This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

How to delete your cache voice in internet explorer. Virus?

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi im having a voice just appear out of no where in internet explorer telling me how to delete my cache and cookies. Is it a virus?
My computers OS is windows 7 32 bit.

Thank you to everyone that helps! :D

Here is my hijack this log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:34:18 AM, on 16/10/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\eMachines\Hotkey Utility\HotkeyUtility.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\eMachines\Hotkey Utility\HotkeyUI.exe
C:\Program Files\D-Link\DWA-125 revA\AirGCFG.exe
C:\Program Files\D-Link\DWA-125 revA\WZCSLDR2.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
C:\Program Files\Xfire\Xfire.exe
C:\Program Files\Xfire\Xfire.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10x_ActiveX.exe
C:\Windows\explorer.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\John\Desktop\HiJackThis.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…05v155r4541s20p
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…05v155r4541s20p
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…05v155r4541s20p
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\5.1.0.29\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\5.1.0.29\IPS\IPSBHO.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\5.1.0.29\coIEPlg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [Hotkey Utility] C:\Program Files\eMachines\Hotkey Utility\HotkeyUtility.exe
O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [D-Link D-Link DWA-125] C:\Program Files\D-Link\DWA-125 revA\AirGCFG.exe
O4 - HKLM\..\Run: [WZCSLDR2] C:\Program Files\D-Link\DWA-125 revA\WZCSLDR2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-2012466219-1071589462-2858221201-1003\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-2012466219-1071589462-2858221201-1003\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos-beta/OnlineScanner.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs:
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: D_Link_DWA-125 Service (D_Link_DWA-125) - Wireless Service - C:\Program Files\D-Link\DWA-125 revA\ANIWZCSdS.exe
O23 - Service: D_Link_DWA-125_WPS Service (D_Link_DWA-125_WPS) - Unknown owner - C:\Program Files\D-Link\DWA-125 revA\ANIWConnService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\eMachines Games\eMachines Game Console\GameConsoleService.exe
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files\eMachines\Registration\GregHSRW.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: SCM_Service - Unknown owner - C:\Windows\System32\WinService.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: Updater Service - Acer Group - C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe

–
End of file - 10659 bytes
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Having said that….Let's get going!! :thumbup:
———-
Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Right-click and Run as Administrator dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Right-click and Run as Administrator GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.
———-

Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post the logs created by DDS, GMER and aswMBR.exe. :)
Hi, thanks for your support!

Here is my DDS log:

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by [removed] at 14:21:02 on 2011-10-16
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.61.1033.18.3063.1836 [GMT 11:00]
.
AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\D-Link\DWA-125 revA\ANIWZCSdS.exe
C:\Program Files\D-Link\DWA-125 revA\ANIWConnService.exe
C:\Program Files\eMachines\Registration\GregHSRW.exe
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\System32\WinService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\eMachines\Hotkey Utility\HotkeyUtility.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\D-Link\DWA-125 revA\AirGCFG.exe
C:\Program Files\D-Link\DWA-125 revA\WZCSLDR2.exe
C:\Program Files\eMachines\Hotkey Utility\HotkeyUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
C:\Program Files\Xfire\Xfire.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Steam\SteamService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Xfire\Xfire.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10x_ActiveX.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com.au/ig?sourceid=navclient&ie;=UTF-8&hl;=en&source;=iglk
uDefault_Page_URL = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l;=0c09&m;=et1862&r;=17350111b206p0405v155r4541s20p
mDefault_Page_URL = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l;=0c09&m;=et1862&r;=17350111b206p0405v155r4541s20p
mStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l;=0c09&m;=et1862&r;=17350111b206p0405v155r4541s20p
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\5.1.0.29\ips\IPSBHO.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Steam] "c:\program files\steam\steam.exe" -silent
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [RESTART_STICKY_NOTES] c:\windows\system32\StikyNot.exe
mRun: [IAStorIcon] c:\program files\intel\intel® rapid storage technology\IAStorIcon.exe
mRun: [Hotkey Utility] c:\program files\emachines\hotkey utility\HotkeyUtility.exe
mRun: [NortonOnlineBackupReminder] "c:\program files\symantec\norton online backup\activation\NobuActivation.exe" UNATTENDED
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [D-Link D-Link DWA-125] c:\program files\d-link\dwa-125 reva\AirGCFG.exe
mRun: [WZCSLDR2] c:\program files\d-link\dwa-125 reva\WZCSLDR2.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
StartupFolder: c:\users\john\appdata\roaming\micros~1\windows\startm~1\programs\startup\xfire.lnk - c:\program files\xfire\Xfire.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg111v2\WG111v2.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = [removed] [removed] [removed]
TCP: Interfaces\{470F9607-C743-4AF5-97EF-DF97D9EC44F4} : DhcpNameServer = [removed] [removed] [removed]
TCP: Interfaces\{84438A68-6013-4957-B852-6D4B0E258D51} : DhcpNameServer = [removed] [removed] [removed]
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs:
.
============= SERVICES / DRIVERS ===============
.
R0 SCMNdisP;General NDIS Protocol Driver;c:\windows\system32\drivers\SCMNdisP.sys [2011-1-18 21728]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0501000.01d\symds.sys [2011-5-11 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0501000.01d\symefa.sys [2011-5-11 744568]
R1 anodlwf;ANOD Network Security Filter driver;c:\windows\system32\drivers\anodlwf.sys [2011-1-27 12800]
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.0.0.125\definitions\bashdefs\20110929.001\BHDrvx86.sys [2011-9-30 816760]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.0.0.125\definitions\ipsdefs\20111014.031\IDSvix86.sys [2011-10-15 368248]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0501000.01d\ironx86.sys [2011-5-11 136312]
R1 SymNetS;Symantec Network Security WFP Driver;c:\windows\system32\drivers\n360\0501000.01d\symnets.sys [2011-5-11 299640]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 D_Link_DWA-125;D_Link_DWA-125 Service;c:\program files\d-link\dwa-125 reva\ANIWZCSdS.exe [2011-1-27 126976]
R2 D_Link_DWA-125_WPS;D_Link_DWA-125_WPS Service;c:\program files\d-link\dwa-125 reva\ANIWConnService.exe [2011-1-27 40960]
R2 Greg_Service;GRegService;c:\program files\emachines\registration\GregHSRW.exe [2009-8-28 1150496]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files\intel\intel® rapid storage technology\IAStorDataMgrSvc.exe [2010-4-2 13336]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-10-13 366152]
R2 N360;Norton 360;c:\program files\norton 360\engine\5.1.0.29\ccsvchst.exe [2011-5-11 130008]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-8-14 2214504]
R2 SCM_Service;SCM_Service;c:\windows\system32\WinService.exe [2011-1-18 180224]
R2 Updater Service;Updater Service;c:\program files\emachines\emachines updater\UpdaterService.exe [2010-4-2 243232]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-7-29 105592]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-5-4 22216]
R3 netr28u;D-Link dnetr28u USB Extensible Wireless LAN Card Driver;c:\windows\system32\drivers\Dnetr28u.sys [2011-1-27 807936]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2010-4-2 68200]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2010-4-2 277536]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-19 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-1-18 135664]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2011-1-24 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-1-18 135664]
S3 RTL8187;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v2.sys [2011-1-18 288768]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-7-2 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-1-20 1343400]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-23 51040]
.
=============== Created Last 30 ================
.
2011-10-16 03:20:01 ——– d—–w- c:\users\john\appdata\local\{277C47B5-8567-4846-BCE3-2650D7B6217E}
2011-10-16 03:19:24 ——– d—–w- c:\users\john\appdata\local\{EE4CBA93-F54D-4B04-A63A-312CA58AEF14}
2011-10-16 03:14:25 ——– d—–w- c:\users\john\appdata\local\{66BFBF90-A45C-46B9-9A91-E97BFE4BE260}
2011-10-15 23:16:38 ——– d—–w- c:\users\john\appdata\local\{A8A5ACEB-7E0A-42DD-9C44-924530CDB8EF}
2011-10-15 23:16:17 ——– d—–w- c:\users\john\appdata\local\{40D9A814-7E79-44B0-865B-7EB4C0A82F39}
2011-10-14 23:53:40 ——– d—–w- c:\users\john\appdata\local\{2DC96C5D-AD3C-486E-8A6E-86F5686A4E6C}
2011-10-14 23:53:04 ——– d—–w- c:\users\john\appdata\local\{175A7F8C-2EE1-414D-AB1F-6B0059698AA1}
2011-10-13 23:34:01 ——– d—–w- c:\users\john\appdata\local\{F3683C86-AE2B-4C31-AA27-B50F6E0DCA9A}
2011-10-13 23:33:49 ——– d—–w- c:\users\john\appdata\local\{2A4A1A40-4C44-4492-AE78-702AB375345F}
2011-10-13 20:29:40 42392 —-a-w- c:\windows\system32\xfcodec.dll
2011-10-13 10:39:29 75776 —-a-w- c:\windows\system32\psisrndr.ax
2011-10-13 10:39:29 571904 —-a-w- c:\windows\system32\oleaut32.dll
2011-10-13 10:39:29 465408 —-a-w- c:\windows\system32\psisdecd.dll
2011-10-13 10:39:29 233472 —-a-w- c:\windows\system32\oleacc.dll
2011-10-13 10:39:25 2334720 —-a-w- c:\windows\system32\win32k.sys
2011-10-13 07:25:00 ——– d—–w- c:\users\john\appdata\local\{06881994-AFC7-45AE-93FE-2A64451B1D5B}
2011-10-13 07:24:24 ——– d—–w- c:\users\john\appdata\local\{ED9A22B0-F288-46C7-A79F-9A1909768005}
2011-10-13 04:09:47 ——– d—–w- c:\users\john\appdata\local\{E5BA6B09-04AD-499F-892B-1AF134A18420}
2011-10-13 04:09:28 ——– d—–w- c:\users\john\appdata\local\{6207A9EC-7C4E-4266-B1E1-B5C6B097FF7B}
2011-10-12 04:45:06 ——– d—–w- c:\users\john\appdata\local\{9B6BFA7F-74F2-4499-BAAD-9BF84E0BC89D}
2011-10-12 04:44:42 ——– d—–w- c:\users\john\appdata\local\{39D94AD3-9D56-4965-AF9A-51768AC932B5}
2011-10-11 06:03:20 ——– d—–w- c:\users\john\appdata\local\{2E2A0155-CBB7-4C04-8DB2-CD5FADD68C7D}
2011-10-11 06:02:43 ——– d—–w- c:\users\john\appdata\local\{9E779AC6-692C-4D36-85AF-414D86FB4EB9}
2011-10-10 04:40:18 ——– d—–w- c:\users\john\appdata\local\{F3162A79-F911-4891-8E07-84C2E396EE76}
2011-10-10 04:39:53 ——– d—–w- c:\users\john\appdata\local\{47B6C83B-ED44-48C2-9C52-A7888FB0076D}
2011-10-09 01:35:40 ——– d—–w- c:\users\john\appdata\local\{54405EF1-84A2-47C9-B2F5-26AAA0E69A60}
2011-10-09 01:35:19 ——– d—–w- c:\users\john\appdata\local\{C67E4AEC-F8F3-41FC-AF03-E0ABB06EFF4B}
2011-10-08 06:53:15 ——– d—–w- c:\users\john\appdata\local\{A20D6F88-268A-4254-9C4D-B54375D18B1B}
2011-10-08 06:53:03 ——– d—–w- c:\users\john\appdata\local\{B8840555-615E-4CD3-800E-4B360142DAB8}
2011-10-05 23:48:47 ——– d—–w- c:\users\john\appdata\local\{1065A89F-49C0-4EA4-B091-2C3305564DB3}
2011-10-05 23:48:09 ——– d—–w- c:\users\john\appdata\local\{7B7B0A95-095E-4CFB-85BB-FA203FACF2E3}
2011-10-05 00:04:34 ——– d—–w- c:\users\john\appdata\local\{EA34DDCB-B72C-479D-AE67-2E1A9DEBD553}
2011-10-05 00:04:21 ——– d—–w- c:\users\john\appdata\local\{EB4CCFA3-D2D5-45B9-B4C0-18C22DFA6E9B}
2011-10-04 14:26:02 ——– d—–w- c:\users\john\appdata\local\{C6D66C78-EC00-4DB6-8397-AB6423EA480B}
2011-10-04 09:47:50 ——– d—–w- c:\users\john\appdata\local\{5E75560E-DEBC-4BB5-A841-A0A6A38AB3BD}
2011-10-04 09:47:25 ——– d—–w- c:\users\john\appdata\local\{1C2D5735-94D7-456F-ADB2-29C0F62F4DFF}
2011-10-03 18:30:17 ——– d—–w- c:\users\john\appdata\local\{000A0A33-F809-490E-B8E4-4BD5E52022AF}
2011-10-03 18:29:40 ——– d—–w- c:\users\john\appdata\local\{E481C62E-1F62-4204-B69B-782461C819CC}
2011-10-02 17:02:37 ——– d—–w- c:\users\john\appdata\local\{5C2C5B45-C37E-4178-862F-B5642612B0E4}
2011-10-02 17:02:14 ——– d—–w- c:\users\john\appdata\local\{4C2BCD77-8009-4149-BC5E-50029A03A618}
2011-10-01 18:38:24 ——– d—–w- c:\users\john\appdata\local\{133B6ACD-DABA-4646-AEE0-741CF1BC4EF4}
2011-10-01 18:38:01 ——– d—–w- c:\users\john\appdata\local\{3E77FA1B-FC15-484F-900B-7111F3AED6D5}
2011-09-30 12:56:55 ——– d—–w- c:\users\john\appdata\local\{437A7368-3E36-4599-9DCD-487CAA5E6700}
2011-09-30 12:56:15 ——– d—–w- c:\users\john\appdata\local\{CE1D89CE-D933-44C2-9E21-6E119EEC2608}
2011-09-29 23:03:24 ——– d—–w- c:\users\john\appdata\local\{23A128F4-C620-4697-BF09-7F3152E9D314}
2011-09-29 23:03:08 ——– d—–w- c:\users\john\appdata\local\{2777E7D5-2D99-45A7-B822-612635B25E2D}
2011-09-28 21:17:24 ——– d—–w- c:\users\john\appdata\local\{9C68FD35-EA4B-445F-ABAA-D590D3980E8A}
2011-09-28 21:17:05 ——– d—–w- c:\users\john\appdata\local\{B9B4217A-6457-4B0B-BBEA-EC365F0D2C06}
2011-09-27 22:33:38 ——– d—–w- c:\program files\StarCraft II
2011-09-27 22:31:53 ——– d—–w- c:\users\john\appdata\local\{5AEE0050-4C3B-4955-AD23-06E52D20AFCE}
2011-09-27 22:31:17 ——– d—–w- c:\users\john\appdata\local\{30383B8F-0A6E-453D-8825-3B0FFB2FA88F}
2011-09-25 18:41:58 ——– d—–w- c:\users\john\appdata\local\{000AAB4D-1EAF-4EAE-9BC2-8BFB944F1A2C}
2011-09-25 18:41:20 ——– d—–w- c:\users\john\appdata\local\{9FEF67A5-9DD6-4EA2-A39D-81F87F4F63E3}
2011-09-24 17:50:59 ——– d—–w- c:\users\john\appdata\local\{01BF8D58-1E50-4DFC-A510-57F9477A0867}
2011-09-24 17:50:23 ——– d—–w- c:\users\john\appdata\local\{5402EC08-5B89-4C0D-97D1-FF8E9AAE72B2}
2011-09-23 22:58:00 ——– d—–w- c:\users\john\appdata\local\{6B6B605A-C713-4BBB-8C26-0E6DEBD0B394}
2011-09-23 17:42:51 ——– d—–w- c:\users\john\appdata\local\{C49ABE85-C4B1-4E52-8AD6-50BB10DCEB06}
2011-09-23 17:42:14 ——– d—–w- c:\users\john\appdata\local\{F31E5C09-7A76-4996-937E-867E7F217836}
2011-09-22 21:59:20 ——– d—–w- c:\users\john\appdata\local\{C151FFC5-A1C6-45D0-A715-0B425F62BA80}
2011-09-22 21:58:55 ——– d—–w- c:\users\john\appdata\local\{1FF8052E-4BD6-4673-B52C-70CFF33BB949}
2011-09-22 02:16:48 ——– d—–w- c:\users\john\appdata\local\{CD581904-0E11-4C46-AEB5-D732435B5B0A}
2011-09-22 02:16:26 ——– d—–w- c:\users\john\appdata\local\{8E9D92C4-969D-4520-B5EC-9C854A4D374F}
2011-09-20 05:32:29 ——– d—–w- c:\users\john\appdata\local\{8037393B-A788-445E-B8B2-9FAC4A17AB7B}
2011-09-20 05:32:04 ——– d—–w- c:\users\john\appdata\local\{F784A5A9-BF61-4AB7-B854-4B5747DD2A32}
2011-09-19 02:39:30 ——– d—–w- c:\users\john\appdata\local\{7A513EAF-448B-49FC-A438-D324F4CD79E2}
2011-09-19 02:38:54 ——– d—–w- c:\users\john\appdata\local\{AC7EECC5-AEB5-434E-903B-6B36F7788FA8}
2011-09-19 00:50:28 ——– d—–w- c:\users\john\appdata\local\{A6B81EEB-A3C7-44A0-8AF5-F677D360BA76}
2011-09-19 00:50:06 ——– d—–w- c:\users\john\appdata\local\{C4593D52-AD69-45BF-AD45-08D91F48DEF8}
2011-09-17 20:36:52 ——– d—–w- c:\users\john\appdata\local\{25D88E27-A9C0-414D-81A6-187DEC2EF970}
2011-09-17 02:55:55 ——– d—–w- c:\users\john\appdata\local\{BF674C5C-DDDA-40FC-8645-C30DA525EBE5}
2011-09-17 02:55:29 ——– d—–w- c:\users\john\appdata\local\{3FFC7638-973A-4AD9-AF2E-9F7B16D49BDF}
2011-09-16 03:35:59 ——– d—–w- c:\users\john\appdata\local\{21DA803F-6181-4BEB-B020-DC665D2C2BAB}
2011-09-16 03:35:40 ——– d—–w- c:\users\john\appdata\local\{1EDF4DF3-7C0D-4C82-8DAD-C787AB8EFF78}
.
==================== Find3M ====================
.
2011-09-25 18:41:42 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-01 02:35:59 1798144 —-a-w- c:\windows\system32\jscript9.dll
2011-09-01 02:28:15 1126912 —-a-w- c:\windows\system32\wininet.dll
2011-09-01 02:22:54 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2011-08-31 06:00:50 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
.
============= FINISH: 14:21:42.92 ===============


Here is my Gmer log:

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-10-16 14:43:29
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD10 rev.01.0
Running: gmer.exe; Driver: C:\Users\John\AppData\Local\Temp\kgldypob.sys


—- System - GMER 1.0.15 —-

SSDT 89043428 ZwAlertResumeThread
SSDT 89043590 ZwAlertThread
SSDT 89043EA0 ZwAllocateVirtualMemory
SSDT 88964608 ZwAlpcConnectPort
SSDT 8903EA48 ZwAssignProcessToJobObject
SSDT 89043178 ZwCreateMutant
SSDT 8903E768 ZwCreateSymbolicLinkObject
SSDT 89041A38 ZwCreateThread
SSDT 8903E858 ZwCreateThreadEx
SSDT 8903EB28 ZwDebugActiveProcess
SSDT 89041700 ZwDuplicateObject
SSDT 89043CC0 ZwFreeVirtualMemory
SSDT 89043268 ZwImpersonateAnonymousToken
SSDT 89043348 ZwImpersonateThread
SSDT 887DB590 ZwLoadDriver
SSDT 89043BC0 ZwMapViewOfSection
SSDT 89043098 ZwOpenEvent
SSDT 890418E0 ZwOpenProcess
SSDT 89043F90 ZwOpenProcessToken
SSDT 8903EE70 ZwOpenSection
SSDT 890417F0 ZwOpenThread
SSDT 8903E958 ZwProtectVirtualMemory
SSDT 89043670 ZwResumeThread
SSDT 89043910 ZwSetContextThread
SSDT 890439F0 ZwSetInformationProcess
SSDT 8903ED28 ZwSetSystemInformation
SSDT 8903EF50 ZwSuspendProcess
SSDT 89043750 ZwSuspendThread
SSDT 89041B38 ZwTerminateProcess
SSDT 89043830 ZwTerminateThread
SSDT 89043AE0 ZwUnmapViewOfSection
SSDT 89043DB0 ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwSaveKey + 13D1 83079349 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 830B2D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, …] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10DB 830B9D90 8 Bytes [28, 34, 04, 89, 90, 35, 04, …]
.text ntkrnlpa.exe!KeRemoveQueueEx + 10F3 830B9DA8 4 Bytes [A0, 3E, 04, 89]
.text ntkrnlpa.exe!KeRemoveQueueEx + 10FF 830B9DB4 4 Bytes [08, 46, 96, 88]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1153 830B9E08 4 Bytes JMP A87C8903
.text ntkrnlpa.exe!KeRemoveQueueEx + 11CF 830B9E84 4 Bytes [78, 31, 04, 89] {JS 0x33; ADD AL, 0x89}
.text …
? C:\Users\John\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Xfire\Xfire.exe[772] kernel32.dll!CreateProcessA 774C2082 5 Bytes JMP 066C316C C:\Program Files\Xfire\xfire_toucan_44598.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[772] kernel32.dll!CreateThread 7750DCC2 5 Bytes JMP 066C2B10 C:\Program Files\Xfire\xfire_toucan_44598.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[772] GDI32.dll!BitBlt 774772C0 5 Bytes JMP 066C2588 C:\Program Files\Xfire\xfire_toucan_44598.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[772] USER32.dll!InvalidateRgn 75E17FA5 5 Bytes JMP 066C276E C:\Program Files\Xfire\xfire_toucan_44598.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[772] USER32.dll!GetCursorPos 75E1A4B3 5 Bytes JMP 066C28A4 C:\Program Files\Xfire\xfire_toucan_44598.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[772] USER32.dll!SetFocus 75E1ABAD 5 Bytes JMP 066C2638 C:\Program Files\Xfire\xfire_toucan_44598.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[772] USER32.dll!SetForegroundWindow 75E1B225 5 Bytes JMP 066C2DA9 C:\Program Files\Xfire\xfire_toucan_44598.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[772] USER32.dll!RegisterClassA 75E1BC6A 5 Bytes JMP 066C2A78 C:\Program Files\Xfire\xfire_toucan_44598.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[772] USER32.dll!CreateWindowExW 75E1EC7C 5 Bytes JMP 066C2E41 C:\Program Files\Xfire\xfire_toucan_44598.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[772] USER32.dll!SetWindowPos 75E21BC4 5 Bytes JMP 066C2CFF C:\Program Files\Xfire\xfire_toucan_44598.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[772] USER32.dll!RedrawWindow 75E229BC 5 Bytes JMP 066C29D7 C:\Program Files\Xfire\xfire_toucan_44598.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[772] USER32.dll!IsWindowVisible 75E24D69 7 Bytes JMP 066C2EFA C:\Program Files\Xfire\xfire_toucan_44598.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[772] USER32.dll!ReleaseDC 75E25421 5 Bytes JMP 066C24ED C:\Program Files\Xfire\xfire_toucan_44598.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[772] USER32.dll!GetDC 75E2544C 5 Bytes JMP 066C2459 C:\Program Files\Xfire\xfire_toucan_44598.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[772] USER32.dll!InvalidateRect 75E2566D 5 Bytes JMP 066C26D0 C:\Program Files\Xfire\xfire_toucan_44598.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[772] USER32.dll!BeginPaint 75E25D14 5 Bytes JMP 066C23C5 C:\Program Files\Xfire\xfire_toucan_44598.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[772] USER32.dll!TrackPopupMenu 75E32228 5 Bytes JMP 066C30C2 C:\Program Files\Xfire\xfire_toucan_44598.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[772] USER32.dll!DialogBoxParamW 75E33B9B 5 Bytes JMP 066C2BB7 C:\Program Files\Xfire\xfire_toucan_44598.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[772] USER32.dll!CreateDialogParamW 75E45630 5 Bytes JMP 066C2C5B C:\Program Files\Xfire\xfire_toucan_44598.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[772] USER32.dll!SetCapture 75E46932 5 Bytes JMP 066C280C C:\Program Files\Xfire\xfire_toucan_44598.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[772] USER32.dll!WindowFromPoint 75E46BE9 5 Bytes JMP 066C293C C:\Program Files\Xfire\xfire_toucan_44598.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] ntdll.dll!NtMapViewOfSection 775E5C28 5 Bytes JMP 063A00B3
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] kernel32.dll!K32GetPerformanceInfo + 1CC 774F62DF 7 Bytes JMP 063A0222
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] kernel32.dll!TerminateProcess + B 77502BC8 7 Bytes JMP 063A038E
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] kernel32.dll!QueryPerformanceCounter + 13 7750C435 7 Bytes JMP 063A02D8
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] kernel32.dll!CreateThread 7750DCC2 5 Bytes JMP 6989723B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] kernel32.dll!FreeLibrary + 8 7750EF6F 7 Bytes JMP 063A0444
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] kernel32.dll!CheckElevation + 2DB 7752959A 7 Bytes JMP 063A016C
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!EnableWindow 75E18D02 5 Bytes JMP 698D9934 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!GetAsyncKeyState 75E1A256 5 Bytes JMP 6987DCCD C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!CallNextHookEx 75E1ABE1 5 Bytes JMP 698F7ACF C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!UnhookWindowsHookEx 75E1ADF9 5 Bytes JMP 6991EA88 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!DefWindowProcA 75E1BB1C 7 Bytes JMP 69899465 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!CreateWindowExA 75E1BF40 5 Bytes JMP 698A3293 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!SetWindowsHookExW 75E1E30C 5 Bytes JMP 698D20C4 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!CreateWindowExW 75E1EC7C 5 Bytes JMP 698FFEAF C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!GetKeyState 75E22B4D 5 Bytes JMP 6987DBA7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!IsDialogMessageW 75E24104 5 Bytes JMP 69A26B23 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!DefWindowProcW 75E2507D 7 Bytes JMP 698F7B32 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!CreateDialogParamA 75E31F42 5 Bytes JMP 69A26390 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!IsDialogMessage 75E32019 5 Bytes JMP 69A26AFB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!DialogBoxParamW 75E33B9B 5 Bytes JMP 6983160B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!CreateDialogIndirectParamA 75E3721D 5 Bytes JMP 69A26400 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!CreateDialogIndirectParamW 75E3EA10 5 Bytes JMP 69A26438 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!DialogBoxIndirectParamW 75E43B7F 5 Bytes JMP 69A2605E C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!EndDialog 75E43BA3 5 Bytes JMP 69A26DCF C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!CreateDialogParamW 75E45630 5 Bytes JMP 69A263C8 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!SetKeyboardState 75E4695A 5 Bytes JMP 69A273E9 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!SendInput 75E47019 5 Bytes JMP 69A27391 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!SetCursorPos 75E5C1B0 5 Bytes JMP 69A2746A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!DialogBoxParamA 75E5CF42 5 Bytes JMP 69A25FF9 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!DialogBoxIndirectParamA 75E5D274 5 Bytes JMP 69A260C3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!MessageBoxIndirectA 75E6E869 5 Bytes JMP 69A25F80 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!MessageBoxIndirectW 75E6E963 5 Bytes JMP 69A25F07 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!MessageBoxExA 75E6E9C9 5 Bytes JMP 69A25EA3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!MessageBoxExW 75E6E9ED 5 Bytes JMP 69A25E3F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] USER32.dll!keybd_event 75E6EC3B 5 Bytes JMP 69A2734E C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] SHELL32.dll!RealDriveType + 173D 7678FE10 4 Bytes [CF, 01, BB, 61]
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] SHELL32.dll!RealDriveType + 1745 7678FE18 8 Bytes [E0, 61, BA, 61, 79, F7, BA, …] {LOOPNZ 0x63; MOV EDX, 0xbaf77961; POPA }
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] ole32.dll!OleLoadFromStream 760D6143 5 Bytes JMP 69A2682D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] ole32.dll!CoGetMarshalSizeMax + 62BD 761054A8 4 Bytes JMP 063A04FE
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] ole32.dll!CoGetClassObject 761054AD 2 Bytes [EB, F9] {JMP 0xfffffffffffffffb}
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] ole32.dll!CoCreateInstance + 3E 76119D49 4 Bytes JMP 063A05B8
.text C:\Program Files\Internet Explorer\iexplore.exe[4520] ole32.dll!CoCreateInstanceEx 76119D4E 2 Bytes [EB, F9] {JMP 0xfffffffffffffffb}
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] USER32.dll!EnableWindow 75E18D02 5 Bytes JMP 698D9934 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] USER32.dll!DialogBoxParamW 75E33B9B 5 Bytes JMP 6983160B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] USER32.dll!DialogBoxIndirectParamW 75E43B7F 5 Bytes JMP 69A2605E C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] USER32.dll!DialogBoxParamA 75E5CF42 5 Bytes JMP 69A25FF9 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] USER32.dll!DialogBoxIndirectParamA 75E5D274 5 Bytes JMP 69A260C3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] USER32.dll!MessageBoxIndirectA 75E6E869 5 Bytes JMP 69A25F80 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] USER32.dll!MessageBoxIndirectW 75E6E963 5 Bytes JMP 69A25F07 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] USER32.dll!MessageBoxExA 75E6E9C9 5 Bytes JMP 69A25EA3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5220] USER32.dll!MessageBoxExW 75E6E9ED 5 Bytes JMP 69A25E3F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] ntdll.dll!NtMapViewOfSection 775E5C28 5 Bytes JMP 0340003A
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] kernel32.dll!K32GetPerformanceInfo + 1CC 774F62DF 7 Bytes JMP 034001AD
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] kernel32.dll!TerminateProcess + B 77502BC8 7 Bytes JMP 03400319
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] kernel32.dll!QueryPerformanceCounter + 13 7750C435 7 Bytes JMP 03400263
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] kernel32.dll!CreateThread 7750DCC2 5 Bytes JMP 6989723B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] kernel32.dll!FreeLibrary + 8 7750EF6F 7 Bytes JMP 034003CF
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] kernel32.dll!CheckElevation + 2DB 7752959A 7 Bytes JMP 034000F7
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!EnableWindow 75E18D02 5 Bytes JMP 698D9934 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!GetAsyncKeyState 75E1A256 5 Bytes JMP 6987DCCD C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!CallNextHookEx 75E1ABE1 5 Bytes JMP 698F7ACF C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!UnhookWindowsHookEx 75E1ADF9 5 Bytes JMP 6991EA88 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!DefWindowProcA 75E1BB1C 7 Bytes JMP 69899465 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!CreateWindowExA 75E1BF40 5 Bytes JMP 698A3293 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!SetWindowsHookExW 75E1E30C 5 Bytes JMP 698D20C4 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!CreateWindowExW 75E1EC7C 5 Bytes JMP 698FFEAF C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!GetKeyState 75E22B4D 5 Bytes JMP 6987DBA7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!IsDialogMessageW 75E24104 5 Bytes JMP 69A26B23 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!DefWindowProcW 75E2507D 7 Bytes JMP 698F7B32 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!CreateDialogParamA 75E31F42 5 Bytes JMP 69A26390 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!IsDialogMessage 75E32019 5 Bytes JMP 69A26AFB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!DialogBoxParamW 75E33B9B 5 Bytes JMP 6983160B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!CreateDialogIndirectParamA 75E3721D 5 Bytes JMP 69A26400 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!CreateDialogIndirectParamW 75E3EA10 5 Bytes JMP 69A26438 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!DialogBoxIndirectParamW 75E43B7F 5 Bytes JMP 69A2605E C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!EndDialog 75E43BA3 5 Bytes JMP 69A26DCF C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!CreateDialogParamW 75E45630 5 Bytes JMP 69A263C8 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!SetKeyboardState 75E4695A 5 Bytes JMP 69A273E9 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!SendInput 75E47019 5 Bytes JMP 69A27391 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!SetCursorPos 75E5C1B0 5 Bytes JMP 69A2746A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!DialogBoxParamA 75E5CF42 5 Bytes JMP 69A25FF9 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!DialogBoxIndirectParamA 75E5D274 5 Bytes JMP 69A260C3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!MessageBoxIndirectA 75E6E869 5 Bytes JMP 69A25F80 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!MessageBoxIndirectW 75E6E963 5 Bytes JMP 69A25F07 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!MessageBoxExA 75E6E9C9 5 Bytes JMP 69A25EA3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!MessageBoxExW 75E6E9ED 5 Bytes JMP 69A25E3F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] USER32.dll!keybd_event 75E6EC3B 5 Bytes JMP 69A2734E C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] SHELL32.dll!RealDriveType + 173D 7678FE10 4 Bytes [CF, 01, BB, 61]
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] SHELL32.dll!RealDriveType + 1745 7678FE18 8 Bytes [E0, 61, BA, 61, 79, F7, BA, …] {LOOPNZ 0x63; MOV EDX, 0xbaf77961; POPA }
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] ole32.dll!OleLoadFromStream 760D6143 5 Bytes JMP 69A2682D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] ole32.dll!CoGetMarshalSizeMax + 62BD 761054A8 7 Bytes JMP 03400485
.text C:\Program Files\Internet Explorer\iexplore.exe[5300] ole32.dll!CoCreateInstance + 3E 76119D49 7 Bytes JMP 0340053F

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume7 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume8 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\ACPI_HAL \Device\0000004e halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

—- Threads - GMER 1.0.15 —-

Thread System [4:5548] B6C50F2E

—- EOF - GMER 1.0.15 —-

And here is my aswMBR Log:

aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-10-16 14:44:20
—————————–
14:44:20.742 OS Version: Windows 6.1.7601 Service Pack 1
14:44:20.742 Number of processors: 4 586 0x2502
14:44:20.742 ComputerName: JOHN-PC UserName: John
14:44:22.676 Initialize success
14:44:44.506 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
14:44:44.506 Disk 0 Vendor: WDC_WD10 01.0 Size: 953869MB BusType: 3
14:44:44.678 Disk 0 MBR read successfully
14:44:44.678 Disk 0 MBR scan
14:44:44.694 Disk 0 Windows 7 default MBR code
14:44:44.694 Disk 0 scanning sectors +1953521664
14:44:45.052 Disk 0 scanning C:\Windows\system32\drivers
14:45:09.420 Service scanning
14:45:10.418 Modules scanning
14:45:40.325 Disk 0 trace - called modules:
14:45:40.341 ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys halmacpi.dll USBPORT.SYS usbehci.sys intelppm.sys Wdf01000.sys Dnetr28u.sys ACPI.sys usbhub.sys ndis.sys vwififlt.sys nwifi.sys
14:45:40.357 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x88452a20]
14:45:40.357 3 CLASSPNP.SYS[8c07b59e] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x8687d028]
14:45:40.357 5 Wdf01000.sys[8b65415e] -> nt!IofCallDriver -> [0x89bbb6f8]
14:45:40.871 7 ACPI.sys[8b6c63d4] -> nt!IofCallDriver -> \Device\USBPDO-4[0x89c73030]
14:45:40.871 9 usbhub.sys[9af6cc88] -> nt!IofCallDriver -> [0x892c17d0]
14:45:40.887 11 ACPI.sys[8b6c63d4] -> nt!IofCallDriver -> \Device\USBPDO-1[0x8929d028]
14:45:40.903 Scan finished successfully
14:49:45.945 Disk 0 MBR has been saved successfully to "C:\Users\John\Desktop\MBR.dat"
14:49:45.945 The log file has been saved successfully to "C:\Users\John\Desktop\aswMBR.txt"


I have attached the other DDS log. :)

Thanks very much for your support!!! :D

Attachments:

Hi jwp1295,

I have a quick question. Are you receiving your internet access in Australia?
———-

Download CKScanner by askey127 from Here & save it to your Desktop.
  • Right-click and Run as Administrator CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
———-

I noticed that you have Malwarebytes on your system already. Please open that program, Update it and then run a Quick Scan. Post the log that is created into your next reply.
———-

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



As a Vista/Win7 user you will need to right click your browser icon and select "Run as Administrator" in order to run this scan.
  • Do not use this instance of your browser for anything besides doing this scan
  • When the scan is complete and the results saved, close that instance of your browser
  • Open a new one the usual way and post the results in this topic.


  • Right-click and Run as Administartor on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/
———-

In your next reply please let me know about your internet access and post the logs created by CKScanner, Malwarebytes and ESET Online Scanner. :)
Hi Jeffce! Yes i am currently receiving my internet acess in Australia. Here is my Malwarebytes Log: Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 7934 Windows 6.1.7601 Service Pack 1 Internet Explorer 9.0.8112.16421 17/10/2011 3:48:56 PM mbam-log-2011-10-17 (15-48-56).txt Scan type: Quick scan Objects scanned: 185828 Time elapsed: 3 minute(s), 50 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Here is my CKScanner log: CKScanner - Additional Security Risks - These are not necessarily bad scanner sequence 3.RP.11.XRNAEF —– EOF —– As for the ESET logs, there was no list of found threats button nor an import to text button. But it did say that no risks were detected. Thank you for your continued support Jeffce!! :D
Hi Jwp1295,


Yes i am currently receiving my internet acess in Australia.

:thumbup:

Things are looking pretty good. I am not seeing any malware in the logs that you have provided. I have read a few places and it seems that your problem may have something to do with the Google Toolbar that you have installed on your system. It seems to be a relatively new problem that has been occurring. Try to uninstall the Google Toolbar and see if the problem remains. Follow the instructions below… :)

Please do the following:

Hold down the Windows key and press R to open a run box
type the following text into the run box

appwiz.cpl

This will open your Programs And Features. A list of installed programs will populate

Remove the following programs:

Java™ 6 Update 26
Google Toolbar for Internet Explorer

———-

You have just deleted an older version of Java with the instructions above. Now please visit the website here to download the most recent version. On the website be sure to click to accept the license and then download and install the Windows x86 Offline version to your computer.
———-

Download TFC to your desktop
  • Close any open windows.
  • Right-click and Run as Administrator the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
———-

In your next reply please let me know if you have any problems with the download/install of Java as well as let me know if you are still having the problems after removing the Google Toolbar.
Hi Jeffce! I have had no problems downloading or installing java. As for the voice problem i have'nt had it again, but i think it's a little premature to say i won't have it again. Rest assured that i will post another topic concerning the matter if problems persist. Thank you for excellent help Jeff! :D
Hi jwp1295,

the voice problem i have'nt had it again

That is great!! :) I am not seeing any malware present in your logs so I think that we can move on.

IT APPEARS THAT YOUR LOGS ARE NOW CLEAN :D SO LETS DO A COUPLE OF THINGS TO WRAP THIS UP!! :D

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Enable Protected Mode in Internet Explorer. This helps Windows Vista users stay more protected from attack by running Internet Explorer with restricted privileges as well as reducing the ability to write, alter or destroy data on your system or install malicious code. To make sure this is running follow these steps:
  • Open Internet Explorer
  • Click on Tools > Internet Options
  • Press Security tab
  • Select Internet zone then place check next to Enable Protected Mode if not already done
  • Do the same for Local Intranet, Trusted Sites and Restricted Sites and then press Apply
  • Restart Internet Explorer and in the bottom right corner of your screen you will see Protected Mode: On showing you it is enabled.
3. Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

4. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. A tutorial on firewalls can be found here. **There are firewalls listed in this tutorial that could be downloaded and used but I would personally only recommend using one of the following two below:
Online Armor Free
Agnitum Outpost Firewall Free

5. Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.

6. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

7. WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

8.Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI