]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xF786D184]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0xF786D158]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetSecurityObject
—- Kernel code sections - GMER 1.0.15 —-
? C:\DOCUME~1\User\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !
—- User code sections - GMER 1.0.15 —-
.text C:\WINDOWS\System32\svchost.exe[376] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00630FE5
.text C:\WINDOWS\System32\svchost.exe[376] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0063000A
.text C:\WINDOWS\System32\svchost.exe[376] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00630FD4
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BC0FEF
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BC0064
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BC0F79
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BC0F8A
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BC0047
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BC0036
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BC009C
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BC0F54
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BC0F28
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BC0F39
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BC0F0D
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BC0FA5
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BC0FD4
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BC0075
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BC001B
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BC0000
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BC00B7
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00BB0040
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00BB0065
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00BB001B
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00BB000A
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00BB0FA8
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00BB0FEF
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00BB0FB9
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [DB, 88]
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00BB0FD4
.text C:\WINDOWS\System32\svchost.exe[376] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00660033
.text C:\WINDOWS\System32\svchost.exe[376] msvcrt.dll!system 77C293C7 5 Bytes JMP 00660FA8
.text C:\WINDOWS\System32\svchost.exe[376] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00660FD4
.text C:\WINDOWS\System32\svchost.exe[376] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0066000C
.text C:\WINDOWS\System32\svchost.exe[376] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00660FC3
.text C:\WINDOWS\System32\svchost.exe[376] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00660FEF
.text C:\WINDOWS\System32\svchost.exe[376] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 00640FEF
.text C:\WINDOWS\System32\svchost.exe[376] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 00640FDE
.text C:\WINDOWS\System32\svchost.exe[376] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 00640014
.text C:\WINDOWS\System32\svchost.exe[376] WININET.dll!InternetOpenUrlW 3D9A6D77 5 Bytes JMP 00640FC3
.text C:\WINDOWS\System32\svchost.exe[376] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00650FEF
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[672] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 62419A20 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[672] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 62419AE2 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\System32\svchost.exe[832] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00D50FEF
.text C:\WINDOWS\System32\svchost.exe[832] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00D50FCA
.text C:\WINDOWS\System32\svchost.exe[832] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00D50000
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00D80FEF
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00D80F9E
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00D80093
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00D80FAF
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00D8006C
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00D80FD4
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00D800C9
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00D80F8D
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D80F66
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D800F5
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00D80F55
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00D8005B
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00D80014
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00D800AE
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00D80040
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00D8002F
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00D800E4
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00D7002C
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00D70058
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00D70FE5
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00D7001B
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00D70F9B
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00D70000
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00D70047
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00D70FB6
.text C:\WINDOWS\System32\svchost.exe[832] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00D60042
.text C:\WINDOWS\System32\svchost.exe[832] msvcrt.dll!system 77C293C7 5 Bytes JMP 00D60FB7
.text C:\WINDOWS\System32\svchost.exe[832] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00D6001D
.text C:\WINDOWS\System32\svchost.exe[832] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00D60FE3
.text C:\WINDOWS\System32\svchost.exe[832] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00D60FC8
.text C:\WINDOWS\System32\svchost.exe[832] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00D60000
.text C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe[924] kernel32.dll!CreateThread + 1A 7C8106F1 4 Bytes CALL 0045024D C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe (Spy Sweeper Engine/Webroot Software, Inc.)
.text C:\WINDOWS\system32\services.exe[1080] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00970000
.text C:\WINDOWS\system32\services.exe[1080] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00970FEF
.text C:\WINDOWS\system32\services.exe[1080] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00970025
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00CD0FE5
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00CD0064
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00CD0F6F
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00CD0049
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00CD0F8A
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00CD0FC0
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00CD00AB
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00CD009A
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00CD0F1C
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00CD0F2D
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00CD00D0
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00CD0F9B
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00CD0000
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00CD007F
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00CD002C
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00CD001B
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00CD0F48
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 009A0FB9
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 009A0F8A
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 009A000A
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 009A0FD4
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 009A0047
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 009A0FEF
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 009A002C
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 009A001B
.text C:\WINDOWS\system32\services.exe[1080] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0099003F
.text C:\WINDOWS\system32\services.exe[1080] msvcrt.dll!system 77C293C7 5 Bytes JMP 0099002E
.text C:\WINDOWS\system32\services.exe[1080] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00990FD2
.text C:\WINDOWS\system32\services.exe[1080] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0099000C
.text C:\WINDOWS\system32\services.exe[1080] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0099001D
.text C:\WINDOWS\system32\services.exe[1080] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00990FE3
.text C:\WINDOWS\system32\services.exe[1080] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00980000
.text C:\WINDOWS\system32\lsass.exe[1092] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00BF0FEF
.text C:\WINDOWS\system32\lsass.exe[1092] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00BF0014
.text C:\WINDOWS\system32\lsass.exe[1092] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00BF0FD4
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00E60FE5
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00E60F50
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00E60F61
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00E60F72
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00E60F83
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00E60F94
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00E60F22
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00E6006A
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E6008C
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E6007B
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00E60ED8
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00E6001B
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00E60000
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00E60F3F
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00E60FAF
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00E60FCA
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00E60F07
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00E50FAF
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00E5006C
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00E50FD4
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00E5000A
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00E5005B
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00E50FEF
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00E50040
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00E5001B
.text C:\WINDOWS\system32\lsass.exe[1092] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00E40F92
.text C:\WINDOWS\system32\lsass.exe[1092] msvcrt.dll!system 77C293C7 5 Bytes JMP 00E4001D
.text C:\WINDOWS\system32\lsass.exe[1092] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00E4000C
.text C:\WINDOWS\system32\lsass.exe[1092] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00E40FE3
.text C:\WINDOWS\system32\lsass.exe[1092] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00E40FAD
.text C:\WINDOWS\system32\lsass.exe[1092] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00E40FD2
.text C:\WINDOWS\system32\lsass.exe[1092] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00E30FE5
.text C:\WINDOWS\system32\svchost.exe[1260] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00E30000
.text C:\WINDOWS\system32\svchost.exe[1260] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00E3002C
.text C:\WINDOWS\system32\svchost.exe[1260] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00E3001B
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00EB0000
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00EB0051
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00EB0036
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00EB0F68
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00EB0025
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00EB0F94
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00EB0F1A
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00EB0062
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00EB0EEE
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00EB0EFF
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00EB0EC9
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00EB0F83
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00EB0FDB
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00EB0F37
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00EB0FAF
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00EB0FC0
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00EB007D
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00E6000A
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00E60F5E
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00E60FC3
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00E60FD4
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00E60F83
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00E60FEF
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00E60F9E
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [06, 89]
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00E60025
.text C:\WINDOWS\system32\svchost.exe[1260] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00E5005A
.text C:\WINDOWS\system32\svchost.exe[1260] msvcrt.dll!system 77C293C7 5 Bytes JMP 00E50FCF
.text C:\WINDOWS\system32\svchost.exe[1260] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00E5002E
.text C:\WINDOWS\system32\svchost.exe[1260] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00E50000
.text C:\WINDOWS\system32\svchost.exe[1260] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00E5003F
.text C:\WINDOWS\system32\svchost.exe[1260] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00E5001D
.text C:\WINDOWS\system32\svchost.exe[1260] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00E40000
.text C:\WINDOWS\system32\svchost.exe[1348] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00B60FEF
.text C:\WINDOWS\system32\svchost.exe[1348] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00B60FC3
.text C:\WINDOWS\system32\svchost.exe[1348] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B60FD4
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BA0FE5
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BA0047
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BA0F52
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BA002C
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BA0F79
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BA0F9B
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BA0EFF
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BA0F26
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BA0EDA
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BA0073
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BA0EC9
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BA0F8A
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BA0000
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BA0F37
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BA0011
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BA0FCA
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BA0062
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00B90FCA
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00B90F9E
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00B9001B
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00B90FE5
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00B90FAF
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00B90000
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00B90051
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00B90036
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00B80F8D
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!system 77C293C7 5 Bytes JMP 00B80FA8
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00B80011
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00B80FE3
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00B80022
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00B80000
.text C:\WINDOWS\system32\svchost.exe[1348] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00B70FEF
.text C:\WINDOWS\System32\svchost.exe[1476] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 021B0FE5
.text C:\WINDOWS\System32\svchost.exe[1476] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 021B0000
.text C:\WINDOWS\System32\svchost.exe[1476] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 021B0FD4
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 0220000A
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02200F80
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02200075
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02200064
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02200047
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0220002C
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02200F48
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02200F65
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02200F12
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 022000AB
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 022000D0
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02200FA5
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02200FEF
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02200090
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02200FCA
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 0220001B
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 02200F37
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 021F0FB9
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 021F006C
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 021F0FD4
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 021F000A
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 021F0051
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 021F0FEF
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 021F0036
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 021F0025
.text C:\WINDOWS\System32\svchost.exe[1476] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 021E0051
.text C:\WINDOWS\System32\svchost.exe[1476] msvcrt.dll!system 77C293C7 5 Bytes JMP 021E0036
.text C:\WINDOWS\System32\svchost.exe[1476] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 021E0FD7
.text C:\WINDOWS\System32\svchost.exe[1476] msvcrt.dll!_open 77C2F566 5 Bytes JMP 021E0000
.text C:\WINDOWS\System32\svchost.exe[1476] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 021E0FC6
.text C:\WINDOWS\System32\svchost.exe[1476] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 021E0011
.text C:\WINDOWS\System32\svchost.exe[1476] WS2_32.dll!socket 71AB4211 5 Bytes JMP 021D0FEF
.text C:\WINDOWS\System32\svchost.exe[1476] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 021C0FEF
.text C:\WINDOWS\System32\svchost.exe[1476] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 021C0FCA
.text C:\WINDOWS\System32\svchost.exe[1476] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 021C0000
.text C:\WINDOWS\System32\svchost.exe[1476] WININET.dll!InternetOpenUrlW 3D9A6D77 5 Bytes JMP 021C001B
.text C:\WINDOWS\system32\svchost.exe[1524] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00630FEF
.text C:\WINDOWS\system32\svchost.exe[1524] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0063001B
.text C:\WINDOWS\system32\svchost.exe[1524] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0063000A
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00660000
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00660F4B
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00660F70
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00660F81
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00660F9E
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00660FB9
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00660F1D
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00660065
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00660EF1
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00660F02
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 006600AF
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00660040
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00660FE5
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00660F3A
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00660FD4
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00660025
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00660080
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00650FB9
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00650F97
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00650FCA
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00650FE5
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00650054
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00650000
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00650039
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00650FA8
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0064003F
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!system 77C293C7 5 Bytes JMP 0064002E
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0064001D
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00640000
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00640FC8
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00640FEF
.text C:\WINDOWS\System32\svchost.exe[1648] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 008A0FE5
.text C:\WINDOWS\System32\svchost.exe[1648] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 008A0011
.text C:\WINDOWS\System32\svchost.exe[1648] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 008A0000
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 008E0000
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 008E0FB6
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 008E00AB
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 008E0090
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 008E0073
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 008E0062
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 008E0F94
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 008E00DC
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 008E0F65
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 008E0108
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 008E0F54
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 008E0FD1
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 008E001B
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 008E0FA5
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 008E0047
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 008E0036
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 008E00F7
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 008D0FD4
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 008D0F9E
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 008D0FE5
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 008D001B
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 008D005B
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 008D0000
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 008D0FC3
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [AD, 88]
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 008D004A
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 008C0FB9
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!system 77C293C7 5 Bytes JMP 008C0044
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 008C0FD4
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!_open 77C2F566 5 Bytes JMP 008C0000
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 008C0033
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 008C0FEF
.text C:\WINDOWS\System32\svchost.exe[1648] WS2_32.dll!socket 71AB4211 5 Bytes JMP 008B0000
.text C:\WINDOWS\system32\svchost.exe[1776] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 006C0FEF
.text C:\WINDOWS\system32\svchost.exe[1776] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 006C0FC3
.text C:\WINDOWS\system32\svchost.exe[1776] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 006C0FD4
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 009E0FE5
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 009E0075
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 009E0F80
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 009E0064
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 009E0FA5
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 009E002C
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 009E0F39
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 009E0F54
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 009E0F0D
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 009E00A6
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 009E0EFC
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 009E003D
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 009E0000
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 009E0F65
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 009E0FC0
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 009E0011
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 009E0F28
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 009D0FCA
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 009D0F8D
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 009D001B
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 009D000A
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 009D0F9E
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 009D0FEF
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 009D0FAF
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [BD, 88]
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 009D0036
.text C:\WINDOWS\system32\svchost.exe[1776] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 009C0FA3
.text C:\WINDOWS\system32\svchost.exe[1776] msvcrt.dll!system 77C293C7 5 Bytes JMP 009C0FB4
.text C:\WINDOWS\system32\svchost.exe[1776] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 009C002E
.text C:\WINDOWS\system32\svchost.exe[1776] msvcrt.dll!_open 77C2F566 5 Bytes JMP 009C000C
.text C:\WINDOWS\system32\svchost.exe[1776] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 009C0FCF
.text C:\WINDOWS\system32\svchost.exe[1776] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 009C001D
.text C:\WINDOWS\system32\svchost.exe[1776] WS2_32.dll!socket 71AB4211 5 Bytes JMP 009B0000
.text C:\WINDOWS\System32\svchost.exe[3440] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00090000
.text C:\WINDOWS\System32\svchost.exe[3440] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0009001B
.text C:\WINDOWS\System32\svchost.exe[3440] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00090FEF
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001B0000
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001B0F79
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001B0064
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001B0F8A
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001B0FA5
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001B0FC0
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001B00B5
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001B009A
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001B00F5
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001B00D0
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 001B0F37
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 001B0047
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 001B0FEF
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 001B007F
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 001B0036
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 001B0025
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 001B0F52
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 002A003D
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 002A008B
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 002A002C
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 002A001B
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 002A007A
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 002A000A
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 002A0069
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 002A004E
.text C:\WINDOWS\System32\svchost.exe[3440] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 003F0040
.text C:\WINDOWS\System32\svchost.exe[3440] msvcrt.dll!system 77C293C7 5 Bytes JMP 003F0025
.text C:\WINDOWS\System32\svchost.exe[3440] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 003F0000
.text C:\WINDOWS\System32\svchost.exe[3440] msvcrt.dll!_open 77C2F566 5 Bytes JMP 003F0FEF
.text C:\WINDOWS\System32\svchost.exe[3440] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 003F0FB5
.text C:\WINDOWS\System32\svchost.exe[3440] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 003F0FD2
.text C:\WINDOWS\System32\svchost.exe[3440] WS2_32.dll!socket 71AB4211 5 Bytes JMP 006F0000
.text C:\WINDOWS\explorer.exe[11880] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00090FEF
.text C:\WINDOWS\explorer.exe[11880] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00090FB9
.text C:\WINDOWS\explorer.exe[11880] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00090FD4
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001B000A
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001B0082
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001B0F8D
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001B0F9E
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001B005B
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001B0FC3
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001B0F6B
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001B00B3
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001B0F35
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001B00D8
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 001B00E9
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 001B004A
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 001B0FEF
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 001B0F7C
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 001B0FD4
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 001B0025
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 001B0F5A
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 002A0FAF
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 002A0051
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 002A0FCA
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 002A0000
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 002A0040
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 002A0FEF
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 002A0025
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 002A0F9E
.text C:\WINDOWS\explorer.exe[11880] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 002B0F81
.text C:\WINDOWS\explorer.exe[11880] msvcrt.dll!system 77C293C7 5 Bytes JMP 002B0FA6
.text C:\WINDOWS\explorer.exe[11880] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 002B0FD2
.text C:\WINDOWS\explorer.exe[11880] msvcrt.dll!_open 77C2F566 5 Bytes JMP 002B0000
.text C:\WINDOWS\explorer.exe[11880] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 002B0FB7
.text C:\WINDOWS\explorer.exe[11880] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 002B0FEF
.text C:\WINDOWS\explorer.exe[11880] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 002D0FEF
.text C:\WINDOWS\explorer.exe[11880] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 002D0014
.text C:\WINDOWS\explorer.exe[11880] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 002D0025
.text C:\WINDOWS\explorer.exe[11880] WININET.dll!InternetOpenUrlW 3D9A6D77 5 Bytes JMP 002D0040
.text C:\WINDOWS\explorer.exe[11880] WS2_32.dll!socket 71AB4211 5 Bytes JMP 02820000
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs SSFS0BB9.SYS (Spy Sweeper FileSystem Filter Driver/Webroot Software Inc (www.webroot.com))
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
Device \Driver\Tcpip \Device\Ip 89DCC710
AttachedDevice \Driver\Tcpip \Device\Ip mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
Device \Driver\Tcpip \Device\Tcp 89DCC710
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
Device \Driver\Tcpip \Device\Udp 89DCC710
AttachedDevice \Driver\Tcpip \Device\Udp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
Device \Driver\Tcpip \Device\RawIp 89DCC710
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
Device \Driver\Tcpip \Device\IPMULTICAST 89DCC710
AttachedDevice \FileSystem\Fastfat \Fat SSFS0BB9.SYS (Spy Sweeper FileSystem Filter Driver/Webroot Software Inc (www.webroot.com))
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
—- Files - GMER 1.0.15 —-
File C:\Documents and Settings\User\Cookies\user@go[1].txt 0 bytes
—- EOF - GMER 1.0.15 —-
Rootkit scan 2011-04-01 17:04:33
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST380021A rev.3.75
Running: gmer.exe; Driver: C:\DOCUME~1\User\LOCALS~1\Temp\awtyapob.sys
—- System - GMER 1.0.15 —-
SSDT 8A9242C8 ZwAllocateVirtualMemory
SSDT 8A963400 ZwCreateKey
SSDT 8A9632A0 ZwCreateProcess
SSDT 8A961020 ZwCreateProcessEx
SSDT 8A999450 ZwCreateThread
SSDT 8A924D48 ZwDeleteKey
SSDT 8A95D020 ZwDeleteValueKey
SSDT 8A924340 ZwQueueApcThread
SSDT 8A91B460 ZwReadVirtualMemory
SSDT 8A99B6D8 ZwRenameKey
SSDT 8A924430 ZwSetContextThread
SSDT 8A978668 ZwSetInformationKey
SSDT 8A9628B0 ZwSetInformationProcess
SSDT 8A999360 ZwSetInformationThread
SSDT 8A941138 ZwSetValueKey
SSDT 8A962838 ZwSuspendProcess
SSDT 8A9243B8 ZwSuspendThread
SSDT 8A9610D0 ZwTerminateProcess
SSDT 8A9993D8 ZwTerminateThread
SSDT 8A91B4D8 ZwWriteVirtualMemory
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xF786D16E]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenKey [0xF786D0CC]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xF786D0A4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xF786D0B8]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetSecurityObject [0xF786D144]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xF786D184]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0xF786D158]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetSecurityObject
—- Kernel code sections - GMER 1.0.15 —-
? C:\DOCUME~1\User\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !
—- User code sections - GMER 1.0.15 —-
.text C:\WINDOWS\System32\svchost.exe[376] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00630FE5
.text C:\WINDOWS\System32\svchost.exe[376] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0063000A
.text C:\WINDOWS\System32\svchost.exe[376] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00630FD4
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BC0FEF
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BC0064
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BC0F79
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BC0F8A
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BC0047
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BC0036
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BC009C
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BC0F54
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BC0F28
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BC0F39
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BC0F0D
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BC0FA5
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BC0FD4
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BC0075
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BC001B
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BC0000
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BC00B7
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00BB0040
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00BB0065
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00BB001B
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00BB000A
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00BB0FA8
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00BB0FEF
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00BB0FB9
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [DB, 88]
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00BB0FD4
.text C:\WINDOWS\System32\svchost.exe[376] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00660033
.text C:\WINDOWS\System32\svchost.exe[376] msvcrt.dll!system 77C293C7 5 Bytes JMP 00660FA8
.text C:\WINDOWS\System32\svchost.exe[376] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00660FD4
.text C:\WINDOWS\System32\svchost.exe[376] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0066000C
.text C:\WINDOWS\System32\svchost.exe[376] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00660FC3
.text C:\WINDOWS\System32\svchost.exe[376] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00660FEF
.text C:\WINDOWS\System32\svchost.exe[376] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 00640FEF
.text C:\WINDOWS\System32\svchost.exe[376] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 00640FDE
.text C:\WINDOWS\System32\svchost.exe[376] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 00640014
.text C:\WINDOWS\System32\svchost.exe[376] WININET.dll!InternetOpenUrlW 3D9A6D77 5 Bytes JMP 00640FC3
.text C:\WINDOWS\System32\svchost.exe[376] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00650FEF
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[672] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 62419A20 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[672] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 62419AE2 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\System32\svchost.exe[832] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00D50FEF
.text C:\WINDOWS\System32\svchost.exe[832] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00D50FCA
.text C:\WINDOWS\System32\svchost.exe[832] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00D50000
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00D80FEF
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00D80F9E
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00D80093
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00D80FAF
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00D8006C
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00D80FD4
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00D800C9
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00D80F8D
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D80F66
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D800F5
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00D80F55
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00D8005B
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00D80014
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00D800AE
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00D80040
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00D8002F
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00D800E4
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00D7002C
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00D70058
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00D70FE5
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00D7001B
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00D70F9B
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00D70000
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00D70047
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00D70FB6
.text C:\WINDOWS\System32\svchost.exe[832] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00D60042
.text C:\WINDOWS\System32\svchost.exe[832] msvcrt.dll!system 77C293C7 5 Bytes JMP 00D60FB7
.text C:\WINDOWS\System32\svchost.exe[832] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00D6001D
.text C:\WINDOWS\System32\svchost.exe[832] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00D60FE3
.text C:\WINDOWS\System32\svchost.exe[832] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00D60FC8
.text C:\WINDOWS\System32\svchost.exe[832] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00D60000
.text C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe[924] kernel32.dll!CreateThread + 1A 7C8106F1 4 Bytes CALL 0045024D C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe (Spy Sweeper Engine/Webroot Software, Inc.)
.text C:\WINDOWS\system32\services.exe[1080] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00970000
.text C:\WINDOWS\system32\services.exe[1080] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00970FEF
.text C:\WINDOWS\system32\services.exe[1080] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00970025
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00CD0FE5
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00CD0064
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00CD0F6F
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00CD0049
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00CD0F8A
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00CD0FC0
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00CD00AB
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00CD009A
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00CD0F1C
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00CD0F2D
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00CD00D0
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00CD0F9B
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00CD0000
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00CD007F
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00CD002C
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00CD001B
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00CD0F48
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 009A0FB9
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 009A0F8A
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 009A000A
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 009A0FD4
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 009A0047
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 009A0FEF
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 009A002C
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 009A001B
.text C:\WINDOWS\system32\services.exe[1080] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0099003F
.text C:\WINDOWS\system32\services.exe[1080] msvcrt.dll!system 77C293C7 5 Bytes JMP 0099002E
.text C:\WINDOWS\system32\services.exe[1080] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00990FD2
.text C:\WINDOWS\system32\services.exe[1080] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0099000C
.text C:\WINDOWS\system32\services.exe[1080] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0099001D
.text C:\WINDOWS\system32\services.exe[1080] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00990FE3
.text C:\WINDOWS\system32\services.exe[1080] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00980000
.text C:\WINDOWS\system32\lsass.exe[1092] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00BF0FEF
.text C:\WINDOWS\system32\lsass.exe[1092] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00BF0014
.text C:\WINDOWS\system32\lsass.exe[1092] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00BF0FD4
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00E60FE5
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00E60F50
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00E60F61
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00E60F72
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00E60F83
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00E60F94
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00E60F22
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00E6006A
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E6008C
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E6007B
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00E60ED8
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00E6001B
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00E60000
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00E60F3F
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00E60FAF
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00E60FCA
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00E60F07
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00E50FAF
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00E5006C
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00E50FD4
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00E5000A
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00E5005B
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00E50FEF
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00E50040
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00E5001B
.text C:\WINDOWS\system32\lsass.exe[1092] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00E40F92
.text C:\WINDOWS\system32\lsass.exe[1092] msvcrt.dll!system 77C293C7 5 Bytes JMP 00E4001D
.text C:\WINDOWS\system32\lsass.exe[1092] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00E4000C
.text C:\WINDOWS\system32\lsass.exe[1092] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00E40FE3
.text C:\WINDOWS\system32\lsass.exe[1092] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00E40FAD
.text C:\WINDOWS\system32\lsass.exe[1092] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00E40FD2
.text C:\WINDOWS\system32\lsass.exe[1092] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00E30FE5
.text C:\WINDOWS\system32\svchost.exe[1260] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00E30000
.text C:\WINDOWS\system32\svchost.exe[1260] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00E3002C
.text C:\WINDOWS\system32\svchost.exe[1260] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00E3001B
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00EB0000
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00EB0051
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00EB0036
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00EB0F68
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00EB0025
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00EB0F94
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00EB0F1A
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00EB0062
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00EB0EEE
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00EB0EFF
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00EB0EC9
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00EB0F83
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00EB0FDB
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00EB0F37
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00EB0FAF
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00EB0FC0
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00EB007D
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00E6000A
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00E60F5E
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00E60FC3
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00E60FD4
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00E60F83
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00E60FEF
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00E60F9E
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [06, 89]
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00E60025
.text C:\WINDOWS\system32\svchost.exe[1260] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00E5005A
.text C:\WINDOWS\system32\svchost.exe[1260] msvcrt.dll!system 77C293C7 5 Bytes JMP 00E50FCF
.text C:\WINDOWS\system32\svchost.exe[1260] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00E5002E
.text C:\WINDOWS\system32\svchost.exe[1260] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00E50000
.text C:\WINDOWS\system32\svchost.exe[1260] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00E5003F
.text C:\WINDOWS\system32\svchost.exe[1260] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00E5001D
.text C:\WINDOWS\system32\svchost.exe[1260] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00E40000
.text C:\WINDOWS\system32\svchost.exe[1348] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00B60FEF
.text C:\WINDOWS\system32\svchost.exe[1348] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00B60FC3
.text C:\WINDOWS\system32\svchost.exe[1348] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B60FD4
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BA0FE5
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BA0047
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BA0F52
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BA002C
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BA0F79
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BA0F9B
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BA0EFF
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BA0F26
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BA0EDA
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BA0073
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BA0EC9
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BA0F8A
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BA0000
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BA0F37
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BA0011
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BA0FCA
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BA0062
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00B90FCA
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00B90F9E
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00B9001B
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00B90FE5
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00B90FAF
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00B90000
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00B90051
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00B90036
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00B80F8D
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!system 77C293C7 5 Bytes JMP 00B80FA8
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00B80011
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00B80FE3
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00B80022
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00B80000
.text C:\WINDOWS\system32\svchost.exe[1348] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00B70FEF
.text C:\WINDOWS\System32\svchost.exe[1476] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 021B0FE5
.text C:\WINDOWS\System32\svchost.exe[1476] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 021B0000
.text C:\WINDOWS\System32\svchost.exe[1476] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 021B0FD4
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 0220000A
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02200F80
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02200075
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02200064
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02200047
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0220002C
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02200F48
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02200F65
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02200F12
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 022000AB
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 022000D0
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02200FA5
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02200FEF
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02200090
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02200FCA
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 0220001B
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 02200F37
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 021F0FB9
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 021F006C
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 021F0FD4
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 021F000A
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 021F0051
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 021F0FEF
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 021F0036
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 021F0025
.text C:\WINDOWS\System32\svchost.exe[1476] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 021E0051
.text C:\WINDOWS\System32\svchost.exe[1476] msvcrt.dll!system 77C293C7 5 Bytes JMP 021E0036
.text C:\WINDOWS\System32\svchost.exe[1476] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 021E0FD7
.text C:\WINDOWS\System32\svchost.exe[1476] msvcrt.dll!_open 77C2F566 5 Bytes JMP 021E0000
.text C:\WINDOWS\System32\svchost.exe[1476] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 021E0FC6
.text C:\WINDOWS\System32\svchost.exe[1476] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 021E0011
.text C:\WINDOWS\System32\svchost.exe[1476] WS2_32.dll!socket 71AB4211 5 Bytes JMP 021D0FEF
.text C:\WINDOWS\System32\svchost.exe[1476] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 021C0FEF
.text C:\WINDOWS\System32\svchost.exe[1476] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 021C0FCA
.text C:\WINDOWS\System32\svchost.exe[1476] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 021C0000
.text C:\WINDOWS\System32\svchost.exe[1476] WININET.dll!InternetOpenUrlW 3D9A6D77 5 Bytes JMP 021C001B
.text C:\WINDOWS\system32\svchost.exe[1524] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00630FEF
.text C:\WINDOWS\system32\svchost.exe[1524] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0063001B
.text C:\WINDOWS\system32\svchost.exe[1524] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0063000A
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00660000
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00660F4B
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00660F70
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00660F81
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00660F9E
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00660FB9
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00660F1D
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00660065
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00660EF1
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00660F02
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 006600AF
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00660040
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00660FE5
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00660F3A
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00660FD4
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00660025
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00660080
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00650FB9
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00650F97
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00650FCA
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00650FE5
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00650054
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00650000
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00650039
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00650FA8
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0064003F
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!system 77C293C7 5 Bytes JMP 0064002E
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0064001D
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00640000
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00640FC8
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00640FEF
.text C:\WINDOWS\System32\svchost.exe[1648] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 008A0FE5
.text C:\WINDOWS\System32\svchost.exe[1648] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 008A0011
.text C:\WINDOWS\System32\svchost.exe[1648] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 008A0000
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 008E0000
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 008E0FB6
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 008E00AB
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 008E0090
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 008E0073
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 008E0062
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 008E0F94
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 008E00DC
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 008E0F65
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 008E0108
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 008E0F54
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 008E0FD1
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 008E001B
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 008E0FA5
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 008E0047
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 008E0036
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 008E00F7
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 008D0FD4
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 008D0F9E
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 008D0FE5
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 008D001B
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 008D005B
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 008D0000
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 008D0FC3
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [AD, 88]
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 008D004A
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 008C0FB9
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!system 77C293C7 5 Bytes JMP 008C0044
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 008C0FD4
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!_open 77C2F566 5 Bytes JMP 008C0000
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 008C0033
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 008C0FEF
.text C:\WINDOWS\System32\svchost.exe[1648] WS2_32.dll!socket 71AB4211 5 Bytes JMP 008B0000
.text C:\WINDOWS\system32\svchost.exe[1776] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 006C0FEF
.text C:\WINDOWS\system32\svchost.exe[1776] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 006C0FC3
.text C:\WINDOWS\system32\svchost.exe[1776] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 006C0FD4
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 009E0FE5
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 009E0075
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 009E0F80
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 009E0064
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 009E0FA5
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 009E002C
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 009E0F39
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 009E0F54
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 009E0F0D
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 009E00A6
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 009E0EFC
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 009E003D
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 009E0000
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 009E0F65
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 009E0FC0
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 009E0011
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 009E0F28
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 009D0FCA
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 009D0F8D
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 009D001B
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 009D000A
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 009D0F9E
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 009D0FEF
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 009D0FAF
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [BD, 88]
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 009D0036
.text C:\WINDOWS\system32\svchost.exe[1776] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 009C0FA3
.text C:\WINDOWS\system32\svchost.exe[1776] msvcrt.dll!system 77C293C7 5 Bytes JMP 009C0FB4
.text C:\WINDOWS\system32\svchost.exe[1776] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 009C002E
.text C:\WINDOWS\system32\svchost.exe[1776] msvcrt.dll!_open 77C2F566 5 Bytes JMP 009C000C
.text C:\WINDOWS\system32\svchost.exe[1776] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 009C0FCF
.text C:\WINDOWS\system32\svchost.exe[1776] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 009C001D
.text C:\WINDOWS\system32\svchost.exe[1776] WS2_32.dll!socket 71AB4211 5 Bytes JMP 009B0000
.text C:\WINDOWS\System32\svchost.exe[3440] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00090000
.text C:\WINDOWS\System32\svchost.exe[3440] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0009001B
.text C:\WINDOWS\System32\svchost.exe[3440] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00090FEF
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001B0000
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001B0F79
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001B0064
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001B0F8A
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001B0FA5
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001B0FC0
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001B00B5
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001B009A
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001B00F5
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001B00D0
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 001B0F37
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 001B0047
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 001B0FEF
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 001B007F
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 001B0036
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 001B0025
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 001B0F52
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 002A003D
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 002A008B
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 002A002C
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 002A001B
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 002A007A
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 002A000A
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 002A0069
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 002A004E
.text C:\WINDOWS\System32\svchost.exe[3440] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 003F0040
.text C:\WINDOWS\System32\svchost.exe[3440] msvcrt.dll!system 77C293C7 5 Bytes JMP 003F0025
.text C:\WINDOWS\System32\svchost.exe[3440] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 003F0000
.text C:\WINDOWS\System32\svchost.exe[3440] msvcrt.dll!_open 77C2F566 5 Bytes JMP 003F0FEF
.text C:\WINDOWS\System32\svchost.exe[3440] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 003F0FB5
.text C:\WINDOWS\System32\svchost.exe[3440] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 003F0FD2
.text C:\WINDOWS\System32\svchost.exe[3440] WS2_32.dll!socket 71AB4211 5 Bytes JMP 006F0000
.text C:\WINDOWS\explorer.exe[11880] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00090FEF
.text C:\WINDOWS\explorer.exe[11880] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00090FB9
.text C:\WINDOWS\explorer.exe[11880] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00090FD4
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001B000A
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001B0082
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001B0F8D
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001B0F9E
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001B005B
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001B0FC3
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001B0F6B
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001B00B3
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001B0F35
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001B00D8
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 001B00E9
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 001B004A
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 001B0FEF
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 001B0F7C
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 001B0FD4
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 001B0025
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 001B0F5A
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 002A0FAF
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 002A0051
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 002A0FCA
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 002A0000
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 002A0040
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 002A0FEF
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 002A0025
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 002A0F9E
.text C:\WINDOWS\explorer.exe[11880] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 002B0F81
.text C:\WINDOWS\explorer.exe[11880] msvcrt.dll!system 77C293C7 5 Bytes JMP 002B0FA6
.text C:\WINDOWS\explorer.exe[11880] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 002B0FD2
.text C:\WINDOWS\explorer.exe[11880] msvcrt.dll!_open 77C2F566 5 Bytes JMP 002B0000
.text C:\WINDOWS\explorer.exe[11880] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 002B0FB7
.text C:\WINDOWS\explorer.exe[11880] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 002B0FEF
.text C:\WINDOWS\explorer.exe[11880] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 002D0FEF
.text C:\WINDOWS\explorer.exe[11880] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 002D0014
.text C:\WINDOWS\explorer.exe[11880] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 002D0025
.text C:\WINDOWS\explorer.exe[11880] WININET.dll!InternetOpenUrlW 3D9A6D77 5 Bytes JMP 002D0040
.text C:\WINDOWS\explorer.exe[11880] WS2_32.dll!socket 71AB4211 5 Bytes JMP 02820000
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs SSFS0BB9.SYS (Spy Sweeper FileSystem Filter Driver/Webroot Software Inc (www.webroot.com))
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
Device \Driver\Tcpip \Device\Ip 89DCC710
AttachedDevice \Driver\Tcpip \Device\Ip mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
Device \Driver\Tcpip \Device\Tcp 89DCC710
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
Device \Driver\Tcpip \Device\Udp 89DCC710
AttachedDevice \Driver\Tcpip \Device\Udp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
Device \Driver\Tcpip \Device\RawIp 89DCC710
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
Device \Driver\Tcpip \Device\IPMULTICAST 89DCC710
AttachedDevice \FileSystem\Fastfat \Fat SSFS0BB9.SYS (Spy Sweeper FileSystem Filter Driver/Webroot Software Inc (www.webroot.com))
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
—- Files - GMER 1.0.15 —-
File C:\Documents and Settings\User\Cookies\user@go[1].txt 0 bytes
—- EOF - GMER 1.0.15 —-
JonTom
Hello slvrthunder
Thank you for the logs.
Thank you for the logs.
- P2P Programs:
- P2P programs are a major source of Malware infections.
- From your log I see you have LimeWire 5.5.8. We do not pass judgment on file-sharing, however we must inform you that engaging in this activity and having this kind of software installed on your system will always make you more susceptible to Malware infections.
- The use of P2P programs may be contributing to your current situation, and you would certainly be doing yourself a favour by removing them.
- If you wish to keep the program(s), please do not use them until your computer is cleaned.
- Information regarding the risk of using these programs can be found from here and here.
- It is strongly recommend that you uninstall any P2P programs you have on your system.
- To do this, Click on "Start" then on "Control Panel" and then on "Add or remove programs".
- A list of currently installed programs will be displayed.
- Find the "LimeWire 5.5.8" program, click on it once and then click on the "Remove" button.
- If you are prompted to re-boot your computer to complete the uninstall please do so.
PLEASE NOTE: - Even if you are using a P2P program that is deemed safe, it is only the program that is safe. Any files that you receive using a "safe" P2P program may be infected with Malware. The malware writers use P2P file-sharing as a major conduit to spread infected files.
- Combofix
- Download ComboFix from one of the following locations:
Link 1
Link 2
- VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
- IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .
- Double click on ComboFix.exe & follow the prompts.
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
- Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
- Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
- Click on Yes, to continue scanning for malware.
- When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
- Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
- Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
- Should there be issues with internet afterward:
In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.
In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.
Please post the ComboFix log in your next reply. - Download ComboFix from one of the following locations:
slvrthunder
ComboFix 11-04-01.01 - User 04/02/2011 1:14.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1423 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: Spy Sweeper with AntiVirus *Disabled/Updated* {B3891867-7230-459B-9987-E7CCFA7A7D1D}
FW: McAfee Firewall *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\User\Local Settings\Application Data\isf.exe
c:\windows\Downloaded Program Files\ODCTOOLS
c:\windows\system32\_003618_.tmp.dll
c:\windows\system32\_003619_.tmp.dll
c:\windows\system32\_003620_.tmp.dll
c:\windows\system32\_003621_.tmp.dll
c:\windows\system32\_003626_.tmp.dll
c:\windows\system32\_003627_.tmp.dll
c:\windows\system32\_003628_.tmp.dll
c:\windows\system32\_003629_.tmp.dll
c:\windows\system32\_003630_.tmp.dll
c:\windows\system32\_003631_.tmp.dll
c:\windows\system32\_003632_.tmp.dll
c:\windows\system32\_003633_.tmp.dll
c:\windows\system32\_003634_.tmp.dll
c:\windows\system32\_003635_.tmp.dll
c:\windows\system32\_003636_.tmp.dll
c:\windows\system32\_003637_.tmp.dll
c:\windows\system32\_003638_.tmp.dll
c:\windows\system32\_003639_.tmp.dll
c:\windows\system32\_003640_.tmp.dll
c:\windows\system32\_003641_.tmp.dll
c:\windows\system32\_003642_.tmp.dll
c:\windows\system32\_003643_.tmp.dll
c:\windows\system32\_003644_.tmp.dll
c:\windows\system32\_003645_.tmp.dll
c:\windows\system32\_003646_.tmp.dll
c:\windows\system32\_003647_.tmp.dll
c:\windows\system32\_003648_.tmp.dll
c:\windows\system32\_003649_.tmp.dll
c:\windows\system32\_003650_.tmp.dll
c:\windows\system32\_003651_.tmp.dll
c:\windows\system32\_003652_.tmp.dll
c:\windows\system32\_003653_.tmp.dll
c:\windows\system32\_003654_.tmp.dll
c:\windows\system32\_003655_.tmp.dll
c:\windows\system32\_003656_.tmp.dll
c:\windows\system32\_003657_.tmp.dll
c:\windows\system32\_003658_.tmp.dll
c:\windows\system32\_003659_.tmp.dll
c:\windows\system32\_003660_.tmp.dll
c:\windows\system32\_003661_.tmp.dll
c:\windows\system32\_003662_.tmp.dll
c:\windows\system32\_003663_.tmp.dll
c:\windows\system32\_003665_.tmp.dll
c:\windows\system32\_003666_.tmp.dll
c:\windows\system32\_003667_.tmp.dll
c:\windows\system32\_003668_.tmp.dll
c:\windows\system32\_003669_.tmp.dll
c:\windows\system32\_003670_.tmp.dll
c:\windows\system32\_003671_.tmp.dll
c:\windows\system32\_003673_.tmp.dll
c:\windows\system32\_003674_.tmp.dll
c:\windows\system32\_003675_.tmp.dll
c:\windows\system32\_003676_.tmp.dll
c:\windows\system32\_003677_.tmp.dll
c:\windows\system32\_003678_.tmp.dll
c:\windows\system32\_003679_.tmp.dll
c:\windows\system32\_003680_.tmp.dll
c:\windows\system32\_003681_.tmp.dll
c:\windows\system32\_003682_.tmp.dll
c:\windows\system32\_003683_.tmp.dll
c:\windows\system32\_003684_.tmp.dll
c:\windows\system32\_003686_.tmp.dll
c:\windows\system32\_003687_.tmp.dll
c:\windows\system32\_003688_.tmp.dll
c:\windows\system32\_003689_.tmp.dll
c:\windows\system32\_003691_.tmp.dll
c:\windows\system32\_003693_.tmp.dll
c:\windows\system32\_003694_.tmp.dll
c:\windows\system32\_003695_.tmp.dll
c:\windows\system32\_003696_.tmp.dll
c:\windows\system32\_003697_.tmp.dll
c:\windows\system32\_003698_.tmp.dll
c:\windows\system32\_003699_.tmp.dll
c:\windows\system32\_003701_.tmp.dll
c:\windows\system32\_003702_.tmp.dll
c:\windows\system32\_003703_.tmp.dll
c:\windows\system32\_003704_.tmp.dll
c:\windows\system32\_003705_.tmp.dll
c:\windows\system32\_003706_.tmp.dll
c:\windows\system32\_003707_.tmp.dll
c:\windows\system32\_003708_.tmp.dll
c:\windows\system32\_003709_.tmp.dll
c:\windows\system32\_003710_.tmp.dll
c:\windows\system32\_003711_.tmp.dll
c:\windows\system32\_003712_.tmp.dll
c:\windows\system32\_003713_.tmp.dll
c:\windows\system32\_003714_.tmp.dll
c:\windows\system32\_003715_.tmp.dll
c:\windows\system32\_003716_.tmp.dll
c:\windows\system32\_003717_.tmp.dll
c:\windows\system32\_003718_.tmp.dll
c:\windows\system32\_003720_.tmp.dll
c:\windows\system32\_003721_.tmp.dll
c:\windows\system32\_003722_.tmp.dll
c:\windows\system32\_003723_.tmp.dll
c:\windows\system32\_003724_.tmp.dll
c:\windows\system32\_003727_.tmp.dll
c:\windows\system32\_003728_.tmp.dll
c:\windows\system32\_003729_.tmp.dll
c:\windows\system32\_003730_.tmp.dll
c:\windows\system32\_003731_.tmp.dll
c:\windows\system32\_003732_.tmp.dll
c:\windows\system32\_003733_.tmp.dll
c:\windows\system32\_003735_.tmp.dll
c:\windows\system32\_003736_.tmp.dll
c:\windows\system32\_003737_.tmp.dll
c:\windows\system32\_003738_.tmp.dll
c:\windows\system32\_003739_.tmp.dll
c:\windows\system32\_003740_.tmp.dll
c:\windows\system32\_003741_.tmp.dll
c:\windows\system32\_003742_.tmp.dll
c:\windows\system32\_003744_.tmp.dll
c:\windows\system32\_003745_.tmp.dll
c:\windows\system32\_003746_.tmp.dll
c:\windows\system32\_003747_.tmp.dll
c:\windows\system32\_003750_.tmp.dll
c:\windows\system32\_003751_.tmp.dll
c:\windows\system32\_003755_.tmp.dll
c:\windows\system32\_003756_.tmp.dll
c:\windows\system32\_003758_.tmp.dll
c:\windows\system32\_003761_.tmp.dll
c:\windows\system32\_003763_.tmp.dll
c:\windows\system32\_003764_.tmp.dll
c:\windows\system32\_003765_.tmp.dll
c:\windows\system32\_003766_.tmp.dll
c:\windows\system32\_003767_.tmp.dll
c:\windows\system32\_003770_.tmp.dll
c:\windows\system32\_003771_.tmp.dll
c:\windows\system32\_003772_.tmp.dll
c:\windows\system32\_003773_.tmp.dll
c:\windows\system32\_003774_.tmp.dll
c:\windows\system32\_003779_.tmp.dll
c:\windows\system32\_003781_.tmp.dll
c:\windows\system32\_003782_.tmp.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-03-02 to 2011-04-02 )))))))))))))))))))))))))))))))
.
.
2011-03-14 16:17 . 2011-03-14 16:17 ——– d—–w- c:\program files\Common Files\Software Update Utility
2011-03-08 22:29 . 2011-03-08 22:29 ——– d—–w- c:\documents and settings\LocalService\Application Data\Apple Computer
2011-03-08 21:38 . 2011-03-08 21:38 ——– d—–w- c:\program files\iPod
2011-03-08 21:38 . 2011-03-08 21:40 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2011-03-08 21:18 . 2011-03-08 21:20 ——– d—–w- c:\program files\QuickTime
2011-03-08 21:14 . 2011-03-08 21:14 ——– d—–w- c:\program files\Apple Software Update
2011-03-08 21:08 . 2011-03-08 21:08 ——– d—–w- c:\program files\Bonjour
2011-03-03 08:08 . 2011-03-03 08:08 ——– d—–w- c:\windows\system32\XPSViewer
2011-03-03 08:08 . 2011-03-03 08:08 ——– d—–w- c:\program files\MSBuild
2011-03-03 08:08 . 2011-03-03 08:08 ——– d—–w- c:\program files\Reference Assemblies
2011-03-03 08:07 . 2008-07-06 12:06 89088 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-03-03 08:06 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2011-03-03 08:06 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2011-03-03 08:06 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2011-03-03 08:06 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2011-03-03 08:06 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2011-03-03 08:06 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2011-03-03 08:06 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2011-03-03 08:06 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2011-03-03 08:06 . 2011-03-03 08:07 ——– d—–w- C:\dbb74f8f171e24df2830baee
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-18 21:36 . 2009-04-27 07:36 41984 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-18 21:36 . 2009-04-27 07:36 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll
2011-02-09 13:53 . 2002-11-26 19:15 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-09 13:53 . 2002-11-26 19:15 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-02 07:58 . 2004-07-14 22:40 2067456 —-a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2004-07-14 22:40 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2004-07-14 22:40 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2001-08-18 11:00 290048 —-a-w- c:\windows\system32\atmfd.dll
2005-06-26 15:17 . 2005-06-26 15:17 774144 —-a-w- c:\program files\RngInterstitial.dll
2004-03-25 00:10 . 2004-03-25 00:10 338800 —-a-w- c:\program files\efxsetup.exe
2004-03-13 14:00 . 2004-03-13 14:00 723870 —-a-w- c:\program files\yahtzee.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Location Finder"="c:\program files\Microsoft Location Finder\LocationFinder.exe" [2005-08-24 101080]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 1318912]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 454784]
"Google Update"="c:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-07-26 136176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-10 28672]
"UpdReg"="c:\windows\Updreg.exe" [2000-05-11 90112]
"AHQInit"="c:\program files\Creative\SBLive\Program\AHQInit.exe" [2001-03-28 102400]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-04-10 679936]
"Lexmark X5100 Series"="c:\program files\Lexmark X5100 Series\lxbabmgr.exe" [2002-12-16 86102]
"DIGStream"="c:\program files\DIGStream\digstream.exe" [2005-10-31 278528]
"DIGServices"="c:\program files\ESPNRunTime\DIGServices.exe" [2005-10-31 101888]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~1\mimboot.exe" [2006-01-19 11776]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-06-29 32768]
"SiteAdvisor"="c:\program files\SiteAdvisor\6172\SiteAdv.exe" [2007-08-24 36640]
"j2 4.2"="c:\program files\j2 Messenger 4.2\J2GDllCmd.exe" [2006-07-14 107008]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2010-03-11 648536]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-12-18 198160]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"snpstd"="c:\windows\vsnpstd.exe" [2003-12-31 40960]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-09-30 1193848]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-02 421160]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2003-6-23 113664]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2002-10-13 45056]
j2 4.2.lnk - c:\program files\j2 Messenger 4.2\J2GTray.exe [2008-3-19 612352]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
Microsoft Works Calendar Reminders.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2001-8-7 24633]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 18:41 294912 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM95\\aim.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:*:Disabled:ooVoo TCP port 443
"443:UDP"= 443:UDP:*:Disabled:ooVoo UDP port 443
"37674:TCP"= 37674:TCP:*:Disabled:ooVoo TCP port 37674
"37674:UDP"= 37674:UDP:*:Disabled:ooVoo UDP port 37674
"37675:UDP"= 37675:UDP:*:Disabled:ooVoo UDP port 37675
.
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\SYSTEM32\DRIVERS\mfetdi2k.sys [7/15/2010 11:21 AM 84072]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [10/10/2006 2:53 PM 5632]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/27/2007 1:39 PM 32256]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [7/15/2010 11:20 AM 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [7/15/2010 11:20 AM 271480]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [7/15/2010 11:21 AM 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [7/15/2010 11:21 AM 141792]
R3 cfwids;McAfee Inc. cfwids;c:\windows\SYSTEM32\DRIVERS\cfwids.sys [7/15/2010 11:21 AM 55840]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\SYSTEM32\DRIVERS\mfefirek.sys [7/15/2010 11:21 AM 313288]
R3 mfendiskmp;mfendiskmp;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [7/15/2010 11:21 AM 88544]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/16/2006 6:51 PM 4096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [7/15/2010 11:21 AM 88544]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\SYSTEM32\DRIVERS\mferkdet.sys [7/15/2010 11:21 AM 84264]
S3 PortlUSB;PortlUSB;c:\windows\SYSTEM32\DRIVERS\SiriusUSB.sys [7/29/2008 2:15 PM 7552]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/8/2009 12:26 PM 24652]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 08:32 128512 —-a-w- c:\windows\SYSTEM32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:50]
.
2011-04-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1445276385-3802400216-3657561249-1006Core.job
- c:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-26 16:01]
.
2011-04-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1445276385-3802400216-3657561249-1006UA.job
- c:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-26 16:01]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
IE: &Google; Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: &Yahoo;! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: Yahoo! &Dictionary; - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps; - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS; - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: musicmatch.com\online
DPF: {0F2AAAE3-7E9E-4B64-AB5D-1CA24C6ACB9C} - hxxp://notes.belf.wnyric.org/dwa85W.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-02 02:31
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
.
c:\documents and settings\User\Application Data\GTek\GTUpdate\AUpdate\EasyLinkAdvisor\DB\{A8DEDC72-3FAC-407B-BC7A-1997B3EC5684}.xml
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1032)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\WRLogonNTF.dll
.
- - - - - - - > 'explorer.exe'(1464)
c:\windows\system32\WININET.dll
c:\program files\SiteAdvisor\6172\saHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\System32\CTsvcCDA.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Webroot\Spy Sweeper\SpySweeper.exe
c:\windows\System32\MsPMSPSv.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
c:\windows\system32\devldr32.exe
c:\windows\system32\wscntfy.exe
c:\program files\Lexmark X5100 Series\lxbabmon.exe
c:\progra~1\MUSICM~1\MUSICM~1\MMDiag.exe
c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\LINKSY~1\LinksysAdvisor.exe
.
**************************************************************************
.
Completion time: 2011-04-02 02:42:37 - machine was rebooted
ComboFix-quarantined-files.txt 2011-04-02 06:42
.
Pre-Run: 41,941,659,648 bytes free
Post-Run: 42,764,054,528 bytes free
.
- - End Of File - - 68844E8C1BFDEF7863805FA5AA4F903B
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1423 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: Spy Sweeper with AntiVirus *Disabled/Updated* {B3891867-7230-459B-9987-E7CCFA7A7D1D}
FW: McAfee Firewall *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\User\Local Settings\Application Data\isf.exe
c:\windows\Downloaded Program Files\ODCTOOLS
c:\windows\system32\_003618_.tmp.dll
c:\windows\system32\_003619_.tmp.dll
c:\windows\system32\_003620_.tmp.dll
c:\windows\system32\_003621_.tmp.dll
c:\windows\system32\_003626_.tmp.dll
c:\windows\system32\_003627_.tmp.dll
c:\windows\system32\_003628_.tmp.dll
c:\windows\system32\_003629_.tmp.dll
c:\windows\system32\_003630_.tmp.dll
c:\windows\system32\_003631_.tmp.dll
c:\windows\system32\_003632_.tmp.dll
c:\windows\system32\_003633_.tmp.dll
c:\windows\system32\_003634_.tmp.dll
c:\windows\system32\_003635_.tmp.dll
c:\windows\system32\_003636_.tmp.dll
c:\windows\system32\_003637_.tmp.dll
c:\windows\system32\_003638_.tmp.dll
c:\windows\system32\_003639_.tmp.dll
c:\windows\system32\_003640_.tmp.dll
c:\windows\system32\_003641_.tmp.dll
c:\windows\system32\_003642_.tmp.dll
c:\windows\system32\_003643_.tmp.dll
c:\windows\system32\_003644_.tmp.dll
c:\windows\system32\_003645_.tmp.dll
c:\windows\system32\_003646_.tmp.dll
c:\windows\system32\_003647_.tmp.dll
c:\windows\system32\_003648_.tmp.dll
c:\windows\system32\_003649_.tmp.dll
c:\windows\system32\_003650_.tmp.dll
c:\windows\system32\_003651_.tmp.dll
c:\windows\system32\_003652_.tmp.dll
c:\windows\system32\_003653_.tmp.dll
c:\windows\system32\_003654_.tmp.dll
c:\windows\system32\_003655_.tmp.dll
c:\windows\system32\_003656_.tmp.dll
c:\windows\system32\_003657_.tmp.dll
c:\windows\system32\_003658_.tmp.dll
c:\windows\system32\_003659_.tmp.dll
c:\windows\system32\_003660_.tmp.dll
c:\windows\system32\_003661_.tmp.dll
c:\windows\system32\_003662_.tmp.dll
c:\windows\system32\_003663_.tmp.dll
c:\windows\system32\_003665_.tmp.dll
c:\windows\system32\_003666_.tmp.dll
c:\windows\system32\_003667_.tmp.dll
c:\windows\system32\_003668_.tmp.dll
c:\windows\system32\_003669_.tmp.dll
c:\windows\system32\_003670_.tmp.dll
c:\windows\system32\_003671_.tmp.dll
c:\windows\system32\_003673_.tmp.dll
c:\windows\system32\_003674_.tmp.dll
c:\windows\system32\_003675_.tmp.dll
c:\windows\system32\_003676_.tmp.dll
c:\windows\system32\_003677_.tmp.dll
c:\windows\system32\_003678_.tmp.dll
c:\windows\system32\_003679_.tmp.dll
c:\windows\system32\_003680_.tmp.dll
c:\windows\system32\_003681_.tmp.dll
c:\windows\system32\_003682_.tmp.dll
c:\windows\system32\_003683_.tmp.dll
c:\windows\system32\_003684_.tmp.dll
c:\windows\system32\_003686_.tmp.dll
c:\windows\system32\_003687_.tmp.dll
c:\windows\system32\_003688_.tmp.dll
c:\windows\system32\_003689_.tmp.dll
c:\windows\system32\_003691_.tmp.dll
c:\windows\system32\_003693_.tmp.dll
c:\windows\system32\_003694_.tmp.dll
c:\windows\system32\_003695_.tmp.dll
c:\windows\system32\_003696_.tmp.dll
c:\windows\system32\_003697_.tmp.dll
c:\windows\system32\_003698_.tmp.dll
c:\windows\system32\_003699_.tmp.dll
c:\windows\system32\_003701_.tmp.dll
c:\windows\system32\_003702_.tmp.dll
c:\windows\system32\_003703_.tmp.dll
c:\windows\system32\_003704_.tmp.dll
c:\windows\system32\_003705_.tmp.dll
c:\windows\system32\_003706_.tmp.dll
c:\windows\system32\_003707_.tmp.dll
c:\windows\system32\_003708_.tmp.dll
c:\windows\system32\_003709_.tmp.dll
c:\windows\system32\_003710_.tmp.dll
c:\windows\system32\_003711_.tmp.dll
c:\windows\system32\_003712_.tmp.dll
c:\windows\system32\_003713_.tmp.dll
c:\windows\system32\_003714_.tmp.dll
c:\windows\system32\_003715_.tmp.dll
c:\windows\system32\_003716_.tmp.dll
c:\windows\system32\_003717_.tmp.dll
c:\windows\system32\_003718_.tmp.dll
c:\windows\system32\_003720_.tmp.dll
c:\windows\system32\_003721_.tmp.dll
c:\windows\system32\_003722_.tmp.dll
c:\windows\system32\_003723_.tmp.dll
c:\windows\system32\_003724_.tmp.dll
c:\windows\system32\_003727_.tmp.dll
c:\windows\system32\_003728_.tmp.dll
c:\windows\system32\_003729_.tmp.dll
c:\windows\system32\_003730_.tmp.dll
c:\windows\system32\_003731_.tmp.dll
c:\windows\system32\_003732_.tmp.dll
c:\windows\system32\_003733_.tmp.dll
c:\windows\system32\_003735_.tmp.dll
c:\windows\system32\_003736_.tmp.dll
c:\windows\system32\_003737_.tmp.dll
c:\windows\system32\_003738_.tmp.dll
c:\windows\system32\_003739_.tmp.dll
c:\windows\system32\_003740_.tmp.dll
c:\windows\system32\_003741_.tmp.dll
c:\windows\system32\_003742_.tmp.dll
c:\windows\system32\_003744_.tmp.dll
c:\windows\system32\_003745_.tmp.dll
c:\windows\system32\_003746_.tmp.dll
c:\windows\system32\_003747_.tmp.dll
c:\windows\system32\_003750_.tmp.dll
c:\windows\system32\_003751_.tmp.dll
c:\windows\system32\_003755_.tmp.dll
c:\windows\system32\_003756_.tmp.dll
c:\windows\system32\_003758_.tmp.dll
c:\windows\system32\_003761_.tmp.dll
c:\windows\system32\_003763_.tmp.dll
c:\windows\system32\_003764_.tmp.dll
c:\windows\system32\_003765_.tmp.dll
c:\windows\system32\_003766_.tmp.dll
c:\windows\system32\_003767_.tmp.dll
c:\windows\system32\_003770_.tmp.dll
c:\windows\system32\_003771_.tmp.dll
c:\windows\system32\_003772_.tmp.dll
c:\windows\system32\_003773_.tmp.dll
c:\windows\system32\_003774_.tmp.dll
c:\windows\system32\_003779_.tmp.dll
c:\windows\system32\_003781_.tmp.dll
c:\windows\system32\_003782_.tmp.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-03-02 to 2011-04-02 )))))))))))))))))))))))))))))))
.
.
2011-03-14 16:17 . 2011-03-14 16:17 ——– d—–w- c:\program files\Common Files\Software Update Utility
2011-03-08 22:29 . 2011-03-08 22:29 ——– d—–w- c:\documents and settings\LocalService\Application Data\Apple Computer
2011-03-08 21:38 . 2011-03-08 21:38 ——– d—–w- c:\program files\iPod
2011-03-08 21:38 . 2011-03-08 21:40 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2011-03-08 21:18 . 2011-03-08 21:20 ——– d—–w- c:\program files\QuickTime
2011-03-08 21:14 . 2011-03-08 21:14 ——– d—–w- c:\program files\Apple Software Update
2011-03-08 21:08 . 2011-03-08 21:08 ——– d—–w- c:\program files\Bonjour
2011-03-03 08:08 . 2011-03-03 08:08 ——– d—–w- c:\windows\system32\XPSViewer
2011-03-03 08:08 . 2011-03-03 08:08 ——– d—–w- c:\program files\MSBuild
2011-03-03 08:08 . 2011-03-03 08:08 ——– d—–w- c:\program files\Reference Assemblies
2011-03-03 08:07 . 2008-07-06 12:06 89088 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-03-03 08:06 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2011-03-03 08:06 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2011-03-03 08:06 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2011-03-03 08:06 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2011-03-03 08:06 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2011-03-03 08:06 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2011-03-03 08:06 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2011-03-03 08:06 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2011-03-03 08:06 . 2011-03-03 08:07 ——– d—–w- C:\dbb74f8f171e24df2830baee
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-18 21:36 . 2009-04-27 07:36 41984 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-18 21:36 . 2009-04-27 07:36 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll
2011-02-09 13:53 . 2002-11-26 19:15 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-09 13:53 . 2002-11-26 19:15 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-02 07:58 . 2004-07-14 22:40 2067456 —-a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2004-07-14 22:40 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2004-07-14 22:40 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2001-08-18 11:00 290048 —-a-w- c:\windows\system32\atmfd.dll
2005-06-26 15:17 . 2005-06-26 15:17 774144 —-a-w- c:\program files\RngInterstitial.dll
2004-03-25 00:10 . 2004-03-25 00:10 338800 —-a-w- c:\program files\efxsetup.exe
2004-03-13 14:00 . 2004-03-13 14:00 723870 —-a-w- c:\program files\yahtzee.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Location Finder"="c:\program files\Microsoft Location Finder\LocationFinder.exe" [2005-08-24 101080]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 1318912]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 454784]
"Google Update"="c:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-07-26 136176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-10 28672]
"UpdReg"="c:\windows\Updreg.exe" [2000-05-11 90112]
"AHQInit"="c:\program files\Creative\SBLive\Program\AHQInit.exe" [2001-03-28 102400]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-04-10 679936]
"Lexmark X5100 Series"="c:\program files\Lexmark X5100 Series\lxbabmgr.exe" [2002-12-16 86102]
"DIGStream"="c:\program files\DIGStream\digstream.exe" [2005-10-31 278528]
"DIGServices"="c:\program files\ESPNRunTime\DIGServices.exe" [2005-10-31 101888]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~1\mimboot.exe" [2006-01-19 11776]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-06-29 32768]
"SiteAdvisor"="c:\program files\SiteAdvisor\6172\SiteAdv.exe" [2007-08-24 36640]
"j2 4.2"="c:\program files\j2 Messenger 4.2\J2GDllCmd.exe" [2006-07-14 107008]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2010-03-11 648536]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-12-18 198160]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"snpstd"="c:\windows\vsnpstd.exe" [2003-12-31 40960]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-09-30 1193848]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-02 421160]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2003-6-23 113664]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2002-10-13 45056]
j2 4.2.lnk - c:\program files\j2 Messenger 4.2\J2GTray.exe [2008-3-19 612352]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
Microsoft Works Calendar Reminders.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2001-8-7 24633]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 18:41 294912 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM95\\aim.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:*:Disabled:ooVoo TCP port 443
"443:UDP"= 443:UDP:*:Disabled:ooVoo UDP port 443
"37674:TCP"= 37674:TCP:*:Disabled:ooVoo TCP port 37674
"37674:UDP"= 37674:UDP:*:Disabled:ooVoo UDP port 37674
"37675:UDP"= 37675:UDP:*:Disabled:ooVoo UDP port 37675
.
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\SYSTEM32\DRIVERS\mfetdi2k.sys [7/15/2010 11:21 AM 84072]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [10/10/2006 2:53 PM 5632]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/27/2007 1:39 PM 32256]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [7/15/2010 11:20 AM 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [7/15/2010 11:20 AM 271480]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [7/15/2010 11:21 AM 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [7/15/2010 11:21 AM 141792]
R3 cfwids;McAfee Inc. cfwids;c:\windows\SYSTEM32\DRIVERS\cfwids.sys [7/15/2010 11:21 AM 55840]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\SYSTEM32\DRIVERS\mfefirek.sys [7/15/2010 11:21 AM 313288]
R3 mfendiskmp;mfendiskmp;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [7/15/2010 11:21 AM 88544]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/16/2006 6:51 PM 4096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [7/15/2010 11:21 AM 88544]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\SYSTEM32\DRIVERS\mferkdet.sys [7/15/2010 11:21 AM 84264]
S3 PortlUSB;PortlUSB;c:\windows\SYSTEM32\DRIVERS\SiriusUSB.sys [7/29/2008 2:15 PM 7552]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/8/2009 12:26 PM 24652]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 08:32 128512 —-a-w- c:\windows\SYSTEM32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:50]
.
2011-04-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1445276385-3802400216-3657561249-1006Core.job
- c:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-26 16:01]
.
2011-04-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1445276385-3802400216-3657561249-1006UA.job
- c:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-26 16:01]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
IE: &Google; Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: &Yahoo;! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: Yahoo! &Dictionary; - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps; - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS; - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: musicmatch.com\online
DPF: {0F2AAAE3-7E9E-4B64-AB5D-1CA24C6ACB9C} - hxxp://notes.belf.wnyric.org/dwa85W.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-02 02:31
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
.
c:\documents and settings\User\Application Data\GTek\GTUpdate\AUpdate\EasyLinkAdvisor\DB\{A8DEDC72-3FAC-407B-BC7A-1997B3EC5684}.xml
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1032)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\WRLogonNTF.dll
.
- - - - - - - > 'explorer.exe'(1464)
c:\windows\system32\WININET.dll
c:\program files\SiteAdvisor\6172\saHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\System32\CTsvcCDA.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Webroot\Spy Sweeper\SpySweeper.exe
c:\windows\System32\MsPMSPSv.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
c:\windows\system32\devldr32.exe
c:\windows\system32\wscntfy.exe
c:\program files\Lexmark X5100 Series\lxbabmon.exe
c:\progra~1\MUSICM~1\MUSICM~1\MMDiag.exe
c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\LINKSY~1\LinksysAdvisor.exe
.
**************************************************************************
.
Completion time: 2011-04-02 02:42:37 - machine was rebooted
ComboFix-quarantined-files.txt 2011-04-02 06:42
.
Pre-Run: 41,941,659,648 bytes free
Post-Run: 42,764,054,528 bytes free
.
- - End Of File - - 68844E8C1BFDEF7863805FA5AA4F903B
JonTom
Hello slvrthunder
Thank you for the log.
You appear to have two antivirus programs running at the same time (McAfee Anti-Virus and Spy Sweeper with AntiVirus). Please make sure that you only have ONE antivirus running on your machine as multiple applications will conflict with each other.
Thank you for the log.
You appear to have two antivirus programs running at the same time (McAfee Anti-Virus and Spy Sweeper with AntiVirus). Please make sure that you only have ONE antivirus running on your machine as multiple applications will conflict with each other.
- Please work through the following steps
- Open Notepad (Click on "Start", then on "Run" and type "notepad" (without quotations) in the Open field, then click on "OK").
- NOTE: Do not Use Wordpad or any other text editor except Notepad or the script will fail.
- Copy and Paste the text in the quotebox below into the open Notepad window:
DirLook::
C:\dbb74f8f171e24df2830baee
DDS::
Trusted Zone: musicmatch.com\online
RegLock::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] - Save this as "CFScript.txt" (including the quotation marks), change the "Save as type" to "All Files" and save it to your desktop.
- Close any open browsers.
- Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
- Refering to the picture below, drag CFScript.txt into ComboFix.exe
[external image: Posted Image]
- When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
- Once the log is produced, re-engage your resident anti virus.
slvrthunder
ComboFix 11-04-01.01 - User 04/02/2011 16:26:00.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1571 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\User\Desktop\CFScript.txt
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: Spy Sweeper with AntiVirus *Disabled/Updated* {B3891867-7230-459B-9987-E7CCFA7A7D1D}
FW: McAfee Firewall *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
((((((((((((((((((((((((( Files Created from 2011-03-02 to 2011-04-02 )))))))))))))))))))))))))))))))
.
.
2011-03-14 16:17 . 2011-03-14 16:17 ——– d—–w- c:\program files\Common Files\Software Update Utility
2011-03-08 22:29 . 2011-03-08 22:29 ——– d—–w- c:\documents and settings\LocalService\Application Data\Apple Computer
2011-03-08 21:38 . 2011-03-08 21:38 ——– d—–w- c:\program files\iPod
2011-03-08 21:38 . 2011-03-08 21:40 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2011-03-08 21:18 . 2011-03-08 21:20 ——– d—–w- c:\program files\QuickTime
2011-03-08 21:14 . 2011-03-08 21:14 ——– d—–w- c:\program files\Apple Software Update
2011-03-08 21:08 . 2011-03-08 21:08 ——– d—–w- c:\program files\Bonjour
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-18 21:36 . 2009-04-27 07:36 41984 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-18 21:36 . 2009-04-27 07:36 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll
2011-02-09 13:53 . 2002-11-26 19:15 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-09 13:53 . 2002-11-26 19:15 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-02 07:58 . 2004-07-14 22:40 2067456 —-a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2004-07-14 22:40 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2004-07-14 22:40 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2001-08-18 11:00 290048 —-a-w- c:\windows\system32\atmfd.dll
2005-06-26 15:17 . 2005-06-26 15:17 774144 —-a-w- c:\program files\RngInterstitial.dll
2004-03-25 00:10 . 2004-03-25 00:10 338800 —-a-w- c:\program files\efxsetup.exe
2004-03-13 14:00 . 2004-03-13 14:00 723870 —-a-w- c:\program files\yahtzee.exe
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of C:\dbb74f8f171e24df2830baee —-
.
2011-03-03 08:06 . 2008-06-19 16:03 73 ——w- c:\dbb74f8f171e24df2830baee\i386\msxpsinc.gpd
2011-03-03 08:06 . 2008-06-19 05:33 72 ——w- c:\dbb74f8f171e24df2830baee\i386\msxpsinc.ppd
2011-03-03 08:06 . 2008-06-19 05:33 72 ——w- c:\dbb74f8f171e24df2830baee\amd64\msxpsinc.ppd
2011-03-03 08:06 . 2008-06-19 05:33 2204 ——w- c:\dbb74f8f171e24df2830baee\i386\msxpsdrv.inf
2011-03-03 08:06 . 2008-06-19 05:33 2204 ——w- c:\dbb74f8f171e24df2830baee\amd64\msxpsdrv.inf
2011-03-03 08:06 . 2008-07-06 12:06 10929 ——w- c:\dbb74f8f171e24df2830baee\amd64\msxpsdrv.cat
2011-03-03 08:06 . 2008-07-06 12:06 10929 ——w- c:\dbb74f8f171e24df2830baee\i386\msxpsdrv.cat
2011-03-03 08:06 . 2008-07-06 12:06 147456 ——w- c:\dbb74f8f171e24df2830baee\amd64\filterpipelineprintproc.dll
2011-03-03 08:06 . 2008-07-06 12:06 89088 ——w- c:\dbb74f8f171e24df2830baee\i386\filterpipelineprintproc.dll
2011-03-03 08:06 . 2008-07-06 12:06 765440 ——w- c:\dbb74f8f171e24df2830baee\i386\mxdwdrv.dll
2011-03-03 08:06 . 2008-07-06 12:06 1676288 ——w- c:\dbb74f8f171e24df2830baee\i386\xpssvcs.dll
2011-03-03 08:06 . 2008-07-06 12:06 748032 ——w- c:\dbb74f8f171e24df2830baee\amd64\mxdwdrv.dll
2008-07-06 22:36 . 2008-07-06 22:36 2936832 ——w- c:\dbb74f8f171e24df2830baee\amd64\xpssvcs.dll
2008-06-19 16:03 . 2008-06-19 16:03 73 ——w- c:\dbb74f8f171e24df2830baee\amd64\msxpsinc.gpd
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Location Finder"="c:\program files\Microsoft Location Finder\LocationFinder.exe" [2005-08-24 101080]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 1318912]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 454784]
"Google Update"="c:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-07-26 136176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-10 28672]
"UpdReg"="c:\windows\Updreg.exe" [2000-05-11 90112]
"AHQInit"="c:\program files\Creative\SBLive\Program\AHQInit.exe" [2001-03-28 102400]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-04-10 679936]
"Lexmark X5100 Series"="c:\program files\Lexmark X5100 Series\lxbabmgr.exe" [2002-12-16 86102]
"DIGStream"="c:\program files\DIGStream\digstream.exe" [2005-10-31 278528]
"DIGServices"="c:\program files\ESPNRunTime\DIGServices.exe" [2005-10-31 101888]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~1\mimboot.exe" [2006-01-19 11776]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-06-29 32768]
"SiteAdvisor"="c:\program files\SiteAdvisor\6172\SiteAdv.exe" [2007-08-24 36640]
"j2 4.2"="c:\program files\j2 Messenger 4.2\J2GDllCmd.exe" [2006-07-14 107008]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2010-03-11 648536]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-12-18 198160]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"snpstd"="c:\windows\vsnpstd.exe" [2003-12-31 40960]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-09-30 1193848]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-02 421160]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2003-6-23 113664]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2002-10-13 45056]
j2 4.2.lnk - c:\program files\j2 Messenger 4.2\J2GTray.exe [2008-3-19 612352]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
Microsoft Works Calendar Reminders.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2001-8-7 24633]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 18:41 294912 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM95\\aim.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:*:Disabled:ooVoo TCP port 443
"443:UDP"= 443:UDP:*:Disabled:ooVoo UDP port 443
"37674:TCP"= 37674:TCP:*:Disabled:ooVoo TCP port 37674
"37674:UDP"= 37674:UDP:*:Disabled:ooVoo UDP port 37674
"37675:UDP"= 37675:UDP:*:Disabled:ooVoo UDP port 37675
.
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\SYSTEM32\DRIVERS\mfetdi2k.sys [7/15/2010 11:21 AM 84072]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [10/10/2006 2:53 PM 5632]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/27/2007 1:39 PM 32256]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [7/15/2010 11:20 AM 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [7/15/2010 11:20 AM 271480]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [7/15/2010 11:21 AM 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [7/15/2010 11:21 AM 141792]
R3 cfwids;McAfee Inc. cfwids;c:\windows\SYSTEM32\DRIVERS\cfwids.sys [7/15/2010 11:21 AM 55840]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\SYSTEM32\DRIVERS\mfefirek.sys [7/15/2010 11:21 AM 313288]
R3 mfendiskmp;mfendiskmp;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [7/15/2010 11:21 AM 88544]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/16/2006 6:51 PM 4096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [7/15/2010 11:21 AM 88544]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\SYSTEM32\DRIVERS\mferkdet.sys [7/15/2010 11:21 AM 84264]
S3 PortlUSB;PortlUSB;c:\windows\SYSTEM32\DRIVERS\SiriusUSB.sys [7/29/2008 2:15 PM 7552]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/8/2009 12:26 PM 24652]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 08:32 128512 —-a-w- c:\windows\SYSTEM32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:50]
.
2011-04-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1445276385-3802400216-3657561249-1006Core.job
- c:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-26 16:01]
.
2011-04-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1445276385-3802400216-3657561249-1006UA.job
- c:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-26 16:01]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
IE: &Google; Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: &Yahoo;! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: Yahoo! &Dictionary; - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps; - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS; - file:///c:\program files\Yahoo!\Common/ycsms.htm
DPF: {0F2AAAE3-7E9E-4B64-AB5D-1CA24C6ACB9C} - hxxp://notes.belf.wnyric.org/dwa85W.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-02 16:40
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1032)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\WRLogonNTF.dll
.
- - - - - - - > 'explorer.exe'(3536)
c:\windows\system32\WININET.dll
c:\program files\SiteAdvisor\6172\saHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-04-02 16:45:07
ComboFix-quarantined-files.txt 2011-04-02 20:45
ComboFix2.txt 2011-04-02 06:42
.
Pre-Run: 42,992,214,016 bytes free
Post-Run: 42,970,263,552 bytes free
.
- - End Of File - - 7D4BC44C2838EE5E25ABB26FC3C166D5
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1571 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\User\Desktop\CFScript.txt
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: Spy Sweeper with AntiVirus *Disabled/Updated* {B3891867-7230-459B-9987-E7CCFA7A7D1D}
FW: McAfee Firewall *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
((((((((((((((((((((((((( Files Created from 2011-03-02 to 2011-04-02 )))))))))))))))))))))))))))))))
.
.
2011-03-14 16:17 . 2011-03-14 16:17 ——– d—–w- c:\program files\Common Files\Software Update Utility
2011-03-08 22:29 . 2011-03-08 22:29 ——– d—–w- c:\documents and settings\LocalService\Application Data\Apple Computer
2011-03-08 21:38 . 2011-03-08 21:38 ——– d—–w- c:\program files\iPod
2011-03-08 21:38 . 2011-03-08 21:40 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2011-03-08 21:18 . 2011-03-08 21:20 ——– d—–w- c:\program files\QuickTime
2011-03-08 21:14 . 2011-03-08 21:14 ——– d—–w- c:\program files\Apple Software Update
2011-03-08 21:08 . 2011-03-08 21:08 ——– d—–w- c:\program files\Bonjour
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-18 21:36 . 2009-04-27 07:36 41984 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-18 21:36 . 2009-04-27 07:36 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll
2011-02-09 13:53 . 2002-11-26 19:15 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-09 13:53 . 2002-11-26 19:15 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-02 07:58 . 2004-07-14 22:40 2067456 —-a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2004-07-14 22:40 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2004-07-14 22:40 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2001-08-18 11:00 290048 —-a-w- c:\windows\system32\atmfd.dll
2005-06-26 15:17 . 2005-06-26 15:17 774144 —-a-w- c:\program files\RngInterstitial.dll
2004-03-25 00:10 . 2004-03-25 00:10 338800 —-a-w- c:\program files\efxsetup.exe
2004-03-13 14:00 . 2004-03-13 14:00 723870 —-a-w- c:\program files\yahtzee.exe
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of C:\dbb74f8f171e24df2830baee —-
.
2011-03-03 08:06 . 2008-06-19 16:03 73 ——w- c:\dbb74f8f171e24df2830baee\i386\msxpsinc.gpd
2011-03-03 08:06 . 2008-06-19 05:33 72 ——w- c:\dbb74f8f171e24df2830baee\i386\msxpsinc.ppd
2011-03-03 08:06 . 2008-06-19 05:33 72 ——w- c:\dbb74f8f171e24df2830baee\amd64\msxpsinc.ppd
2011-03-03 08:06 . 2008-06-19 05:33 2204 ——w- c:\dbb74f8f171e24df2830baee\i386\msxpsdrv.inf
2011-03-03 08:06 . 2008-06-19 05:33 2204 ——w- c:\dbb74f8f171e24df2830baee\amd64\msxpsdrv.inf
2011-03-03 08:06 . 2008-07-06 12:06 10929 ——w- c:\dbb74f8f171e24df2830baee\amd64\msxpsdrv.cat
2011-03-03 08:06 . 2008-07-06 12:06 10929 ——w- c:\dbb74f8f171e24df2830baee\i386\msxpsdrv.cat
2011-03-03 08:06 . 2008-07-06 12:06 147456 ——w- c:\dbb74f8f171e24df2830baee\amd64\filterpipelineprintproc.dll
2011-03-03 08:06 . 2008-07-06 12:06 89088 ——w- c:\dbb74f8f171e24df2830baee\i386\filterpipelineprintproc.dll
2011-03-03 08:06 . 2008-07-06 12:06 765440 ——w- c:\dbb74f8f171e24df2830baee\i386\mxdwdrv.dll
2011-03-03 08:06 . 2008-07-06 12:06 1676288 ——w- c:\dbb74f8f171e24df2830baee\i386\xpssvcs.dll
2011-03-03 08:06 . 2008-07-06 12:06 748032 ——w- c:\dbb74f8f171e24df2830baee\amd64\mxdwdrv.dll
2008-07-06 22:36 . 2008-07-06 22:36 2936832 ——w- c:\dbb74f8f171e24df2830baee\amd64\xpssvcs.dll
2008-06-19 16:03 . 2008-06-19 16:03 73 ——w- c:\dbb74f8f171e24df2830baee\amd64\msxpsinc.gpd
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Location Finder"="c:\program files\Microsoft Location Finder\LocationFinder.exe" [2005-08-24 101080]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 1318912]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 454784]
"Google Update"="c:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-07-26 136176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-10 28672]
"UpdReg"="c:\windows\Updreg.exe" [2000-05-11 90112]
"AHQInit"="c:\program files\Creative\SBLive\Program\AHQInit.exe" [2001-03-28 102400]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-04-10 679936]
"Lexmark X5100 Series"="c:\program files\Lexmark X5100 Series\lxbabmgr.exe" [2002-12-16 86102]
"DIGStream"="c:\program files\DIGStream\digstream.exe" [2005-10-31 278528]
"DIGServices"="c:\program files\ESPNRunTime\DIGServices.exe" [2005-10-31 101888]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~1\mimboot.exe" [2006-01-19 11776]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-06-29 32768]
"SiteAdvisor"="c:\program files\SiteAdvisor\6172\SiteAdv.exe" [2007-08-24 36640]
"j2 4.2"="c:\program files\j2 Messenger 4.2\J2GDllCmd.exe" [2006-07-14 107008]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2010-03-11 648536]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-12-18 198160]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"snpstd"="c:\windows\vsnpstd.exe" [2003-12-31 40960]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-09-30 1193848]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-02 421160]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2003-6-23 113664]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2002-10-13 45056]
j2 4.2.lnk - c:\program files\j2 Messenger 4.2\J2GTray.exe [2008-3-19 612352]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
Microsoft Works Calendar Reminders.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2001-8-7 24633]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 18:41 294912 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM95\\aim.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:*:Disabled:ooVoo TCP port 443
"443:UDP"= 443:UDP:*:Disabled:ooVoo UDP port 443
"37674:TCP"= 37674:TCP:*:Disabled:ooVoo TCP port 37674
"37674:UDP"= 37674:UDP:*:Disabled:ooVoo UDP port 37674
"37675:UDP"= 37675:UDP:*:Disabled:ooVoo UDP port 37675
.
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\SYSTEM32\DRIVERS\mfetdi2k.sys [7/15/2010 11:21 AM 84072]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [10/10/2006 2:53 PM 5632]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/27/2007 1:39 PM 32256]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [7/15/2010 11:20 AM 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [7/15/2010 11:20 AM 271480]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [7/15/2010 11:21 AM 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [7/15/2010 11:21 AM 141792]
R3 cfwids;McAfee Inc. cfwids;c:\windows\SYSTEM32\DRIVERS\cfwids.sys [7/15/2010 11:21 AM 55840]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\SYSTEM32\DRIVERS\mfefirek.sys [7/15/2010 11:21 AM 313288]
R3 mfendiskmp;mfendiskmp;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [7/15/2010 11:21 AM 88544]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/16/2006 6:51 PM 4096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [7/15/2010 11:21 AM 88544]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\SYSTEM32\DRIVERS\mferkdet.sys [7/15/2010 11:21 AM 84264]
S3 PortlUSB;PortlUSB;c:\windows\SYSTEM32\DRIVERS\SiriusUSB.sys [7/29/2008 2:15 PM 7552]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/8/2009 12:26 PM 24652]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 08:32 128512 —-a-w- c:\windows\SYSTEM32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:50]
.
2011-04-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1445276385-3802400216-3657561249-1006Core.job
- c:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-26 16:01]
.
2011-04-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1445276385-3802400216-3657561249-1006UA.job
- c:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-26 16:01]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
IE: &Google; Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: &Yahoo;! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: Yahoo! &Dictionary; - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps; - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS; - file:///c:\program files\Yahoo!\Common/ycsms.htm
DPF: {0F2AAAE3-7E9E-4B64-AB5D-1CA24C6ACB9C} - hxxp://notes.belf.wnyric.org/dwa85W.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-02 16:40
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1032)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\WRLogonNTF.dll
.
- - - - - - - > 'explorer.exe'(3536)
c:\windows\system32\WININET.dll
c:\program files\SiteAdvisor\6172\saHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-04-02 16:45:07
ComboFix-quarantined-files.txt 2011-04-02 20:45
ComboFix2.txt 2011-04-02 06:42
.
Pre-Run: 42,992,214,016 bytes free
Post-Run: 42,970,263,552 bytes free
.
- - End Of File - - 7D4BC44C2838EE5E25ABB26FC3C166D5
JonTom
Hello slvrthunder
Thank you for the log.
Please work your way through the following steps:
Thank you for the log.
Please work your way through the following steps:
- Clean out your temporary files
- Please download ATF Cleaner by Atribune by clicking here and save the file (called ATF-Cleaner.exe) to your desktop.
- Run the program by double clicking the ATF-Cleaner.exe icon located on your desktop.
- Check the boxes to the left of the following:
- Windows Temp
- Current User Temp
- All Users Temp
- Temporary Internet Files
- Java Cache
- The rest are optional. If you want to remove everything check the "Select All" box.
- Click on "Empty Selected" to begin cleaning.
- Once the "Done Cleaning" message appears, click OK.
- If you use Firefox, Click on the Firefox tab and repeat the above process.
- When you have finished cleaning, click on the "Exit" button in the main menu.
- MalwareBytes AntiMalware:
- I can see that you have MBAM installed.
- Double click on your MalwareBytes AntiMalware icon to launch the program.
- Click on the "Update" tab and then on "Check for Updates".
- The program will now install the latest Malware definition files.
- Once complete, click on the "Scanner" tab, select "Perform Quick Scan"and then click on "Scan".
- Once the program has scanned your computer, a log file will be created in Notepad.
- Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
- If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
- When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
- The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
- Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
- Come back here to this thread and Paste the log in your next reply.
- Please update your Java
- To update your Java, Click on "Start" then on "Control Panel" and then on the Java icon (looks like a coffee cup).
- In the window that opens, click on the "Update" tab, and then on "Update Now".
- Your Java should begin to update. Please follow any prompts that you receive.
- Please run the following scan
- Note: You will need to use Internet Explorer for this scan.
- Note for Vista/Windows 7 Users: ESET is compatible but Internet Explorer must be run as Administrator. To do this, right-click on your Internet Explorer icon and select "Run as Administrator".
- Please disable your real time security programs before performing the scan.
- Scan your system with Eset Online Scanner
- Place a check mark in the box YES, I accept the Terms Of Use.
- Click the [external image: Posted Image] button.
- For alternate browsers only: (Microsoft Internet Explorer users can skip these steps).
- Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
- Double click on the [external image: Posted Image] icon on your desktop.
- Check [external image: Posted Image]
- Click the [external image: Posted Image] button.
- Accept any security warnings from your browser.
- Check [external image: Posted Image]
- Make sure that the option to "Remove Found Threats" is UN checked.
- Push the "Start" button.
- ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
- When the scan completes, push [external image: Posted Image]
- Push [external image: Posted Image], and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
- Push the [external image: Posted Image] button.
- Push [external image: Posted Image]
Please post the MBAM and ESET logs in your next reply and let me know how the machine is running now.
slvrthunder
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6255
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
4/3/2011 9:33:14 AM
mbam-log-2011-04-03 (09-33-06).txt
Scan type: Quick scan
Objects scanned: 178587
Time elapsed: 8 minute(s), 59 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\AppID\ActiveX.DLL (Adware.180Solutions) -> No action taken.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6255
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
4/3/2011 9:33:14 AM
mbam-log-2011-04-03 (09-33-06).txt
Scan type: Quick scan
Objects scanned: 178587
Time elapsed: 8 minute(s), 59 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\AppID\ActiveX.DLL (Adware.180Solutions) -> No action taken.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
JonTom
Hello slvrthunder

Please allow MBAM to remove that entry and then complete the remaining stepsRegistry Keys Infected:
HKEY_CLASSES_ROOT\AppID\ActiveX.DLL (Adware.180Solutions) -> No action taken.
slvrthunder
C:\Documents and Settings\All Users\Application Data\AOL Downloads\SUD4131\setup.exe probably a variant of Win32/Agent.HZHBURL trojan
C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install\6.1.41.2\setup.exe probably a variant of Win32/Agent.HZHBURL trojan
C:\Documents and Settings\User\Application Data\Sun\Java\Deployment\cache\6.0\26\1e758e5a-6b284b9f a variant of Win32/Kryptik.MEO trojan
C:\Qoobox\Quarantine\C\Documents and Settings\User\Local Settings\Application Data\isf.exe.vir a variant of Win32/Kryptik.MEO trojan
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1236\A0123053.exe a variant of Win32/Kryptik.MEO trojan
slvrthunder
It appears that I had posted the same MBAM log twice. I let MBAM remove the entry. Here is the log…
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6255
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
4/3/2011 9:33:31 AM
mbam-log-2011-04-03 (09-33-31).txt
Scan type: Quick scan
Objects scanned: 178587
Time elapsed: 8 minute(s), 59 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\AppID\ActiveX.DLL (Adware.180Solutions) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
JonTom
Hello slvrthunder
No problem.
ESET has detected files quarantined by ComboFix and an infected restore point. We will deal with these itmes when we remove our tools. The scan also revealed an infected Java cache and some additional files that we will deal with now:
It appears that I had posted the same MBAM log twice
ESET has detected files quarantined by ComboFix and an infected restore point. We will deal with these itmes when we remove our tools. The scan also revealed an infected Java cache and some additional files that we will deal with now:
- Please Clear Your Sun Java Cache
- Click on "Start", then on "Control Panel" and then on the Java icon (looks like a coffee cup). If you do not see the icon, look to your left and click "Switch to Classic View".
- On the "General" tab, under "Temporary Internet Files", click the "Settings" button.
- Next, click on the "Delete Files" button.
- There are two options in the window to clear the cache - ("Applications and Applets" and "Trace and Log Files").
- Leave BOTH Checked
- Click "OK" on Delete Temporary Files Window.
- Note: This deletes all of the Downloaded Applications and Applets from the Cache.
- Click "OK" to leave the Temporary Files Window.
- Click "OK" to leave the Java Control Panel.
- Please download OTM
- Please download OTM by OldTimer by clicking here.
- Save the file (called OTM.exe) to your desktop.
- Double click on the OTM.exe icon to run the program. (Note: If you are running on Vista/Windows 7, right-click on the file and choose Run As Administrator).
- Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
:Processes explorer.exe :Files C:\Documents and Settings\All Users\Application Data\AOL Downloads\SUD4131\setup.exe C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install\6.1.41.2\setup.exe :Commands [Purity] [EmptyTemp] [Emptyflash] [Start Explorer] [Reboot]
- Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
- Click the Moveit! button.
- Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
- Close OTM.
- Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File -> Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
Please post the OTM log in your next reply along with a new DDS scan and let me know how the machine is running now.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI