This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Searchqu.com Problem

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I accidently downloaded "ilivid" and after that whenever i opened a new tab in internet explorer, it would open to "searchqu.com" i recently was able to uninstall the searchqu tool bar from Programs and features. and it doesnt appear when i open a new tab. But i am concerned i still may be infected.
Thanks in advance!
Here is my Hijack This log:


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:08:22 PM, on 11/05/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16766)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\eMachines\Hotkey Utility\HotkeyUtility.exe
C:\Program Files\eMachines\Hotkey Utility\HotkeyUI.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\D-Link\DWA-125 revA\AirGCFG.exe
C:\Program Files\D-Link\DWA-125 revA\WZCSLDR2.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Steam\Steam.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
C:\Program Files\Xfire\Xfire.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10p_ActiveX.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre6\bin\javaw.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\John\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…05v155r4541s20p
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…05v155r4541s20p
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…05v155r4541s20p
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\5.1.0.29\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\5.1.0.29\IPS\IPSBHO.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI3C8A~1\ToolBar\searchqudtx.dll (file missing)
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\5.1.0.29\coIEPlg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI3C8A~1\ToolBar\searchqudtx.dll (file missing)
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Hotkey Utility] C:\Program Files\eMachines\Hotkey Utility\HotkeyUtility.exe
O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [D-Link D-Link DWA-125] C:\Program Files\D-Link\DWA-125 revA\AirGCFG.exe
O4 - HKLM\..\Run: [WZCSLDR2] C:\Program Files\D-Link\DWA-125 revA\WZCSLDR2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D1E1F7ED622A0E5D.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs:
O23 - Service: D_Link_DWA-125 Service (D_Link_DWA-125) - Wireless Service - C:\Program Files\D-Link\DWA-125 revA\ANIWZCSdS.exe
O23 - Service: D_Link_DWA-125_WPS Service (D_Link_DWA-125_WPS) - Unknown owner - C:\Program Files\D-Link\DWA-125 revA\ANIWConnService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\eMachines Games\eMachines Game Console\GameConsoleService.exe
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files\eMachines\Registration\GregHSRW.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SCM_Service - Unknown owner - C:\Windows\System32\WinService.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: Updater Service - Acer Group - C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe

–
End of file - 9309 bytes
Hi and Welcome!! :wavey: My name is Jeff. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

**Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort. This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.**

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
Let's get going!! :thumbup:


Please RUN HijackThis.

Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis.
  • Place a check mark beside each one of the following items:

    O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI3C8A~1\ToolBar\searchqudtx.dll (file missing)
    O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI3C8A~1\ToolBar\searchqudtx.dll (file missing)

  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.

Reboot Your System.
———-

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Right click and Run as Administrator the DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
———-

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Right click and Run as Administrator GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.
———-

aswMBR

Lets get a scan of your Master Boot Record shall we:
  • Download aswMBR.exe ( 511KB ) to your desktop.
  • Right click and Run as Administrator the aswMBR.exe to run it
  • Click the Scan button to start scan
  • On completion of the scan click Save Log, save it to your Desktop and post in your next reply

In your next reply please post the logs to:
  • DDS
  • GMER
  • aswMBR
I'm sorry to be a pain but i have looked at the how to disable your security programs and the instructions for my antivirus (Norton 360) doesnt work. it says "Right-click the Norton 360 icon in the system tray and select Open Tasks and Settings Window." but when i right click on the norton 360 icon in the system tray there is no option labeled "Open Tasks and Settings Window" and i cannot seem to get into it when i run the program normaly. Again sorry to be a pain.
Hi Jwp1295. :)

When you say that you can not get into Norton 360 what do you mean by that? Try these instructions to disable Norton:
  • Right click the Norton icon in your Windows application tray (down by where your clock is at on your desktop)
  • The Norton 360 control panel will display and you will see the Firewall enabled and Auto Protect menu options checked.
  • Uncheck both of those options to disable your Firewall and Auto Protect feature
  • You will be asked to select a time frame for disabling these features…check forever for now and we will restart Norton later
  • Exit Norton 360 by selecting the X at the top right hand corner of the screen.
  • It should now be turned off.
If it still does not disable go ahead and follow these instructions without disabling it.

If you have not already done so please RUN HijackThis.

Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis.
  • Place a check mark beside each one of the following items:

    O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI3C8A~1\ToolBar\searchqudtx.dll (file missing)
    O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI3C8A~1\ToolBar\searchqudtx.dll (file missing)

  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.

Reboot Your System in Safe Mode
———-

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Right click and Run as Administrator the DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
———-

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Right click and Run as Administrator GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.
———-

aswMBR

Lets get a scan of your Master Boot Record shall we:
  • Download aswMBR.exe ( 511KB ) to your desktop.
  • Right click and Run as Administrator the aswMBR.exe to run it
  • Click the Scan button to start scan
  • On completion of the scan click Save Log, save it to your Desktop and post in your next reply

In your next reply please post the logs to:
  • DDS
  • GMER
  • aswMBR
Hi, the instruction you gave me to turn my anitvirus off worked! Thank you :) !

Here is the DDS.txt report

.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 21:53:23.88 on Fri 13/05/2011
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.61.1033.18.3063.1875 [GMT -7:00]
.
AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\D-Link\DWA-125 revA\ANIWConnService.exe
C:\Program Files\eMachines\Registration\GregHSRW.exe
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\System32\WinService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\eMachines\Hotkey Utility\HotkeyUtility.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\eMachines\Hotkey Utility\HotkeyUI.exe
C:\Program Files\D-Link\DWA-125 revA\AirGCFG.exe
C:\Program Files\D-Link\DWA-125 revA\WZCSLDR2.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
C:\Program Files\Xfire\Xfire.exe
C:\Program Files\Common Files\Steam\SteamService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10p_ActiveX.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\John\Desktop\dds.scr
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l;=0c09&m;=et1862&r;=17350111b206p0405v155r4541s20p
mDefault_Page_URL = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l;=0c09&m;=et1862&r;=17350111b206p0405v155r4541s20p
mStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l;=0c09&m;=et1862&r;=17350111b206p0405v155r4541s20p
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\5.1.0.29\ips\IPSBHO.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Steam] "c:\program files\steam\steam.exe" -silent
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [IAStorIcon] c:\program files\intel\intel® rapid storage technology\IAStorIcon.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Hotkey Utility] c:\program files\emachines\hotkey utility\HotkeyUtility.exe
mRun: [NortonOnlineBackupReminder] "c:\program files\symantec\norton online backup\activation\NobuActivation.exe" UNATTENDED
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [D-Link D-Link DWA-125] c:\program files\d-link\dwa-125 reva\AirGCFG.exe
mRun: [WZCSLDR2] c:\program files\d-link\dwa-125 reva\WZCSLDR2.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\users\john\appdata\roaming\micros~1\windows\startm~1\programs\startup\xfire.lnk - c:\program files\xfire\Xfire.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg111v2\WG111v2.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs:
.
============= SERVICES / DRIVERS ===============
.
R0 SCMNdisP;General NDIS Protocol Driver;c:\windows\system32\drivers\SCMNdisP.sys [2011-1-17 21728]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0501000.01d\symds.sys [2011-5-10 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0501000.01d\symefa.sys [2011-5-10 744568]
R1 anodlwf;ANOD Network Security Filter driver;c:\windows\system32\drivers\anodlwf.sys [2011-1-26 12800]
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.0.0.125\definitions\bashdefs\20110430.001\BHDrvx86.sys [2011-5-3 802936]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.0.0.125\definitions\ipsdefs\20110511.001\IDSvix86.sys [2011-5-12 353912]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0501000.01d\ironx86.sys [2011-5-10 136312]
R1 SymNetS;Symantec Network Security WFP Driver;c:\windows\system32\drivers\n360\0501000.01d\symnets.sys [2011-5-10 296568]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 D_Link_DWA-125_WPS;D_Link_DWA-125_WPS Service;c:\program files\d-link\dwa-125 reva\ANIWConnService.exe [2011-1-26 40960]
R2 Greg_Service;GRegService;c:\program files\emachines\registration\GregHSRW.exe [2009-8-28 1150496]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files\intel\intel® rapid storage technology\IAStorDataMgrSvc.exe [2010-4-1 13336]
R2 N360;Norton 360;c:\program files\norton 360\engine\5.1.0.29\ccsvchst.exe [2011-5-10 130008]
R2 SCM_Service;SCM_Service;c:\windows\system32\WinService.exe [2011-1-17 180224]
R2 Updater Service;Updater Service;c:\program files\emachines\emachines updater\UpdaterService.exe [2010-4-1 243232]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-5-10 105592]
R3 netr28u;D-Link dnetr28u USB Extensible Wireless LAN Card Driver;c:\windows\system32\drivers\Dnetr28u.sys [2011-1-26 807936]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2010-4-1 68200]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2010-4-1 277536]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 D_Link_DWA-125;D_Link_DWA-125 Service;c:\program files\d-link\dwa-125 reva\ANIWZCSdS.exe [2011-1-26 126976]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-1-17 135664]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2011-1-24 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-1-17 135664]
S3 RTL8187;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v2.sys [2011-1-17 288768]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-1-19 1343400]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
.
=============== Created Last 30 ================
.
2011-05-14 04:49:12 ——– d—–w- c:\users\john\appdata\local\ElevatedDiagnostics
2011-05-14 04:35:54 ——– d—–w- c:\users\john\appdata\local\{9E7D8463-1B45-409E-8E55-A6240183A230}
2011-05-12 23:03:19 ——– d—–w- c:\users\john\appdata\local\{581199E2-1C35-4A53-838C-B1AE093C716B}
2011-05-12 02:12:40 75776 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2011-05-12 02:12:40 5888 —-a-w- c:\windows\system32\drivers\usbd.sys
2011-05-12 02:12:40 43008 —-a-w- c:\windows\system32\drivers\usbehci.sys
2011-05-12 02:12:40 284160 —-a-w- c:\windows\system32\drivers\usbport.sys
2011-05-12 02:12:40 258560 —-a-w- c:\windows\system32\drivers\usbhub.sys
2011-05-12 02:12:40 24064 —-a-w- c:\windows\system32\drivers\usbuhci.sys
2011-05-12 02:12:40 20480 —-a-w- c:\windows\system32\drivers\usbohci.sys
2011-05-12 02:12:39 3957632 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-05-12 02:12:38 3901824 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-05-12 00:35:09 ——– d—–w- c:\users\john\appdata\local\{F86AC700-8930-48AF-BB0B-79104BFFF5AC}
2011-05-10 23:29:48 744568 —-a-w- c:\windows\system32\drivers\n360\0501000.01d\symefa.sys
2011-05-10 23:29:48 50168 —-a-w- c:\windows\system32\drivers\n360\0501000.01d\srtspx.sys
2011-05-10 23:29:48 340088 —-a-w- c:\windows\system32\drivers\n360\0501000.01d\symds.sys
2011-05-10 23:29:48 296568 —-a-w- c:\windows\system32\drivers\n360\0501000.01d\symnets.sys
2011-05-10 23:29:47 516216 —-a-w- c:\windows\system32\drivers\n360\0501000.01d\srtsp.sys
2011-05-10 23:29:47 136312 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\ironx86.sys
2011-05-10 23:29:34 ——– d—–w- c:\windows\system32\drivers\n360\0501000.01D
2011-05-10 23:08:43 ——– d—–w- c:\users\john\appdata\local\{32934AAB-5956-4DD6-AC90-1E6228933233}
2011-05-04 03:45:48 ——– d—–w- c:\users\john\appdata\local\NPE
2011-05-04 00:47:53 ——– d—–w- c:\users\john\appdata\roaming\Malwarebytes
2011-05-04 00:47:51 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-04 00:47:51 ——– d—–w- c:\progra~2\Malwarebytes
2011-05-04 00:47:48 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-05-04 00:47:48 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-05-03 22:19:27 ——– d—–w- c:\users\john\appdata\local\Ilivid Player
2011-05-03 22:19:13 ——– d—–w- c:\users\john\appdata\local\{6D5A271B-DCF7-4B1B-BF31-134EEFDF89B6}
2011-05-03 04:43:44 ——– d—–w- c:\users\john\.thumbnails
2011-05-03 04:41:32 ——– d—–w- c:\users\john\.gimp-2.6
2011-05-03 04:15:20 ——– d—–w- c:\users\john\appdata\local\PackageAware
2011-05-02 17:01:52 ——– d—–w- c:\users\john\appdata\local\{10B98C34-A8BD-4A6C-A8C6-6C80D0B916A8}
2011-05-01 18:22:59 ——– d—–w- c:\users\john\appdata\local\{D276AC3B-46DC-41E6-A2E2-D3066FE6F749}
2011-04-30 22:50:55 ——– d—–w- c:\users\john\appdata\local\{1B42A745-938E-484C-96AD-EDDE93EB1D27}
2011-04-30 16:57:57 ——– d—–w- c:\users\john\appdata\local\{C0259F46-9B4C-48BC-8A90-0761D7E4EB49}
2011-04-29 22:54:37 ——– d—–w- c:\users\john\appdata\local\{62479380-573A-4821-AC46-096135CA0674}
2011-04-28 22:13:11 ——– d—–w- c:\users\john\appdata\local\{5AC04D5F-CCB0-4579-AE97-9825003325B1}
2011-04-27 18:35:50 ——– d—–w- c:\users\john\appdata\local\{91473006-8ED3-43F1-9D55-C015C4D6CD70}
2011-04-27 06:28:32 ——– d—–w- c:\users\john\appdata\local\{EB242858-B407-4056-A699-075D629517E8}
2011-04-26 18:27:46 ——– d—–w- c:\users\john\appdata\local\{4BB2C536-7AFE-458F-8EB0-208260A5D223}
2011-04-25 20:08:59 ——– d—–w- c:\users\john\appdata\local\{14E80F3F-D297-4E5F-B06A-29225B6DD05A}
2011-04-24 17:36:02 ——– d—–w- c:\users\john\appdata\local\{02A08A8A-8E34-4285-BEFB-9D00CA13FCB9}
2011-04-24 03:55:51 2331136 —-a-w- c:\windows\system32\win32k.sys
2011-04-24 03:55:47 191488 —-a-w- c:\windows\system32\FXSCOVER.exe
2011-04-24 03:55:45 288256 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-04-24 03:55:40 1164288 —-a-w- c:\windows\system32\mfc42u.dll
2011-04-24 03:55:40 1137664 —-a-w- c:\windows\system32\mfc42.dll
2011-04-24 03:55:36 740864 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-24 03:55:30 95744 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-24 03:55:30 69632 —-a-w- c:\windows\system32\drivers\bowser.sys
2011-04-24 03:55:30 221696 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-24 03:55:30 123392 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-24 03:33:36 ——– d—–w- c:\users\john\appdata\local\{5BD4ED26-7B5D-471E-91DA-351B0BACEE0B}
.
==================== Find3M ====================
.
2011-04-08 11:28:58 41872 —-a-w- c:\windows\system32\xfcodec.dll
2011-03-12 11:31:58 442880 —-a-w- c:\windows\system32\XpsPrint.dll
2011-03-11 05:39:35 1686016 —-a-w- c:\windows\system32\esent.dll
2011-03-11 05:37:34 74240 —-a-w- c:\windows\system32\fsutil.exe
2011-03-03 05:29:23 132608 —-a-w- c:\windows\system32\dnsrslvr.dll
2011-03-03 05:27:30 28672 —-a-w- c:\windows\system32\dnscacheugc.exe
2011-02-26 05:33:07 2614784 —-a-w- c:\windows\explorer.exe
2011-02-24 05:32:44 981504 —-a-w- c:\windows\system32\wininet.dll
2011-02-24 05:30:16 44544 —-a-w- c:\windows\system32\licmgr10.dll
2011-02-24 04:23:48 386048 —-a-w- c:\windows\system32\html.iec
2011-02-24 03:50:26 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2011-02-23 15:27:00 941160 —-a-w- c:\windows\system32\nvdispco322090.dll
2011-02-23 15:27:00 837736 —-a-w- c:\windows\system32\nvgenco322040.dll
2011-02-23 15:27:00 57960 —-a-w- c:\windows\system32\OpenCL.dll
2011-02-23 15:27:00 5654120 —-a-w- c:\windows\system32\nvwgf2um.dll
2011-02-23 15:27:00 4942952 —-a-w- c:\windows\system32\nvcuda.dll
2011-02-23 15:27:00 2895976 —-a-w- c:\windows\system32\nvcuvid.dll
2011-02-23 15:27:00 2251368 —-a-w- c:\windows\system32\nvcuvenc.dll
2011-02-23 15:27:00 1965672 —-a-w- c:\windows\system32\nvapi.dll
2011-02-23 15:27:00 15047272 —-a-w- c:\windows\system32\nvoglv32.dll
2011-02-23 15:27:00 13011560 —-a-w- c:\windows\system32\nvcompiler.dll
2011-02-23 15:27:00 10079336 —-a-w- c:\windows\system32\nvd3dum.dll
2011-02-19 05:33:11 802304 —-a-w- c:\windows\system32\FntCache.dll
2011-02-19 05:32:48 1074176 —-a-w- c:\windows\system32\DWrite.dll
2011-02-19 05:32:35 739840 —-a-w- c:\windows\system32\d2d1.dll
2011-02-19 05:32:08 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-02-19 03:37:02 294912 —-a-w- c:\windows\system32\atmfd.dll
2011-02-18 05:36:26 428032 —-a-w- c:\windows\system32\vbscript.dll
2011-02-18 05:33:29 31232 —-a-w- c:\windows\system32\prevhost.exe
.
============= FINISH: 21:54:02.67 ===============


Here is the Gmer log:

GMER 1.0.15.15627 - http://www.gmer.net
Rootkit scan 2011-05-13 22:26:32
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD10 rev.01.0
Running: gmer.exe; Driver: C:\Users\John\AppData\Local\Temp\kgldypob.sys


—- System - GMER 1.0.15 —-

SSDT 88ED4510 ZwAlertResumeThread
SSDT 88ED45F0 ZwAlertThread
SSDT 88ED4F00 ZwAllocateVirtualMemory
SSDT 88E6B598 ZwAlpcConnectPort
SSDT 88ED69B8 ZwAssignProcessToJobObject
SSDT 88ED6F60 ZwCreateMutant
SSDT 88ED66D8 ZwCreateSymbolicLinkObject
SSDT 88EDA660 ZwCreateThread
SSDT 88ED67C8 ZwCreateThreadEx
SSDT 88ED6A98 ZwDebugActiveProcess
SSDT 88EDA328 ZwDuplicateObject
SSDT 88ED4D20 ZwFreeVirtualMemory
SSDT 88ED4350 ZwImpersonateAnonymousToken
SSDT 88ED4430 ZwImpersonateThread
SSDT 88DCBE10 ZwLoadDriver
SSDT 88ED4C20 ZwMapViewOfSection
SSDT 88ED6E80 ZwOpenEvent
SSDT 88EDA508 ZwOpenProcess
SSDT 88ED4FD0 ZwOpenProcessToken
SSDT 88ED6CC0 ZwOpenSection
SSDT 88EDA418 ZwOpenThread
SSDT 88ED68C8 ZwProtectVirtualMemory
SSDT 88ED46D0 ZwResumeThread
SSDT 88ED4970 ZwSetContextThread
SSDT 88ED4A50 ZwSetInformationProcess
SSDT 88ED6B78 ZwSetSystemInformation
SSDT 88ED6DA0 ZwSuspendProcess
SSDT 88ED47B0 ZwSuspendThread
SSDT 88EDA760 ZwTerminateProcess
SSDT 88ED4890 ZwTerminateThread
SSDT 88ED4B40 ZwUnmapViewOfSection
SSDT 88ED4E10 ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwSaveKeyEx + 13BD 8307C569 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 830A1092 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, …] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!RtlSidHashLookup + 224 830A8834 8 Bytes [10, 45, ED, 88, F0, 45, ED, …]
.text ntkrnlpa.exe!RtlSidHashLookup + 23C 830A884C 4 Bytes [00, 4F, ED, 88]
.text ntkrnlpa.exe!RtlSidHashLookup + 248 830A8858 4 Bytes [98, B5, E6, 88]
.text ntkrnlpa.exe!RtlSidHashLookup + 29C 830A88AC 4 Bytes [B8, 69, ED, 88]
.text ntkrnlpa.exe!RtlSidHashLookup + 318 830A8928 4 Bytes [60, 6F, ED, 88]
.text …
.text peauth.sys 95547C9D 28 Bytes [15, 73, BC, 71, E9, C7, 2B, …]
.text peauth.sys 95547CC1 28 Bytes [15, 73, BC, 71, E9, C7, 2B, …]
? C:\Users\John\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Xfire\Xfire.exe[4008] kernel32.dll!CreateProcessA 75F82062 5 Bytes JMP 064337AC C:\Program Files\Xfire\xfire_toucan_44183.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[4008] kernel32.dll!CreateThread 75FD281D 5 Bytes JMP 06433150 C:\Program Files\Xfire\xfire_toucan_44183.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[4008] GDI32.dll!BitBlt 75D97180 5 Bytes JMP 06432BC8 C:\Program Files\Xfire\xfire_toucan_44183.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[4008] USER32.dll!InvalidateRgn 75C18099 5 Bytes JMP 06432DAE C:\Program Files\Xfire\xfire_toucan_44183.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[4008] USER32.dll!CreateDialogParamW 75C19BFF 5 Bytes JMP 0643329B C:\Program Files\Xfire\xfire_toucan_44183.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[4008] USER32.dll!GetCursorPos 75C1C198 5 Bytes JMP 06432EE4 C:\Program Files\Xfire\xfire_toucan_44183.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[4008] USER32.dll!SetFocus 75C1CBA9 5 Bytes JMP 06432C78 C:\Program Files\Xfire\xfire_toucan_44183.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[4008] USER32.dll!SetForegroundWindow 75C1D3AE 5 Bytes JMP 064333E9 C:\Program Files\Xfire\xfire_toucan_44183.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[4008] USER32.dll!RegisterClassA 75C1E225 5 Bytes JMP 064330B8 C:\Program Files\Xfire\xfire_toucan_44183.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[4008] USER32.dll!CreateWindowExW 75C20E51 5 Bytes JMP 06433481 C:\Program Files\Xfire\xfire_toucan_44183.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[4008] USER32.dll!SetWindowPos 75C23581 5 Bytes JMP 0643333F C:\Program Files\Xfire\xfire_toucan_44183.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[4008] USER32.dll!RedrawWindow 75C252A2 5 Bytes JMP 06433017 C:\Program Files\Xfire\xfire_toucan_44183.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[4008] USER32.dll!IsWindowVisible 75C26939 7 Bytes JMP 0643353A C:\Program Files\Xfire\xfire_toucan_44183.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[4008] USER32.dll!GetDC 75C27041 5 Bytes JMP 06432A99 C:\Program Files\Xfire\xfire_toucan_44183.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[4008] USER32.dll!ReleaseDC 75C27055 5 Bytes JMP 06432B2D C:\Program Files\Xfire\xfire_toucan_44183.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[4008] USER32.dll!BeginPaint 75C27B87 5 Bytes JMP 06432A05 C:\Program Files\Xfire\xfire_toucan_44183.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[4008] USER32.dll!InvalidateRect 75C27BC9 5 Bytes JMP 06432D10 C:\Program Files\Xfire\xfire_toucan_44183.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[4008] USER32.dll!TrackPopupMenu 75C44B3B 5 Bytes JMP 06433702 C:\Program Files\Xfire\xfire_toucan_44183.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[4008] USER32.dll!DialogBoxParamW 75C4564A 5 Bytes JMP 064331F7 C:\Program Files\Xfire\xfire_toucan_44183.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[4008] USER32.dll!SetCapture 75C46B2A 5 Bytes JMP 06432E4C C:\Program Files\Xfire\xfire_toucan_44183.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[4008] USER32.dll!WindowFromPoint 75C46D0C 5 Bytes JMP 06432F7C C:\Program Files\Xfire\xfire_toucan_44183.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[4888] USER32.dll!CreateWindowExW 75C20E51 5 Bytes JMP 6A5C8197 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4888] USER32.dll!DialogBoxIndirectParamW 75C44AA7 5 Bytes JMP 6A6EFED8 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4888] USER32.dll!DialogBoxParamW 75C4564A 5 Bytes JMP 6A4E4BA7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4888] USER32.dll!DialogBoxParamA 75C5CF6A 5 Bytes JMP 6A6EFE75 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4888] USER32.dll!DialogBoxIndirectParamA 75C5D29C 5 Bytes JMP 6A6EFF3B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4888] USER32.dll!MessageBoxIndirectA 75C6E8C9 5 Bytes JMP 6A6EFE0A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4888] USER32.dll!MessageBoxIndirectW 75C6E9C3 5 Bytes JMP 6A6EFD9F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4888] USER32.dll!MessageBoxExA 75C6EA29 5 Bytes JMP 6A6EFD3D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4888] USER32.dll!MessageBoxExW 75C6EA4D 5 Bytes JMP 6A6EFCDB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] ntdll.dll!NtMapViewOfSection 76FE4ED0 5 Bytes JMP 03AA003A
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!CreateDialogParamW 75C19BFF 5 Bytes JMP 6A51C5A8 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!EnableWindow 75C1A72E 5 Bytes JMP 6A51C523 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!GetAsyncKeyState 75C1C09A 5 Bytes JMP 6A4DD6E9 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!UnhookWindowsHookEx 75C1CC7B 5 Bytes JMP 6A5D83A2 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!CallNextHookEx 75C1CC8F 5 Bytes JMP 6A5B9D94 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!CreateWindowExW 75C20E51 5 Bytes JMP 6A5C8197 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!SetWindowsHookExW 75C2210A 5 Bytes JMP 6A57463B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!GetKeyState 75C24FDA 5 Bytes JMP 6A51D79A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!IsDialogMessageW 75C26F06 3 Bytes JMP 6A4E4284 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!IsDialogMessageW + 4 75C26F0A 1 Byte [F4]
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!CreateDialogParamA 75C33E79 5 Bytes JMP 6A6F0ACE C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!IsDialogMessage 75C3407A 5 Bytes JMP 6A6F036F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!CreateDialogIndirectParamA 75C39110 5 Bytes JMP 6A6F0B05 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!CreateDialogIndirectParamW 75C408AD 5 Bytes JMP 6A6F0B3C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!DialogBoxIndirectParamW 75C44AA7 5 Bytes JMP 6A6EFED8 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!EndDialog 75C4555C 5 Bytes JMP 6A4E5AE9 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!DialogBoxParamW 75C4564A 5 Bytes JMP 6A4E4BA7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!SetKeyboardState 75C46B52 5 Bytes JMP 6A6F06D4 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!SendInput 75C47055 5 Bytes JMP 6A6F1298 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!SetCursorPos 75C5C1D8 5 Bytes JMP 6A6F12F0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!DialogBoxParamA 75C5CF6A 5 Bytes JMP 6A6EFE75 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!DialogBoxIndirectParamA 75C5D29C 5 Bytes JMP 6A6EFF3B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!MessageBoxIndirectA 75C6E8C9 5 Bytes JMP 6A6EFE0A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!MessageBoxIndirectW 75C6E9C3 5 Bytes JMP 6A6EFD9F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!MessageBoxExA 75C6EA29 5 Bytes JMP 6A6EFD3D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!MessageBoxExW 75C6EA4D 5 Bytes JMP 6A6EFCDB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] USER32.dll!keybd_event 75C6EC9B 5 Bytes JMP 6A6F1623 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] SHELL32.dll!SHChangeNotification_Lock + 45BA 7628B440 4 Bytes [11, 36, CC, 68]
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] SHELL32.dll!SHChangeNotification_Lock + 45C2 7628B448 8 Bytes [5F, 35, CC, 68, D0, 73, CB, …]
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] ole32.dll!OleLoadFromStream 76E45BF6 5 Bytes JMP 6A6F022B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] ole32.dll!CoGetContextToken + 5C0 76E7A38F 7 Bytes JMP 03AA00F7
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] ole32.dll!CoCreateInstance 76E9590C 5 Bytes JMP 6A5C8C85 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4936] ole32.dll!CoCreateInstance + 3E 76E9594A 7 Bytes JMP 03AA01B1
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] ntdll.dll!NtMapViewOfSection 76FE4ED0 5 Bytes JMP 03B0003A
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!CreateDialogParamW 75C19BFF 5 Bytes JMP 6A51C5A8 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!EnableWindow 75C1A72E 5 Bytes JMP 6A51C523 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!GetAsyncKeyState 75C1C09A 5 Bytes JMP 6A4DD6E9 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!UnhookWindowsHookEx 75C1CC7B 5 Bytes JMP 6A5D83A2 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!CallNextHookEx 75C1CC8F 5 Bytes JMP 6A5B9D94 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!CreateWindowExW 75C20E51 5 Bytes JMP 6A5C8197 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!SetWindowsHookExW 75C2210A 5 Bytes JMP 6A57463B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!GetKeyState 75C24FDA 5 Bytes JMP 6A51D79A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!IsDialogMessageW 75C26F06 3 Bytes JMP 6A4E4284 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!IsDialogMessageW + 4 75C26F0A 1 Byte [F4]
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!CreateDialogParamA 75C33E79 5 Bytes JMP 6A6F0ACE C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!IsDialogMessage 75C3407A 5 Bytes JMP 6A6F036F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!CreateDialogIndirectParamA 75C39110 5 Bytes JMP 6A6F0B05 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!CreateDialogIndirectParamW 75C408AD 5 Bytes JMP 6A6F0B3C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!DialogBoxIndirectParamW 75C44AA7 5 Bytes JMP 6A6EFED8 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!EndDialog 75C4555C 5 Bytes JMP 6A4E5AE9 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!DialogBoxParamW 75C4564A 5 Bytes JMP 6A4E4BA7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!SetKeyboardState 75C46B52 5 Bytes JMP 6A6F06D4 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!SendInput 75C47055 5 Bytes JMP 6A6F1298 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!SetCursorPos 75C5C1D8 5 Bytes JMP 6A6F12F0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!DialogBoxParamA 75C5CF6A 5 Bytes JMP 6A6EFE75 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!DialogBoxIndirectParamA 75C5D29C 5 Bytes JMP 6A6EFF3B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!MessageBoxIndirectA 75C6E8C9 5 Bytes JMP 6A6EFE0A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!MessageBoxIndirectW 75C6E9C3 5 Bytes JMP 6A6EFD9F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!MessageBoxExA 75C6EA29 5 Bytes JMP 6A6EFD3D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!MessageBoxExW 75C6EA4D 5 Bytes JMP 6A6EFCDB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] USER32.dll!keybd_event 75C6EC9B 5 Bytes JMP 6A6F1623 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] SHELL32.dll!SHChangeNotification_Lock + 45BA 7628B440 4 Bytes [11, 36, CC, 68]
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] SHELL32.dll!SHChangeNotification_Lock + 45C2 7628B448 8 Bytes [5F, 35, CC, 68, D0, 73, CB, …]
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] ole32.dll!OleLoadFromStream 76E45BF6 5 Bytes JMP 6A6F022B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] ole32.dll!CoGetContextToken + 5C0 76E7A38F 7 Bytes JMP 03B0033A
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] ole32.dll!CoCreateInstance 76E9590C 5 Bytes JMP 6A5C8C85 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5916] ole32.dll!CoCreateInstance + 3E 76E9594A 7 Bytes JMP 03B003F4

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume7 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume8 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\ACPI_HAL \Device\0000004e halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-


Here is the aswMBR log:
aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-05-13 22:27:47
—————————–
22:27:47.854 OS Version: Windows 6.1.7600
22:27:47.854 Number of processors: 4 586 0x2502
22:27:47.854 ComputerName: JOHN-PC UserName: John
22:27:49.117 Initialize success
22:27:50.693 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
22:27:50.708 Disk 0 Vendor: WDC_WD10 01.0 Size: 953869MB BusType: 3
22:27:50.724 Disk 0 MBR read successfully
22:27:50.724 Disk 0 MBR scan
22:27:50.740 Disk 0 Windows 7 default MBR code
22:27:50.771 Disk 0 scanning sectors +1953521664
22:27:50.880 Disk 0 scanning C:\Windows\system32\drivers
22:28:11.628 Service scanning
22:28:12.470 Disk 0 trace - called modules:
22:28:12.486 ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys halmacpi.dll
22:28:12.486 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x88251030]
22:28:12.486 3 CLASSPNP.SYS[8be9659e] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x866e7028]
22:28:12.486 Scan finished successfully
22:28:31.768 Disk 0 MBR has been saved successfully to "C:\Users\John\Desktop\MBR.dat"
22:28:31.768 The log file has been saved successfully to "C:\Users\John\Desktop\aswMBR.txt"


Thanks you again for your continued assistance! ^_^

Attachments:

Hi Jwp1295.

I see that you have Malwarebytes already on your system.

Select Perform quick scan, then click Scan as shown below.

[external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.

The log can also be found here:
C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
———-

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
http://www.eset.com/onlinescan/

In your next reply please post the logs to Malwarebytes and ESET Online Scan. :)
Hi, I'm having a problem with ESET Online scan. When the scan completes, there is no button saying "List of found threats" also there is no "Export to text file" Thank you for your help :)
Hi Jwp1295.

Since there was no log produced by ESET Online Scanner that means that it came back without finding anything.

Were you able to run Malwarebytes and did it produce a log? If so could you post the log so that I can take a look at it please. :)

Go to Start ==> Type Run ==> Right Click and Run as Administrator Run ==> copy/paste the line below into the Run box and click OK:
cmd /c rd /s /q "c:\users\john\appdata\local\Ilivid Player"


In your next reply please tell me how your system is running and post the log to Malwarebytes. :)
Hi :)! My system is running fine, internet explorer no longer opens searchqu.com, and when i paste the line into run a small window appears, I think that is the command prompt, Otherwise my system is running normally. Here is the Malwarebyes log: Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6571 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 16/05/2011 4:21:08 PM mbam-log-2011-05-16 (16-21-08).txt Scan type: Quick scan Objects scanned: 147315 Time elapsed: 1 minute(s), 54 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Thank you for your support :)
Hi Jwp1295.

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 9.1 first. Be sure to move any PDF documents to another folder first though.
———-

Now I need you to go ahead and run DDS once more and post the log that is created in your next reply.
Hi :)! Here is the DDS log: . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 17:38:42.94 on Tue 17/05/2011 Internet Explorer: 8.0.7600.16385 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.61.1033.18.3063.2180 [GMT -7:00] . AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\D-Link\DWA-125 revA\ANIWZCSdS.exe C:\Program Files\D-Link\DWA-125 revA\ANIWConnService.exe C:\Program Files\eMachines\Registration\GregHSRW.exe C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe C:\Windows\System32\WinService.exe C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\WUDFHost.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\SearchIndexer.exe C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskhost.exe C:\Windows\Explorer.EXE C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe C:\Program Files\eMachines\Hotkey Utility\HotkeyUtility.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Program Files\D-Link\DWA-125 revA\AirGCFG.exe C:\Program Files\D-Link\DWA-125 revA\WZCSLDR2.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\eMachines\Hotkey Utility\HotkeyUI.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Steam\Steam.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe C:\Program Files\NETGEAR\WG111v2\WG111v2.exe C:\Program Files\Xfire\Xfire.exe C:\Program Files\Common Files\Steam\SteamService.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\John\Desktop\dds.scr C:\Windows\system32\conhost.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uDefault_Page_URL = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l;=0c09&m;=et1862&r;=17350111b206p0405v155r4541s20p mDefault_Page_URL = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l;=0c09&m;=et1862&r;=17350111b206p0405v155r4541s20p mStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l;=0c09&m;=et1862&r;=17350111b206p0405v155r4541s20p BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\5.1.0.29\ips\IPSBHO.DLL BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [Steam] "c:\program files\steam\steam.exe" -silent uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" mRun: [IAStorIcon] c:\program files\intel\intel® rapid storage technology\IAStorIcon.exe mRun: [Hotkey Utility] c:\program files\emachines\hotkey utility\HotkeyUtility.exe mRun: [NortonOnlineBackupReminder] "c:\program files\symantec\norton online backup\activation\NobuActivation.exe" UNATTENDED mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s mRun: [D-Link D-Link DWA-125] c:\program files\d-link\dwa-125 reva\AirGCFG.exe mRun: [WZCSLDR2] c:\program files\d-link\dwa-125 reva\WZCSLDR2.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRunOnce: [Uninstall Adobe Download Manager] "c:\users\john\appdata\local\temp\getPlusUninst_Adobe.exe" /Get1noarp StartupFolder: c:\users\john\appdata\roaming\micros~1\windows\startm~1\programs\startup\xfire.lnk - c:\program files\xfire\Xfire.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg111v2\WG111v2.exe mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll AppInit_DLLs: . ============= SERVICES / DRIVERS =============== . R?2 D_Link_DWA-125;D_Link_DWA-125 Service;c:\program files\d-link\dwa-125 reva\ANIWZCSdS.exe [2011-1-26 126976] R0 SCMNdisP;General NDIS Protocol Driver;c:\windows\system32\drivers\SCMNdisP.sys [2011-1-17 21728] R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0501000.01d\symds.sys [2011-5-10 340088] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0501000.01d\symefa.sys [2011-5-10 744568] R1 anodlwf;ANOD Network Security Filter driver;c:\windows\system32\drivers\anodlwf.sys [2011-1-26 12800] R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.0.0.125\definitions\bashdefs\20110430.001\BHDrvx86.sys [2011-5-3 802936] R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.0.0.125\definitions\ipsdefs\20110514.001\IDSvix86.sys [2011-5-17 353912] R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0501000.01d\ironx86.sys [2011-5-10 136312] R1 SymNetS;Symantec Network Security WFP Driver;c:\windows\system32\drivers\n360\0501000.01d\symnets.sys [2011-5-10 296568] R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128] R2 D_Link_DWA-125_WPS;D_Link_DWA-125_WPS Service;c:\program files\d-link\dwa-125 reva\ANIWConnService.exe [2011-1-26 40960] R2 Greg_Service;GRegService;c:\program files\emachines\registration\GregHSRW.exe [2009-8-28 1150496] R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files\intel\intel® rapid storage technology\IAStorDataMgrSvc.exe [2010-4-1 13336] R2 N360;Norton 360;c:\program files\norton 360\engine\5.1.0.29\ccsvchst.exe [2011-5-10 130008] R2 SCM_Service;SCM_Service;c:\windows\system32\WinService.exe [2011-1-17 180224] R2 Updater Service;Updater Service;c:\program files\emachines\emachines updater\UpdaterService.exe [2010-4-1 243232] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-5-10 105592] R3 netr28u;D-Link dnetr28u USB Extensible Wireless LAN Card Driver;c:\windows\system32\drivers\Dnetr28u.sys [2011-1-26 807936] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2010-4-1 68200] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2010-4-1 277536] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-1-17 135664] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2011-1-24 39272] S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-1-17 135664] S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232] S3 RTL8187;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v2.sys [2011-1-17 288768] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-1-19 1343400] S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040] . =============== Created Last 30 ================ . 2011-05-17 15:23:41 ——– d—–w- c:\progra~2\McAfee Security Scan 2011-05-17 15:23:40 ——– d—–w- c:\program files\McAfee Security Scan 2011-05-17 15:17:06 ——– d—–w- c:\users\john\appdata\local\{8007732D-7D24-4EEB-9E04-AC421F51D2DE} 2011-05-16 23:08:53 ——– d—–w- c:\users\john\appdata\local\{F7DEBCDB-C77B-4B70-9835-0A3112CF725E} 2011-05-16 00:27:38 ——– d—–w- c:\users\john\appdata\local\{652C2B43-B277-4201-9D65-2F8F979197E4} 2011-05-14 19:49:49 ——– d—–w- c:\program files\ESET 2011-05-14 19:41:06 ——– d—–w- c:\users\john\appdata\local\{0E8BE295-EBDD-4CB7-BB8B-633A49D8C58D} 2011-05-14 05:00:28 123904 —-a-w- c:\windows\system32\poqexec.exe 2011-05-14 04:49:12 ——– d—–w- c:\users\john\appdata\local\ElevatedDiagnostics 2011-05-14 04:35:54 ——– d—–w- c:\users\john\appdata\local\{9E7D8463-1B45-409E-8E55-A6240183A230} 2011-05-12 23:03:19 ——– d—–w- c:\users\john\appdata\local\{581199E2-1C35-4A53-838C-B1AE093C716B} 2011-05-12 02:12:40 75776 —-a-w- c:\windows\system32\drivers\usbccgp.sys 2011-05-12 02:12:40 5888 —-a-w- c:\windows\system32\drivers\usbd.sys 2011-05-12 02:12:40 43008 —-a-w- c:\windows\system32\drivers\usbehci.sys 2011-05-12 02:12:40 284160 —-a-w- c:\windows\system32\drivers\usbport.sys 2011-05-12 02:12:40 258560 —-a-w- c:\windows\system32\drivers\usbhub.sys 2011-05-12 02:12:40 24064 —-a-w- c:\windows\system32\drivers\usbuhci.sys 2011-05-12 02:12:40 20480 —-a-w- c:\windows\system32\drivers\usbohci.sys 2011-05-12 02:12:39 3957632 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-05-12 02:12:38 3901824 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-05-12 00:35:09 ——– d—–w- c:\users\john\appdata\local\{F86AC700-8930-48AF-BB0B-79104BFFF5AC} 2011-05-10 23:29:48 744568 —-a-w- c:\windows\system32\drivers\n360\0501000.01d\symefa.sys 2011-05-10 23:29:48 50168 —-a-w- c:\windows\system32\drivers\n360\0501000.01d\srtspx.sys 2011-05-10 23:29:48 340088 —-a-w- c:\windows\system32\drivers\n360\0501000.01d\symds.sys 2011-05-10 23:29:48 296568 —-a-w- c:\windows\system32\drivers\n360\0501000.01d\symnets.sys 2011-05-10 23:29:47 516216 —-a-w- c:\windows\system32\drivers\n360\0501000.01d\srtsp.sys 2011-05-10 23:29:47 136312 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\ironx86.sys 2011-05-10 23:29:34 ——– d—–w- c:\windows\system32\drivers\n360\0501000.01D 2011-05-10 23:08:43 ——– d—–w- c:\users\john\appdata\local\{32934AAB-5956-4DD6-AC90-1E6228933233} 2011-05-04 03:45:48 ——– d—–w- c:\users\john\appdata\local\NPE 2011-05-04 00:47:53 ——– d—–w- c:\users\john\appdata\roaming\Malwarebytes 2011-05-04 00:47:51 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-05-04 00:47:51 ——– d—–w- c:\progra~2\Malwarebytes 2011-05-04 00:47:48 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-05-04 00:47:48 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-05-03 22:19:13 ——– d—–w- c:\users\john\appdata\local\{6D5A271B-DCF7-4B1B-BF31-134EEFDF89B6} 2011-05-03 04:43:44 ——– d—–w- c:\users\john\.thumbnails 2011-05-03 04:41:32 ——– d—–w- c:\users\john\.gimp-2.6 2011-05-03 04:15:20 ——– d—–w- c:\users\john\appdata\local\PackageAware 2011-05-02 17:01:52 ——– d—–w- c:\users\john\appdata\local\{10B98C34-A8BD-4A6C-A8C6-6C80D0B916A8} 2011-05-01 18:22:59 ——– d—–w- c:\users\john\appdata\local\{D276AC3B-46DC-41E6-A2E2-D3066FE6F749} 2011-04-30 22:50:55 ——– d—–w- c:\users\john\appdata\local\{1B42A745-938E-484C-96AD-EDDE93EB1D27} 2011-04-30 16:57:57 ——– d—–w- c:\users\john\appdata\local\{C0259F46-9B4C-48BC-8A90-0761D7E4EB49} 2011-04-29 22:54:37 ——– d—–w- c:\users\john\appdata\local\{62479380-573A-4821-AC46-096135CA0674} 2011-04-28 22:13:11 ——– d—–w- c:\users\john\appdata\local\{5AC04D5F-CCB0-4579-AE97-9825003325B1} 2011-04-27 18:35:50 ——– d—–w- c:\users\john\appdata\local\{91473006-8ED3-43F1-9D55-C015C4D6CD70} 2011-04-27 06:28:32 ——– d—–w- c:\users\john\appdata\local\{EB242858-B407-4056-A699-075D629517E8} 2011-04-26 18:27:46 ——– d—–w- c:\users\john\appdata\local\{4BB2C536-7AFE-458F-8EB0-208260A5D223} 2011-04-25 20:08:59 ——– d—–w- c:\users\john\appdata\local\{14E80F3F-D297-4E5F-B06A-29225B6DD05A} 2011-04-24 17:36:02 ——– d—–w- c:\users\john\appdata\local\{02A08A8A-8E34-4285-BEFB-9D00CA13FCB9} 2011-04-24 03:55:51 2331136 —-a-w- c:\windows\system32\win32k.sys 2011-04-24 03:55:47 191488 —-a-w- c:\windows\system32\FXSCOVER.exe 2011-04-24 03:55:45 288256 —-a-w- c:\windows\system32\XpsGdiConverter.dll 2011-04-24 03:55:40 1164288 —-a-w- c:\windows\system32\mfc42u.dll 2011-04-24 03:55:40 1137664 —-a-w- c:\windows\system32\mfc42.dll 2011-04-24 03:55:36 740864 —-a-w- c:\windows\system32\inetcomm.dll 2011-04-24 03:55:30 95744 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-04-24 03:55:30 69632 —-a-w- c:\windows\system32\drivers\bowser.sys 2011-04-24 03:55:30 221696 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-04-24 03:55:30 123392 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-04-24 03:33:36 ——– d—–w- c:\users\john\appdata\local\{5BD4ED26-7B5D-471E-91DA-351B0BACEE0B} . ==================== Find3M ==================== . 2011-04-08 11:28:58 41872 —-a-w- c:\windows\system32\xfcodec.dll 2011-03-12 11:31:58 442880 —-a-w- c:\windows\system32\XpsPrint.dll 2011-03-11 05:39:35 1686016 —-a-w- c:\windows\system32\esent.dll 2011-03-11 05:37:34 74240 —-a-w- c:\windows\system32\fsutil.exe 2011-03-03 05:29:23 132608 —-a-w- c:\windows\system32\dnsrslvr.dll 2011-03-03 05:27:30 28672 —-a-w- c:\windows\system32\dnscacheugc.exe 2011-02-26 05:33:07 2614784 —-a-w- c:\windows\explorer.exe 2011-02-24 05:32:44 981504 —-a-w- c:\windows\system32\wininet.dll 2011-02-24 05:30:16 44544 —-a-w- c:\windows\system32\licmgr10.dll 2011-02-24 04:23:48 386048 —-a-w- c:\windows\system32\html.iec 2011-02-24 03:50:26 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2011-02-23 15:27:00 941160 —-a-w- c:\windows\system32\nvdispco322090.dll 2011-02-23 15:27:00 837736 —-a-w- c:\windows\system32\nvgenco322040.dll 2011-02-23 15:27:00 57960 —-a-w- c:\windows\system32\OpenCL.dll 2011-02-23 15:27:00 5654120 —-a-w- c:\windows\system32\nvwgf2um.dll 2011-02-23 15:27:00 4942952 —-a-w- c:\windows\system32\nvcuda.dll 2011-02-23 15:27:00 2895976 —-a-w- c:\windows\system32\nvcuvid.dll 2011-02-23 15:27:00 2251368 —-a-w- c:\windows\system32\nvcuvenc.dll 2011-02-23 15:27:00 1965672 —-a-w- c:\windows\system32\nvapi.dll 2011-02-23 15:27:00 15047272 —-a-w- c:\windows\system32\nvoglv32.dll 2011-02-23 15:27:00 13011560 —-a-w- c:\windows\system32\nvcompiler.dll 2011-02-23 15:27:00 10079336 —-a-w- c:\windows\system32\nvd3dum.dll 2011-02-19 05:33:11 802304 —-a-w- c:\windows\system32\FntCache.dll 2011-02-19 05:32:48 1074176 —-a-w- c:\windows\system32\DWrite.dll 2011-02-19 05:32:35 739840 —-a-w- c:\windows\system32\d2d1.dll 2011-02-19 05:32:08 34304 —-a-w- c:\windows\system32\atmlib.dll 2011-02-19 03:37:02 294912 —-a-w- c:\windows\system32\atmfd.dll 2011-02-18 05:36:26 428032 —-a-w- c:\windows\system32\vbscript.dll 2011-02-18 05:33:29 31232 —-a-w- c:\windows\system32\prevhost.exe . ============= FINISH: 17:39:07.07 =============== I have also attached the attach log just in case you need it :) Thanks for your continued support :)
Hi Jwp1295.

IT APPEARS THAT YOUR LOGS ARE NOW CLEAN :D SO LETS DO A COUPLE OF THINGS TO WRAP THIS UP!! :D

This infection appears to have been cleaned, but as the malware could be configured to run any program a remote
attacker requires, it's impossible to be 100% sure that any machine is clean.


**All of the remaining tools that we have used, as well as logs you created from these tools, can be deleted by
right-clicking them and selecting delete so that they aren't cluttering up your desktop.**


Here are some tips to reduce the potential for spyware infection in the
future
:


1. Make your Internet Explorer more secure - This can be done by following these
simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Use and Update an Anti-Virus Software - I can not overemphasize the need for you
to use and update your Anti-virus application on a regular basis. With the ever increasing number of new variants of
malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a
firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default
configuration can lower your risk greatly. A tutorial on Firewalls and a listing of some available ones can be found
here.
**Do not install more than one firewall program because they will conflict with each other**

4. Make sure you keep your Windows OS current by visiting Windows update regularly to download and
install any critical updates and service packs. Without these you are leaving the back door open.

5. Filehippo's Update Checker.
It is a free utilitiy that scan your computer for installed software, checks the versions and then sends this information to see
if there are any newer releases. Available software updates are displayed and you can decide which ones to download and
install. Among many other types of programs, they includes a number of the Anti-Spyware, Firewall/Security and
Anti-Virus programs that have been recommended (though not all of them). Note: Definition files should be updated
from within the programs themselves. The Update Checker look for newer versions of the software program, not definition
files
.

6. Consider a custom hosts file such as MVPS
HOSTS
. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party
Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom
hosts file.

7. WOT , Web of Trust, As 'Googling' is such
an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors,
deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's
color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
  • Green to go
  • Yellow for caution
  • Red to stop
WOT has an add-on available for both Firefox and IE.

8. Install Spybot - Search and Destroy - Download and install
Spybot - Search and Destroy with its TeaTimer
option. This will provide real time spyware and hijacker protection on your computer alongside your virus protection.
You should scan your computer with the program on a regular basis just as you would with your anti-virus software. A
tutorial on installing and using this product can be found here:
Instructions for - Spybot S & D.

9. Finally, I strongly recommend that you read TonyKlein's good advice
So how did I get infected in the first place?
Thank you so much for your support! the quality of your support was amazing and i will definately reccomend my friends here if they ever need any tech support! Thank you again, you were wonderful! :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI