This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

XP Total Security 2011 taken over my computer

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

XP Total Security 2011 pop-ups that keep coming and it won't allow me to open Internet Explorer. I am posting this from my laptop(a different computer). I have run a scan from Super AntiSpyware that didn't help. I have Malwarebytes' Anti-Malware but it will not open. McAfee is currently scanning. I am running Windows xp and have the Service Pack 3.
Hello slvrthunder and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.

I am posting this from my laptop

You will need to download the required tools using your laptop and then transfer them to the infected machine. If you use a flash drive for the transfer, please run the following tool first to reduce the chances of cross infection:

  • Please download Flash Disinfector


    • Click here to download Flash Disinfector and save the file (called Flash_Disinfector.exe) to your desktop.
    • Double click on the Flash_Disinfector.exe icon to run the program and follow any prompts that may appear.
    • The program may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so if prompted.
    • Wait until Flash disinfector has finished scanning and then exit the program.
    • Reboot your computer.

    Lets begin with rKill and see if it allows us to run some system scans.

  • rkill


    • Please download rkill (Courtesy of Bleepingcomputer.com).
    • There are 5 different versions of this tool. If one of them will not run, please try the next one in the list.
    • Note: Vista and Windows 7 Users must right click and select "Run as Administrator" to run the tool.
    • Note: You only need to get one of the tools to run, not all of them.


    1. rkill.exe
    2. rkill.com
    3. rkill.scr
    4. WiNlOgOn.exe
    5. uSeRiNiT.exe

    Note: You will likely see a message from this rogue telling you the file is infected. Ignore the message. Leave the message OPEN, do not close the message.

    Run rkill repeatedly until it's able to do it's job. This may take a few tries.

    You'll be able to tell rkill has done it's job when your desktop (explorer.exe) cycles off and then on again.

  • Please perform the following scan


    • Please download DDS from here and save it to your desktop.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Double click on the DDS icon to run the tool (may take up to 3 minutes to run).
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
    • Please post the contents of the DDS.txt and Attach.txt logs in your next reply.

  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOTKIT" entries


Please post the DDS logs and the GMER log in your next reply.

If you are still unable to run the scans after running rKill just let me know :)
. DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 10:58:54.06 on Fri 04/01/2011 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1547 [GMT -4:00] . AV: Spy Sweeper with AntiVirus *Disabled/Updated* {B3891867-7230-459B-9987-E7CCFA7A7D1D} AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Firewall *Enabled* . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\System32\CTsvcCDA.EXE C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\system32\devldr32.exe C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe C:\Program Files\DIGStream\digstream.exe C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\SiteAdvisor\6172\SiteAdv.exe C:\Program Files\Lexmark X5100 Series\lxbabmon.exe C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\WINDOWS\vsnpstd.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Microsoft Location Finder\LocationFinder.exe C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\j2 Messenger 4.2\J2GTray.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe E:\dds.scr . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.yahoo.com/ uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn4\yt.dll BHO: {089fd14d-132b-48fc-8861-0048ae113215} - c:\program files\siteadvisor\6253\SiteAdv.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20101124091320.dll BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: AIM Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\program files\aim toolbar\aimtb.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn4\YTSingleInstance.dll BHO: {fdd3b846-8d59-4ffb-8758-209b6ad74acc} - c:\program files\microsoft money\system\mnyviewer.dll TB: McAfee SiteAdvisor: {0bf43445-2f28-4351-9252-17fe6e806aa0} - c:\program files\siteadvisor\6253\SiteAdv.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn4\yt.dll TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File EB: &Yahoo! Messenger: {4528bbe0-4e08-11d5-ad55-00010333d0ad} - c:\progra~1\yahoo!\common\yhexbmesus.dll EB: MoneySide: {9404901d-06da-4b23-a0ee-3ea4f64ec9b3} - c:\program files\microsoft money\system\mnyviewer.dll uRun: [Microsoft Location Finder] "c:\program files\microsoft location finder\LocationFinder.exe" uRun: [SUPERAntiSpyware] "c:\program files\superantispyware\SUPERAntiSpyware.exe" uRun: [EasyLinkAdvisor] "c:\program files\linksys easylink advisor\LinksysAgent.exe" /startup uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Google Update] "c:\documents and settings\user\local settings\application data\google\update\GoogleUpdate.exe" /c mRun: [Microsoft Works Update Detection] "c:\program files\common files\microsoft shared\works shared\WkUFind.exe" mRun: [UpdReg] c:\windows\Updreg.exe mRun: [AHQInit] "c:\program files\creative\sblive\program\AHQInit.exe" mRun: [AdaptecDirectCD] "c:\program files\roxio\easy cd creator 5\directcd\DirectCD.exe" mRun: [Lexmark X5100 Series] "c:\program files\lexmark x5100 series\lxbabmgr.exe" mRun: [DIGStream] "c:\program files\digstream\digstream.exe" mRun: [DIGServices] "c:\program files\espnruntime\DIGServices.exe" /brand=ESPN /priority=0 /poll=24 mRun: [MimBoot] c:\progra~1\musicm~1\musicm~1\mimboot.exe mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe" mRun: [SiteAdvisor] "c:\program files\siteadvisor\6172\SiteAdv.exe" mRun: [j2 4.2] "c:\program files\j2 messenger 4.2\J2GDllCmd.exe" /R mRun: [BlackBerryAutoUpdate] c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe /background mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [AppleSyncNotifier] "c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe" mRun: [snpstd] c:\windows\vsnpstd.exe mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\j242~1.lnk - c:\program files\j2 messenger 4.2\J2GTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~2.lnk - c:\program files\microsoft office\office\OSA9.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\common files\microsoft shared\works shared\wkcalrem.exe IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html IE: &Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html IE: Translate into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html IE: Yahoo! &Dictionary - file:///c:\program files\yahoo!\Common/ycdict.htm IE: Yahoo! &Maps - file:///c:\program files\yahoo!\Common/ycmap.htm IE: Yahoo! &SMS - file:///c:\program files\yahoo!\Common/ycsms.htm IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim95\aim.exe IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {301DA1EE-F65C-4188-A417-9E915CC8FBFA} - c:\program files\microsoft money\system\mnyviewer.dll Trusted Zone: musicmatch.com\online DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://dcode.support.microsoft.com/dcode/ActiveX/MSDcode.cab DPF: {0F2AAAE3-7E9E-4B64-AB5D-1CA24C6ACB9C} - hxxp://notes.belf.wnyric.org/dwa85W.cab DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/3/9/8/398422c0-8d3e-40e1-a617-af65a72a0465/LegitCheckControl.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1005.cab DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1150326369750 DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - hxxp://www.nick.com/common/groove/gx/GrooveAX28.cab DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} - hxxp://notes.belf.wnyric.org/dwa7W.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Handler: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - c:\program files\siteadvisor\6253\SiteAdv.dll Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll Notify: WRNotifier - WRLogonNTF.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL LSA: Notification Packages = scecli scecli scecli scecli scecli scecli mASetup: {A509B1FF-37FF-4bFF-8CFF-4F3A747040FF} - c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,launchinfsectionex c:\program files\internet explorer\clrtour.inf,DefaultInstall.ResetTour,,12 . ============= SERVICES / DRIVERS =============== . R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2010-7-15 386840] R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2010-7-15 84072] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2006-10-10 5632] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2007-2-27 32256] R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-7-15 271480] R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-7-15 271480] R2 McProxy;McAfee Proxy Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-7-15 271480] R2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2010-7-15 171168] R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2010-7-15 188136] R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\common files\mcafee\systemcore\mfevtps.exe [2010-7-15 141792] R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files\webroot\spy sweeper\SpySweeper.exe [2007-10-15 3567928] R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-7-15 55840] R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2010-7-15 152960] R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-7-15 313288] R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2010-7-15 88544] R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2006-2-16 4096] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2010-7-15 52104] S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2010-7-15 88544] S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-7-15 84264] S3 PortlUSB;PortlUSB;c:\windows\system32\drivers\SiriusUSB.sys [2008-7-29 7552] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-1-8 24652] . =============== Created Last 30 ================ . 2011-03-31 00:17:49 331776 –sha-w- c:\docume~1\user\locals~1\applic~1\isf.exe 2011-03-14 16:17:08 ——– d—–w- c:\program files\common files\Software Update Utility 2011-03-08 21:38:37 ——– d—–w- c:\program files\iPod 2011-03-08 21:38:33 ——– d—–w- c:\docume~1\alluse~1\applic~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521} 2011-03-08 21:20:06 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll 2011-03-08 21:20:06 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll 2011-03-08 21:20:06 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll 2011-03-08 21:20:06 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll 2011-03-08 21:20:06 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll 2011-03-08 21:20:06 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll 2011-03-08 21:20:06 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin.dll 2011-03-08 21:08:13 ——– d—–w- c:\program files\Bonjour 2011-03-03 08:08:32 ——– d—–w- c:\windows\system32\XPSViewer 2011-03-03 08:07:49 89088 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll 2011-03-03 08:06:56 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll 2011-03-03 08:06:56 597504 ——w- c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe 2011-03-03 08:06:56 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2011-03-03 08:06:56 575488 ——w- c:\windows\system32\xpsshhdr.dll 2011-03-03 08:06:56 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll 2011-03-03 08:06:56 1676288 ——w- c:\windows\system32\xpssvcs.dll 2011-03-03 08:06:56 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll 2011-03-03 08:06:56 117760 ——w- c:\windows\system32\prntvpt.dll 2011-03-03 08:06:55 ——– d—–w- C:\dbb74f8f171e24df2830baee . ==================== Find3M ==================== . 2011-02-18 21:36:58 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll 2011-02-09 13:53:52 270848 —-a-w- c:\windows\system32\sbe.dll 2011-02-09 13:53:52 186880 —-a-w- c:\windows\system32\encdec.dll 2011-02-02 07:58:35 2067456 —-a-w- c:\windows\system32\mstscax.dll 2011-01-27 11:57:06 677888 —-a-w- c:\windows\system32\mstsc.exe 2011-01-21 14:44:37 439296 —-a-w- c:\windows\system32\shimgvw.dll 2011-01-07 14:09:02 290048 —-a-w- c:\windows\system32\atmfd.dll 2005-06-26 15:17:11 774144 —-a-w- c:\program files\RngInterstitial.dll 2004-03-25 00:10:31 338800 —-a-w- c:\program files\efxsetup.exe 2004-03-13 14:00:05 723870 —-a-w- c:\program files\yahtzee.exe . ============= FINISH: 11:01:09.76 ===============
. UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_11-03-05.01) . Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 10/22/2002 2:53:47 PM System Uptime: 3/31/2011 9:35:55 PM (14 hours ago) . Motherboard: Dell Computer Corp. | | Processor: Intel® Pentium® 4 CPU 2.00GHz | Microprocessor | 1999/400mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 74 GiB total, 39.03 GiB free. D: is CDROM () E: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP1217: 3/13/2011 6:58:45 AM - System Checkpoint RP1218: 3/14/2011 8:12:44 AM - System Checkpoint RP1219: 3/15/2011 11:49:19 AM - System Checkpoint RP1220: 3/16/2011 3:00:23 AM - Software Distribution Service 3.0 RP1221: 3/17/2011 3:23:12 AM - System Checkpoint RP1222: 3/18/2011 3:34:42 AM - System Checkpoint RP1223: 3/19/2011 4:34:42 AM - System Checkpoint RP1224: 3/20/2011 5:34:42 AM - System Checkpoint RP1225: 3/21/2011 6:34:43 AM - System Checkpoint RP1226: 3/22/2011 7:34:42 AM - System Checkpoint RP1227: 3/23/2011 8:34:33 AM - System Checkpoint RP1228: 3/24/2011 9:34:32 AM - System Checkpoint RP1229: 3/25/2011 3:00:21 AM - Software Distribution Service 3.0 RP1230: 3/26/2011 3:34:32 AM - System Checkpoint RP1231: 3/27/2011 4:34:32 AM - System Checkpoint RP1232: 3/28/2011 5:34:32 AM - System Checkpoint RP1233: 3/29/2011 6:00:35 AM - System Checkpoint RP1234: 3/30/2011 7:00:40 AM - System Checkpoint RP1235: 3/31/2011 7:08:53 AM - System Checkpoint RP1236: 4/1/2011 7:40:17 AM - System Checkpoint . ==== Installed Programs ====================== . 3D Groove Playback Engine Ad-aware 6 Professional Adobe Acrobat 4.0 Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Photoshop 6.0 Adobe Reader 9.4.2 Adobe Shockwave Player Adobe SVG Viewer AIM 7 AIM Toolbar AOL Instant Messenger Apple Application Support Apple Mobile Device Support Apple Software Update ATI Display Driver BlackBerry Desktop Software 5.0.1 BlackBerry Device Software Updater Bonjour Canon PIXMA iP5000 Canon Utilities Easy-PhotoPrint Classic PhoneTools Compatibility Pack for the 2007 Office system Critical Update for Windows Media Player 11 (KB959772) CutePDF Writer 2.8 Dell Digital Jukebox Driver Dell Modem-On-Hold Dell Picture Studio - Dell Image Expert Dell Solution Center Digital Line Detect Digital Photo Navigator 1.5 Download Updater (AOL LLC) Drivers Install For Linksys Easylink Advisor Easy CD Creator 5 Basic ESPN RunTime File Extension Finder Finale Reader 2011 Full Tilt Poker GE 98063 EasyCam GNU Solfege 3.16.4 Google Chrome Google Toolbar for Internet Explorer Help and Support Customization HighMAT Extension to Microsoft Windows XP CD Writing Wizard Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB2158563) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) Intel® PRO Ethernet Adapter and Software Intel® PROSet II InterActual Player InterVideo WinDVD iTunes j2 Messenger 4.2 Java Auto Updater Java™ 6 Update 22 Lexmark X5100 Series LimeWire 5.5.8 Linksys EasyLink Advisor 1.6 (0032) Malwarebytes' Anti-Malware McAfee SecurityCenter Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2416447) Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Extended Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Data Access Components KB870669 Microsoft Encarta Encyclopedia Standard 2002 Microsoft Excel 2000 SR-1 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Location Finder Microsoft Money 2002 Microsoft Money 2002 System Pack Microsoft National Language Support Downlevel APIs Microsoft Outlook 2000 SR-1 Microsoft Picture It! Photo 2002 Microsoft PowerPoint 2000 SR-1 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft VC9 runtime libraries Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Word 2000 SR-1 Microsoft Word 2002 Microsoft Works 2002 Setup Launcher Microsoft Works 6.0 Microsoft Works Suite Add-in for Microsoft Word Microsoft XML Parser MobileMe Control Panel Modem Helper Move Media Player MSN Music Assistant MSXML 4.0 SP2 (KB925672) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 6 Service Pack 2 (KB973686) Musicmatch® Jukebox Musicnotes Software Suite 1.4.6 My Sirius Studio NEF Codec Nero Suite Paint Shop Pro 7 PCFriendly Picasa 3 PowerDirector Express PowerDVD PowerProducer PowerTeacher Gradebook QuickTime RealPlayer Rhapsody Player Engine Safari Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Microsoft .NET Framework 4 Extended (KB2416472) Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 8 (KB2183461) Security Update for Windows Internet Explorer 8 (KB2360131) Security Update for Windows Internet Explorer 8 (KB2416400) Security Update for Windows Internet Explorer 8 (KB2482017) Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Internet Explorer 8 (KB974455) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2279986) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981957) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Security Update for Windows XP (KB982802) ServiceProvider Shockwave Skype Toolbars Skype™ 5.1 Solero Music Viewer 8.0.29.370 Sound Blaster Live! Value Spy Sweeper SUPERAntiSpyware Free Edition TWC Client ActiveX Controls Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB968220) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB976749) Update for Windows Internet Explorer 8 (KB980182) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) URGE VideoLAN VLC media player 0.8.1 Viewpoint Media Player WebFldrs XP Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 Works Suite OS Pack Works Synchronization Yahoo! extras Yahoo! Software Update Yahoo! Toolbar Yahtzee 1.1.6 . ==== Event Viewer Messages From Past Week ======== . 4/1/2011 12:39:57 AM, error: Service Control Manager [7031] - The McShield service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. 3/31/2011 1:36:06 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service McNaiAnn with arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40} 3/31/2011 1:34:59 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips intelppm IPSec mfehidk mfetdi2k MRxSmb NetBIOS NetBT RasAcd Rdbss SASDIFSV SASKUTIL Tcpip 3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning. 3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The McShield service depends on the McAfee Validation Trust Protection Service service which failed to start because of the following error: The dependency service or group failed to start. 3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The McAfee Validation Trust Protection Service service depends on the McAfee Inc. mfehidk service which failed to start because of the following error: A device attached to the system is not functioning. 3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The McAfee Proxy Service service depends on the McAfee Firewall Core Service service which failed to start because of the following error: The dependency service or group failed to start. 3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The McAfee Personal Firewall Service service depends on the McAfee Firewall Core Service service which failed to start because of the following error: The dependency service or group failed to start. 3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The McAfee Network Agent service depends on the McAfee Firewall Core Service service which failed to start because of the following error: The dependency service or group failed to start. 3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The McAfee Firewall Core Service service depends on the McAfee Validation Trust Protection Service service which failed to start because of the following error: The dependency service or group failed to start. 3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The McAfee Anti-Spam Service service depends on the McAfee Firewall Core Service service which failed to start because of the following error: The dependency service or group failed to start. 3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBT service which failed to start because of the following error: A device attached to the system is not functioning. 3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 3/31/2011 1:34:59 PM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 3/31/2011 1:34:23 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 3/30/2011 10:08:15 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the HTTP SSL service to connect. 3/30/2011 10:08:15 PM, error: Service Control Manager [7000] - The HTTP SSL service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 3/30/2011 10:06:03 PM, error: Service Control Manager [7000] - The Webroot Spy Sweeper Engine service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 3/30/2011 10:06:02 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Webroot Spy Sweeper Engine service to connect. . ==== End Of File ===========================
GMER 1.0.15.15570 - http://www.gmer.net
Rootkit scan 2011-04-01 17:04:33
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST380021A rev.3.75
Running: gmer.exe; Driver: C:\DOCUME~1\User\LOCALS~1\Temp\awtyapob.sys


—- System - GMER 1.0.15 —-

SSDT 8A9242C8 ZwAllocateVirtualMemory
SSDT 8A963400 ZwCreateKey
SSDT 8A9632A0 ZwCreateProcess
SSDT 8A961020 ZwCreateProcessEx
SSDT 8A999450 ZwCreateThread
SSDT 8A924D48 ZwDeleteKey
SSDT 8A95D020 ZwDeleteValueKey
SSDT 8A924340 ZwQueueApcThread
SSDT 8A91B460 ZwReadVirtualMemory
SSDT 8A99B6D8 ZwRenameKey
SSDT 8A924430 ZwSetContextThread
SSDT 8A978668 ZwSetInformationKey
SSDT 8A9628B0 ZwSetInformationProcess
SSDT 8A999360 ZwSetInformationThread
SSDT 8A941138 ZwSetValueKey
SSDT 8A962838 ZwSuspendProcess
SSDT 8A9243B8 ZwSuspendThread
SSDT 8A9610D0 ZwTerminateProcess
SSDT 8A9993D8 ZwTerminateThread
SSDT 8A91B4D8 ZwWriteVirtualMemory

Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xF786D16E]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenKey [0xF786D0CC]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xF786D0A4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xF786D0B8]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetSecurityObject [0xF786D144]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xF786D184]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0xF786D158]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetSecurityObject

—- Kernel code sections - GMER 1.0.15 —-

? C:\DOCUME~1\User\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\System32\svchost.exe[376] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00630FE5
.text C:\WINDOWS\System32\svchost.exe[376] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0063000A
.text C:\WINDOWS\System32\svchost.exe[376] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00630FD4
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BC0FEF
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BC0064
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BC0F79
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BC0F8A
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BC0047
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BC0036
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BC009C
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BC0F54
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BC0F28
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BC0F39
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BC0F0D
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BC0FA5
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BC0FD4
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BC0075
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BC001B
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BC0000
.text C:\WINDOWS\System32\svchost.exe[376] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BC00B7
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00BB0040
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00BB0065
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00BB001B
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00BB000A
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00BB0FA8
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00BB0FEF
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00BB0FB9
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [DB, 88]
.text C:\WINDOWS\System32\svchost.exe[376] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00BB0FD4
.text C:\WINDOWS\System32\svchost.exe[376] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00660033
.text C:\WINDOWS\System32\svchost.exe[376] msvcrt.dll!system 77C293C7 5 Bytes JMP 00660FA8
.text C:\WINDOWS\System32\svchost.exe[376] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00660FD4
.text C:\WINDOWS\System32\svchost.exe[376] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0066000C
.text C:\WINDOWS\System32\svchost.exe[376] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00660FC3
.text C:\WINDOWS\System32\svchost.exe[376] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00660FEF
.text C:\WINDOWS\System32\svchost.exe[376] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 00640FEF
.text C:\WINDOWS\System32\svchost.exe[376] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 00640FDE
.text C:\WINDOWS\System32\svchost.exe[376] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 00640014
.text C:\WINDOWS\System32\svchost.exe[376] WININET.dll!InternetOpenUrlW 3D9A6D77 5 Bytes JMP 00640FC3
.text C:\WINDOWS\System32\svchost.exe[376] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00650FEF
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[672] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 62419A20 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[672] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 62419AE2 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\System32\svchost.exe[832] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00D50FEF
.text C:\WINDOWS\System32\svchost.exe[832] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00D50FCA
.text C:\WINDOWS\System32\svchost.exe[832] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00D50000
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00D80FEF
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00D80F9E
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00D80093
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00D80FAF
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00D8006C
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00D80FD4
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00D800C9
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00D80F8D
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D80F66
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D800F5
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00D80F55
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00D8005B
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00D80014
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00D800AE
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00D80040
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00D8002F
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00D800E4
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00D7002C
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00D70058
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00D70FE5
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00D7001B
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00D70F9B
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00D70000
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00D70047
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00D70FB6
.text C:\WINDOWS\System32\svchost.exe[832] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00D60042
.text C:\WINDOWS\System32\svchost.exe[832] msvcrt.dll!system 77C293C7 5 Bytes JMP 00D60FB7
.text C:\WINDOWS\System32\svchost.exe[832] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00D6001D
.text C:\WINDOWS\System32\svchost.exe[832] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00D60FE3
.text C:\WINDOWS\System32\svchost.exe[832] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00D60FC8
.text C:\WINDOWS\System32\svchost.exe[832] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00D60000
.text C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe[924] kernel32.dll!CreateThread + 1A 7C8106F1 4 Bytes CALL 0045024D C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe (Spy Sweeper Engine/Webroot Software, Inc.)
.text C:\WINDOWS\system32\services.exe[1080] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00970000
.text C:\WINDOWS\system32\services.exe[1080] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00970FEF
.text C:\WINDOWS\system32\services.exe[1080] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00970025
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00CD0FE5
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00CD0064
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00CD0F6F
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00CD0049
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00CD0F8A
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00CD0FC0
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00CD00AB
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00CD009A
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00CD0F1C
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00CD0F2D
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00CD00D0
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00CD0F9B
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00CD0000
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00CD007F
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00CD002C
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00CD001B
.text C:\WINDOWS\system32\services.exe[1080] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00CD0F48
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 009A0FB9
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 009A0F8A
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 009A000A
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 009A0FD4
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 009A0047
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 009A0FEF
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 009A002C
.text C:\WINDOWS\system32\services.exe[1080] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 009A001B
.text C:\WINDOWS\system32\services.exe[1080] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0099003F
.text C:\WINDOWS\system32\services.exe[1080] msvcrt.dll!system 77C293C7 5 Bytes JMP 0099002E
.text C:\WINDOWS\system32\services.exe[1080] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00990FD2
.text C:\WINDOWS\system32\services.exe[1080] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0099000C
.text C:\WINDOWS\system32\services.exe[1080] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0099001D
.text C:\WINDOWS\system32\services.exe[1080] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00990FE3
.text C:\WINDOWS\system32\services.exe[1080] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00980000
.text C:\WINDOWS\system32\lsass.exe[1092] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00BF0FEF
.text C:\WINDOWS\system32\lsass.exe[1092] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00BF0014
.text C:\WINDOWS\system32\lsass.exe[1092] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00BF0FD4
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00E60FE5
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00E60F50
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00E60F61
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00E60F72
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00E60F83
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00E60F94
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00E60F22
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00E6006A
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E6008C
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E6007B
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00E60ED8
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00E6001B
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00E60000
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00E60F3F
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00E60FAF
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00E60FCA
.text C:\WINDOWS\system32\lsass.exe[1092] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00E60F07
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00E50FAF
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00E5006C
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00E50FD4
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00E5000A
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00E5005B
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00E50FEF
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00E50040
.text C:\WINDOWS\system32\lsass.exe[1092] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00E5001B
.text C:\WINDOWS\system32\lsass.exe[1092] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00E40F92
.text C:\WINDOWS\system32\lsass.exe[1092] msvcrt.dll!system 77C293C7 5 Bytes JMP 00E4001D
.text C:\WINDOWS\system32\lsass.exe[1092] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00E4000C
.text C:\WINDOWS\system32\lsass.exe[1092] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00E40FE3
.text C:\WINDOWS\system32\lsass.exe[1092] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00E40FAD
.text C:\WINDOWS\system32\lsass.exe[1092] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00E40FD2
.text C:\WINDOWS\system32\lsass.exe[1092] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00E30FE5
.text C:\WINDOWS\system32\svchost.exe[1260] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00E30000
.text C:\WINDOWS\system32\svchost.exe[1260] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00E3002C
.text C:\WINDOWS\system32\svchost.exe[1260] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00E3001B
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00EB0000
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00EB0051
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00EB0036
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00EB0F68
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00EB0025
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00EB0F94
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00EB0F1A
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00EB0062
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00EB0EEE
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00EB0EFF
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00EB0EC9
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00EB0F83
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00EB0FDB
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00EB0F37
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00EB0FAF
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00EB0FC0
.text C:\WINDOWS\system32\svchost.exe[1260] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00EB007D
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00E6000A
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00E60F5E
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00E60FC3
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00E60FD4
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00E60F83
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00E60FEF
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00E60F9E
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [06, 89]
.text C:\WINDOWS\system32\svchost.exe[1260] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00E60025
.text C:\WINDOWS\system32\svchost.exe[1260] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00E5005A
.text C:\WINDOWS\system32\svchost.exe[1260] msvcrt.dll!system 77C293C7 5 Bytes JMP 00E50FCF
.text C:\WINDOWS\system32\svchost.exe[1260] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00E5002E
.text C:\WINDOWS\system32\svchost.exe[1260] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00E50000
.text C:\WINDOWS\system32\svchost.exe[1260] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00E5003F
.text C:\WINDOWS\system32\svchost.exe[1260] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00E5001D
.text C:\WINDOWS\system32\svchost.exe[1260] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00E40000
.text C:\WINDOWS\system32\svchost.exe[1348] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00B60FEF
.text C:\WINDOWS\system32\svchost.exe[1348] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00B60FC3
.text C:\WINDOWS\system32\svchost.exe[1348] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B60FD4
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BA0FE5
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BA0047
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BA0F52
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BA002C
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BA0F79
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BA0F9B
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BA0EFF
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BA0F26
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BA0EDA
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BA0073
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BA0EC9
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BA0F8A
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BA0000
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BA0F37
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BA0011
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BA0FCA
.text C:\WINDOWS\system32\svchost.exe[1348] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BA0062
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00B90FCA
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00B90F9E
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00B9001B
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00B90FE5
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00B90FAF
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00B90000
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00B90051
.text C:\WINDOWS\system32\svchost.exe[1348] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00B90036
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00B80F8D
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!system 77C293C7 5 Bytes JMP 00B80FA8
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00B80011
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00B80FE3
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00B80022
.text C:\WINDOWS\system32\svchost.exe[1348] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00B80000
.text C:\WINDOWS\system32\svchost.exe[1348] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00B70FEF
.text C:\WINDOWS\System32\svchost.exe[1476] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 021B0FE5
.text C:\WINDOWS\System32\svchost.exe[1476] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 021B0000
.text C:\WINDOWS\System32\svchost.exe[1476] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 021B0FD4
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 0220000A
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02200F80
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02200075
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02200064
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02200047
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0220002C
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02200F48
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02200F65
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02200F12
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 022000AB
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 022000D0
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02200FA5
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02200FEF
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02200090
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02200FCA
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 0220001B
.text C:\WINDOWS\System32\svchost.exe[1476] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 02200F37
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 021F0FB9
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 021F006C
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 021F0FD4
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 021F000A
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 021F0051
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 021F0FEF
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 021F0036
.text C:\WINDOWS\System32\svchost.exe[1476] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 021F0025
.text C:\WINDOWS\System32\svchost.exe[1476] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 021E0051
.text C:\WINDOWS\System32\svchost.exe[1476] msvcrt.dll!system 77C293C7 5 Bytes JMP 021E0036
.text C:\WINDOWS\System32\svchost.exe[1476] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 021E0FD7
.text C:\WINDOWS\System32\svchost.exe[1476] msvcrt.dll!_open 77C2F566 5 Bytes JMP 021E0000
.text C:\WINDOWS\System32\svchost.exe[1476] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 021E0FC6
.text C:\WINDOWS\System32\svchost.exe[1476] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 021E0011
.text C:\WINDOWS\System32\svchost.exe[1476] WS2_32.dll!socket 71AB4211 5 Bytes JMP 021D0FEF
.text C:\WINDOWS\System32\svchost.exe[1476] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 021C0FEF
.text C:\WINDOWS\System32\svchost.exe[1476] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 021C0FCA
.text C:\WINDOWS\System32\svchost.exe[1476] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 021C0000
.text C:\WINDOWS\System32\svchost.exe[1476] WININET.dll!InternetOpenUrlW 3D9A6D77 5 Bytes JMP 021C001B
.text C:\WINDOWS\system32\svchost.exe[1524] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00630FEF
.text C:\WINDOWS\system32\svchost.exe[1524] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0063001B
.text C:\WINDOWS\system32\svchost.exe[1524] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0063000A
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00660000
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00660F4B
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00660F70
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00660F81
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00660F9E
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00660FB9
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00660F1D
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00660065
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00660EF1
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00660F02
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 006600AF
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00660040
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00660FE5
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00660F3A
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00660FD4
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00660025
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00660080
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00650FB9
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00650F97
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00650FCA
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00650FE5
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00650054
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00650000
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00650039
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00650FA8
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0064003F
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!system 77C293C7 5 Bytes JMP 0064002E
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0064001D
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00640000
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00640FC8
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00640FEF
.text C:\WINDOWS\System32\svchost.exe[1648] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 008A0FE5
.text C:\WINDOWS\System32\svchost.exe[1648] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 008A0011
.text C:\WINDOWS\System32\svchost.exe[1648] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 008A0000
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 008E0000
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 008E0FB6
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 008E00AB
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 008E0090
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 008E0073
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 008E0062
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 008E0F94
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 008E00DC
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 008E0F65
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 008E0108
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 008E0F54
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 008E0FD1
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 008E001B
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 008E0FA5
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 008E0047
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 008E0036
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 008E00F7
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 008D0FD4
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 008D0F9E
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 008D0FE5
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 008D001B
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 008D005B
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 008D0000
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 008D0FC3
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [AD, 88]
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 008D004A
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 008C0FB9
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!system 77C293C7 5 Bytes JMP 008C0044
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 008C0FD4
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!_open 77C2F566 5 Bytes JMP 008C0000
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 008C0033
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 008C0FEF
.text C:\WINDOWS\System32\svchost.exe[1648] WS2_32.dll!socket 71AB4211 5 Bytes JMP 008B0000
.text C:\WINDOWS\system32\svchost.exe[1776] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 006C0FEF
.text C:\WINDOWS\system32\svchost.exe[1776] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 006C0FC3
.text C:\WINDOWS\system32\svchost.exe[1776] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 006C0FD4
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 009E0FE5
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 009E0075
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 009E0F80
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 009E0064
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 009E0FA5
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 009E002C
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 009E0F39
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 009E0F54
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 009E0F0D
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 009E00A6
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 009E0EFC
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 009E003D
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 009E0000
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 009E0F65
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 009E0FC0
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 009E0011
.text C:\WINDOWS\system32\svchost.exe[1776] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 009E0F28
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 009D0FCA
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 009D0F8D
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 009D001B
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 009D000A
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 009D0F9E
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 009D0FEF
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 009D0FAF
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [BD, 88]
.text C:\WINDOWS\system32\svchost.exe[1776] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 009D0036
.text C:\WINDOWS\system32\svchost.exe[1776] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 009C0FA3
.text C:\WINDOWS\system32\svchost.exe[1776] msvcrt.dll!system 77C293C7 5 Bytes JMP 009C0FB4
.text C:\WINDOWS\system32\svchost.exe[1776] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 009C002E
.text C:\WINDOWS\system32\svchost.exe[1776] msvcrt.dll!_open 77C2F566 5 Bytes JMP 009C000C
.text C:\WINDOWS\system32\svchost.exe[1776] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 009C0FCF
.text C:\WINDOWS\system32\svchost.exe[1776] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 009C001D
.text C:\WINDOWS\system32\svchost.exe[1776] WS2_32.dll!socket 71AB4211 5 Bytes JMP 009B0000
.text C:\WINDOWS\System32\svchost.exe[3440] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00090000
.text C:\WINDOWS\System32\svchost.exe[3440] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0009001B
.text C:\WINDOWS\System32\svchost.exe[3440] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00090FEF
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001B0000
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001B0F79
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001B0064
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001B0F8A
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001B0FA5
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001B0FC0
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001B00B5
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001B009A
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001B00F5
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001B00D0
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 001B0F37
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 001B0047
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 001B0FEF
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 001B007F
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 001B0036
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 001B0025
.text C:\WINDOWS\System32\svchost.exe[3440] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 001B0F52
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 002A003D
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 002A008B
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 002A002C
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 002A001B
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 002A007A
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 002A000A
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 002A0069
.text C:\WINDOWS\System32\svchost.exe[3440] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 002A004E
.text C:\WINDOWS\System32\svchost.exe[3440] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 003F0040
.text C:\WINDOWS\System32\svchost.exe[3440] msvcrt.dll!system 77C293C7 5 Bytes JMP 003F0025
.text C:\WINDOWS\System32\svchost.exe[3440] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 003F0000
.text C:\WINDOWS\System32\svchost.exe[3440] msvcrt.dll!_open 77C2F566 5 Bytes JMP 003F0FEF
.text C:\WINDOWS\System32\svchost.exe[3440] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 003F0FB5
.text C:\WINDOWS\System32\svchost.exe[3440] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 003F0FD2
.text C:\WINDOWS\System32\svchost.exe[3440] WS2_32.dll!socket 71AB4211 5 Bytes JMP 006F0000
.text C:\WINDOWS\explorer.exe[11880] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00090FEF
.text C:\WINDOWS\explorer.exe[11880] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00090FB9
.text C:\WINDOWS\explorer.exe[11880] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00090FD4
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001B000A
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001B0082
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001B0F8D
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001B0F9E
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001B005B
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001B0FC3
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001B0F6B
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001B00B3
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001B0F35
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001B00D8
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 001B00E9
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 001B004A
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 001B0FEF
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 001B0F7C
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 001B0FD4
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 001B0025
.text C:\WINDOWS\explorer.exe[11880] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 001B0F5A
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 002A0FAF
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 002A0051
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 002A0FCA
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 002A0000
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 002A0040
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 002A0FEF
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 002A0025
.text C:\WINDOWS\explorer.exe[11880] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 002A0F9E
.text C:\WINDOWS\explorer.exe[11880] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 002B0F81
.text C:\WINDOWS\explorer.exe[11880] msvcrt.dll!system 77C293C7 5 Bytes JMP 002B0FA6
.text C:\WINDOWS\explorer.exe[11880] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 002B0FD2
.text C:\WINDOWS\explorer.exe[11880] msvcrt.dll!_open 77C2F566 5 Bytes JMP 002B0000
.text C:\WINDOWS\explorer.exe[11880] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 002B0FB7
.text C:\WINDOWS\explorer.exe[11880] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 002B0FEF
.text C:\WINDOWS\explorer.exe[11880] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 002D0FEF
.text C:\WINDOWS\explorer.exe[11880] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 002D0014
.text C:\WINDOWS\explorer.exe[11880] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 002D0025
.text C:\WINDOWS\explorer.exe[11880] WININET.dll!InternetOpenUrlW 3D9A6D77 5 Bytes JMP 002D0040
.text C:\WINDOWS\explorer.exe[11880] WS2_32.dll!socket 71AB4211 5 Bytes JMP 02820000

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs SSFS0BB9.SYS (Spy Sweeper FileSystem Filter Driver/Webroot Software Inc (www.webroot.com))
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (McAfee Link Driver/McAfee, Inc.)

Device \Driver\Tcpip \Device\Ip 89DCC710

AttachedDevice \Driver\Tcpip \Device\Ip mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)

Device \Driver\Tcpip \Device\Tcp 89DCC710

AttachedDevice \Driver\Tcpip \Device\Tcp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)

Device \Driver\Tcpip \Device\Udp 89DCC710

AttachedDevice \Driver\Tcpip \Device\Udp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)

Device \Driver\Tcpip \Device\RawIp 89DCC710

AttachedDevice \Driver\Tcpip \Device\RawIp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)

Device \Driver\Tcpip \Device\IPMULTICAST 89DCC710

AttachedDevice \FileSystem\Fastfat \Fat SSFS0BB9.SYS (Spy Sweeper FileSystem Filter Driver/Webroot Software Inc (www.webroot.com))
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (McAfee Link Driver/McAfee, Inc.)

—- Files - GMER 1.0.15 —-

File C:\Documents and Settings\User\Cookies\user@go[1].txt 0 bytes

—- EOF - GMER 1.0.15 —-
Hello slvrthunder

Thank you for the logs.

  • P2P Programs:


    • P2P programs are a major source of Malware infections.
    • From your log I see you have LimeWire 5.5.8. We do not pass judgment on file-sharing, however we must inform you that engaging in this activity and having this kind of software installed on your system will always make you more susceptible to Malware infections.
    • The use of P2P programs may be contributing to your current situation, and you would certainly be doing yourself a favour by removing them.
    • If you wish to keep the program(s), please do not use them until your computer is cleaned.
    • Information regarding the risk of using these programs can be found from here and here.
    • It is strongly recommend that you uninstall any P2P programs you have on your system.
    • To do this, Click on "Start" then on "Control Panel" and then on "Add or remove programs".
    • A list of currently installed programs will be displayed.
    • Find the "LimeWire 5.5.8" program, click on it once and then click on the "Remove" button.
    • If you are prompted to re-boot your computer to complete the uninstall please do so.


      PLEASE NOTE:
    • Even if you are using a P2P program that is deemed safe, it is only the program that is safe. Any files that you receive using a "safe" P2P program may be infected with Malware. The malware writers use P2P file-sharing as a major conduit to spread infected files.

  • Combofix


    • Download ComboFix from one of the following locations:

      Link 1
      Link 2

    • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

    • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .
    • Double click on ComboFix.exe & follow the prompts.

    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
    • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    [external image: Posted Image]

    • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]

    • Click on Yes, to continue scanning for malware.
    • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
    • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
    • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
    • Should there be issues with internet afterward:

      In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

      In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.

    Please post the ComboFix log in your next reply.
ComboFix 11-04-01.01 - User 04/02/2011 1:14.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1423 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: Spy Sweeper with AntiVirus *Disabled/Updated* {B3891867-7230-459B-9987-E7CCFA7A7D1D}
FW: McAfee Firewall *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\User\Local Settings\Application Data\isf.exe
c:\windows\Downloaded Program Files\ODCTOOLS
c:\windows\system32\_003618_.tmp.dll
c:\windows\system32\_003619_.tmp.dll
c:\windows\system32\_003620_.tmp.dll
c:\windows\system32\_003621_.tmp.dll
c:\windows\system32\_003626_.tmp.dll
c:\windows\system32\_003627_.tmp.dll
c:\windows\system32\_003628_.tmp.dll
c:\windows\system32\_003629_.tmp.dll
c:\windows\system32\_003630_.tmp.dll
c:\windows\system32\_003631_.tmp.dll
c:\windows\system32\_003632_.tmp.dll
c:\windows\system32\_003633_.tmp.dll
c:\windows\system32\_003634_.tmp.dll
c:\windows\system32\_003635_.tmp.dll
c:\windows\system32\_003636_.tmp.dll
c:\windows\system32\_003637_.tmp.dll
c:\windows\system32\_003638_.tmp.dll
c:\windows\system32\_003639_.tmp.dll
c:\windows\system32\_003640_.tmp.dll
c:\windows\system32\_003641_.tmp.dll
c:\windows\system32\_003642_.tmp.dll
c:\windows\system32\_003643_.tmp.dll
c:\windows\system32\_003644_.tmp.dll
c:\windows\system32\_003645_.tmp.dll
c:\windows\system32\_003646_.tmp.dll
c:\windows\system32\_003647_.tmp.dll
c:\windows\system32\_003648_.tmp.dll
c:\windows\system32\_003649_.tmp.dll
c:\windows\system32\_003650_.tmp.dll
c:\windows\system32\_003651_.tmp.dll
c:\windows\system32\_003652_.tmp.dll
c:\windows\system32\_003653_.tmp.dll
c:\windows\system32\_003654_.tmp.dll
c:\windows\system32\_003655_.tmp.dll
c:\windows\system32\_003656_.tmp.dll
c:\windows\system32\_003657_.tmp.dll
c:\windows\system32\_003658_.tmp.dll
c:\windows\system32\_003659_.tmp.dll
c:\windows\system32\_003660_.tmp.dll
c:\windows\system32\_003661_.tmp.dll
c:\windows\system32\_003662_.tmp.dll
c:\windows\system32\_003663_.tmp.dll
c:\windows\system32\_003665_.tmp.dll
c:\windows\system32\_003666_.tmp.dll
c:\windows\system32\_003667_.tmp.dll
c:\windows\system32\_003668_.tmp.dll
c:\windows\system32\_003669_.tmp.dll
c:\windows\system32\_003670_.tmp.dll
c:\windows\system32\_003671_.tmp.dll
c:\windows\system32\_003673_.tmp.dll
c:\windows\system32\_003674_.tmp.dll
c:\windows\system32\_003675_.tmp.dll
c:\windows\system32\_003676_.tmp.dll
c:\windows\system32\_003677_.tmp.dll
c:\windows\system32\_003678_.tmp.dll
c:\windows\system32\_003679_.tmp.dll
c:\windows\system32\_003680_.tmp.dll
c:\windows\system32\_003681_.tmp.dll
c:\windows\system32\_003682_.tmp.dll
c:\windows\system32\_003683_.tmp.dll
c:\windows\system32\_003684_.tmp.dll
c:\windows\system32\_003686_.tmp.dll
c:\windows\system32\_003687_.tmp.dll
c:\windows\system32\_003688_.tmp.dll
c:\windows\system32\_003689_.tmp.dll
c:\windows\system32\_003691_.tmp.dll
c:\windows\system32\_003693_.tmp.dll
c:\windows\system32\_003694_.tmp.dll
c:\windows\system32\_003695_.tmp.dll
c:\windows\system32\_003696_.tmp.dll
c:\windows\system32\_003697_.tmp.dll
c:\windows\system32\_003698_.tmp.dll
c:\windows\system32\_003699_.tmp.dll
c:\windows\system32\_003701_.tmp.dll
c:\windows\system32\_003702_.tmp.dll
c:\windows\system32\_003703_.tmp.dll
c:\windows\system32\_003704_.tmp.dll
c:\windows\system32\_003705_.tmp.dll
c:\windows\system32\_003706_.tmp.dll
c:\windows\system32\_003707_.tmp.dll
c:\windows\system32\_003708_.tmp.dll
c:\windows\system32\_003709_.tmp.dll
c:\windows\system32\_003710_.tmp.dll
c:\windows\system32\_003711_.tmp.dll
c:\windows\system32\_003712_.tmp.dll
c:\windows\system32\_003713_.tmp.dll
c:\windows\system32\_003714_.tmp.dll
c:\windows\system32\_003715_.tmp.dll
c:\windows\system32\_003716_.tmp.dll
c:\windows\system32\_003717_.tmp.dll
c:\windows\system32\_003718_.tmp.dll
c:\windows\system32\_003720_.tmp.dll
c:\windows\system32\_003721_.tmp.dll
c:\windows\system32\_003722_.tmp.dll
c:\windows\system32\_003723_.tmp.dll
c:\windows\system32\_003724_.tmp.dll
c:\windows\system32\_003727_.tmp.dll
c:\windows\system32\_003728_.tmp.dll
c:\windows\system32\_003729_.tmp.dll
c:\windows\system32\_003730_.tmp.dll
c:\windows\system32\_003731_.tmp.dll
c:\windows\system32\_003732_.tmp.dll
c:\windows\system32\_003733_.tmp.dll
c:\windows\system32\_003735_.tmp.dll
c:\windows\system32\_003736_.tmp.dll
c:\windows\system32\_003737_.tmp.dll
c:\windows\system32\_003738_.tmp.dll
c:\windows\system32\_003739_.tmp.dll
c:\windows\system32\_003740_.tmp.dll
c:\windows\system32\_003741_.tmp.dll
c:\windows\system32\_003742_.tmp.dll
c:\windows\system32\_003744_.tmp.dll
c:\windows\system32\_003745_.tmp.dll
c:\windows\system32\_003746_.tmp.dll
c:\windows\system32\_003747_.tmp.dll
c:\windows\system32\_003750_.tmp.dll
c:\windows\system32\_003751_.tmp.dll
c:\windows\system32\_003755_.tmp.dll
c:\windows\system32\_003756_.tmp.dll
c:\windows\system32\_003758_.tmp.dll
c:\windows\system32\_003761_.tmp.dll
c:\windows\system32\_003763_.tmp.dll
c:\windows\system32\_003764_.tmp.dll
c:\windows\system32\_003765_.tmp.dll
c:\windows\system32\_003766_.tmp.dll
c:\windows\system32\_003767_.tmp.dll
c:\windows\system32\_003770_.tmp.dll
c:\windows\system32\_003771_.tmp.dll
c:\windows\system32\_003772_.tmp.dll
c:\windows\system32\_003773_.tmp.dll
c:\windows\system32\_003774_.tmp.dll
c:\windows\system32\_003779_.tmp.dll
c:\windows\system32\_003781_.tmp.dll
c:\windows\system32\_003782_.tmp.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-03-02 to 2011-04-02 )))))))))))))))))))))))))))))))
.
.
2011-03-14 16:17 . 2011-03-14 16:17 ——– d—–w- c:\program files\Common Files\Software Update Utility
2011-03-08 22:29 . 2011-03-08 22:29 ——– d—–w- c:\documents and settings\LocalService\Application Data\Apple Computer
2011-03-08 21:38 . 2011-03-08 21:38 ——– d—–w- c:\program files\iPod
2011-03-08 21:38 . 2011-03-08 21:40 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2011-03-08 21:18 . 2011-03-08 21:20 ——– d—–w- c:\program files\QuickTime
2011-03-08 21:14 . 2011-03-08 21:14 ——– d—–w- c:\program files\Apple Software Update
2011-03-08 21:08 . 2011-03-08 21:08 ——– d—–w- c:\program files\Bonjour
2011-03-03 08:08 . 2011-03-03 08:08 ——– d—–w- c:\windows\system32\XPSViewer
2011-03-03 08:08 . 2011-03-03 08:08 ——– d—–w- c:\program files\MSBuild
2011-03-03 08:08 . 2011-03-03 08:08 ——– d—–w- c:\program files\Reference Assemblies
2011-03-03 08:07 . 2008-07-06 12:06 89088 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-03-03 08:06 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2011-03-03 08:06 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2011-03-03 08:06 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2011-03-03 08:06 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2011-03-03 08:06 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2011-03-03 08:06 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2011-03-03 08:06 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2011-03-03 08:06 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2011-03-03 08:06 . 2011-03-03 08:07 ——– d—–w- C:\dbb74f8f171e24df2830baee
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-18 21:36 . 2009-04-27 07:36 41984 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-18 21:36 . 2009-04-27 07:36 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll
2011-02-09 13:53 . 2002-11-26 19:15 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-09 13:53 . 2002-11-26 19:15 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-02 07:58 . 2004-07-14 22:40 2067456 —-a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2004-07-14 22:40 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2004-07-14 22:40 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2001-08-18 11:00 290048 —-a-w- c:\windows\system32\atmfd.dll
2005-06-26 15:17 . 2005-06-26 15:17 774144 —-a-w- c:\program files\RngInterstitial.dll
2004-03-25 00:10 . 2004-03-25 00:10 338800 —-a-w- c:\program files\efxsetup.exe
2004-03-13 14:00 . 2004-03-13 14:00 723870 —-a-w- c:\program files\yahtzee.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Location Finder"="c:\program files\Microsoft Location Finder\LocationFinder.exe" [2005-08-24 101080]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 1318912]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 454784]
"Google Update"="c:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-07-26 136176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-10 28672]
"UpdReg"="c:\windows\Updreg.exe" [2000-05-11 90112]
"AHQInit"="c:\program files\Creative\SBLive\Program\AHQInit.exe" [2001-03-28 102400]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-04-10 679936]
"Lexmark X5100 Series"="c:\program files\Lexmark X5100 Series\lxbabmgr.exe" [2002-12-16 86102]
"DIGStream"="c:\program files\DIGStream\digstream.exe" [2005-10-31 278528]
"DIGServices"="c:\program files\ESPNRunTime\DIGServices.exe" [2005-10-31 101888]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~1\mimboot.exe" [2006-01-19 11776]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-06-29 32768]
"SiteAdvisor"="c:\program files\SiteAdvisor\6172\SiteAdv.exe" [2007-08-24 36640]
"j2 4.2"="c:\program files\j2 Messenger 4.2\J2GDllCmd.exe" [2006-07-14 107008]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2010-03-11 648536]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-12-18 198160]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"snpstd"="c:\windows\vsnpstd.exe" [2003-12-31 40960]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-09-30 1193848]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-02 421160]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2003-6-23 113664]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2002-10-13 45056]
j2 4.2.lnk - c:\program files\j2 Messenger 4.2\J2GTray.exe [2008-3-19 612352]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
Microsoft Works Calendar Reminders.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2001-8-7 24633]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 18:41 294912 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM95\\aim.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:*:Disabled:ooVoo TCP port 443
"443:UDP"= 443:UDP:*:Disabled:ooVoo UDP port 443
"37674:TCP"= 37674:TCP:*:Disabled:ooVoo TCP port 37674
"37674:UDP"= 37674:UDP:*:Disabled:ooVoo UDP port 37674
"37675:UDP"= 37675:UDP:*:Disabled:ooVoo UDP port 37675
.
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\SYSTEM32\DRIVERS\mfetdi2k.sys [7/15/2010 11:21 AM 84072]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [10/10/2006 2:53 PM 5632]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/27/2007 1:39 PM 32256]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [7/15/2010 11:20 AM 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [7/15/2010 11:20 AM 271480]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [7/15/2010 11:21 AM 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [7/15/2010 11:21 AM 141792]
R3 cfwids;McAfee Inc. cfwids;c:\windows\SYSTEM32\DRIVERS\cfwids.sys [7/15/2010 11:21 AM 55840]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\SYSTEM32\DRIVERS\mfefirek.sys [7/15/2010 11:21 AM 313288]
R3 mfendiskmp;mfendiskmp;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [7/15/2010 11:21 AM 88544]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/16/2006 6:51 PM 4096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [7/15/2010 11:21 AM 88544]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\SYSTEM32\DRIVERS\mferkdet.sys [7/15/2010 11:21 AM 84264]
S3 PortlUSB;PortlUSB;c:\windows\SYSTEM32\DRIVERS\SiriusUSB.sys [7/29/2008 2:15 PM 7552]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/8/2009 12:26 PM 24652]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 08:32 128512 —-a-w- c:\windows\SYSTEM32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:50]
.
2011-04-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1445276385-3802400216-3657561249-1006Core.job
- c:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-26 16:01]
.
2011-04-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1445276385-3802400216-3657561249-1006UA.job
- c:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-26 16:01]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
IE: &Google; Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: &Yahoo;! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: Yahoo! &Dictionary; - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps; - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS; - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: musicmatch.com\online
DPF: {0F2AAAE3-7E9E-4B64-AB5D-1CA24C6ACB9C} - hxxp://notes.belf.wnyric.org/dwa85W.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-02 02:31
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
.
c:\documents and settings\User\Application Data\GTek\GTUpdate\AUpdate\EasyLinkAdvisor\DB\{A8DEDC72-3FAC-407B-BC7A-1997B3EC5684}.xml
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1032)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\WRLogonNTF.dll
.
- - - - - - - > 'explorer.exe'(1464)
c:\windows\system32\WININET.dll
c:\program files\SiteAdvisor\6172\saHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\System32\CTsvcCDA.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Webroot\Spy Sweeper\SpySweeper.exe
c:\windows\System32\MsPMSPSv.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
c:\windows\system32\devldr32.exe
c:\windows\system32\wscntfy.exe
c:\program files\Lexmark X5100 Series\lxbabmon.exe
c:\progra~1\MUSICM~1\MUSICM~1\MMDiag.exe
c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\LINKSY~1\LinksysAdvisor.exe
.
**************************************************************************
.
Completion time: 2011-04-02 02:42:37 - machine was rebooted
ComboFix-quarantined-files.txt 2011-04-02 06:42
.
Pre-Run: 41,941,659,648 bytes free
Post-Run: 42,764,054,528 bytes free
.
- - End Of File - - 68844E8C1BFDEF7863805FA5AA4F903B
Hello slvrthunder

Thank you for the log.

You appear to have two antivirus programs running at the same time (McAfee Anti-Virus and Spy Sweeper with AntiVirus). Please make sure that you only have ONE antivirus running on your machine as multiple applications will conflict with each other.

  • Please work through the following steps


  • Open Notepad (Click on "Start", then on "Run" and type "notepad" (without quotations) in the Open field, then click on "OK").
  • NOTE: Do not Use Wordpad or any other text editor except Notepad or the script will fail.
  • Copy and Paste the text in the quotebox below into the open Notepad window:

    DirLook::
    C:\dbb74f8f171e24df2830baee

    DDS::
    Trusted Zone: musicmatch.com\online

    RegLock::
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

  • Save this as "CFScript.txt" (including the quotation marks), change the "Save as type" to "All Files" and save it to your desktop.
  • Close any open browsers.
  • Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Refering to the picture below, drag CFScript.txt into ComboFix.exe

    [external image: Posted Image]

  • When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
  • Once the log is produced, re-engage your resident anti virus.
ComboFix 11-04-01.01 - User 04/02/2011 16:26:00.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1571 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\User\Desktop\CFScript.txt
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: Spy Sweeper with AntiVirus *Disabled/Updated* {B3891867-7230-459B-9987-E7CCFA7A7D1D}
FW: McAfee Firewall *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
((((((((((((((((((((((((( Files Created from 2011-03-02 to 2011-04-02 )))))))))))))))))))))))))))))))
.
.
2011-03-14 16:17 . 2011-03-14 16:17 ——– d—–w- c:\program files\Common Files\Software Update Utility
2011-03-08 22:29 . 2011-03-08 22:29 ——– d—–w- c:\documents and settings\LocalService\Application Data\Apple Computer
2011-03-08 21:38 . 2011-03-08 21:38 ——– d—–w- c:\program files\iPod
2011-03-08 21:38 . 2011-03-08 21:40 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2011-03-08 21:20 . 2011-03-08 21:20 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2011-03-08 21:18 . 2011-03-08 21:20 ——– d—–w- c:\program files\QuickTime
2011-03-08 21:14 . 2011-03-08 21:14 ——– d—–w- c:\program files\Apple Software Update
2011-03-08 21:08 . 2011-03-08 21:08 ——– d—–w- c:\program files\Bonjour
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-18 21:36 . 2009-04-27 07:36 41984 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-18 21:36 . 2009-04-27 07:36 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll
2011-02-09 13:53 . 2002-11-26 19:15 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-09 13:53 . 2002-11-26 19:15 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-02 07:58 . 2004-07-14 22:40 2067456 —-a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2004-07-14 22:40 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2004-07-14 22:40 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2001-08-18 11:00 290048 —-a-w- c:\windows\system32\atmfd.dll
2005-06-26 15:17 . 2005-06-26 15:17 774144 —-a-w- c:\program files\RngInterstitial.dll
2004-03-25 00:10 . 2004-03-25 00:10 338800 —-a-w- c:\program files\efxsetup.exe
2004-03-13 14:00 . 2004-03-13 14:00 723870 —-a-w- c:\program files\yahtzee.exe
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of C:\dbb74f8f171e24df2830baee —-
.
2011-03-03 08:06 . 2008-06-19 16:03 73 ——w- c:\dbb74f8f171e24df2830baee\i386\msxpsinc.gpd
2011-03-03 08:06 . 2008-06-19 05:33 72 ——w- c:\dbb74f8f171e24df2830baee\i386\msxpsinc.ppd
2011-03-03 08:06 . 2008-06-19 05:33 72 ——w- c:\dbb74f8f171e24df2830baee\amd64\msxpsinc.ppd
2011-03-03 08:06 . 2008-06-19 05:33 2204 ——w- c:\dbb74f8f171e24df2830baee\i386\msxpsdrv.inf
2011-03-03 08:06 . 2008-06-19 05:33 2204 ——w- c:\dbb74f8f171e24df2830baee\amd64\msxpsdrv.inf
2011-03-03 08:06 . 2008-07-06 12:06 10929 ——w- c:\dbb74f8f171e24df2830baee\amd64\msxpsdrv.cat
2011-03-03 08:06 . 2008-07-06 12:06 10929 ——w- c:\dbb74f8f171e24df2830baee\i386\msxpsdrv.cat
2011-03-03 08:06 . 2008-07-06 12:06 147456 ——w- c:\dbb74f8f171e24df2830baee\amd64\filterpipelineprintproc.dll
2011-03-03 08:06 . 2008-07-06 12:06 89088 ——w- c:\dbb74f8f171e24df2830baee\i386\filterpipelineprintproc.dll
2011-03-03 08:06 . 2008-07-06 12:06 765440 ——w- c:\dbb74f8f171e24df2830baee\i386\mxdwdrv.dll
2011-03-03 08:06 . 2008-07-06 12:06 1676288 ——w- c:\dbb74f8f171e24df2830baee\i386\xpssvcs.dll
2011-03-03 08:06 . 2008-07-06 12:06 748032 ——w- c:\dbb74f8f171e24df2830baee\amd64\mxdwdrv.dll
2008-07-06 22:36 . 2008-07-06 22:36 2936832 ——w- c:\dbb74f8f171e24df2830baee\amd64\xpssvcs.dll
2008-06-19 16:03 . 2008-06-19 16:03 73 ——w- c:\dbb74f8f171e24df2830baee\amd64\msxpsinc.gpd
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Location Finder"="c:\program files\Microsoft Location Finder\LocationFinder.exe" [2005-08-24 101080]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 1318912]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 454784]
"Google Update"="c:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-07-26 136176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-10 28672]
"UpdReg"="c:\windows\Updreg.exe" [2000-05-11 90112]
"AHQInit"="c:\program files\Creative\SBLive\Program\AHQInit.exe" [2001-03-28 102400]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-04-10 679936]
"Lexmark X5100 Series"="c:\program files\Lexmark X5100 Series\lxbabmgr.exe" [2002-12-16 86102]
"DIGStream"="c:\program files\DIGStream\digstream.exe" [2005-10-31 278528]
"DIGServices"="c:\program files\ESPNRunTime\DIGServices.exe" [2005-10-31 101888]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~1\mimboot.exe" [2006-01-19 11776]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-06-29 32768]
"SiteAdvisor"="c:\program files\SiteAdvisor\6172\SiteAdv.exe" [2007-08-24 36640]
"j2 4.2"="c:\program files\j2 Messenger 4.2\J2GDllCmd.exe" [2006-07-14 107008]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2010-03-11 648536]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-12-18 198160]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"snpstd"="c:\windows\vsnpstd.exe" [2003-12-31 40960]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-09-30 1193848]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-02 421160]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2003-6-23 113664]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2002-10-13 45056]
j2 4.2.lnk - c:\program files\j2 Messenger 4.2\J2GTray.exe [2008-3-19 612352]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
Microsoft Works Calendar Reminders.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2001-8-7 24633]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 18:41 294912 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM95\\aim.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:*:Disabled:ooVoo TCP port 443
"443:UDP"= 443:UDP:*:Disabled:ooVoo UDP port 443
"37674:TCP"= 37674:TCP:*:Disabled:ooVoo TCP port 37674
"37674:UDP"= 37674:UDP:*:Disabled:ooVoo UDP port 37674
"37675:UDP"= 37675:UDP:*:Disabled:ooVoo UDP port 37675
.
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\SYSTEM32\DRIVERS\mfetdi2k.sys [7/15/2010 11:21 AM 84072]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [10/10/2006 2:53 PM 5632]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/27/2007 1:39 PM 32256]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [7/15/2010 11:20 AM 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [7/15/2010 11:20 AM 271480]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [7/15/2010 11:21 AM 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [7/15/2010 11:21 AM 141792]
R3 cfwids;McAfee Inc. cfwids;c:\windows\SYSTEM32\DRIVERS\cfwids.sys [7/15/2010 11:21 AM 55840]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\SYSTEM32\DRIVERS\mfefirek.sys [7/15/2010 11:21 AM 313288]
R3 mfendiskmp;mfendiskmp;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [7/15/2010 11:21 AM 88544]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/16/2006 6:51 PM 4096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [7/15/2010 11:21 AM 88544]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\SYSTEM32\DRIVERS\mferkdet.sys [7/15/2010 11:21 AM 84264]
S3 PortlUSB;PortlUSB;c:\windows\SYSTEM32\DRIVERS\SiriusUSB.sys [7/29/2008 2:15 PM 7552]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/8/2009 12:26 PM 24652]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 08:32 128512 —-a-w- c:\windows\SYSTEM32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:50]
.
2011-04-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1445276385-3802400216-3657561249-1006Core.job
- c:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-26 16:01]
.
2011-04-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1445276385-3802400216-3657561249-1006UA.job
- c:\documents and settings\User\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-26 16:01]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
IE: &Google; Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: &Yahoo;! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: Yahoo! &Dictionary; - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps; - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS; - file:///c:\program files\Yahoo!\Common/ycsms.htm
DPF: {0F2AAAE3-7E9E-4B64-AB5D-1CA24C6ACB9C} - hxxp://notes.belf.wnyric.org/dwa85W.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-02 16:40
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1032)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\WRLogonNTF.dll
.
- - - - - - - > 'explorer.exe'(3536)
c:\windows\system32\WININET.dll
c:\program files\SiteAdvisor\6172\saHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-04-02 16:45:07
ComboFix-quarantined-files.txt 2011-04-02 20:45
ComboFix2.txt 2011-04-02 06:42
.
Pre-Run: 42,992,214,016 bytes free
Post-Run: 42,970,263,552 bytes free
.
- - End Of File - - 7D4BC44C2838EE5E25ABB26FC3C166D5
Hello slvrthunder

Thank you for the log.

Please work your way through the following steps:

  • Clean out your temporary files


    • Please download ATF Cleaner by Atribune by clicking here and save the file (called ATF-Cleaner.exe) to your desktop.
    • Run the program by double clicking the ATF-Cleaner.exe icon located on your desktop.
    • Check the boxes to the left of the following:

    • Windows Temp
    • Current User Temp
    • All Users Temp
    • Temporary Internet Files
    • Java Cache

    • The rest are optional. If you want to remove everything check the "Select All" box.
    • Click on "Empty Selected" to begin cleaning.
    • Once the "Done Cleaning" message appears, click OK.
    • If you use Firefox, Click on the Firefox tab and repeat the above process.
    • When you have finished cleaning, click on the "Exit" button in the main menu.

  • MalwareBytes AntiMalware:


    • I can see that you have MBAM installed.
    • Double click on your MalwareBytes AntiMalware icon to launch the program.
    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform Quick Scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

  • Please update your Java


    • To update your Java, Click on "Start" then on "Control Panel" and then on the Java icon (looks like a coffee cup).
    • In the window that opens, click on the "Update" tab, and then on "Update Now".
    • Your Java should begin to update. Please follow any prompts that you receive.

  • Please run the following scan


    • Note: You will need to use Internet Explorer for this scan.
    • Note for Vista/Windows 7 Users: ESET is compatible but Internet Explorer must be run as Administrator. To do this, right-click on your Internet Explorer icon and select "Run as Administrator".
    • Please disable your real time security programs before performing the scan.


    • Scan your system with Eset Online Scanner
    • Place a check mark in the box YES, I accept the Terms Of Use.
    • Click the [external image: Posted Image] button.
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps).
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.


    • Check [external image: Posted Image]
    • Click the [external image: Posted Image] button.
    • Accept any security warnings from your browser.
    • Check [external image: Posted Image]
    • Make sure that the option to "Remove Found Threats" is UN checked.
    • Push the "Start" button.
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push [external image: Posted Image]
    • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • Push the [external image: Posted Image] button.
    • Push [external image: Posted Image]

    Please post the MBAM and ESET logs in your next reply and let me know how the machine is running now.
Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6255 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 4/3/2011 9:33:14 AM mbam-log-2011-04-03 (09-33-06).txt Scan type: Quick scan Objects scanned: 178587 Time elapsed: 8 minute(s), 59 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\AppID\ActiveX.DLL (Adware.180Solutions) -> No action taken. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6255 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 4/3/2011 9:33:14 AM mbam-log-2011-04-03 (09-33-06).txt Scan type: Quick scan Objects scanned: 178587 Time elapsed: 8 minute(s), 59 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\AppID\ActiveX.DLL (Adware.180Solutions) -> No action taken. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hello slvrthunder

Registry Keys Infected:
HKEY_CLASSES_ROOT\AppID\ActiveX.DLL (Adware.180Solutions) -> No action taken.

Please allow MBAM to remove that entry and then complete the remaining steps :)
C:\Documents and Settings\All Users\Application Data\AOL Downloads\SUD4131\setup.exe probably a variant of Win32/Agent.HZHBURL trojan C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install\6.1.41.2\setup.exe probably a variant of Win32/Agent.HZHBURL trojan C:\Documents and Settings\User\Application Data\Sun\Java\Deployment\cache\6.0\26\1e758e5a-6b284b9f a variant of Win32/Kryptik.MEO trojan C:\Qoobox\Quarantine\C\Documents and Settings\User\Local Settings\Application Data\isf.exe.vir a variant of Win32/Kryptik.MEO trojan C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1236\A0123053.exe a variant of Win32/Kryptik.MEO trojan
It appears that I had posted the same MBAM log twice. I let MBAM remove the entry. Here is the log… Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6255 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 4/3/2011 9:33:31 AM mbam-log-2011-04-03 (09-33-31).txt Scan type: Quick scan Objects scanned: 178587 Time elapsed: 8 minute(s), 59 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\AppID\ActiveX.DLL (Adware.180Solutions) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hello slvrthunder

It appears that I had posted the same MBAM log twice

:) No problem.

ESET has detected files quarantined by ComboFix and an infected restore point. We will deal with these itmes when we remove our tools. The scan also revealed an infected Java cache and some additional files that we will deal with now:

  • Please Clear Your Sun Java Cache


    • Click on "Start", then on "Control Panel" and then on the Java icon (looks like a coffee cup). If you do not see the icon, look to your left and click "Switch to Classic View".
    • On the "General" tab, under "Temporary Internet Files", click the "Settings" button.
    • Next, click on the "Delete Files" button.
    • There are two options in the window to clear the cache - ("Applications and Applets" and "Trace and Log Files").
    • Leave BOTH Checked
    • Click "OK" on Delete Temporary Files Window.
    • Note: This deletes all of the Downloaded Applications and Applets from the Cache.
    • Click "OK" to leave the Temporary Files Window.
    • Click "OK" to leave the Java Control Panel.

  • Please download OTM


    • Please download OTM by OldTimer by clicking here.
    • Save the file (called OTM.exe) to your desktop.
    • Double click on the OTM.exe icon to run the program. (Note: If you are running on Vista/Windows 7, right-click on the file and choose Run As Administrator).
    • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):


    :Processes 
    explorer.exe
    
    :Files
    C:\Documents and Settings\All Users\Application Data\AOL Downloads\SUD4131\setup.exe
    C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install\6.1.41.2\setup.exe
    
    :Commands
    [Purity]
    [EmptyTemp]
    [Emptyflash]
    [Start Explorer]
    [Reboot]




    • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
    • Click the Moveit! button.
    • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
    • Close OTM.
    • Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File -> Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

    Please post the OTM log in your next reply along with a new DDS scan and let me know how the machine is running now.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI