This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware I need removed

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My pop up blocker is on but I have pop ups. Ran all 5 of my programs and removed what was there but the pop ups are still coming. Need your help again. Here's the log from hijackthis:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:37:15 PM, on 6/1/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19048)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Kodak\KODAK Share Button App\Listener.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
C:\Program Files\Nova Development\Greeting Card Factory Photo Card Maker 2.0\ReminderApp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\FileHippo.com\UpdateChecker.exe
C:\Users\Susan\AppData\Roaming\Microsoft\Windows\xxtlbph.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Secunia\PSI\psi_tray.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Users\Susan\AppData\Roaming\NBT\nbt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Susan\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?fr=mcafee&p=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110512170435.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Monitor] "C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe"
O4 - HKLM\..\Run: [ReminderApp] C:\Program Files\Nova Development\Greeting Card Factory Photo Card Maker 2.0\ReminderApp.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [PMBVolumeWatcher] C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [FileHippo.com] "C:\Program Files\FileHippo.com\UpdateChecker.exe" /background
O4 - HKCU\..\Run: [NBT] C:\Users\Susan\AppData\Roaming\NBT\nbt.exe
O4 - HKCU\..\Run: [cpjd[r2Ddkb9LmTrRp] C:\Users\Susan\AppData\Roaming\Microsoft\Windows\xxtlbph.exe
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Secunia PSI Tray.lnk = C:\Program Files\Secunia\PSI\psi_tray.exe
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: jpip - {B92DD248-E3D5-4A92-B311-C9B841681455} - C:\Program Files\LizardTech\Express View\expressview.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sidlet - {B92DD248-E3D5-4A92-B311-C9B841681455} - C:\Program Files\LizardTech\Express View\expressview.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LeapFrog Connect Device Service - LeapFrog Enterprises, Inc. - C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: PMBDeviceInfoProvider - Sony Corporation - C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files\Secunia\PSI\PSIA.exe
O23 - Service: Secunia Update Agent - Secunia - C:\Program Files\Secunia\PSI\sua.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

–
End of file - 10848 bytes
Hello susanaj and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.

Lets take a closer look at your system with the following scans:

  • Please perform the following scan


    • Please download DDS from here and save it to your desktop.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Right click on the DDS icon and select "Run as Administrator" to run the tool (may take up to 3 minutes to run).
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
    • Please post the contents of the DDS.txt and Attach.txt logs in your next reply.
  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Right click on GMER.exe and select "Run as Administrator" to run the program. If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Please post the DDS logs and the GMER log in your next reply. If you encounter any problems with the scans just let me know :)
Here's the logs: . DDS (Ver_2011-06-02.03) - NTFSx86 Internet Explorer: 8.0.6001.19048 Run by [removed] at 18:31:11 on 2011-06-02 . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\SLsvc.exe C:\Program Files\Dell\DellDock\DockLogin.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\AERTSrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe C:\Windows\system32\rundll32.exe C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe C:\Windows\system32\PSIService.exe C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files\Secunia\PSI\PSIA.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Kodak\KODAK Share Button App\Listener.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Dell Support Center\bin\sprtcmd.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe C:\Program Files\Nova Development\Greeting Card Factory Photo Card Maker 2.0\ReminderApp.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\McAfee.com\Agent\mcagent.exe C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\FileHippo.com\UpdateChecker.exe C:\Users\Susan\AppData\Roaming\Microsoft\Windows\xxtlbph.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Secunia\PSI\psi_tray.exe C:\Program Files\Secunia\PSI\sua.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\system32\taskeng.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\Users\Susan\AppData\Roaming\NBT\nbt.exe c:\PROGRA~1\mcafee\msc\mcupdmgr.exe c:\PROGRA~1\mcafee.com\agent\McUpdate.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\Susan\Desktop\dds.scr C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ mSearch Bar = hxxp://www.google.com uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20110512170435.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [FileHippo.com] "c:\program files\filehippo.com\UpdateChecker.exe" /background uRun: [NBT] c:\users\susan\appdata\roaming\nbt\nbt.exe uRun: [cpjd[r2Ddkb9LmTrRp] c:\users\susan\appdata\roaming\microsoft\windows\xxtlbph.exe mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [Monitor] "c:\program files\leapfrog\leapfrog connect\Monitor.exe" mRun: [ReminderApp] c:\program files\nova development\greeting card factory photo card maker 2.0\ReminderApp.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [PMBVolumeWatcher] c:\program files\sony\pmb\PMBVolumeWatcher.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-explorer: NoAutoUpdate = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Google Sidewiki… IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{D27BA063-362D-43E4-A87C-9B4E94CE0394} : DhcpNameServer = [removed] [removed] Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Handler: jpip - {B92DD248-E3D5-4A92-B311-C9B841681455} - c:\program files\lizardtech\express view\expressview.dll Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Handler: sidlet - {B92DD248-E3D5-4A92-B311-C9B841681455} - c:\program files\lizardtech\express view\expressview.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll Notify: igfxcui - igfxdev.dll . ============= SERVICES / DRIVERS =============== . R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86 R? FlyUsb;FLY Fusion R? fssfltr;fssfltr R? fsssvc;Windows Live Family Safety Service R? mfebopk;McAfee Inc. mfebopk R? mferkdet;McAfee Inc. mferkdet R? mferkdk;McAfee Inc. mferkdk R? PSI;PSI R? TomTomHOMEService;TomTomHOMEService R? wlcrasvc;Windows Live Mesh remote connections service R? WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0 S? AERTFilters;Andrea RT Filters Service S? cfwids;McAfee Inc. cfwids S? DockLoginService;Dock Login Service S? FontCache;Windows Font Cache Service S? Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service S? Lavasoft Kernexplorer;Lavasoft helper driver S? Lbd;Lbd S? McAfee SiteAdvisor Service;McAfee SiteAdvisor Service S? McMPFSvc;McAfee Personal Firewall Service S? McNaiAnn;McAfee VirusScan Announcer S? McProxy;McAfee Proxy Service S? McShield;McShield S? mfeavfk;McAfee Inc. mfeavfk S? mfefire;McAfee Firewall Core Service S? mfefirek;McAfee Inc. mfefirek S? mfehidk;McAfee Inc. mfehidk S? mfenlfk;McAfee NDIS Light Filter S? mfevtp;McAfee Validation Trust Protection Service S? mfewfpk;McAfee Inc. mfewfpk S? PMBDeviceInfoProvider;PMBDeviceInfoProvider S? Secunia PSI Agent;Secunia PSI Agent S? Secunia Update Agent;Secunia Update Agent . =============== Created Last 30 ================ . 2011-05-27 02:48:49 ——– d—–w- c:\users\susan\appdata\roaming\iWin 2011-05-23 17:30:44 ——– d—–w- c:\users\susan\appdata\roaming\NBT 2011-05-23 17:30:41 ——– d—–w- c:\program files\MPAccess 2011-05-20 03:06:10 ——– d—–w- c:\users\susan\appdata\local\{D99E27A1-64D1-4196-B3C4-F593DF9389E5} 2011-05-12 03:24:57 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat . ==================== Find3M ==================== . 2011-05-29 14:11:30 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-05-29 14:11:20 22712 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-05-20 03:06:23 848 –sha-w- c:\programdata\KGyGaAvL.sys 2011-05-01 12:03:05 404128 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-05-01 11:59:30 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-04-18 10:23:39 16432 —-a-w- c:\windows\system32\lsdelete.exe 2011-04-14 19:01:38 95824 —-a-w- c:\windows\system32\drivers\mfeapfk.sys 2011-04-14 19:01:38 9344 —-a-w- c:\windows\system32\drivers\mfeclnk.sys 2011-04-14 19:01:38 84488 —-a-w- c:\windows\system32\drivers\mferkdet.sys 2011-04-14 19:01:38 64584 —-a-w- c:\windows\system32\drivers\mfenlfk.sys 2011-04-14 19:01:38 56064 —-a-w- c:\windows\system32\drivers\cfwids.sys 2011-04-14 19:01:38 52320 —-a-w- c:\windows\system32\drivers\mfebopk.sys 2011-04-14 19:01:38 387480 —-a-w- c:\windows\system32\drivers\mfehidk.sys 2011-04-14 19:01:38 314088 —-a-w- c:\windows\system32\drivers\mfefirek.sys 2011-04-14 19:01:38 165032 —-a-w- c:\windows\system32\drivers\mfewfpk.sys 2011-04-14 19:01:38 153280 —-a-w- c:\windows\system32\drivers\mfeavfk.sys 2011-03-12 21:55:52 876032 —-a-w- c:\windows\system32\XpsPrint.dll 2011-03-10 17:03:51 1162240 —-a-w- c:\windows\system32\mfc42u.dll 2011-03-10 17:03:51 1136640 —-a-w- c:\windows\system32\mfc42.dll . ============= FINISH: 18:32:00.51 =============== . ==== Installed Programs ====================== . Update for Microsoft Office 2007 (KB2508958) 32 Bit HP CIO Components Installer Acrobat.com Ad-Aware Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader X (10.0.1) Adobe Shockwave Player 11.5 Apple Application Support Apple Mobile Device Support Apple Software Update AudioLabel Bonjour BufferChm Canon Camera Access Library Canon Camera Support Core Library Canon Camera Window DC_DV 5 for ZoomBrowser EX Canon Camera Window DC_DV 6 for ZoomBrowser EX Canon Camera Window MC 6 for ZoomBrowser EX Canon RAW Image Task for ZoomBrowser EX Canon RemoteCapture Task for ZoomBrowser EX Canon Utilities Digital Photo Professional 2.1 Canon Utilities EOS Utility Canon Utilities PhotoStitch Canon Utilities ZoomBrowser EX Color Efex Pro 3.0 Corel Sampler Compatibility Pack for the 2007 Office system Copy Copy Utility Corel MediaOne Corel Paint Shop Pro Photo X2 Corel Painter Photo Essentials 4 D3DX10 Dell Dock Dell Support Center (Support Software) DELL0604 Destinations DeviceDiscovery Digital Concepts Image Manager DJ_AIO_05_F4400_Software_Min EDocs EOS USB WIA Driver ESET Online Scanner v3 F4400 Family Tree Maker 2010 ffdshow [rev 2527] [2008-12-19] FileHippo.com Update Checker GPBaseService2 Greeting Card Factory Photo Card Maker 2.0 Haali Media Splitter Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) HP Customer Participation Program 13.0 HP Deskjet F4400 Printer Driver Software 13.0 Rel .5 HP Imaging Device Functions 13.0 HP Print Projects 1.0 HP Smart Web Printing 4.5 HP Solution Center 13.0 HP Update HPPhotoGadget hpPrintProjects HPProductAssistant hpWLPGInstaller ImageSkill Background Remover 3 Intel® Graphics Media Accelerator Driver Intel® PRO Network Connections 12.1.11.0 Java Auto Updater Java™ 6 Update 25 Java™ 6 Update 7 Junk Mail filter update KODAK Share Button App LeapFrog Connect LeapFrog Leapster2 Plugin LeapFrog My Pals Plugin LeapFrog Tag Plugin LizardTech DjVu Control Lizardtech Express View Browser Plug-in Malwarebytes' Anti-Malware version 1.51.0.1200 MarketResearch Mavis Beacon Teaches Typing 18 McAfee Internet Security McAfee Virtual Technician Mesh Runtime Messenger Companion Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft Application Error Reporting Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office Live Add-in 1.5 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Primary Interoperability Assemblies 2005 Microsoft Search Enhancement Pack Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable - KB2467175 Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 Microsoft Works Microsoft WSE 3.0 MSVCRT MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) NBT oDesk Team OGA Notifier 2.0.0048.0 PHOTORECOVERY LE PMB QuickTime Realtek High Definition Audio Driver Roxio Creator Audio Roxio Creator Copy Roxio Creator Data Roxio Creator DE Roxio Creator Tools Roxio Express Labeler 3 Roxio Update Manager SA3020 Device Manager SA30xx Media Converter Scan ScanToWeb Secunia PSI (2.0.0.3001) Security Update for 2007 Microsoft Office System (KB2288621) Security Update for 2007 Microsoft Office System (KB2288931) Security Update for 2007 Microsoft Office System (KB2345043) Security Update for 2007 Microsoft Office System (KB2466156) Security Update for 2007 Microsoft Office System (KB2509488) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft Office Access 2007 (KB979440) Security Update for Microsoft Office Excel 2007 (KB2464583) Security Update for Microsoft Office Groove 2007 (KB2494047) Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office PowerPoint 2007 (KB2535818) Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623) Security Update for Microsoft Office Publisher 2007 (KB2284697) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB2344993) Security Update for Windows Media Encoder (KB2447961) Security Update for Windows Media Encoder (KB979332) Segoe UI SmartWebPrinting SolutionCenter Spelling Dictionaries Support For Adobe Reader 9 Status TC Web Conferencing TomTom HOME 2.7.3.1894 TomTom HOME Visual Studio Merge Modules Toolbox TrayApp Ulead Photo Explorer 8.0 SE Uninstall Dual Mode Camera (ST606) Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Infopath 2007 Help (KB963662) Update for Microsoft Office OneNote 2007 (KB980729) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Outlook 2007 (KB2509470) Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) Update for Outlook 2007 Junk Email Filter (KB2536413) Use the entry named LeapFrog Connect to uninstall (LeapFrog Leapster2 Plugin) Use the entry named LeapFrog Connect to uninstall (LeapFrog My Pals Plugin) Use the entry named LeapFrog Connect to uninstall (LeapFrog Tag Plugin) Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 Visual C++ 8.0 CRT (x86) WinSXS MSM WebReg Windows Driver Package - Eastman Kodak KODAK Digital Camera (01/29/2010 1.4.1.0) Windows Driver Package - LeapFrog (FlyUsb) USB (11/05/2008 1.1.1.0) Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net (09/10/2009 02.03.05.012) Windows Live Communications Platform Windows Live Essentials Windows Live Family Safety Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Mail Windows Live Mesh Windows Live Mesh ActiveX Control for Remote Connections Windows Live Messenger Windows Live Messenger Companion Core Windows Live MIME IFilter Windows Live Movie Maker Windows Live OneCare safety scanner Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live Remote Client Windows Live Remote Client Resources Windows Live Remote Service Windows Live Remote Service Resources Windows Live SOXE Windows Live SOXE Definitions Windows Live Sync Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources Windows Media Encoder 9 Series WOT for Internet Explorer WOT Services . ==== End Of File ===========================
Here's the gmer log:

GMER 1.0.15.15640 - http://www.gmer.net
Rootkit scan 2011-06-03 06:34:58
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD3200AAKS-75L9A0 rev.01.03E01
Running: gmer.exe; Driver: C:\Users\Susan\AppData\Local\Temp\pgloypow.sys


—- System - GMER 1.0.15 —-

Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0x8823A1E8]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0x8823A212]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0x8823A1FE]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0x8823A1D4]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwYieldExecution 82A71982 5 Bytes JMP 8823A1D8 \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 82C370D3 5 Bytes JMP 8823A216 \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 82C5682A 7 Bytes JMP 8823A1EC \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 82C56AED 5 Bytes JMP 8823A202 \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
? C:\Users\Susan\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[372] kernel32.dll!LoadLibraryW 76D49362 5 Bytes JMP 715A9AE2 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[372] kernel32.dll!LoadLibraryA 76D494DC 5 Bytes JMP 715A9A20 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Windows\System32\svchost.exe[556] ntdll.dll!NtCreateFile 77BC4224 5 Bytes JMP 000B0000
.text C:\Windows\System32\svchost.exe[556] ntdll.dll!NtCreateProcess 77BC42E4 5 Bytes JMP 000B0FC0
.text C:\Windows\System32\svchost.exe[556] ntdll.dll!NtProtectVirtualMemory 77BC4B84 5 Bytes JMP 000B0FE5
.text C:\Windows\System32\svchost.exe[556] kernel32.dll!GetStartupInfoW 76D21929 5 Bytes JMP 00090098
.text C:\Windows\System32\svchost.exe[556] kernel32.dll!GetStartupInfoA 76D219C9 5 Bytes JMP 00090F5C
.text C:\Windows\System32\svchost.exe[556] kernel32.dll!CreateProcessW 76D21BF3 5 Bytes JMP 00090F2D
.text C:\Windows\System32\svchost.exe[556] kernel32.dll!CreateProcessA 76D21C28 5 Bytes JMP 000900C4
.text C:\Windows\System32\svchost.exe[556] kernel32.dll!VirtualProtect 76D21DC3 5 Bytes JMP 00090F8F
.text C:\Windows\System32\svchost.exe[556] kernel32.dll!CreateNamedPipeA 76D22EF5 5 Bytes JMP 0009002C
.text C:\Windows\System32\svchost.exe[556] kernel32.dll!CreateNamedPipeW 76D25C0C 5 Bytes JMP 00090047
.text C:\Windows\System32\svchost.exe[556] kernel32.dll!CreatePipe 76D48E6E 5 Bytes JMP 00090F6D
.text C:\Windows\System32\svchost.exe[556] kernel32.dll!LoadLibraryExW 76D49109 5 Bytes JMP 00090FAA
.text C:\Windows\System32\svchost.exe[556] kernel32.dll!LoadLibraryW 76D49362 5 Bytes JMP 00090069
.text C:\Windows\System32\svchost.exe[556] kernel32.dll!LoadLibraryExA 76D494B4 5 Bytes JMP 00090FD1
.text C:\Windows\System32\svchost.exe[556] kernel32.dll!LoadLibraryA 76D494DC 5 Bytes JMP 00090058
.text C:\Windows\System32\svchost.exe[556] kernel32.dll!VirtualProtectEx 76D4DBDA 5 Bytes JMP 00090F7E
.text C:\Windows\System32\svchost.exe[556] kernel32.dll!GetProcAddress 76D6903B 5 Bytes JMP 00090F1C
.text C:\Windows\System32\svchost.exe[556] kernel32.dll!CreateFileW 76D6AECB 5 Bytes JMP 00090011
.text C:\Windows\System32\svchost.exe[556] kernel32.dll!CreateFileA 76D6CE5F 5 Bytes JMP 00090000
.text C:\Windows\System32\svchost.exe[556] kernel32.dll!WinExec 76DB5CF7 5 Bytes JMP 000900A9
.text C:\Windows\System32\svchost.exe[556] msvcrt.dll!_wsystem 77407F2F 5 Bytes JMP 001B0081
.text C:\Windows\System32\svchost.exe[556] msvcrt.dll!system 7740804B 5 Bytes JMP 001B0070
.text C:\Windows\System32\svchost.exe[556] msvcrt.dll!_creat 7740BBE1 5 Bytes JMP 001B003A
.text C:\Windows\System32\svchost.exe[556] msvcrt.dll!_open 7740D106 5 Bytes JMP 001B000C
.text C:\Windows\System32\svchost.exe[556] msvcrt.dll!_wcreat 7740D326 5 Bytes JMP 001B0055
.text C:\Windows\System32\svchost.exe[556] msvcrt.dll!_wopen 7740D501 5 Bytes JMP 001B001D
.text C:\Windows\System32\svchost.exe[556] ADVAPI32.dll!RegCreateKeyExA 76E239AB 5 Bytes JMP 000A003D
.text C:\Windows\System32\svchost.exe[556] ADVAPI32.dll!RegCreateKeyA 76E23BA9 5 Bytes JMP 000A002C
.text C:\Windows\System32\svchost.exe[556] ADVAPI32.dll!RegOpenKeyA 76E289C7 5 Bytes JMP 000A0FE5
.text C:\Windows\System32\svchost.exe[556] ADVAPI32.dll!RegCreateKeyW 76E3391E 5 Bytes JMP 000A0F9B
.text C:\Windows\System32\svchost.exe[556] ADVAPI32.dll!RegCreateKeyExW 76E341F1 5 Bytes JMP 000A004E
.text C:\Windows\System32\svchost.exe[556] ADVAPI32.dll!RegOpenKeyExA 76E37C42 5 Bytes JMP 000A000A
.text C:\Windows\System32\svchost.exe[556] ADVAPI32.dll!RegOpenKeyW 76E3E2B5 5 Bytes JMP 000A0FD4
.text C:\Windows\System32\svchost.exe[556] ADVAPI32.dll!RegOpenKeyExW 76E47BA1 5 Bytes JMP 000A001B
.text C:\Windows\System32\svchost.exe[556] WS2_32.dll!socket 773836D1 5 Bytes JMP 001A0FEF
.text C:\Windows\system32\services.exe[716] ntdll.dll!NtCreateFile 77BC4224 5 Bytes JMP 00140000
.text C:\Windows\system32\services.exe[716] ntdll.dll!NtCreateProcess 77BC42E4 5 Bytes JMP 00140FE5
.text C:\Windows\system32\services.exe[716] ntdll.dll!NtProtectVirtualMemory 77BC4B84 5 Bytes JMP 0014001B
.text C:\Windows\system32\services.exe[716] kernel32.dll!GetStartupInfoW 76D21929 5 Bytes JMP 001500BD
.text C:\Windows\system32\services.exe[716] kernel32.dll!GetStartupInfoA 76D219C9 5 Bytes JMP 001500A2
.text C:\Windows\system32\services.exe[716] kernel32.dll!CreateProcessW 76D21BF3 5 Bytes JMP 001500F3
.text C:\Windows\system32\services.exe[716] kernel32.dll!CreateProcessA 76D21C28 5 Bytes JMP 001500D8
.text C:\Windows\system32\services.exe[716] kernel32.dll!VirtualProtect 76D21DC3 5 Bytes JMP 00150F92
.text C:\Windows\system32\services.exe[716] kernel32.dll!CreateNamedPipeA 76D22EF5 5 Bytes JMP 00150FD4
.text C:\Windows\system32\services.exe[716] kernel32.dll!CreateNamedPipeW 76D25C0C 5 Bytes JMP 00150025
.text C:\Windows\system32\services.exe[716] kernel32.dll!CreatePipe 76D48E6E 5 Bytes JMP 00150091
.text C:\Windows\system32\services.exe[716] kernel32.dll!LoadLibraryExW 76D49109 5 Bytes JMP 0015006C
.text C:\Windows\system32\services.exe[716] kernel32.dll!LoadLibraryW 76D49362 5 Bytes JMP 00150040
.text C:\Windows\system32\services.exe[716] kernel32.dll!LoadLibraryExA 76D494B4 5 Bytes JMP 0015005B
.text C:\Windows\system32\services.exe[716] kernel32.dll!LoadLibraryA 76D494DC 5 Bytes JMP 00150FB9
.text C:\Windows\system32\services.exe[716] kernel32.dll!VirtualProtectEx 76D4DBDA 5 Bytes JMP 00150F81
.text C:\Windows\system32\services.exe[716] kernel32.dll!GetProcAddress 76D6903B 5 Bytes JMP 00150F41
.text C:\Windows\system32\services.exe[716] kernel32.dll!CreateFileW 76D6AECB 5 Bytes JMP 0015000A
.text C:\Windows\system32\services.exe[716] kernel32.dll!CreateFileA 76D6CE5F 5 Bytes JMP 00150FEF
.text C:\Windows\system32\services.exe[716] kernel32.dll!WinExec 76DB5CF7 5 Bytes JMP 00150F5C
.text C:\Windows\system32\services.exe[716] ADVAPI32.dll!RegCreateKeyExA 76E239AB 5 Bytes JMP 0016007A
.text C:\Windows\system32\services.exe[716] ADVAPI32.dll!RegCreateKeyA 76E23BA9 5 Bytes JMP 0016004E
.text C:\Windows\system32\services.exe[716] ADVAPI32.dll!RegOpenKeyA 76E289C7 5 Bytes JMP 00160000
.text C:\Windows\system32\services.exe[716] ADVAPI32.dll!RegCreateKeyW 76E3391E 5 Bytes JMP 00160069
.text C:\Windows\system32\services.exe[716] ADVAPI32.dll!RegCreateKeyExW 76E341F1 5 Bytes JMP 0016008B
.text C:\Windows\system32\services.exe[716] ADVAPI32.dll!RegOpenKeyExA 76E37C42 5 Bytes JMP 00160022
.text C:\Windows\system32\services.exe[716] ADVAPI32.dll!RegOpenKeyW 76E3E2B5 5 Bytes JMP 00160011
.text C:\Windows\system32\services.exe[716] ADVAPI32.dll!RegOpenKeyExW 76E47BA1 5 Bytes JMP 00160033
.text C:\Windows\system32\services.exe[716] msvcrt.dll!_wsystem 77407F2F 5 Bytes JMP 0048006E
.text C:\Windows\system32\services.exe[716] msvcrt.dll!system 7740804B 5 Bytes JMP 00480053
.text C:\Windows\system32\services.exe[716] msvcrt.dll!_creat 7740BBE1 5 Bytes JMP 0048001D
.text C:\Windows\system32\services.exe[716] msvcrt.dll!_open 7740D106 5 Bytes JMP 00480000
.text C:\Windows\system32\services.exe[716] msvcrt.dll!_wcreat 7740D326 5 Bytes JMP 0048002E
.text C:\Windows\system32\services.exe[716] msvcrt.dll!_wopen 7740D501 5 Bytes JMP 00480FE3
.text C:\Windows\system32\services.exe[716] WS2_32.dll!socket 773836D1 5 Bytes JMP 0017000A
.text C:\Windows\system32\lsass.exe[732] ntdll.dll!NtCreateFile 77BC4224 5 Bytes JMP 00190FEF
.text C:\Windows\system32\lsass.exe[732] ntdll.dll!NtCreateProcess 77BC42E4 5 Bytes JMP 00190FCA
.text C:\Windows\system32\lsass.exe[732] ntdll.dll!NtProtectVirtualMemory 77BC4B84 5 Bytes JMP 00190000
.text C:\Windows\system32\lsass.exe[732] kernel32.dll!GetStartupInfoW 76D21929 5 Bytes JMP 001E0F50
.text C:\Windows\system32\lsass.exe[732] kernel32.dll!GetStartupInfoA 76D219C9 5 Bytes JMP 001E0F6B
.text C:\Windows\system32\lsass.exe[732] kernel32.dll!CreateProcessW 76D21BF3 5 Bytes JMP 001E0F1A
.text C:\Windows\system32\lsass.exe[732] kernel32.dll!CreateProcessA 76D21C28 5 Bytes JMP 001E0F2B
.text C:\Windows\system32\lsass.exe[732] kernel32.dll!VirtualProtect 76D21DC3 5 Bytes JMP 001E0067
.text C:\Windows\system32\lsass.exe[732] kernel32.dll!CreateNamedPipeA 76D22EF5 5 Bytes JMP 001E000A
.text C:\Windows\system32\lsass.exe[732] kernel32.dll!CreateNamedPipeW 76D25C0C 5 Bytes JMP 001E0FC3
.text C:\Windows\system32\lsass.exe[732] kernel32.dll!CreatePipe 76D48E6E 5 Bytes JMP 001E0096
.text C:\Windows\system32\lsass.exe[732] kernel32.dll!LoadLibraryExW 76D49109 5 Bytes JMP 001E0F8D
.text C:\Windows\system32\lsass.exe[732] kernel32.dll!LoadLibraryW 76D49362 5 Bytes JMP 001E0F9E
.text C:\Windows\system32\lsass.exe[732] kernel32.dll!LoadLibraryExA 76D494B4 5 Bytes JMP 001E004A
.text C:\Windows\system32\lsass.exe[732] kernel32.dll!LoadLibraryA 76D494DC 5 Bytes JMP 001E0025
.text C:\Windows\system32\lsass.exe[732] kernel32.dll!VirtualProtectEx 76D4DBDA 5 Bytes JMP 001E0F7C
.text C:\Windows\system32\lsass.exe[732] kernel32.dll!GetProcAddress 76D6903B 5 Bytes JMP 001E00CC
.text C:\Windows\system32\lsass.exe[732] kernel32.dll!CreateFileW 76D6AECB 5 Bytes JMP 001E0FD4
.text C:\Windows\system32\lsass.exe[732] kernel32.dll!CreateFileA 76D6CE5F 5 Bytes JMP 001E0FE5
.text C:\Windows\system32\lsass.exe[732] kernel32.dll!WinExec 76DB5CF7 5 Bytes JMP 001E00B1
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!RegCreateKeyExA 76E239AB 5 Bytes JMP 00860F7C
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!RegCreateKeyA 76E23BA9 5 Bytes JMP 00860014
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!RegOpenKeyA 76E289C7 5 Bytes JMP 00860FEF
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!RegCreateKeyW 76E3391E 5 Bytes JMP 00860F8D
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!RegCreateKeyExW 76E341F1 5 Bytes JMP 00860F6B
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!RegOpenKeyExA 76E37C42 5 Bytes JMP 00860FB9
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!RegOpenKeyW 76E3E2B5 5 Bytes JMP 00860FCA
.text C:\Windows\system32\lsass.exe[732] ADVAPI32.dll!RegOpenKeyExW 76E47BA1 5 Bytes JMP 00860FA8
.text C:\Windows\system32\lsass.exe[732] msvcrt.dll!_wsystem 77407F2F 5 Bytes JMP 00880FA3
.text C:\Windows\system32\lsass.exe[732] msvcrt.dll!system 7740804B 5 Bytes JMP 00880FBE
.text C:\Windows\system32\lsass.exe[732] msvcrt.dll!_creat 7740BBE1 5 Bytes JMP 0088001D
.text C:\Windows\system32\lsass.exe[732] msvcrt.dll!_open 7740D106 5 Bytes JMP 00880FEF
.text C:\Windows\system32\lsass.exe[732] msvcrt.dll!_wcreat 7740D326 5 Bytes JMP 0088002E
.text C:\Windows\system32\lsass.exe[732] msvcrt.dll!_wopen 7740D501 5 Bytes JMP 0088000C
.text C:\Windows\system32\lsass.exe[732] WS2_32.dll!socket 773836D1 5 Bytes JMP 00870FEF
.text C:\Windows\system32\svchost.exe[904] ntdll.dll!NtCreateFile 77BC4224 5 Bytes JMP 001D0000
.text C:\Windows\system32\svchost.exe[904] ntdll.dll!NtCreateProcess 77BC42E4 5 Bytes JMP 001D001B
.text C:\Windows\system32\svchost.exe[904] ntdll.dll!NtProtectVirtualMemory 77BC4B84 5 Bytes JMP 001D0FE5
.text C:\Windows\system32\svchost.exe[904] kernel32.dll!GetStartupInfoW 76D21929 5 Bytes JMP 001E00BD
.text C:\Windows\system32\svchost.exe[904] kernel32.dll!GetStartupInfoA 76D219C9 5 Bytes JMP 001E00AC
.text C:\Windows\system32\svchost.exe[904] kernel32.dll!CreateProcessW 76D21BF3 5 Bytes JMP 001E0F41
.text C:\Windows\system32\svchost.exe[904] kernel32.dll!CreateProcessA 76D21C28 5 Bytes JMP 001E0F5C
.text C:\Windows\system32\svchost.exe[904] kernel32.dll!VirtualProtect 76D21DC3 5 Bytes JMP 001E0F92
.text C:\Windows\system32\svchost.exe[904] kernel32.dll!CreateNamedPipeA 76D22EF5 5 Bytes JMP 001E002C
.text C:\Windows\system32\svchost.exe[904] kernel32.dll!CreateNamedPipeW 76D25C0C 5 Bytes JMP 001E0051
.text C:\Windows\system32\svchost.exe[904] kernel32.dll!CreatePipe 76D48E6E 5 Bytes JMP 001E0F77
.text C:\Windows\system32\svchost.exe[904] kernel32.dll!LoadLibraryExW 76D49109 5 Bytes JMP 001E0FAF
.text C:\Windows\system32\svchost.exe[904] kernel32.dll!LoadLibraryW 76D49362 5 Bytes JMP 001E006C
.text C:\Windows\system32\svchost.exe[904] kernel32.dll!LoadLibraryExA 76D494B4 5 Bytes JMP 001E0FC0
.text C:\Windows\system32\svchost.exe[904] kernel32.dll!LoadLibraryA 76D494DC 5 Bytes JMP 001E0FE5
.text C:\Windows\system32\svchost.exe[904] kernel32.dll!VirtualProtectEx 76D4DBDA 5 Bytes JMP 001E0087
.text C:\Windows\system32\svchost.exe[904] kernel32.dll!GetProcAddress 76D6903B 5 Bytes JMP 001E00F3
.text C:\Windows\system32\svchost.exe[904] kernel32.dll!CreateFileW 76D6AECB 5 Bytes JMP 001E001B
.text C:\Windows\system32\svchost.exe[904] kernel32.dll!CreateFileA 76D6CE5F 5 Bytes JMP 001E0000
.text C:\Windows\system32\svchost.exe[904] kernel32.dll!WinExec 76DB5CF7 5 Bytes JMP 001E00D8
.text C:\Windows\system32\svchost.exe[904] msvcrt.dll!_wsystem 77407F2F 5 Bytes JMP 00820F90
.text C:\Windows\system32\svchost.exe[904] msvcrt.dll!system 7740804B 5 Bytes JMP 00820FAB
.text C:\Windows\system32\svchost.exe[904] msvcrt.dll!_creat 7740BBE1 5 Bytes JMP 0082001B
.text C:\Windows\system32\svchost.exe[904] msvcrt.dll!_open 7740D106 5 Bytes JMP 00820FE3
.text C:\Windows\system32\svchost.exe[904] msvcrt.dll!_wcreat 7740D326 5 Bytes JMP 00820FC6
.text C:\Windows\system32\svchost.exe[904] msvcrt.dll!_wopen 7740D501 5 Bytes JMP 00820000
.text C:\Windows\system32\svchost.exe[904] ADVAPI32.dll!RegCreateKeyExA 76E239AB 5 Bytes JMP 001F002F
.text C:\Windows\system32\svchost.exe[904] ADVAPI32.dll!RegCreateKeyA 76E23BA9 5 Bytes JMP 001F0FA8
.text C:\Windows\system32\svchost.exe[904] ADVAPI32.dll!RegOpenKeyA 76E289C7 5 Bytes JMP 001F000A
.text C:\Windows\system32\svchost.exe[904] ADVAPI32.dll!RegCreateKeyW 76E3391E 5 Bytes JMP 001F0F8D
.text C:\Windows\system32\svchost.exe[904] ADVAPI32.dll!RegCreateKeyExW 76E341F1 5 Bytes JMP 001F0F72
.text C:\Windows\system32\svchost.exe[904] ADVAPI32.dll!RegOpenKeyExA 76E37C42 5 Bytes JMP 001F0FDE
.text C:\Windows\system32\svchost.exe[904] ADVAPI32.dll!RegOpenKeyW 76E3E2B5 5 Bytes JMP 001F0FEF
.text C:\Windows\system32\svchost.exe[904] ADVAPI32.dll!RegOpenKeyExW 76E47BA1 5 Bytes JMP 001F0FCD
.text C:\Windows\system32\svchost.exe[904] WS2_32.dll!socket 773836D1 5 Bytes JMP 00200000
.text C:\Windows\System32\svchost.exe[956] ntdll.dll!NtCreateFile 77BC4224 5 Bytes JMP 0031000A
.text C:\Windows\System32\svchost.exe[956] ntdll.dll!NtCreateProcess 77BC42E4 5 Bytes JMP 0031002C
.text C:\Windows\System32\svchost.exe[956] ntdll.dll!NtProtectVirtualMemory 77BC4B84 5 Bytes JMP 0031001B
.text C:\Windows\System32\svchost.exe[956] kernel32.dll!GetStartupInfoW 76D21929 5 Bytes JMP 002F008A
.text C:\Windows\System32\svchost.exe[956] kernel32.dll!GetStartupInfoA 76D219C9 5 Bytes JMP 002F0065
.text C:\Windows\System32\svchost.exe[956] kernel32.dll!CreateProcessW 76D21BF3 5 Bytes JMP 002F0EFD
.text C:\Windows\System32\svchost.exe[956] kernel32.dll!CreateProcessA 76D21C28 5 Bytes JMP 002F0F0E
.text C:\Windows\System32\svchost.exe[956] kernel32.dll!VirtualProtect 76D21DC3 5 Bytes JMP 002F0F5C
.text C:\Windows\System32\svchost.exe[956] kernel32.dll!CreateNamedPipeA 76D22EF5 5 Bytes JMP 002F0FC3
.text C:\Windows\System32\svchost.exe[956] kernel32.dll!CreateNamedPipeW 76D25C0C 5 Bytes JMP 002F001E
.text C:\Windows\System32\svchost.exe[956] kernel32.dll!CreatePipe 76D48E6E 5 Bytes JMP 002F0F3A
.text C:\Windows\System32\svchost.exe[956] kernel32.dll!LoadLibraryExW 76D49109 5 Bytes JMP 002F0040
.text C:\Windows\System32\svchost.exe[956] kernel32.dll!LoadLibraryW 76D49362 5 Bytes JMP 002F002F
.text C:\Windows\System32\svchost.exe[956] kernel32.dll!LoadLibraryExA 76D494B4 5 Bytes JMP 002F0F83
.text C:\Windows\System32\svchost.exe[956] kernel32.dll!LoadLibraryA 76D494DC 5 Bytes JMP 002F0FA8
.text C:\Windows\System32\svchost.exe[956] kernel32.dll!VirtualProtectEx 76D4DBDA 5 Bytes JMP 002F0F4B
.text C:\Windows\System32\svchost.exe[956] kernel32.dll!GetProcAddress 76D6903B 5 Bytes JMP 002F0EE2
.text C:\Windows\System32\svchost.exe[956] kernel32.dll!CreateFileW 76D6AECB 5 Bytes JMP 002F0FD4
.text C:\Windows\System32\svchost.exe[956] kernel32.dll!CreateFileA 76D6CE5F 5 Bytes JMP 002F0FEF
.text C:\Windows\System32\svchost.exe[956] kernel32.dll!WinExec 76DB5CF7 5 Bytes JMP 002F0F29
.text C:\Windows\System32\svchost.exe[956] msvcrt.dll!_wsystem 77407F2F 5 Bytes JMP 00330F8B
.text C:\Windows\System32\svchost.exe[956] msvcrt.dll!system 7740804B 5 Bytes JMP 00330016
.text C:\Windows\System32\svchost.exe[956] msvcrt.dll!_creat 7740BBE1 5 Bytes JMP 00330FB7
.text C:\Windows\System32\svchost.exe[956] msvcrt.dll!_open 7740D106 5 Bytes JMP 00330FEF
.text C:\Windows\System32\svchost.exe[956] msvcrt.dll!_wcreat 7740D326 5 Bytes JMP 00330FA6
.text C:\Windows\System32\svchost.exe[956] msvcrt.dll!_wopen 7740D501 5 Bytes JMP 00330FDE
.text C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!RegCreateKeyExA 76E239AB 5 Bytes JMP 00300040
.text C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!RegCreateKeyA 76E23BA9 5 Bytes JMP 00300FA8
.text C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!RegOpenKeyA 76E289C7 5 Bytes JMP 00300FEF
.text C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!RegCreateKeyW 76E3391E 5 Bytes JMP 0030002F
.text C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!RegCreateKeyExW 76E341F1 5 Bytes JMP 00300051
.text C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!RegOpenKeyExA 76E37C42 5 Bytes JMP 00300014
.text C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!RegOpenKeyW 76E3E2B5 5 Bytes JMP 00300FD4
.text C:\Windows\System32\svchost.exe[956] ADVAPI32.dll!RegOpenKeyExW 76E47BA1 5 Bytes JMP 00300FB9
.text C:\Windows\System32\svchost.exe[956] WS2_32.dll!socket 773836D1 5 Bytes JMP 0032000A
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateFile 77BC4224 5 Bytes JMP 001A000A
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateProcess 77BC42E4 5 Bytes JMP 001A002C
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtProtectVirtualMemory 77BC4B84 5 Bytes JMP 001A001B
.text C:\Windows\system32\svchost.exe[972] kernel32.dll!GetStartupInfoW 76D21929 5 Bytes JMP 002F0F6A
.text C:\Windows\system32\svchost.exe[972] kernel32.dll!GetStartupInfoA 76D219C9 5 Bytes JMP 002F0F8F
.text C:\Windows\system32\svchost.exe[972] kernel32.dll!CreateProcessW 76D21BF3 1 Byte [E9]
.text C:\Windows\system32\svchost.exe[972] kernel32.dll!CreateProcessW 76D21BF3 5 Bytes JMP 002F00F7
.text C:\Windows\system32\svchost.exe[972] kernel32.dll!CreateProcessA 76D21C28 5 Bytes JMP 002F00DC
.text C:\Windows\system32\svchost.exe[972] kernel32.dll!VirtualProtect 76D21DC3 5 Bytes JMP 002F0FA0
.text C:\Windows\system32\svchost.exe[972] kernel32.dll!CreateNamedPipeA 76D22EF5 5 Bytes JMP 002F0FDB
.text C:\Windows\system32\svchost.exe[972] kernel32.dll!CreateNamedPipeW 76D25C0C 5 Bytes JMP 002F0022
.text C:\Windows\system32\svchost.exe[972] kernel32.dll!CreatePipe 76D48E6E 5 Bytes JMP 002F00BA
.text C:\Windows\system32\svchost.exe[972] kernel32.dll!LoadLibraryExW 76D49109 5 Bytes JMP 002F007A
.text C:\Windows\system32\svchost.exe[972] kernel32.dll!LoadLibraryW 76D49362 5 Bytes JMP 002F004E
.text C:\Windows\system32\svchost.exe[972] kernel32.dll!LoadLibraryExA 76D494B4 5 Bytes JMP 002F0069
.text C:\Windows\system32\svchost.exe[972] kernel32.dll!LoadLibraryA 76D494DC 5 Bytes JMP 002F0033
.text C:\Windows\system32\svchost.exe[972] kernel32.dll!VirtualProtectEx 76D4DBDA 5 Bytes JMP 002F009F
.text C:\Windows\system32\svchost.exe[972] kernel32.dll!GetProcAddress 76D6903B 5 Bytes JMP 002F0F3B
.text C:\Windows\system32\svchost.exe[972] kernel32.dll!CreateFileW 76D6AECB 5 Bytes JMP 002F0011
.text C:\Windows\system32\svchost.exe[972] kernel32.dll!CreateFileA 76D6CE5F 5 Bytes JMP 002F0000
.text C:\Windows\system32\svchost.exe[972] kernel32.dll!WinExec 76DB5CF7 5 Bytes JMP 002F00CB
.text C:\Windows\system32\svchost.exe[972] msvcrt.dll!_wsystem 77407F2F 5 Bytes JMP 008B0056
.text C:\Windows\system32\svchost.exe[972] msvcrt.dll!system 7740804B 5 Bytes JMP 008B0FC1
.text C:\Windows\system32\svchost.exe[972] msvcrt.dll!_creat 7740BBE1 5 Bytes JMP 008B001D
.text C:\Windows\system32\svchost.exe[972] msvcrt.dll!_open 7740D106 5 Bytes JMP 008B0000
.text C:\Windows\system32\svchost.exe[972] msvcrt.dll!_wcreat 7740D326 5 Bytes JMP 008B0FD2
.text C:\Windows\system32\svchost.exe[972] msvcrt.dll!_wopen 7740D501 5 Bytes JMP 008B0FEF
.text C:\Windows\system32\svchost.exe[972] ADVAPI32.dll!RegCreateKeyExA 76E239AB 5 Bytes JMP 00890FD4
.text C:\Windows\system32\svchost.exe[972] ADVAPI32.dll!RegCreateKeyA 76E23BA9 5 Bytes JMP 00890065
.text C:\Windows\system32\svchost.exe[972] ADVAPI32.dll!RegOpenKeyA 76E289C7 5 Bytes JMP 00890000
.text C:\Windows\system32\svchost.exe[972] ADVAPI32.dll!RegCreateKeyW 76E3391E 5 Bytes JMP 00890076
.text C:\Windows\system32\svchost.exe[972] ADVAPI32.dll!RegCreateKeyExW 76E341F1 5 Bytes JMP 00890091
.text C:\Windows\system32\svchost.exe[972] ADVAPI32.dll!RegOpenKeyExA 76E37C42 5 Bytes JMP 00890040
.text C:\Windows\system32\svchost.exe[972] ADVAPI32.dll!RegOpenKeyW 76E3E2B5 5 Bytes JMP 0089001B
.text C:\Windows\system32\svchost.exe[972] ADVAPI32.dll!RegOpenKeyExW 76E47BA1 5 Bytes JMP 00890FEF
.text C:\Windows\system32\svchost.exe[972] WS2_32.dll!socket 773836D1 5 Bytes JMP 008A0000
.text C:\Windows\System32\svchost.exe[1132] ntdll.dll!NtCreateFile 77BC4224 5 Bytes JMP 00220FEF
.text C:\Windows\System32\svchost.exe[1132] ntdll.dll!NtCreateProcess 77BC42E4 5 Bytes JMP 0022001B
.text C:\Windows\System32\svchost.exe[1132] ntdll.dll!NtProtectVirtualMemory 77BC4B84 5 Bytes JMP 0022000A
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!GetStartupInfoW 76D21929 5 Bytes JMP 001C0060
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!GetStartupInfoA 76D219C9 5 Bytes JMP 001C0F1A
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!CreateProcessW 76D21BF3 5 Bytes JMP 001C0EDA
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!CreateProcessA 76D21C28 5 Bytes JMP 001C0EEB
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!VirtualProtect 76D21DC3 5 Bytes JMP 001C0F5A
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!CreateNamedPipeA 76D22EF5 5 Bytes JMP 001C0FC3
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!CreateNamedPipeW 76D25C0C 5 Bytes JMP 001C0FA8
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!CreatePipe 76D48E6E 5 Bytes JMP 001C0F35
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!LoadLibraryExW 76D49109 5 Bytes JMP 001C0F6B
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!LoadLibraryW 76D49362 5 Bytes JMP 001C0F86
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!LoadLibraryExA 76D494B4 5 Bytes JMP 001C0028
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!LoadLibraryA 76D494DC 5 Bytes JMP 001C0F97
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!VirtualProtectEx 76D4DBDA 5 Bytes JMP 001C0045
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!GetProcAddress 76D6903B 5 Bytes JMP 001C0082
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!CreateFileW 76D6AECB 5 Bytes JMP 001C0FD4
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!CreateFileA 76D6CE5F 5 Bytes JMP 001C0FE5
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!WinExec 76DB5CF7 5 Bytes JMP 001C0071
.text C:\Windows\System32\svchost.exe[1132] msvcrt.dll!_wsystem 77407F2F 5 Bytes JMP 00860044
.text C:\Windows\System32\svchost.exe[1132] msvcrt.dll!system 7740804B 5 Bytes JMP 00860029
.text C:\Windows\System32\svchost.exe[1132] msvcrt.dll!_creat 7740BBE1 5 Bytes JMP 00860FDE
.text C:\Windows\System32\svchost.exe[1132] msvcrt.dll!_open 7740D106 5 Bytes JMP 00860FEF
.text C:\Windows\System32\svchost.exe[1132] msvcrt.dll!_wcreat 7740D326 5 Bytes JMP 00860FC3
.text C:\Windows\System32\svchost.exe[1132] msvcrt.dll!_wopen 7740D501 5 Bytes JMP 0086000C
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!RegCreateKeyExA 76E239AB 5 Bytes JMP 00210F9E
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!RegCreateKeyA 76E23BA9 5 Bytes JMP 00210036
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!RegOpenKeyA 76E289C7 5 Bytes JMP 00210FEF
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!RegCreateKeyW 76E3391E 5 Bytes JMP 00210FB9
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!RegCreateKeyExW 76E341F1 5 Bytes JMP 00210F8D
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!RegOpenKeyExA 76E37C42 5 Bytes JMP 00210014
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!RegOpenKeyW 76E3E2B5 5 Bytes JMP 00210FD4
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!RegOpenKeyExW 76E47BA1 5 Bytes JMP 00210025
.text C:\Windows\System32\svchost.exe[1132] WS2_32.dll!socket 773836D1 5 Bytes JMP 00240000
.text C:\Windows\System32\svchost.exe[1168] ntdll.dll!NtCreateFile 77BC4224 5 Bytes JMP 00AE0000
.text C:\Windows\System32\svchost.exe[1168] ntdll.dll!NtCreateProcess 77BC42E4 5 Bytes JMP 00AE0FE5
.text C:\Windows\System32\svchost.exe[1168] ntdll.dll!NtProtectVirtualMemory 77BC4B84 5 Bytes JMP 00AE001B
.text C:\Windows\System32\svchost.exe[1168] kernel32.dll!GetStartupInfoW 76D21929 5 Bytes JMP 00A30F3C
.text C:\Windows\System32\svchost.exe[1168] kernel32.dll!GetStartupInfoA 76D219C9 5 Bytes JMP 00A30F61
.text C:\Windows\System32\svchost.exe[1168] kernel32.dll!CreateProcessW 76D21BF3 5 Bytes JMP 00A300C9
.text C:\Windows\System32\svchost.exe[1168] kernel32.dll!CreateProcessA 76D21C28 5 Bytes JMP 00A300B8
.text C:\Windows\System32\svchost.exe[1168] kernel32.dll!VirtualProtect 76D21DC3 5 Bytes JMP 00A30071
.text C:\Windows\System32\svchost.exe[1168] kernel32.dll!CreateNamedPipeA 76D22EF5 5 Bytes JMP 00A30FC3
.text C:\Windows\System32\svchost.exe[1168] kernel32.dll!CreateNamedPipeW 76D25C0C 5 Bytes JMP 00A30014
.text C:\Windows\System32\svchost.exe[1168] kernel32.dll!CreatePipe 76D48E6E 5 Bytes JMP 00A3008C
.text C:\Windows\System32\svchost.exe[1168] kernel32.dll!LoadLibraryExW 76D49109 5 Bytes JMP 00A30F97
.text C:\Windows\System32\svchost.exe[1168] kernel32.dll!LoadLibraryW 76D49362 5 Bytes JMP 00A3004A
.text C:\Windows\System32\svchost.exe[1168] kernel32.dll!LoadLibraryExA 76D494B4 5 Bytes JMP 00A30FA8
.text C:\Windows\System32\svchost.exe[1168] kernel32.dll!LoadLibraryA 76D494DC 5 Bytes JMP 00A30039
.text C:\Windows\System32\svchost.exe[1168] kernel32.dll!VirtualProtectEx 76D4DBDA 5 Bytes JMP 00A30F72
.text C:\Windows\System32\svchost.exe[1168] kernel32.dll!GetProcAddress 76D6903B 5 Bytes JMP 00A300E4
.text C:\Windows\System32\svchost.exe[1168] kernel32.dll!CreateFileW 76D6AECB 5 Bytes JMP 00A30FDE
.text C:\Windows\System32\svchost.exe[1168] kernel32.dll!CreateFileA 76D6CE5F 5 Bytes JMP 00A30FEF
.text C:\Windows\System32\svchost.exe[1168] kernel32.dll!WinExec 76DB5CF7 5 Bytes JMP 00A3009D
.text C:\Windows\System32\svchost.exe[1168] msvcrt.dll!_wsystem 77407F2F 5 Bytes JMP 00EA0F99
.text C:\Windows\System32\svchost.exe[1168] msvcrt.dll!system 7740804B 5 Bytes JMP 00EA002E
.text C:\Windows\System32\svchost.exe[1168] msvcrt.dll!_creat 7740BBE1 5 Bytes JMP 00EA001D
.text C:\Windows\System32\svchost.exe[1168] msvcrt.dll!_open 7740D106 5 Bytes JMP 00EA0000
.text C:\Windows\System32\svchost.exe[1168] msvcrt.dll!_wcreat 7740D326 5 Bytes JMP 00EA0FC8
.text C:\Windows\System32\svchost.exe[1168] msvcrt.dll!_wopen 7740D501 5 Bytes JMP 00EA0FE3
.text C:\Windows\System32\svchost.exe[1168] ADVAPI32.dll!RegCreateKeyExA 76E239AB 5 Bytes JMP 00A40047
.text C:\Windows\System32\svchost.exe[1168] ADVAPI32.dll!RegCreateKeyA 76E23BA9 5 Bytes JMP 00A40036
.text C:\Windows\System32\svchost.exe[1168] ADVAPI32.dll!RegOpenKeyA 76E289C7 5 Bytes JMP 00A40FEF
.text C:\Windows\System32\svchost.exe[1168] ADVAPI32.dll!RegCreateKeyW 76E3391E 5 Bytes JMP 00A40FA5
.text C:\Windows\System32\svchost.exe[1168] ADVAPI32.dll!RegCreateKeyExW 76E341F1 5 Bytes JMP 00A40F8A
.text C:\Windows\System32\svchost.exe[1168] ADVAPI32.dll!RegOpenKeyExA 76E37C42 5 Bytes JMP 00A40000
.text C:\Windows\System32\svchost.exe[1168] ADVAPI32.dll!RegOpenKeyW 76E3E2B5 5 Bytes JMP 00A40FD4
.text C:\Windows\System32\svchost.exe[1168] ADVAPI32.dll!RegOpenKeyExW 76E47BA1 5 Bytes JMP 00A4001B
.text C:\Windows\System32\svchost.exe[1168] WS2_32.dll!socket 773836D1 5 Bytes JMP 00E90000
.text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtCreateFile 77BC4224 5 Bytes JMP 010C0000
.text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtCreateProcess 77BC42E4 5 Bytes JMP 010C0FD4
.text C:\Windows\system32\svchost.exe[1184] ntdll.dll!NtProtectVirtualMemory 77BC4B84 5 Bytes JMP 010C0FE5
.text C:\Windows\system32\svchost.exe[1184] kernel32.dll!GetStartupInfoW 76D21929 5 Bytes JMP 010A0089
.text C:\Windows\system32\svchost.exe[1184] kernel32.dll!GetStartupInfoA 76D219C9 5 Bytes JMP 010A0F4D
.text C:\Windows\system32\svchost.exe[1184] kernel32.dll!CreateProcessW 76D21BF3 5 Bytes JMP 010A00C6
.text C:\Windows\system32\svchost.exe[1184] kernel32.dll!CreateProcessA 76D21C28 5 Bytes JMP 010A00B5
.text C:\Windows\system32\svchost.exe[1184] kernel32.dll!VirtualProtect 76D21DC3 5 Bytes JMP 010A006E
.text C:\Windows\system32\svchost.exe[1184] kernel32.dll!CreateNamedPipeA 76D22EF5 5 Bytes JMP 010A0FC3
.text C:\Windows\system32\svchost.exe[1184] kernel32.dll!CreateNamedPipeW 76D25C0C 5 Bytes JMP 010A000A
.text C:\Windows\system32\svchost.exe[1184] kernel32.dll!CreatePipe 76D48E6E 5 Bytes JMP 010A0F68
.text C:\Windows\system32\svchost.exe[1184] kernel32.dll!LoadLibraryExW 76D49109 5 Bytes JMP 010A0051
.text C:\Windows\system32\svchost.exe[1184] kernel32.dll!LoadLibraryW 76D49362 5 Bytes JMP 010A0F94
.text C:\Windows\system32\svchost.exe[1184] kernel32.dll!LoadLibraryExA 76D494B4 5 Bytes JMP 010A0036
.text C:\Windows\system32\svchost.exe[1184] kernel32.dll!LoadLibraryA 76D494DC 5 Bytes JMP 010A001B
.text C:\Windows\system32\svchost.exe[1184] kernel32.dll!VirtualProtectEx 76D4DBDA 5 Bytes JMP 010A0F79
.text C:\Windows\system32\svchost.exe[1184] kernel32.dll!GetProcAddress 76D6903B 5 Bytes JMP 010A0F14
.text C:\Windows\system32\svchost.exe[1184] kernel32.dll!CreateFileW 76D6AECB 5 Bytes JMP 010A0FD4
.text C:\Windows\system32\svchost.exe[1184] kernel32.dll!CreateFileA 76D6CE5F 5 Bytes JMP 010A0FEF
.text C:\Windows\system32\svchost.exe[1184] kernel32.dll!WinExec 76DB5CF7 5 Bytes JMP 010A00A4
.text C:\Windows\system32\svchost.exe[1184] msvcrt.dll!_wsystem 77407F2F 5 Bytes JMP 010F0F86
.text C:\Windows\system32\svchost.exe[1184] msvcrt.dll!system 7740804B 5 Bytes JMP 010F0FA1
.text C:\Windows\system32\svchost.exe[1184] msvcrt.dll!_creat 7740BBE1 5 Bytes JMP 010F0FBC
.text C:\Windows\system32\svchost.exe[1184] msvcrt.dll!_open 7740D106 5 Bytes JMP 010F0000
.text C:\Windows\system32\svchost.exe[1184] msvcrt.dll!_wcreat 7740D326 5 Bytes JMP 010F0011
.text C:\Windows\system32\svchost.exe[1184] msvcrt.dll!_wopen 7740D501 5 Bytes JMP 010F0FE3
.text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!RegCreateKeyExA 76E239AB 5 Bytes JMP 010B0F9A
.text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!RegCreateKeyA 76E23BA9 5 Bytes JMP 010B0FAB
.text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!RegOpenKeyA 76E289C7 5 Bytes JMP 010B0FEF
.text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!RegCreateKeyW 76E3391E 5 Bytes JMP 010B003C
.text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!RegCreateKeyExW 76E341F1 5 Bytes JMP 010B0F89
.text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!RegOpenKeyExA 76E37C42 5 Bytes JMP 010B0FCD
.text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!RegOpenKeyW 76E3E2B5 5 Bytes JMP 010B0FDE
.text C:\Windows\system32\svchost.exe[1184] ADVAPI32.dll!RegOpenKeyExW 76E47BA1 5 Bytes JMP 010B0FBC
.text C:\Windows\system32\svchost.exe[1184] WS2_32.dll!socket 773836D1 5 Bytes JMP 010D0000
.text C:\Windows\system32\svchost.exe[1184] WININET.dll!InternetOpenA 77CFD690 5 Bytes JMP 01F90FE5
.text C:\Windows\system32\svchost.exe[1184] WININET.dll!InternetOpenW 77CFDB09 5 Bytes JMP 01F90FD4
.text C:\Windows\system32\svchost.exe[1184] WININET.dll!InternetOpenUrlA 77CFF3A4 5 Bytes JMP 01F90FC3
.text C:\Windows\system32\svchost.exe[1184] WININET.dll!InternetOpenUrlW 77D46D5F 5 Bytes JMP 01F90014
.text C:\Windows\system32\svchost.exe[1256] ntdll.dll!NtCreateFile 77BC4224 5 Bytes JMP 00720FEF
.text C:\Windows\system32\svchost.exe[1256] ntdll.dll!NtCreateProcess 77BC42E4 5 Bytes JMP 00720025
.text C:\Windows\system32\svchost.exe[1256] ntdll.dll!NtProtectVirtualMemory 77BC4B84 5 Bytes JMP 0072000A
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!GetStartupInfoW 76D21929 5 Bytes JMP 001E00AB
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!GetStartupInfoA 76D219C9 5 Bytes JMP 001E0F6F
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!CreateProcessW 76D21BF3 5 Bytes JMP 001E00E1
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!CreateProcessA 76D21C28 5 Bytes JMP 001E0F4A
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!VirtualProtect 76D21DC3 5 Bytes JMP 001E006E
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!CreateNamedPipeA 76D22EF5 5 Bytes JMP 001E001B
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!CreateNamedPipeW 76D25C0C 5 Bytes JMP 001E0FCA
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!CreatePipe 76D48E6E 5 Bytes JMP 001E0090
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!LoadLibraryExW 76D49109 5 Bytes JMP 001E0F94
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!LoadLibraryW 76D49362 5 Bytes JMP 001E0040
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!LoadLibraryExA 76D494B4 5 Bytes JMP 001E0051
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!LoadLibraryA 76D494DC 5 Bytes JMP 001E0FAF
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!VirtualProtectEx 76D4DBDA 5 Bytes JMP 001E007F
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!GetProcAddress 76D6903B 5 Bytes JMP 001E00F2
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!CreateFileW 76D6AECB 5 Bytes JMP 001E0FE5
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!CreateFileA 76D6CE5F 5 Bytes JMP 001E0000
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!WinExec 76DB5CF7 5 Bytes JMP 001E00D0
.text C:\Windows\system32\svchost.exe[1256] msvcrt.dll!_wsystem 77407F2F 5 Bytes JMP 0074005A
.text C:\Windows\system32\svchost.exe[1256] msvcrt.dll!system 7740804B 5 Bytes JMP 00740049
.text C:\Windows\system32\svchost.exe[1256] msvcrt.dll!_creat 7740BBE1 5 Bytes JMP 0074002E
.text C:\Windows\system32\svchost.exe[1256] msvcrt.dll!_open 7740D106 5 Bytes JMP 00740000
.text C:\Windows\system32\svchost.exe[1256] msvcrt.dll!_wcreat 7740D326 5 Bytes JMP 00740FCF
.text C:\Windows\system32\svchost.exe[1256] msvcrt.dll!_wopen 7740D501 5 Bytes JMP 00740011
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegCreateKeyExA 76E239AB 5 Bytes JMP 00710F9E
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegCreateKeyA 76E23BA9 5 Bytes JMP 00710040
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegOpenKeyA 76E289C7 5 Bytes JMP 00710000
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegCreateKeyW 76E3391E 5 Bytes JMP 00710FB9
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegCreateKeyExW 76E341F1 5 Bytes JMP 00710F8D
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegOpenKeyExA 76E37C42 5 Bytes JMP 00710FEF
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegOpenKeyW 76E3E2B5 5 Bytes JMP 00710025
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegOpenKeyExW 76E47BA1 5 Bytes JMP 00710FD4
.text C:\Windows\system32\svchost.exe[1256] WS2_32.dll!socket 773836D1 5 Bytes JMP 00730FEF
.text C:\Windows\system32\svchost.exe[1288] ntdll.dll!NtCreateFile 77BC4224 5 Bytes JMP 000E0000
.text C:\Windows\system32\svchost.exe[1288] ntdll.dll!NtCreateProcess 77BC42E4 5 Bytes JMP 000E0FD4
.text C:\Windows\system32\svchost.exe[1288] ntdll.dll!NtProtectVirtualMemory 77BC4B84 5 Bytes JMP 000E0FEF
.text C:\Windows\system32\svchost.exe[1288] kernel32.dll!GetStartupInfoW 76D21929 5 Bytes JMP 00070071
.text C:\Windows\system32\svchost.exe[1288] kernel32.dll!GetStartupInfoA 76D219C9 5 Bytes JMP 00070F21
.text C:\Windows\system32\svchost.exe[1288] kernel32.dll!CreateProcessW 76D21BF3 5 Bytes JMP 0007009D
.text C:\Windows\system32\svchost.exe[1288] kernel32.dll!CreateProcessA 76D21C28 5 Bytes JMP 00070F10
.text C:\Windows\system32\svchost.exe[1288] kernel32.dll!VirtualProtect 76D21DC3 5 Bytes JMP 00070F4D
.text C:\Windows\system32\svchost.exe[1288] kernel32.dll!CreateNamedPipeA 76D22EF5 5 Bytes JMP 00070FB9
.text C:\Windows\system32\svchost.exe[1288] kernel32.dll!CreateNamedPipeW 76D25C0C 5 Bytes JMP 00070F9E
.text C:\Windows\system32\svchost.exe[1288] kernel32.dll!CreatePipe 76D48E6E 5 Bytes JMP 00070F3C
.text C:\Windows\system32\svchost.exe[1288] kernel32.dll!LoadLibraryExW 76D49109 5 Bytes JMP 0007001B
.text C:\Windows\system32\svchost.exe[1288] kernel32.dll!LoadLibraryW 76D49362 5 Bytes JMP 00070F68
.text C:\Windows\system32\svchost.exe[1288] kernel32.dll!LoadLibraryExA 76D494B4 5 Bytes JMP 0007000A
.text C:\Windows\system32\svchost.exe[1288] kernel32.dll!LoadLibraryA 76D494DC 5 Bytes JMP 00070F79
.text C:\Windows\system32\svchost.exe[1288] kernel32.dll!VirtualProtectEx 76D4DBDA 5 Bytes JMP 00070042
.text C:\Windows\system32\svchost.exe[1288] kernel32.dll!GetProcAddress 76D6903B 5 Bytes JMP 000700AE
.text C:\Windows\system32\svchost.exe[1288] kernel32.dll!CreateFileW 76D6AECB 5 Bytes JMP 00070FCA
.text C:\Windows\system32\svchost.exe[1288] kernel32.dll!CreateFileA 76D6CE5F 5 Bytes JMP 00070FE5
.text C:\Windows\system32\svchost.exe[1288] kernel32.dll!WinExec 76DB5CF7 5 Bytes JMP 0007008C
.text C:\Windows\system32\svchost.exe[1288] msvcrt.dll!_wsystem 77407F2F 5 Bytes JMP 00100FA8
.text C:\Windows\system32\svchost.exe[1288] msvcrt.dll!system 7740804B 5 Bytes JMP 00100033
.text C:\Windows\system32\svchost.exe[1288] msvcrt.dll!_creat 7740BBE1 5 Bytes JMP 00100011
.text C:\Windows\system32\svchost.exe[1288] msvcrt.dll!_open 7740D106 5 Bytes JMP 00100FE3
.text C:\Windows\system32\svchost.exe[1288] msvcrt.dll!_wcreat 7740D326 5 Bytes JMP 00100022
.text C:\Windows\system32\svchost.exe[1288] msvcrt.dll!_wopen 7740D501 5 Bytes JMP 00100000
.text C:\Windows\system32\svchost.exe[1288] ADVAPI32.dll!RegCreateKeyExA 76E239AB 5 Bytes JMP 000D006C
.text C:\Windows\system32\svchost.exe[1288] ADVAPI32.dll!RegCreateKeyA 76E23BA9 5 Bytes JMP 000D005B
.text C:\Windows\system32\svchost.exe[1288] ADVAPI32.dll!RegOpenKeyA 76E289C7 5 Bytes JMP 000D0000
.text C:\Windows\system32\svchost.exe[1288] ADVAPI32.dll!RegCreateKeyW 76E3391E 5 Bytes JMP 000D0FD4
.text C:\Windows\system32\svchost.exe[1288] ADVAPI32.dll!RegCreateKeyExW 76E341F1 5 Bytes JMP 000D007D
.text C:\Windows\system32\svchost.exe[1288] ADVAPI32.dll!RegOpenKeyExA 76E37C42 5 Bytes JMP 000D0FEF
.text C:\Windows\system32\svchost.exe[1288] ADVAPI32.dll!RegOpenKeyW 76E3E2B5 5 Bytes JMP 000D001B
.text C:\Windows\system32\svchost.exe[1288] ADVAPI32.dll!RegOpenKeyExW 76E47BA1 5 Bytes JMP 000D0040
.text C:\Windows\system32\svchost.exe[1288] WS2_32.dll!socket 773836D1 5 Bytes JMP 000F0FEF
.text C:\Windows\system32\svchost.exe[1336] ntdll.dll!NtCreateFile 77BC4224 5 Bytes JMP 009C0000
.text C:\Windows\system32\svchost.exe[1336] ntdll.dll!NtCreateProcess 77BC42E4 5 Bytes JMP 009C0011
.text C:\Windows\system32\svchost.exe[1336] ntdll.dll!NtProtectVirtualMemory 77BC4B84 5 Bytes JMP 009C0FE5
.text C:\Windows\system32\svchost.exe[1336] kernel32.dll!GetStartupInfoW 76D21929 5 Bytes JMP 001D00BF
.text C:\Windows\system32\svchost.exe[1336] kernel32.dll!GetStartupInfoA 76D219C9 5 Bytes JMP 001D00AE
.text C:\Windows\system32\svchost.exe[1336] kernel32.dll!CreateProcessW 76D21BF3 5 Bytes JMP 001D00EB
.text C:\Windows\system32\svchost.exe[1336] kernel32.dll!CreateProcessA 76D21C28 5 Bytes JMP 001D00DA
.text C:\Windows\system32\svchost.exe[1336] kernel32.dll!VirtualProtect 76D21DC3 5 Bytes JMP 001D0082
.text C:\Windows\system32\svchost.exe[1336] kernel32.dll!CreateNamedPipeA 76D22EF5 5 Bytes JMP 001D0FEF
.text C:\Windows\system32\svchost.exe[1336] kernel32.dll!CreateNamedPipeW 76D25C0C 5 Bytes JMP 001D0FD4
.text C:\Windows\system32\svchost.exe[1336] kernel32.dll!CreatePipe 76D48E6E 5 Bytes JMP 001D0F83
.text C:\Windows\system32\svchost.exe[1336] kernel32.dll!LoadLibraryExW 76D49109 5 Bytes JMP 001D0FA8
.text C:\Windows\system32\svchost.exe[1336] kernel32.dll!LoadLibraryW 76D49362 5 Bytes JMP 001D004A
.text C:\Windows\system32\svchost.exe[1336] kernel32.dll!LoadLibraryExA 76D494B4 5 Bytes JMP 001D005B
.text C:\Windows\system32\svchost.exe[1336] kernel32.dll!LoadLibraryA 76D494DC 5 Bytes JMP 001D0FC3
.text C:\Windows\system32\svchost.exe[1336] kernel32.dll!VirtualProtectEx 76D4DBDA 5 Bytes JMP 001D0093
.text C:\Windows\system32\svchost.exe[1336] kernel32.dll!GetProcAddress 76D6903B 5 Bytes JMP 001D00FC
.text C:\Windows\system32\svchost.exe[1336] kernel32.dll!CreateFileW 76D6AECB 5 Bytes JMP 001D001B
.text C:\Windows\system32\svchost.exe[1336] kernel32.dll!CreateFileA 76D6CE5F 5 Bytes JMP 001D000A
.text C:\Windows\system32\svchost.exe[1336] kernel32.dll!WinExec 76DB5CF7 5 Bytes JMP 001D0F5E
.text C:\Windows\system32\svchost.exe[1336] msvcrt.dll!_wsystem 77407F2F 5 Bytes JMP 009E0053
.text C:\Windows\system32\svchost.exe[1336] msvcrt.dll!system 7740804B 5 Bytes JMP 009E0038
.text C:\Windows\system32\svchost.exe[1336] msvcrt.dll!_creat 7740BBE1 5 Bytes JMP 009E001D
.text C:\Windows\system32\svchost.exe[1336] msvcrt.dll!_open 7740D106 5 Bytes JMP 009E0000
.text C:\Windows\system32\svchost.exe[1336] msvcrt.dll!_wcreat 7740D326 5 Bytes JMP 009E0FC8
.text C:\Windows\system32\svchost.exe[1336] msvcrt.dll!_wopen 7740D501 5 Bytes JMP 009E0FE3
.text C:\Windows\system32\svchost.exe[1336] ADVAPI32.dll!RegCreateKeyExA 76E239AB 5 Bytes JMP 00970F8D
.text C:\Windows\system32\svchost.exe[1336] ADVAPI32.dll!RegCreateKeyA 76E23BA9 5 Bytes JMP 00970025
.text C:\Windows\system32\svchost.exe[1336] ADVAPI32.dll!RegOpenKeyA 76E289C7 5 Bytes JMP 00970FEF
.text C:\Windows\system32\svchost.exe[1336] ADVAPI32.dll!RegCreateKeyW 76E3391E 5 Bytes JMP 00970FA8
.text C:\Windows\system32\svchost.exe[1336] ADVAPI32.dll!RegCreateKeyExW 76E341F1 5 Bytes JMP 00970F7C
.text C:\Windows\system32\svchost.exe[1336] ADVAPI32.dll!RegOpenKeyExA 76E37C42 5 Bytes JMP 00970014
.text C:\Windows\system32\svchost.exe[1336] ADVAPI32.dll!RegOpenKeyW 76E3E2B5 5 Bytes JMP 00970FD4
.text C:\Windows\system32\svchost.exe[1336] ADVAPI32.dll!RegOpenKeyExW 76E47BA1 5 Bytes JMP 00970FC3
.text C:\Windows\system32\svchost.exe[1336] WS2_32.dll!socket 773836D1 5 Bytes JMP 009D0FEF
.text C:\Windows\system32\svchost.exe[1336] WinInet.dll!InternetOpenA 77CFD690 5 Bytes JMP 009F0FEF
.text C:\Windows\system32\svchost.exe[1336] WinInet.dll!InternetOpenW 77CFDB09 5 Bytes JMP 009F0FCA
.text C:\Windows\system32\svchost.exe[1336] WinInet.dll!InternetOpenUrlA 77CFF3A4 5 Bytes JMP 009F0FB9
.text C:\Windows\system32\svchost.exe[1336] WinInet.dll!InternetOpenUrlW 77D46D5F 5 Bytes JMP 009F000A
.text C:\Windows\system32\svchost.exe[1484] ntdll.dll!NtCreateFile 77BC4224 5 Bytes JMP 026D0000
.text C:\Windows\system32\svchost.exe[1484] ntdll.dll!NtCreateProcess 77BC42E4 5 Bytes JMP 026D002C
.text C:\Windows\system32\svchost.exe[1484] ntdll.dll!NtProtectVirtualMemory 77BC4B84 5 Bytes JMP 026D0011
.text C:\Windows\system32\svchost.exe[1484] kernel32.dll!GetStartupInfoW 76D21929 5 Bytes JMP 026B0F66
.text C:\Windows\system32\svchost.exe[1484] kernel32.dll!GetStartupInfoA 76D219C9 5 Bytes JMP 026B0F77
.text C:\Windows\system32\svchost.exe[1484] kernel32.dll!CreateProcessW 76D21BF3 5 Bytes JMP 026B0F55
.text C:\Windows\system32\svchost.exe[1484] kernel32.dll!CreateProcessA 76D21C28 5 Bytes JMP 026B00E2
.text C:\Windows\system32\svchost.exe[1484] kernel32.dll!VirtualProtect 76D21DC3 5 Bytes JMP 026B0073
.text C:\Windows\system32\svchost.exe[1484] kernel32.dll!CreateNamedPipeA 76D22EF5 5 Bytes JMP 026B0011
.text C:\Windows\system32\svchost.exe[1484] kernel32.dll!CreateNamedPipeW 76D25C0C 5 Bytes JMP 026B0022
.text C:\Windows\system32\svchost.exe[1484] kernel32.dll!CreatePipe 76D48E6E 5 Bytes JMP 026B0F88
.text C:\Windows\system32\svchost.exe[1484] kernel32.dll!LoadLibraryExW 76D49109 5 Bytes JMP 026B0062
.text C:\Windows\system32\svchost.exe[1484] kernel32.dll!LoadLibraryW 76D49362 5 Bytes JMP 026B0FB6
.text C:\Windows\system32\svchost.exe[1484] kernel32.dll!LoadLibraryExA 76D494B4 5 Bytes JMP 026B0FA5
.text C:\Windows\system32\svchost.exe[1484] kernel32.dll!LoadLibraryA 76D494DC 5 Bytes JMP 026B003D
.text C:\Windows\system32\svchost.exe[1484] kernel32.dll!VirtualProtectEx 76D4DBDA 5 Bytes JMP 026B0098
.text C:\Windows\system32\svchost.exe[1484] kernel32.dll!GetProcAddress 76D6903B 5 Bytes JMP 026B0107
.text C:\Windows\system32\svchost.exe[1484] kernel32.dll!CreateFileW 76D6AECB 5 Bytes JMP 026B0000
.text C:\Windows\system32\svchost.exe[1484] kernel32.dll!CreateFileA 76D6CE5F 5 Bytes JMP 026B0FE5
.text C:\Windows\system32\svchost.exe[1484] kernel32.dll!WinExec 76DB5CF7 5 Bytes JMP 026B00D1
.text C:\Windows\system32\svchost.exe[1484] msvcrt.dll!_wsystem 77407F2F 5 Bytes JMP 02710050
.text C:\Windows\system32\svchost.exe[1484] msvcrt.dll!system 7740804B 5 Bytes JMP 0271003F
.text C:\Windows\system32\svchost.exe[1484] msvcrt.dll!_creat 7740BBE1 5 Bytes JMP 0271002E
.text C:\Windows\system32\svchost.exe[1484] msvcrt.dll!_open 7740D106 5 Bytes JMP 02710000
.text C:\Windows\system32\svchost.exe[1484] msvcrt.dll!_wcreat 7740D326 5 Bytes JMP 02710FD9
.text C:\Windows\system32\svchost.exe[1484] msvcrt.dll!_wopen 7740D501 5 Bytes JMP 02710011
.text C:\Windows\system32\svchost.exe[1484] ADVAPI32.dll!RegCreateKeyExA 76E239AB 5 Bytes JMP 026C0FB2
.text C:\Windows\system32\svchost.exe[1484] ADVAPI32.dll!RegCreateKeyA 76E23BA9 5 Bytes JMP 026C0FC3
.text C:\Windows\system32\svchost.exe[1484] ADVAPI32.dll!RegOpenKeyA 76E289C7 5 Bytes JMP 026C0FE5
.text C:\Windows\system32\svchost.exe[1484] ADVAPI32.dll!RegCreateKeyW 76E3391E 5 Bytes JMP 026C0054
.text C:\Windows\system32\svchost.exe[1484] ADVAPI32.dll!RegCreateKeyExW 76E341F1 5 Bytes JMP 026C0F97
.text C:\Windows\system32\svchost.exe[1484] ADVAPI32.dll!RegOpenKeyExA 76E37C42 5 Bytes JMP 026C0FD4
.text C:\Windows\system32\svchost.exe[1484] ADVAPI32.dll!RegOpenKeyW 76E3E2B5 5 Bytes JMP 026C000A
.text C:\Windows\system32\svchost.exe[1484] ADVAPI32.dll!RegOpenKeyExW 76E47BA1 5 Bytes JMP 026C002F
.text C:\Windows\system32\svchost.exe[1484] WS2_32.dll!socket 773836D1 5 Bytes JMP 02700FEF
.text C:\Windows\system32\svchost.exe[1700] ntdll.dll!NtCreateFile 77BC4224 5 Bytes JMP 0061000A
.text C:\Windows\system32\svchost.exe[1700] ntdll.dll!NtCreateProcess 77BC42E4 5 Bytes JMP 00610FD4
.text C:\Windows\system32\svchost.exe[1700] ntdll.dll!NtProtectVirtualMemory 77BC4B84 5 Bytes JMP 00610FEF
.text C:\Windows\system32\svchost.exe[1700] kernel32.dll!GetStartupInfoW 76D21929 5 Bytes JMP 005A0F35
.text C:\Windows\system32\svchost.exe[1700] kernel32.dll!GetStartupInfoA 76D219C9 5 Bytes JMP 005A0F46
.text C:\Windows\system32\svchost.exe[1700] kernel32.dll!CreateProcessW 76D21BF3 5 Bytes JMP 005A0EF5
.text C:\Windows\system32\svchost.exe[1700] kernel32.dll!CreateProcessA 76D21C28 5 Bytes JMP 005A0F10
.text C:\Windows\system32\svchost.exe[1700] kernel32.dll!VirtualProtect 76D21DC3 5 Bytes JMP 005A0056
.text C:\Windows\system32\svchost.exe[1700] kernel32.dll!CreateNamedPipeA 76D22EF5 5 Bytes JMP 005A0FCA
.text C:\Windows\system32\svchost.exe[1700] kernel32.dll!CreateNamedPipeW 76D25C0C 5 Bytes JMP 005A0FB9
.text C:\Windows\system32\svchost.exe[1700] kernel32.dll!CreatePipe 76D48E6E 5 Bytes JMP 005A0071
.text C:\Windows\system32\svchost.exe[1700] kernel32.dll!LoadLibraryExW 76D49109 5 Bytes JMP 005A0045
.text C:\Windows\system32\svchost.exe[1700] kernel32.dll!LoadLibraryW 76D49362 5 Bytes JMP 005A0F97
.text C:\Windows\system32\svchost.exe[1700] kernel32.dll!LoadLibraryExA 76D494B4 5 Bytes JMP 005A0F86
.text C:\Windows\system32\svchost.exe[1700] kernel32.dll!LoadLibraryA 76D494DC 5 Bytes JMP 005A0FA8
.text C:\Windows\system32\svchost.exe[1700] kernel32.dll!VirtualProtectEx 76D4DBDA 5 Bytes JMP 005A0F61
.text C:\Windows\system32\svchost.exe[1700] kernel32.dll!GetProcAddress 76D6903B 5 Bytes JMP 005A00B1
.text C:\Windows\system32\svchost.exe[1700] kernel32.dll!CreateFileW 76D6AECB 5 Bytes JMP 005A0000
.text C:\Windows\system32\svchost.exe[1700] kernel32.dll!CreateFileA 76D6CE5F 5 Bytes JMP 005A0FE5
.text C:\Windows\system32\svchost.exe[1700] kernel32.dll!WinExec 76DB5CF7 5 Bytes JMP 005A0096
.text C:\Windows\system32\svchost.exe[1700] msvcrt.dll!_wsystem 77407F2F 5 Bytes JMP 00630025
.text C:\Windows\system32\svchost.exe[1700] msvcrt.dll!system 7740804B 5 Bytes JMP 00630F9A
.text C:\Windows\system32\svchost.exe[1700] msvcrt.dll!_creat 7740BBE1 5 Bytes JMP 00630FC6
.text C:\Windows\system32\svchost.exe[1700] msvcrt.dll!_open 7740D106 5 Bytes JMP 00630FE3
.text C:\Windows\system32\svchost.exe[1700] msvcrt.dll!_wcreat 7740D326 5 Bytes JMP 00630FAB
.text C:\Windows\system32\svchost.exe[1700] msvcrt.dll!_wopen 7740D501 5 Bytes JMP 00630000
.text C:\Windows\system32\svchost.exe[1700] ADVAPI32.dll!RegCreateKeyExA 76E239AB 5 Bytes JMP 00600F83
.text C:\Windows\system32\svchost.exe[1700] ADVAPI32.dll!RegCreateKeyA 76E23BA9 5 Bytes JMP 00600F94
.text C:\Windows\system32\svchost.exe[1700] ADVAPI32.dll!RegOpenKeyA 76E289C7 5 Bytes JMP 00600FEF
.text C:\Windows\system32\svchost.exe[1700] ADVAPI32.dll!RegCreateKeyW 76E3391E 5 Bytes JMP 00600025
.text C:\Windows\system32\svchost.exe[1700] ADVAPI32.dll!RegCreateKeyExW 76E341F1 5 Bytes JMP 00600F72
.text C:\Windows\system32\svchost.exe[1700] ADVAPI32.dll!RegOpenKeyExA 76E37C42 5 Bytes JMP 00600000
.text C:\Windows\system32\svchost.exe[1700] ADVAPI32.dll!RegOpenKeyW 76E3E2B5 5 Bytes JMP 00600FCA
.text C:\Windows\system32\svchost.exe[1700] ADVAPI32.dll!RegOpenKeyExW 76E47BA1 1 Byte [E9]
.text C:\Windows\system32\svchost.exe[1700] ADVAPI32.dll!RegOpenKeyExW 76E47BA1 5 Bytes JMP 00600FA5
.text C:\Windows\system32\svchost.exe[1700] WS2_32.dll!socket 773836D1 5 Bytes JMP 00620FEF
.text C:\Windows\system32\svchost.exe[2024] ntdll.dll!NtCreateFile 77BC4224 5 Bytes JMP 008B0FEF
.text C:\Windows\system32\svchost.exe[2024] ntdll.dll!NtCreateProcess 77BC42E4 5 Bytes JMP 008B000A
.text C:\Windows\system32\svchost.exe[2024] ntdll.dll!NtProtectVirtualMemory 77BC4B84 5 Bytes JMP 008B0FDE
.text C:\Windows\system32\svchost.exe[2024] kernel32.dll!GetStartupInfoW 76D21929 5 Bytes JMP 00880F04
.text C:\Windows\system32\svchost.exe[2024] kernel32.dll!GetStartupInfoA 76D219C9 5 Bytes JMP 00880054
.text C:\Windows\system32\svchost.exe[2024] kernel32.dll!CreateProcessW 76D21BF3 5 Bytes JMP 00880076
.text C:\Windows\system32\svchost.exe[2024] kernel32.dll!CreateProcessA 76D21C28 5 Bytes JMP 00880EE9
.text C:\Windows\system32\svchost.exe[2024] kernel32.dll!VirtualProtect 76D21DC3 5 Bytes JMP 00880F5F
.text C:\Windows\system32\svchost.exe[2024] kernel32.dll!CreateNamedPipeA 76D22EF5 5 Bytes JMP 00880011
.text C:\Windows\system32\svchost.exe[2024] kernel32.dll!CreateNamedPipeW 76D25C0C 5 Bytes JMP 00880FCA
.text C:\Windows\system32\svchost.exe[2024] kernel32.dll!CreatePipe 76D48E6E 5 Bytes JMP 00880F29
.text C:\Windows\system32\svchost.exe[2024] kernel32.dll!LoadLibraryExW 76D49109 5 Bytes JMP 00880F70
.text C:\Windows\system32\svchost.exe[2024] kernel32.dll!LoadLibraryW 76D49362 5 Bytes JMP 00880FA8
.text C:\Windows\system32\svchost.exe[2024] kernel32.dll!LoadLibraryExA 76D494B4 5 Bytes JMP 00880F97
.text C:\Windows\system32\svchost.exe[2024] kernel32.dll!LoadLibraryA 76D494DC 5 Bytes JMP 00880FB9
.text C:\Windows\system32\svchost.exe[2024] kernel32.dll!VirtualProtectEx 76D4DBDA 5 Bytes JMP 00880F4E
.text C:\Windows\system32\svchost.exe[2024] kernel32.dll!GetProcAddress 76D6903B 5 Bytes JMP 0088009B
.text C:\Windows\system32\svchost.exe[2024] kernel32.dll!CreateFileW 76D6AECB 5 Bytes JMP 00880FE5
.text C:\Windows\system32\svchost.exe[2024] kernel32.dll!CreateFileA 76D6CE5F 5 Bytes JMP 00880000
.text C:\Windows\system32\svchost.exe[2024] kernel32.dll!WinExec 76DB5CF7 5 Bytes JMP 00880065
.text C:\Windows\system32\svchost.exe[2024] msvcrt.dll!_wsystem 77407F2F 5 Bytes JMP 009C0025
.text C:\Windows\system32\svchost.exe[2024] msvcrt.dll!system 7740804B 5 Bytes JMP 009C0F90
.text C:\Windows\system32\svchost.exe[2024] msvcrt.dll!_creat 7740BBE1 5 Bytes JMP 009C0FBC
.text C:\Windows\system32\svchost.exe[2024] msvcrt.dll!_open 7740D106 5 Bytes JMP 009C0FEF
.text C:\Windows\system32\svchost.exe[2024] msvcrt.dll!_wcreat 7740D326 5 Bytes JMP 009C0FAB
.text C:\Windows\system32\svchost.exe[2024] msvcrt.dll!_wopen 7740D501 5 Bytes JMP 009C0000
.text C:\Windows\system32\svchost.exe[2024] ADVAPI32.dll!RegCreateKeyExA 76E239AB 5 Bytes JMP 008A0084
.text C:\Windows\system32\svchost.exe[2024] ADVAPI32.dll!RegCreateKeyA 76E23BA9 5 Bytes JMP 008A0058
.text C:\Windows\system32\svchost.exe[2024] ADVAPI32.dll!RegOpenKeyA 76E289C7 5 Bytes JMP 008A0000
.text C:\Windows\system32\svchost.exe[2024] ADVAPI32.dll!RegCreateKeyW 76E3391E 5 Bytes JMP 008A0069
.text C:\Windows\system32\svchost.exe[2024] ADVAPI32.dll!RegCreateKeyExW 76E341F1 5 Bytes JMP 008A0FC7
.text C:\Windows\system32\svchost.exe[2024] ADVAPI32.dll!RegOpenKeyExA 76E37C42 5 Bytes JMP 008A002C
.text C:\Windows\system32\svchost.exe[2024] ADVAPI32.dll!RegOpenKeyW 76E3E2B5 5 Bytes JMP 008A0011
.text C:\Windows\system32\svchost.exe[2024] ADVAPI32.dll!RegOpenKeyExW 76E47BA1 5 Bytes JMP 008A003D
.text C:\Windows\system32\svchost.exe[2068] ntdll.dll!NtCreateFile 77BC4224 5 Bytes JMP 00A10FE5
.text C:\Windows\system32\svchost.exe[2068] ntdll.dll!NtCreateProcess 77BC42E4 5 Bytes JMP 00A10000
.text C:\Windows\system32\svchost.exe[2068] ntdll.dll!NtProtectVirtualMemory 77BC4B84 5 Bytes JMP 00A10FD4
.text C:\Windows\system32\svchost.exe[2068] kernel32.dll!GetStartupInfoW 76D21929 5 Bytes JMP 009F0F36
.text C:\Windows\system32\svchost.exe[2068] kernel32.dll!GetStartupInfoA 76D219C9 5 Bytes JMP 009F0086
.text C:\Windows\system32\svchost.exe[2068] kernel32.dll!CreateProcessW 76D21BF3 5 Bytes JMP 009F00A1
.text C:\Windows\system32\svchost.exe[2068] kernel32.dll!CreateProcessA 76D21C28 5 Bytes JMP 009F0F0A
.text C:\Windows\system32\svchost.exe[2068] kernel32.dll!VirtualProtect 76D21DC3 5 Bytes JMP 009F0064
.text C:\Windows\system32\svchost.exe[2068] kernel32.dll!CreateNamedPipeA 76D22EF5 5 Bytes JMP 009F0011
.text C:\Windows\system32\svchost.exe[2068] kernel32.dll!CreateNamedPipeW 76D25C0C 5 Bytes JMP 009F0022
.text C:\Windows\system32\svchost.exe[2068] kernel32.dll!CreatePipe 76D48E6E 5 Bytes JMP 009F0075
.text C:\Windows\system32\svchost.exe[2068] kernel32.dll!LoadLibraryExW 76D49109 5 Bytes JMP 009F0F8A
.text C:\Windows\system32\svchost.exe[2068] kernel32.dll!LoadLibraryW 76D49362 5 Bytes JMP 009F0FA5
.text C:\Windows\system32\svchost.exe[2068] kernel32.dll!LoadLibraryExA 76D494B4 5 Bytes JMP 009F0047
.text C:\Windows\system32\svchost.exe[2068] kernel32.dll!LoadLibraryA 76D494DC 5 Bytes JMP 009F0FC0
.text C:\Windows\system32\svchost.exe[2068] kernel32.dll!VirtualProtectEx 76D4DBDA 5 Bytes JMP 009F0F6F
.text C:\Windows\system32\svchost.exe[2068] kernel32.dll!GetProcAddress 76D6903B 5 Bytes JMP 009F00B2
.text C:\Windows\system32\svchost.exe[2068] kernel32.dll!CreateFileW 76D6AECB 5 Bytes JMP 009F0FE5
.text C:\Windows\system32\svchost.exe[2068] kernel32.dll!CreateFileA 76D6CE5F 5 Bytes JMP 009F0000
.text C:\Windows\system32\svchost.exe[2068] kernel32.dll!WinExec 76DB5CF7 5 Bytes JMP 009F0F25
.text C:\Windows\system32\svchost.exe[2068] msvcrt.dll!_wsystem 77407F2F 5 Bytes JMP 00A30F92
.text C:\Windows\system32\svchost.exe[2068] msvcrt.dll!system 7740804B 5 Bytes JMP 00A30FAD
.text C:\Windows\system32\svchost.exe[2068] msvcrt.dll!_creat 7740BBE1 5 Bytes JMP 00A30FD2
.text C:\Windows\system32\svchost.exe[2068] msvcrt.dll!_open 7740D106 5 Bytes JMP 00A30000
.text C:\Windows\system32\svchost.exe[2068] msvcrt.dll!_wcreat 7740D326 5 Bytes JMP 00A30027
.text C:\Windows\system32\svchost.exe[2068] msvcrt.dll!_wopen 7740D501 5 Bytes JMP 00A30FE3
.text C:\Windows\system32\svchost.exe[2068] ADVAPI32.dll!RegCreateKeyExA 76E239AB 5 Bytes JMP 00A0003D
.text C:\Windows\system32\svchost.exe[2068] ADVAPI32.dll!RegCreateKeyA 76E23BA9 5 Bytes JMP 00A0002C
.text C:\Windows\system32\svchost.exe[2068] ADVAPI32.dll!RegOpenKeyA 76E289C7 5 Bytes JMP 00A00FE5
.text C:\Windows\system32\svchost.exe[2068] ADVAPI32.dll!RegCreateKeyW 76E3391E 5 Bytes JMP 00A00F9B
.text C:\Windows\system32\svchost.exe[2068] ADVAPI32.dll!RegCreateKeyExW 76E341F1 5 Bytes JMP 00A0004E
.text C:\Windows\system32\svchost.exe[2068] ADVAPI32.dll!RegOpenKeyExA 76E37C42 5 Bytes JMP 00A0001B
.text C:\Windows\system32\svchost.exe[2068] ADVAPI32.dll!RegOpenKeyW 76E3E2B5 5 Bytes JMP 00A0000A
.text C:\Windows\system32\svchost.exe[2068] ADVAPI32.dll!RegOpenKeyExW 76E47BA1 5 Bytes JMP 00A00FC0
.text C:\Windows\system32\svchost.exe[2068] WS2_32.dll!socket 773836D1 5 Bytes JMP 00A20000
.text C:\Windows\System32\svchost.exe[2108] ntdll.dll!NtCreateFile 77BC4224 5 Bytes JMP 000B0000
.text C:\Windows\System32\svchost.exe[2108] ntdll.dll!NtCreateProcess 77BC42E4 5 Bytes JMP 000B0022
.text C:\Windows\System32\svchost.exe[2108] ntdll.dll!NtProtectVirtualMemory 77BC4B84 5 Bytes JMP 000B0011
.text C:\Windows\System32\svchost.exe[2108] kernel32.dll!GetStartupInfoW 76D21929 5 Bytes JMP 00050F44
.text C:\Windows\System32\svchost.exe[2108] kernel32.dll!GetStartupInfoA 76D219C9 5 Bytes JMP 00050F55
.text C:\Windows\System32\svchost.exe[2108] kernel32.dll!CreateProcessW 76D21BF3 5 Bytes JMP 000500D1
.text C:\Windows\System32\svchost.exe[2108] kernel32.dll!CreateProcessA 76D21C28 5 Bytes JMP 000500C0
.text C:\Windows\System32\svchost.exe[2108] kernel32.dll!VirtualProtect 76D21DC3 5 Bytes JMP 00050051
.text C:\Windows\System32\svchost.exe[2108] kernel32.dll!CreateNamedPipeA 76D22EF5 5 Bytes JMP 00050FC0
.text C:\Windows\System32\svchost.exe[2108] kernel32.dll!CreateNamedPipeW 76D25C0C 5 Bytes JMP 00050011
.text C:\Windows\System32\svchost.exe[2108] kernel32.dll!CreatePipe 76D48E6E 5 Bytes JMP 00050080
.text C:\Windows\System32\svchost.exe[2108] kernel32.dll!LoadLibraryExW 76D49109 5 Bytes JMP 00050040
.text C:\Windows\System32\svchost.exe[2108] kernel32.dll!LoadLibraryW 76D49362 5 Bytes JMP 00050F94
.text C:\Windows\System32\svchost.exe[2108] kernel32.dll!LoadLibraryExA 76D494B4 5 Bytes JMP 00050F83
.text C:\Windows\System32\svchost.exe[2108] kernel32.dll!LoadLibraryA 76D494DC 5 Bytes JMP 00050FAF
.text C:\Windows\System32\svchost.exe[2108] kernel32.dll!VirtualProtectEx 76D4DBDA 5 Bytes JMP 00050F66
.text C:\Windows\System32\svchost.exe[2108] kernel32.dll!GetProcAddress 76D6903B 5 Bytes JMP 00050F1F
.text C:\Windows\System32\svchost.exe[2108] kernel32.dll!CreateFileW 76D6AECB 5 Bytes JMP 00050FDB
.text C:\Windows\System32\svchost.exe[2108] kernel32.dll!CreateFileA 76D6CE5F 5 Bytes JMP 00050000
.text C:\Windows\System32\svchost.exe[2108] kernel32.dll!WinExec 76DB5CF7 5 Bytes JMP 0005009B
.text C:\Windows\System32\svchost.exe[2108] msvcrt.dll!_wsystem 77407F2F 5 Bytes JMP 000C003F
.text C:\Windows\System32\svchost.exe[2108] msvcrt.dll!system 7740804B 5 Bytes JMP 000C0FBE
.text C:\Windows\System32\svchost.exe[2108] msvcrt.dll!_creat 7740BBE1 5 Bytes JMP 000C001D
.text C:\Windows\System32\svchost.exe[2108] msvcrt.dll!_open 7740D106 5 Bytes JMP 000C0FEF
.text C:\Windows\System32\svchost.exe[2108] msvcrt.dll!_wcreat 7740D326 5 Bytes JMP 000C002E
.text C:\Windows\System32\svchost.exe[2108] msvcrt.dll!_wopen 7740D501 5 Bytes JMP 000C000C
.text C:\Windows\System32\svchost.exe[2108] ADVAPI32.dll!RegCreateKeyExA 76E239AB 5 Bytes JMP 0006003D
.text C:\Windows\System32\svchost.exe[2108] ADVAPI32.dll!RegCreateKeyA 76E23BA9 5 Bytes JMP 0006002C
.text C:\Windows\System32\svchost.exe[2108] ADVAPI32.dll!RegOpenKeyA 76E289C7 5 Bytes JMP 00060000
.text C:\Windows\System32\svchost.exe[2108] ADVAPI32.dll!RegCreateKeyW 76E3391E 5 Bytes JMP 00060FA5
.text C:\Windows\System32\svchost.exe[2108] ADVAPI32.dll!RegCreateKeyExW 76E341F1 5 Bytes JMP 00060F80
.text C:\Windows\System32\svchost.exe[2108] ADVAPI32.dll!RegOpenKeyExA 76E37C42 5 Bytes JMP 0006001B
.text C:\Windows\System32\svchost.exe[2108] ADVAPI32.dll!RegOpenKeyW 76E3E2B5 5 Bytes JMP 00060FDB
.text C:\Windows\System32\svchost.exe[2108] ADVAPI32.dll!RegOpenKeyExW 76E47BA1 5 Bytes JMP 00060FCA
.text C:\Windows\System32\svchost.exe[2108] WS2_32.dll!socket 773836D1 5 Bytes JMP 00200FE5
.text C:\Windows\Explorer.EXE[3580] ntdll.dll!NtCreateFile 77BC4224 5 Bytes JMP 0283000A
.text C:\Windows\Explorer.EXE[3580] ntdll.dll!NtCreateProcess 77BC42E4 5 Bytes JMP 02830FD4
.text C:\Windows\Explorer.EXE[3580] ntdll.dll!NtProtectVirtualMemory 77BC4B84 5 Bytes JMP 02830FEF
.text C:\Windows\Explorer.EXE[3580] kernel32.dll!GetStartupInfoW 76D21929 5 Bytes JMP 02810F6D
.text C:\Windows\Explorer.EXE[3580] kernel32.dll!GetStartupInfoA 76D219C9 5 Bytes JMP 028100B3
.text C:\Windows\Explorer.EXE[3580] kernel32.dll!CreateProcessW 76D21BF3 5 Bytes JMP 02810F41
.text C:\Windows\Explorer.EXE[3580] kernel32.dll!CreateProcessA 76D21C28 5 Bytes JMP 02810F52
.text C:\Windows\Explorer.EXE[3580] kernel32.dll!VirtualProtect 76D21DC3 5 Bytes JMP 02810F99
.text C:\Windows\Explorer.EXE[3580] kernel32.dll!CreateNamedPipeA 76D22EF5 5 Bytes JMP 02810036
.text C:\Windows\Explorer.EXE[3580] kernel32.dll!CreateNamedPipeW 76D25C0C 5 Bytes JMP 02810051
.text C:\Windows\Explorer.EXE[3580] kernel32.dll!CreatePipe 76D48E6E 5 Bytes JMP 028100A2
.text C:\Windows\Explorer.EXE[3580] kernel32.dll!LoadLibraryExW 76D49109 5 Bytes JMP 0281007D
.text C:\Windows\Explorer.EXE[3580] kernel32.dll!LoadLibraryW 76D49362 5 Bytes JMP 02810FE5
.text C:\Windows\Explorer.EXE[3580] kernel32.dll!LoadLibraryExA 76D494B4 5 Bytes JMP 02810FCA
.text C:\Windows\Explorer.EXE[3580] kernel32.dll!LoadLibraryA 76D494DC 5 Bytes JMP 02810062
.text C:\Windows\Explorer.EXE[3580] kernel32.dll!VirtualProtectEx 76D4DBDA 5 Bytes JMP 02810F88
.text C:\Windows\Explorer.EXE[3580] kernel32.dll!GetProcAddress 76D6903B 5 Bytes JMP 02810F26
.text C:\Windows\Explorer.EXE[3580] kernel32.dll!CreateFileW 76D6AECB 5 Bytes JMP 0281001B
.text C:\Windows\Explorer.EXE[3580] kernel32.dll!CreateFileA 76D6CE5F 5 Bytes JMP 02810000
.text C:\Windows\Explorer.EXE[3580] kernel32.dll!WinExec 76DB5CF7 5 Bytes JMP 028100CE
.text C:\Windows\Explorer.EXE[3580] ADVAPI32.dll!RegCreateKeyExA 76E239AB 5 Bytes JMP 02820F97
.text C:\Windows\Explorer.EXE[3580] ADVAPI32.dll!RegCreateKeyA 76E23BA9 5 Bytes JMP 0282002F
.text C:\Windows\Explorer.EXE[3580] ADVAPI32.dll!RegOpenKeyA 76E289C7 5 Bytes JMP 02820FEF
.text C:\Windows\Explorer.EXE[3580] ADVAPI32.dll!RegCreateKeyW 76E3391E 5 Bytes JMP 02820FA8
.text C:\Windows\Explorer.EXE[3580] ADVAPI32.dll!RegCreateKeyExW 76E341F1 5 Bytes JMP 0282004A
.text C:\Windows\Explorer.EXE[3580] ADVAPI32.dll!RegOpenKeyExA 76E37C42 5 Bytes JMP 02820014
.text C:\Windows\Explorer.EXE[3580] ADVAPI32.dll!RegOpenKeyW 76E3E2B5 5 Bytes JMP 02820FDE
.text C:\Windows\Explorer.EXE[3580] ADVAPI32.dll!RegOpenKeyExW 76E47BA1 5 Bytes JMP 02820FC3
.text C:\Windows\Explorer.EXE[3580] msvcrt.dll!_wsystem 77407F2F 5 Bytes JMP 02860F9E
.text C:\Windows\Explorer.EXE[3580] msvcrt.dll!system 7740804B 5 Bytes JMP 02860FB9
.text C:\Windows\Explorer.EXE[3580] msvcrt.dll!_creat 7740BBE1 5 Bytes JMP 02860FEF
.text C:\Windows\Explorer.EXE[3580] msvcrt.dll!_open 7740D106 5 Bytes JMP 0286000C
.text C:\Windows\Explorer.EXE[3580] msvcrt.dll!_wcreat 7740D326 5 Bytes JMP 02860FCA
.text C:\Windows\Explorer.EXE[3580] msvcrt.dll!_wopen 7740D501 5 Bytes JMP 02860029
.text C:\Windows\Explorer.EXE[3580] WS2_32.dll!socket 773836D1 5 Bytes JMP 02850FEF
.text C:\Windows\Explorer.EXE[3580] WININET.dll!InternetReadFile 77CE654B 5 Bytes JMP 05D82D20 c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Windows\Explorer.EXE[3580] WININET.dll!InternetCloseHandle 77CE9088 5 Bytes JMP 05D82C00 c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Windows\Explorer.EXE[3580] WININET.dll!HttpOpenRequestA 77CED508 5 Bytes JMP 05D82EC0 c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Windows\Explorer.EXE[3580] WININET.dll!InternetConnectA 77CEDEAE 5 Bytes JMP 05D82FC0 c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Windows\Explorer.EXE[3580] WININET.dll!InternetOpenA 77CFD690 5 Bytes JMP 028B0FEF
.text C:\Windows\Explorer.EXE[3580] WININET.dll!InternetOpenW 77CFDB09 5 Bytes JMP 028B000A
.text C:\Windows\Explorer.EXE[3580] WININET.dll!InternetOpenUrlA 77CFF3A4 5 Bytes JMP 028B0FD4
.text C:\Windows\Explorer.EXE[3580] WININET.dll!InternetOpenUrlW 77D46D5F 5 Bytes JMP 028B002F
.text C:\Windows\system32\svchost.exe[4384] ntdll.dll!NtCreateFile 77BC4224 5 Bytes JMP 00040FE5
.text C:\Windows\system32\svchost.exe[4384] ntdll.dll!NtCreateProcess 77BC42E4 5 Bytes JMP 00040FB9
.text C:\Windows\system32\svchost.exe[4384] ntdll.dll!NtProtectVirtualMemory 77BC4B84 5 Bytes JMP 00040FCA
.text C:\Windows\system32\svchost.exe[4384] kernel32.dll!GetStartupInfoW 76D21929 5 Bytes JMP 0001009B
.text C:\Windows\system32\svchost.exe[4384] kernel32.dll!GetStartupInfoA 76D219C9 5 Bytes JMP 00010F5F
.text C:\Windows\system32\svchost.exe[4384] kernel32.dll!CreateProcessW 76D21BF3 5 Bytes JMP 00010F3A
.text C:\Windows\system32\svchost.exe[4384] kernel32.dll!CreateProcessA 76D21C28 5 Bytes JMP 000100D1
.text C:\Windows\system32\svchost.exe[4384] kernel32.dll!VirtualProtect 76D21DC3 5 Bytes JMP 00010F9C
.text C:\Windows\system32\svchost.exe[4384] kernel32.dll!CreateNamedPipeA 76D22EF5 5 Bytes JMP 00010036
.text C:\Windows\system32\svchost.exe[4384] kernel32.dll!CreateNamedPipeW 76D25C0C 5 Bytes JMP 00010047
.text C:\Windows\system32\svchost.exe[4384] kernel32.dll!CreatePipe 76D48E6E 5 Bytes JMP 00010F70
.text C:\Windows\system32\svchost.exe[4384] kernel32.dll!LoadLibraryExW 76D49109 5 Bytes JMP 00010FB9
.text C:\Windows\system32\svchost.exe[4384] kernel32.dll!LoadLibraryW 76D49362 5 Bytes JMP 00010FCA
.text C:\Windows\system32\svchost.exe[4384] kernel32.dll!LoadLibraryExA 76D494B4 5 Bytes JMP 0001006C
.text C:\Windows\system32\svchost.exe[4384] kernel32.dll!LoadLibraryA 76D494DC 5 Bytes JMP 00010FDB
.text C:\Windows\system32\svchost.exe[4384] kernel32.dll!VirtualProtectEx 76D4DBDA 5 Bytes JMP 00010F8B
.text C:\Windows\system32\svchost.exe[4384] kernel32.dll!GetProcAddress 76D6903B 5 Bytes JMP 00010F29
.text C:\Windows\system32\svchost.exe[4384] kernel32.dll!CreateFileW 76D6AECB 5 Bytes JMP 00010011
.text C:\Windows\system32\svchost.exe[4384] kernel32.dll!CreateFileA 76D6CE5F 5 Bytes JMP 00010000
.text C:\Windows\system32\svchost.exe[4384] kernel32.dll!WinExec 76DB5CF7 5 Bytes JMP 000100B6
.text C:\Windows\system32\svchost.exe[4384] msvcrt.dll!_wsystem 77407F2F 5 Bytes JMP 0006004B
.text C:\Windows\system32\svchost.exe[4384] msvcrt.dll!system 7740804B 5 Bytes JMP 0006003A
.text C:\Windows\system32\svchost.exe[4384] msvcrt.dll!_creat 7740BBE1 5 Bytes JMP 00060029
.text C:\Windows\system32\svchost.exe[4384] msvcrt.dll!_open 7740D106 5 Bytes JMP 00060000
.text C:\Windows\system32\svchost.exe[4384] msvcrt.dll!_wcreat 7740D326 5 Bytes JMP 00060FD4
.text C:\Windows\system32\svchost.exe[4384] msvcrt.dll!_wopen 7740D501 5 Bytes JMP 00060FEF
.text C:\Windows\system32\svchost.exe[4384] ADVAPI32.dll!RegCreateKeyExA 76E239AB 5 Bytes JMP 00070F94
.text C:\Windows\system32\svchost.exe[4384] ADVAPI32.dll!RegCreateKeyA 76E23BA9 5 Bytes JMP 0007002C
.text C:\Windows\system32\svchost.exe[4384] ADVAPI32.dll!RegOpenKeyA 76E289C7 5 Bytes JMP 00070FEF
.text C:\Windows\system32\svchost.exe[4384] ADVAPI32.dll!RegCreateKeyW 76E3391E 5 Bytes JMP 00070FAF
.text C:\Windows\system32\svchost.exe[4384] ADVAPI32.dll!RegCreateKeyExW 76E341F1 5 Bytes JMP 00070F79
.text C:\Windows\system32\svchost.exe[4384] ADVAPI32.dll!RegOpenKeyExA 76E37C42 5 Bytes JMP 00070FD4
.text C:\Windows\system32\svchost.exe[4384] ADVAPI32.dll!RegOpenKeyW 76E3E2B5 5 Bytes JMP 0007000A
.text C:\Windows\system32\svchost.exe[4384] ADVAPI32.dll!RegOpenKeyExW 76E47BA1 5 Bytes JMP 0007001B
.text C:\Windows\system32\svchost.exe[4384] WS2_32.dll!socket 773836D1 5 Bytes JMP 00080FEF

—- Devices - GMER 1.0.15 —-

Device Ntfs.sys (NT File System Driver/Microsoft Corporation)

AttachedDevice mfehidk.sys (McAfee Link Driver/McAfee, Inc.)

Device fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)

AttachedDevice \Driver\tdx \Device\Tcp mfewfpk.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\Udp mfewfpk.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device Fs_Rec.SYS (File System Recognizer Driver/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
Hello susanaj

Thank you for the logs :)

  • Combofix


  • Download ComboFix from one of the following locations:

    Link 1
    Link 2

  • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .
  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
  • Should there be issues with internet afterward:

    In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

    In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.

Please post the ComboFix log in your next reply.
Here's the combofix log:

ComboFix 11-06-04.02 - Susan 06/03/2011 17:59:33.3.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.2036.910 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Susan\AppData\Roaming\Microsoft\Windows\xxtlbph.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-05-03 to 2011-06-03 )))))))))))))))))))))))))))))))
.
.
2011-06-03 23:15 . 2011-06-03 23:18 ——– d—–w- c:\users\Susan\AppData\Local\temp
2011-06-03 23:15 . 2011-06-03 23:15 ——– d—–w- c:\users\Public\AppData\Local\temp
2011-06-03 23:15 . 2011-06-03 23:15 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-05-27 02:48 . 2011-05-27 02:48 ——– d—–w- c:\users\Susan\AppData\Roaming\iWin
2011-05-23 17:30 . 2011-06-03 11:15 ——– d—–w- c:\users\Susan\AppData\Roaming\NBT
2011-05-23 17:30 . 2011-05-26 03:28 ——– d—–w- c:\program files\MPAccess
2011-05-20 03:06 . 2011-05-20 03:06 ——– d—–w- c:\users\Susan\AppData\Local\{D99E27A1-64D1-4196-B3C4-F593DF9389E5}
2011-05-12 03:24 . 2011-04-07 12:01 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-29 14:11 . 2009-03-19 02:48 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-29 14:11 . 2009-03-19 02:48 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-05-20 03:06 . 2011-04-07 03:28 848 –sha-w- c:\programdata\KGyGaAvL.sys
2011-05-01 12:03 . 2011-05-01 12:02 404128 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-01 11:59 . 2010-04-16 01:30 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-04-18 10:23 . 2009-09-26 03:27 16432 —-a-w- c:\windows\system32\lsdelete.exe
2011-04-14 19:01 . 2010-07-10 20:04 9344 —-a-w- c:\windows\system32\drivers\mfeclnk.sys
2011-04-14 19:01 . 2010-07-10 20:04 95824 —-a-w- c:\windows\system32\drivers\mfeapfk.sys
2011-04-14 19:01 . 2010-07-10 20:04 84488 —-a-w- c:\windows\system32\drivers\mferkdet.sys
2011-04-14 19:01 . 2010-07-10 20:04 64584 —-a-w- c:\windows\system32\drivers\mfenlfk.sys
2011-04-14 19:01 . 2010-07-10 20:04 56064 —-a-w- c:\windows\system32\drivers\cfwids.sys
2011-04-14 19:01 . 2010-07-10 20:04 52320 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2011-04-14 19:01 . 2010-07-10 20:04 314088 —-a-w- c:\windows\system32\drivers\mfefirek.sys
2011-04-14 19:01 . 2010-07-10 20:04 165032 —-a-w- c:\windows\system32\drivers\mfewfpk.sys
2011-04-14 19:01 . 2010-07-10 20:04 153280 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2011-04-14 19:01 . 2009-03-25 16:06 387480 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2011-03-14 15:51 . 2010-06-24 16:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-03-12 21:55 . 2011-04-28 03:42 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-03-10 17:03 . 2011-04-13 23:53 1162240 —-a-w- c:\windows\system32\mfc42u.dll
2011-03-10 17:03 . 2011-04-13 23:53 1136640 —-a-w- c:\windows\system32\mfc42.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-09-20 39408]
"FileHippo.com"="c:\program files\FileHippo.com\UpdateChecker.exe" [2010-08-09 248832]
"NBT"="c:\users\Susan\AppData\Roaming\NBT\nbt.exe" [2011-05-23 552960]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 4907008]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-10-04 206064]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 133656]
"Monitor"="c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe" [2010-11-19 193880]
"ReminderApp"="c:\program files\Nova Development\Greeting Card Factory Photo Card Maker 2.0\ReminderApp.exe" [2008-10-07 180224]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-04-05 1195408]
"PMBVolumeWatcher"="c:\program files\Sony\PMB\PMBVolumeWatcher.exe" [2010-03-24 599328]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2011-1-10 291896]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-23 1295656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoAutoUpdate"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-11-10 18:49 932288 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel File Shell Monitor]
2008-08-08 23:30 16712 —-a-r- c:\program files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader]
2008-08-08 23:30 532808 —-a-r- c:\program files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2009-11-13 11:31 247144 —-a-w- c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 FlyUsb;FLY Fusion;c:\windows\system32\DRIVERS\FlyUsb.sys [2009-07-31 19456]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-04-14 84488]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 15544]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-12-03 64288]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2011-04-14 64584]
S1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2011-04-14 165032]
S2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-05 77824]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-09-24 155648]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2010-03-10 271480]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2010-03-10 271480]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 271480]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-04-14 188136]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2011-04-14 141792]
S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\Sony\PMB\PMBDeviceInfoProvider.exe [2009-10-24 360224]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\PSIA.exe [2011-01-10 993848]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files\Secunia\PSI\sua.exe [2011-01-10 399416]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2011-04-14 56064]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2011-05-16 2151128]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [2011-02-04 15232]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2011-04-14 314088]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - PGLOYPOW
*Deregistered* - mfeavfk01
*Deregistered* - pgloypow
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-03 c:\windows\Tasks\User_Feed_Synchronization-{CB1B7F5E-9FDE-47FB-879B-269873459B27}.job
- c:\windows\system32\msfeedssync.exe [2011-05-14 04:43]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mSearch Bar = hxxp://www.google.com
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
IE: Google Sidewiki…
TCP: DhcpNameServer = [removed] [removed]
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-cpjd[r2Ddkb9LmTrRp - c:\users\Susan\AppData\Roaming\Microsoft\Windows\xxtlbph.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-03 18:18
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-06-03 18:22:49
ComboFix-quarantined-files.txt 2011-06-03 23:22
.
Pre-Run: 219,251,159,040 bytes free
Post-Run: 219,463,987,200 bytes free
.
- - End Of File - - E50CC51BFB3EC62D34F719ECEAD64250
Hello susanaj

Thank you for the log.

If you have the anti virus component of Lavasoft Ad-Watch Live! installed, I suggest you uninstall it as you already have McAfee Anti-Virus and Anti-Spyware running. Pleaase make sure you only have ONE real time anti virus running on your machine.

  • Please scan the following files


  • Please go to VirusTotal


  • On the page you'll find a "Browse" button.
  • Click on the Browse button.
  • In the Choose File to Upload window which opens, copy and paste this into the File Name box.


c:\users\Susan\AppData\Roaming\NBT\nbt.exe


  • Next, click the Open button.
  • Then click the "Send File" button just below.
  • This will scan the file. Please be patient.
  • If you get a message saying File has already been analyzed: click Reanalyze file now.
  • Once scanned, copy and paste the link to the results page in your next reply.
Hello susanaj

Thank you for the scan result.

Please work your way through the following steps:

  • Please download SystemLook by JPShortstuff


    • Please download SystemLook by JPShortstuff by clicking here or here and save the file (called SystemLook.exe) to your desktop.
    • Double click SystemLook.exe to run the program.
    • Copy the content of the following codebox into the main textfield:

    :dir
    c:\users\Susan\AppData\Roaming\iWin
    c:\users\Susan\AppData\Roaming\NBT
    c:\users\Susan\AppData\Local\{D99E27A1-64D1-4196-B3C4-F593DF9389E5}

    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    • Note: The log can also be found on your Desktop entitled SystemLook.txt

  • MalwareBytes AntiMalware:


    • I can see that you have MBAM installed.
    • Double click on your MalwareBytes AntiMalware icon to launch the program.
    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform Quick Scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

    Please post the Systemlook log and the MBAM log in your next reply.

    Are you still receiving the popups?
I am still having the popups. What worries me most is the fact that they seem to know what website I'm on. they say "congrtulations what the tech visitor" "congratulations amazon visitor".

SystemLook 04.09.10 by jpshortstuff
Log created at 10:25 on 04/06/2011 by Susan
Administrator - Elevation successful

========== dir ==========

c:\users\Susan\AppData\Roaming\iWin - Parameters: "(none)"

—Files—
None found.

—Folders—
EmeraldTear d—— [02:48 27/05/2011]

c:\users\Susan\AppData\Roaming\NBT - Parameters: "(none)"

—Files—
config.cfg –a—- 3450544 bytes [17:30 23/05/2011] [11:38 04/06/2011]
nbt.exe –a—- 552960 bytes [17:30 23/05/2011] [17:30 23/05/2011]
NBTUninstall.exe –a—- 282624 bytes [17:32 23/05/2011] [17:32 23/05/2011]

—Folders—
None found.

c:\users\Susan\AppData\Local\{D99E27A1-64D1-4196-B3C4-F593DF9389E5} - Parameters: "(none)"

—Files—
None found.

—Folders—
None found.

-= EOF =-

***********************************************************

Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org

Database version: 6751

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19048

6/2/2011 12:29:59 AM
mbam-log-2011-06-02 (00-29-58).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 393958
Time elapsed: 1 hour(s), 42 minute(s), 54 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Hello susanaj

Sounds like we still have more to do. Please work your way through the following steps:

  • Please search for the following folder

    • Right-click your "Windows Orb" button and select "Explore".
    • Navigate to and delete the following folder in bold.

    c:\users\Susan\AppData\Local\{D99E27A1-64D1-4196-B3C4-F593DF9389E5} <==== Delete this folder.

    • Once deleted, empty your recycle bin.

  • Please un-install your outdated Java


    • Click on "Windows Orb" then on "Computer" and then on the "Uninstall or change a program" tab.
    • A list of currently installed programs will be displayed.
    • Find the "Java™ 6 Update 7" program, click on it once and then click on the "uninstall" button.
    • If you are prompted to re-boot your computer to complete the uninstall please do so.

  • Next


    • Copy and Paste the text in the code box below into Notepad

    @Echo on
    pushd\windows\system32\drivers\etc
    attrib -h -s -r hosts
    echo 127.0.0.1 localhost>HOSTS
    attrib +r +h +s hosts
    popd
    ipconfig /release
    ipconfig /renew
    ipconfig /flushdns
    netsh winsock reset all
    netsh int ip reset all
    shutdown -r -t 1
    del %0

    • Save this as flush.bat to your desktop.
    • You will see an icon on your desktop called flush.bat
    • Right click on it and choose to "Run as Administrator").
    • The computer will reboot itself.

    Do you use a router? If so please reset it using the instructions below:

  • Please reset your Router


    • This can be done by inserting something tiny like a paper clip end or pencil tip into a small hole labeled "reset" located on the back of the router.
    • Press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds).
    • If you don’t know the router's default password, you can look it up here
    • You also need to reconfigure any security settings you had in place prior to the reset.
    • You may also need to consult with your Internet service provider to find out which DNS servers your network should be using.

  • Temporary File Cleaner


    • Download TFC to your desktop.
    • Close any open windows.
    • Right click the TFC icon and select "Run as Administrator" to run the program.
    • TFC will close all open programs itself in order to run.
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish.
    • Once complete it should automatically reboot your machine.
    • If your machine does not reboot automatically, manually reboot to ensure a complete clean.
    • Note: After running TFC your machine may take slightly longer to boot the first time. This is normal.

    After working through those steps, lets see what the following scan can tell us:

  • Please run the following scan


    • Note: You will need to use Internet Explorer for this scan.
    • Note for Vista/Windows 7 Users: ESET is compatible but Internet Explorer must be run as Administrator. To do this, right-click on your Internet Explorer icon and select "Run as Administrator".
    • Please disable your real time security programs before performing the scan.


    • Scan your system with Eset Online Scanner
    • Place a check mark in the box YES, I accept the Terms Of Use.
    • Click the [external image: Posted Image] button.
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps).
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.


    • Check [external image: Posted Image]
    • Click the [external image: Posted Image] button.
    • Accept any security warnings from your browser.
    • Check [external image: Posted Image]
    • Make sure that the option to "Remove Found Threats" is UN checked.
    • Push the "Start" button.
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push [external image: Posted Image]
    • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • Push the [external image: Posted Image] button.
    • Push [external image: Posted Image]

    Please post the ESET log in your next reply.
Hello susanaj

What is "Windows Orb" button?

The Windows Orb is the Start button for Vista/Win7 machines (basically because it no longer has "start" written on it and is circular, like an orb).

  • Please download OTM


  • Please download OTM by OldTimer by clicking here.
  • Save the file (called OTM.exe) to your desktop.
  • Right-click on OTM.exe and choose Run As Administrator.
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):


:Processes 
explorer.exe

:Files
C:\Windows\System32\config\systemprofile\Desktop\Improve Your PC.lnk

:Commands
[Purity]
[EmptyTemp]
[Emptyflash]
[Start Explorer]
[Reboot]

  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM.
  • Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File -> Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Please post the OTM log and a new DDS log in your next reply and let me know how the machine is running now :)
Here's the OTM log: All processes killed ========== PROCESSES ========== No active process named explorer.exe was found! ========== FILES ========== C:\Windows\System32\config\systemprofile\Desktop\Improve Your PC.lnk moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes User: Susan ->Temp folder emptied: 304746 bytes ->Temporary Internet Files folder emptied: 14722044 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 1117 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 825229 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes %systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 15.00 mb OTM by OldTimer - Version 3.1.18.0 log created on 06052011_091314 Files moved on Reboot… Registry entries deleted on Reboot… ********************************************* Here's the DDS log: . DDS (Ver_2011-06-02.03) - NTFSx86 Internet Explorer: 8.0.6001.19048 Run by [removed] at 9:18:36 on 2011-06-05 . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\SLsvc.exe C:\Program Files\Dell\DellDock\DockLogin.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Program Files\Kodak\KODAK Share Button App\Listener.exe C:\Windows\system32\AERTSrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Windows\Explorer.EXE C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe C:\Windows\system32\rundll32.exe C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe C:\Windows\system32\PSIService.exe C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files\Secunia\PSI\PSIA.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Dell Support Center\bin\sprtcmd.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe C:\Program Files\Nova Development\Greeting Card Factory Photo Card Maker 2.0\ReminderApp.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\McAfee.com\Agent\mcagent.exe C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Users\Susan\AppData\Roaming\NBT\nbt.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe C:\Program Files\Secunia\PSI\sua.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\taskeng.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\servicing\TrustedInstaller.exe C:\Users\Susan\Desktop\dds.scr C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ mSearch Bar = hxxp://www.google.com uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20110605072841.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [FileHippo.com] "c:\program files\filehippo.com\UpdateChecker.exe" /background uRun: [NBT] c:\users\susan\appdata\roaming\nbt\nbt.exe mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [Monitor] "c:\program files\leapfrog\leapfrog connect\Monitor.exe" mRun: [ReminderApp] c:\program files\nova development\greeting card factory photo card maker 2.0\ReminderApp.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [PMBVolumeWatcher] c:\program files\sony\pmb\PMBVolumeWatcher.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-explorer: NoAutoUpdate = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Google Sidewiki… IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{D27BA063-362D-43E4-A87C-9B4E94CE0394} : DhcpNameServer = [removed] [removed] Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~1\mcafee\msc\McSnIePl.dll Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Handler: jpip - {B92DD248-E3D5-4A92-B311-C9B841681455} - c:\program files\lizardtech\express view\expressview.dll Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Handler: sidlet - {B92DD248-E3D5-4A92-B311-C9B841681455} - c:\program files\lizardtech\express view\expressview.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll Notify: igfxcui - igfxdev.dll . ============= SERVICES / DRIVERS =============== . R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86 R? FlyUsb;FLY Fusion R? fssfltr;fssfltr R? fsssvc;Windows Live Family Safety Service R? Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service R? Lavasoft Kernexplorer;Lavasoft helper driver R? mferkdet;McAfee Inc. mferkdet R? mferkdk;McAfee Inc. mferkdk R? PSI;PSI R? TomTomHOMEService;TomTomHOMEService R? wlcrasvc;Windows Live Mesh remote connections service R? WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0 S? AERTFilters;Andrea RT Filters Service S? cfwids;McAfee Inc. cfwids S? DockLoginService;Dock Login Service S? FontCache;Windows Font Cache Service S? Lbd;Lbd S? McAfee SiteAdvisor Service;McAfee SiteAdvisor Service S? McMPFSvc;McAfee Personal Firewall Service S? McNaiAnn;McAfee VirusScan Announcer S? McProxy;McAfee Proxy Service S? McShield;McAfee McShield S? mfeavfk;McAfee Inc. mfeavfk S? mfebopk;McAfee Inc. mfebopk S? mfefire;McAfee Firewall Core Service S? mfefirek;McAfee Inc. mfefirek S? mfehidk;McAfee Inc. mfehidk S? mfenlfk;McAfee NDIS Light Filter S? mfevtp;McAfee Validation Trust Protection Service S? mfewfpk;McAfee Inc. mfewfpk S? PMBDeviceInfoProvider;PMBDeviceInfoProvider S? Secunia PSI Agent;Secunia PSI Agent S? Secunia Update Agent;Secunia Update Agent . =============== Created Last 30 ================ . 2011-06-05 14:13:14 ——– d—–w- C:\_OTM 2011-06-03 23:22:58 ——– d-sh–w- C:\$RECYCLE.BIN 2011-06-03 23:22:52 ——– d—–w- c:\users\susan\appdata\local\temp 2011-06-03 22:55:37 98816 —-a-w- c:\windows\sed.exe 2011-06-03 22:55:37 518144 —-a-w- c:\windows\SWREG.exe 2011-06-03 22:55:37 256512 —-a-w- c:\windows\PEV.exe 2011-06-03 22:55:37 208896 —-a-w- c:\windows\MBR.exe 2011-05-27 02:48:49 ——– d—–w- c:\users\susan\appdata\roaming\iWin 2011-05-23 17:30:44 ——– d—–w- c:\users\susan\appdata\roaming\NBT 2011-05-23 17:30:41 ——– d—–w- c:\program files\MPAccess 2011-05-12 03:24:57 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat . ==================== Find3M ==================== . 2011-05-29 14:11:30 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-05-29 14:11:20 22712 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-05-20 03:06:23 848 –sha-w- c:\programdata\KGyGaAvL.sys 2011-05-01 12:03:05 404128 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-05-01 11:59:30 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-04-18 10:23:39 16432 —-a-w- c:\windows\system32\lsdelete.exe 2011-03-13 16:20:10 9344 —-a-w- c:\windows\system32\drivers\mfeclnk.sys 2011-03-13 16:20:10 85984 —-a-w- c:\windows\system32\drivers\mferkdet.sys 2011-03-13 16:20:10 64648 —-a-w- c:\windows\system32\drivers\mfenlfk.sys 2011-03-13 16:20:10 59288 —-a-w- c:\windows\system32\drivers\mfebopk.sys 2011-03-13 16:20:10 57432 —-a-w- c:\windows\system32\drivers\cfwids.sys 2011-03-13 16:20:10 459728 —-a-w- c:\windows\system32\drivers\mfehidk.sys 2011-03-13 16:20:10 337912 —-a-w- c:\windows\system32\drivers\mfefirek.sys 2011-03-13 16:20:10 179248 —-a-w- c:\windows\system32\drivers\mfeavfk.sys 2011-03-13 16:20:10 163400 —-a-w- c:\windows\system32\drivers\mfewfpk.sys 2011-03-13 16:20:10 118784 —-a-w- c:\windows\system32\drivers\mfeapfk.sys 2011-03-12 21:55:52 876032 —-a-w- c:\windows\system32\XpsPrint.dll 2011-03-10 17:03:51 1162240 —-a-w- c:\windows\system32\mfc42u.dll 2011-03-10 17:03:51 1136640 —-a-w- c:\windows\system32\mfc42.dll . ============= FINISH: 9:20:42.18 ===============

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI