Spyware / Malware / Virus Removal
Can't Remove W32/sdbot.worm Virus
16 min read
techmut
Topic Starter
Ran McAfee virus scan on son's comp and it finds the W32/Sdbot.worm virus. Says it cannot be removed. McAfee says up to date engines and DATs should remove it but it's not happenning. Also refers to a file P432.dll in the c:\windows\system32 directory which I cannot delete.
This thing seems to be randomly causing McAfee's protections to disable and System Restore just plain wont work. Have had Winsock problems also but that may be another story.
The computer seems to be running "pretty good" otherwise. Just would like to get rid of the "worm" if possible.
Any thoughts folks? Thanks in advance for any help.
LDTate
Hello and Welcome to the forum.
I suggest you do this:
Download SDFix and save it to your Desktop.
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in Safe Mode by doing the following :
I suggest you do this:
Download SDFix and save it to your Desktop.
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in Safe Mode by doing the following :
- Restart your computer
- After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
- Instead of Windows loading as normal, the Advanced Options Menu should appear;
- Select the first option, to run Windows in Safe Mode, then press Enter.
- Choose your usual account.
- Open the extracted SDFix folder and double click RunThis.bat to start the script.
- Type Y to begin the cleanup process.
- It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
- Press any Key and it will restart the PC.
- When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
- Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum). - Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
techmut
OK LDT…..hope I did this correctly.
SDFix Report is as follows:
SDFix: Version 1.81
Run by [removed]
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
Client IP-IPX
MsaSvc
nlc
amir6iyaoav
ImagePath:
"C:\WINDOWS\system32\svchosts.exe" -e mc-110-12-0000501
C:\WINDOWS\system32\msasvc.exe
C:\WINDOWS\system32\mbti.exe
C:\WINDOWS\system32\rsbmsc.exe /service
Client IP-IPX - Deleted
MsaSvc - Deleted
nlc - Deleted
amir6iyaoav - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Resetting AppInit_DLLs value
Rebooting…
Normal Mode:
Checking Files:
Below files will be copied to Backups folder then removed:
C:\WINDOWS\SYSTEM32\TMP_7V.DLL - Deleted
C:\-20644~1 - Deleted
C:\WINDOWS\SYSTEM32\79280A41.EXE - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\2.dllb - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\6.dllb - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\7.dllb - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\2.dllb - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\6.dllb - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\7.dllb - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun1.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun10.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun3.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun5.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun1.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun12.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun17.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun2.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun20.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun5.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun7.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun8.exe - Deleted
C:\WINDOWS\Temp\cjnr4r4770AFCEA.tmp - Deleted
C:\WINDOWS\Temp\cjnr4r4770AFCEC.tmp - Deleted
C:\WINDOWS\Temp\cjnr4r4770AFCED.tmp - Deleted
C:\WINDOWS\Temp\cjnr4r4770AFCFB.tmp - Deleted
C:\WINDOWS\odbc.INI - Deleted
C:\WINDOWS\system32\12.tmp - Deleted
C:\WINDOWS\system32\hpsvc.exe - Deleted
C:\WINDOWS\system32\spooIsv.exe - Deleted
C:\WINDOWS\Temp\$_2341235.TMP - Deleted
C:\WINDOWS\Temp\removalfile.bat - Deleted
Removing Temp Files
ADS Check:
Checking if ADS is attached to system32 Folder
C:\WINDOWS\system32
No streams found.
Checking if ADS is attached to svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.
Final Check:
Remaining Services:
——————
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32"="C:\\WINDOWS\\system32:*:Enabled:lockx"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Steam\\SteamApps\\decker6\\day of defeat source\\hl2.exe"="C:\\Program Files\\Steam\\SteamApps\\decker6\\day of defeat source\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\Xfire\\Xfire.exe"="C:\\Program Files\\Xfire\\Xfire.exe:*:Enabled:Xfire"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Disabled:LimeWire"
"C:\\WINDOWS\\system32\\mbti.exe"="C:\\WINDOWS\\system32\\mbti.exe:*:Enabled:Microsoft ® Windows Network Latency Controller"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Disabled:America Online 9.0"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Disabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Disabled:AOL"
"C:\\Program Files\\Steam\\Steam.exe"="C:\\Program Files\\Steam\\Steam.exe:*:Enabled:Steam"
"C:\\Program Files\\Steam\\SteamApps\\decker6\\counter-strike source\\hl2.exe"="C:\\Program Files\\Steam\\SteamApps\\decker6\\counter-strike source\\hl2.exe:*:Enabled:hl2"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Steam\\SteamApps\\manmini\\day of defeat source\\hl2.exe"="C:\\Program Files\\Steam\\SteamApps\\manmini\\day of defeat source\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\Steam\\SteamApps\\manmini\\counter-strike source\\hl2.exe"="C:\\Program Files\\Steam\\SteamApps\\manmini\\counter-strike source\\hl2.exe:*:Enabled:hl2"
"C:\\WINDOWS\\gsvpm.exe"="C:\\WINDOWS\\gsvpm.exe:*:Enabled:AntiVirusUpdateExe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files:
—————
Backups Folder: - C:\SDFix\backups\backups.zip
Checking For Files with Hidden Attributes:
C:\Program Files\Microsoft Works Suite 2005\Setup\MNYINSTA.DLL
C:\Program Files\Microsoft Works Suite 2005\Setup\SETUPLNG.DLL
C:\Documents and Settings\Bubba\Application Data\??mantec\cmd.exe
C:\Program Files\America Online 9.0\aolphx.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\America Online 9.0\RBM.exe
C:\Program Files\Microsoft Works Suite 2005\Setup\LAUNCHER.EXE
C:\Program Files\Microsoft Works Suite 2005\Setup\RMVSUITE.EXE
C:\Program Files\Microsoft Works Suite 2005\Setup\UNREGWTR.EXE
C:\Program Files\àdobe\w?auboot.exe
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
C:\Documents and Settings\Bubba\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp
C:\Documents and Settings\Bubba\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp
C:\Documents and Settings\Bubba\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp
C:\Documents and Settings\Bubba\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp
C:\Program Files\Google\BITA8.tmp
C:\WINDOWS\system32\ehhkj.tmp
C:\WINDOWS\system32\config\default.tmp.LOG
C:\WINDOWS\system32\config\software.tmp.LOG
C:\WINDOWS\system32\config\system.tmp.LOG
Finished
HijackThis Log is:
Logfile of HijackThis v1.99.1
Scan saved at 7:34:37 PM, on 5/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\SiteAdvisor\6028\SAService.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\Program Files\SiteAdvisor\6028\SiteAdv.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.optonline.net/Home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {1E93AC48-1C87-4C55-F64F-1AE34B90F9CE} - C:\WINDOWS\system32\vix.dll
O2 - BHO: (no name) - {30000273-8230-4dd4-be4f-6889d1e74167} - (no file)
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: (no name) - {7F5A2699-38CD-4B98-B193-5916D6566B01} - (no file)
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {90051074-A0DF-49B4-94E8-E6A212240E89} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {c9e3f918-b62d-4859-8335-6c31f9576fc0} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {D38439EC-4A7F-42b4-90C2-D810D7778FDD} - (no file)
O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} - (no file)
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [gwiz] C:\WINDOWS\system32\ntsystem.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AntiVirusUpdateExe] C:\WINDOWS\gsvpm.exe
O4 - HKLM\..\RunServices: [E30A8607] C:\WINDOWS\system32\rsbmsc.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [freestyle] lockx.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = C:\Program Files\Dell Wireless\PRISMCFG.exe
O8 - Extra context menu item: &AOL; Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: &Google; Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search; - http://edits.mywebsearch.com/toolbaredits/…arch.jhtml?p=ZS
O8 - Extra context menu item: &Translate; English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Bubba\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.howstuffworks.com
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://amiuptodate.mcafee.com/vsc/bin/2,0,…pdatePortal.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1150937271991
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1151184111625
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…008/mcfscan.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: lfpdsg - lfpdsg.dll (file missing)
O20 - Winlogon Notify: p4reg - C:\WINDOWS\SYSTEM32\p432.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: carbinyl - {8d8c2387-7f80-4022-9be6-43630a969558} - (no file)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6028\SAService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Windows Genuine Advantage Validation (wgav) - Unknown owner - C:\WINDOWS\system32\wgav.exe (file missing)
Will patiently await next instructions.
SDFix Report is as follows:
SDFix: Version 1.81
Run by [removed]
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
Client IP-IPX
MsaSvc
nlc
amir6iyaoav
ImagePath:
"C:\WINDOWS\system32\svchosts.exe" -e mc-110-12-0000501
C:\WINDOWS\system32\msasvc.exe
C:\WINDOWS\system32\mbti.exe
C:\WINDOWS\system32\rsbmsc.exe /service
Client IP-IPX - Deleted
MsaSvc - Deleted
nlc - Deleted
amir6iyaoav - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Resetting AppInit_DLLs value
Rebooting…
Normal Mode:
Checking Files:
Below files will be copied to Backups folder then removed:
C:\WINDOWS\SYSTEM32\TMP_7V.DLL - Deleted
C:\-20644~1 - Deleted
C:\WINDOWS\SYSTEM32\79280A41.EXE - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\2.dllb - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\6.dllb - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\7.dllb - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\2.dllb - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\6.dllb - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\7.dllb - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun1.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun10.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun3.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun5.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun1.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun12.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun17.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun2.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun20.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun5.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun7.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun8.exe - Deleted
C:\WINDOWS\Temp\cjnr4r4770AFCEA.tmp - Deleted
C:\WINDOWS\Temp\cjnr4r4770AFCEC.tmp - Deleted
C:\WINDOWS\Temp\cjnr4r4770AFCED.tmp - Deleted
C:\WINDOWS\Temp\cjnr4r4770AFCFB.tmp - Deleted
C:\WINDOWS\odbc.INI - Deleted
C:\WINDOWS\system32\12.tmp - Deleted
C:\WINDOWS\system32\hpsvc.exe - Deleted
C:\WINDOWS\system32\spooIsv.exe - Deleted
C:\WINDOWS\Temp\$_2341235.TMP - Deleted
C:\WINDOWS\Temp\removalfile.bat - Deleted
Removing Temp Files
ADS Check:
Checking if ADS is attached to system32 Folder
C:\WINDOWS\system32
No streams found.
Checking if ADS is attached to svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.
Final Check:
Remaining Services:
——————
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32"="C:\\WINDOWS\\system32:*:Enabled:lockx"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Steam\\SteamApps\\decker6\\day of defeat source\\hl2.exe"="C:\\Program Files\\Steam\\SteamApps\\decker6\\day of defeat source\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\Xfire\\Xfire.exe"="C:\\Program Files\\Xfire\\Xfire.exe:*:Enabled:Xfire"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Disabled:LimeWire"
"C:\\WINDOWS\\system32\\mbti.exe"="C:\\WINDOWS\\system32\\mbti.exe:*:Enabled:Microsoft ® Windows Network Latency Controller"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Disabled:America Online 9.0"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Disabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Disabled:AOL"
"C:\\Program Files\\Steam\\Steam.exe"="C:\\Program Files\\Steam\\Steam.exe:*:Enabled:Steam"
"C:\\Program Files\\Steam\\SteamApps\\decker6\\counter-strike source\\hl2.exe"="C:\\Program Files\\Steam\\SteamApps\\decker6\\counter-strike source\\hl2.exe:*:Enabled:hl2"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Steam\\SteamApps\\manmini\\day of defeat source\\hl2.exe"="C:\\Program Files\\Steam\\SteamApps\\manmini\\day of defeat source\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\Steam\\SteamApps\\manmini\\counter-strike source\\hl2.exe"="C:\\Program Files\\Steam\\SteamApps\\manmini\\counter-strike source\\hl2.exe:*:Enabled:hl2"
"C:\\WINDOWS\\gsvpm.exe"="C:\\WINDOWS\\gsvpm.exe:*:Enabled:AntiVirusUpdateExe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files:
—————
Backups Folder: - C:\SDFix\backups\backups.zip
Checking For Files with Hidden Attributes:
C:\Program Files\Microsoft Works Suite 2005\Setup\MNYINSTA.DLL
C:\Program Files\Microsoft Works Suite 2005\Setup\SETUPLNG.DLL
C:\Documents and Settings\Bubba\Application Data\??mantec\cmd.exe
C:\Program Files\America Online 9.0\aolphx.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\America Online 9.0\RBM.exe
C:\Program Files\Microsoft Works Suite 2005\Setup\LAUNCHER.EXE
C:\Program Files\Microsoft Works Suite 2005\Setup\RMVSUITE.EXE
C:\Program Files\Microsoft Works Suite 2005\Setup\UNREGWTR.EXE
C:\Program Files\àdobe\w?auboot.exe
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
C:\Documents and Settings\Bubba\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp
C:\Documents and Settings\Bubba\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp
C:\Documents and Settings\Bubba\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp
C:\Documents and Settings\Bubba\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp
C:\Program Files\Google\BITA8.tmp
C:\WINDOWS\system32\ehhkj.tmp
C:\WINDOWS\system32\config\default.tmp.LOG
C:\WINDOWS\system32\config\software.tmp.LOG
C:\WINDOWS\system32\config\system.tmp.LOG
Finished
HijackThis Log is:
Logfile of HijackThis v1.99.1
Scan saved at 7:34:37 PM, on 5/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\SiteAdvisor\6028\SAService.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\Program Files\SiteAdvisor\6028\SiteAdv.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.optonline.net/Home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {1E93AC48-1C87-4C55-F64F-1AE34B90F9CE} - C:\WINDOWS\system32\vix.dll
O2 - BHO: (no name) - {30000273-8230-4dd4-be4f-6889d1e74167} - (no file)
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: (no name) - {7F5A2699-38CD-4B98-B193-5916D6566B01} - (no file)
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {90051074-A0DF-49B4-94E8-E6A212240E89} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {c9e3f918-b62d-4859-8335-6c31f9576fc0} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {D38439EC-4A7F-42b4-90C2-D810D7778FDD} - (no file)
O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} - (no file)
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [gwiz] C:\WINDOWS\system32\ntsystem.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AntiVirusUpdateExe] C:\WINDOWS\gsvpm.exe
O4 - HKLM\..\RunServices: [E30A8607] C:\WINDOWS\system32\rsbmsc.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [freestyle] lockx.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = C:\Program Files\Dell Wireless\PRISMCFG.exe
O8 - Extra context menu item: &AOL; Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: &Google; Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search; - http://edits.mywebsearch.com/toolbaredits/…arch.jhtml?p=ZS
O8 - Extra context menu item: &Translate; English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Bubba\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.howstuffworks.com
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://amiuptodate.mcafee.com/vsc/bin/2,0,…pdatePortal.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1150937271991
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1151184111625
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…008/mcfscan.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: lfpdsg - lfpdsg.dll (file missing)
O20 - Winlogon Notify: p4reg - C:\WINDOWS\SYSTEM32\p432.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: carbinyl - {8d8c2387-7f80-4022-9be6-43630a969558} - (no file)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6028\SAService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Windows Genuine Advantage Validation (wgav) - Unknown owner - C:\WINDOWS\system32\wgav.exe (file missing)
Will patiently await next instructions.
techmut
Oh, in case it's important…..
I had mentioned previous internet connect and Winsock problems.
After running SDFix and HijackThis, then the reboot, I couldn't connect to the internet. A while ago I had downloaded a program - WinsockFix - which, after running it I was then able to connect normally.
Obviously this is not normal but sometimes this is the only way to get online.
Thanks.
I had mentioned previous internet connect and Winsock problems.
After running SDFix and HijackThis, then the reboot, I couldn't connect to the internet. A while ago I had downloaded a program - WinsockFix - which, after running it I was then able to connect normally.
Obviously this is not normal but sometimes this is the only way to get online.
Thanks.
LDTate
This is a rather nasty infection.W32.Loxbot.A is a worm that opens a back door and can receive commands from a remote attacker. It can spread using AOL Instant Messenger. The worm also uses rootkit capabilities to hide its process in memory.
Download and install AVG Antirootkit
http://www.softpedia.com/get/Antivirus/AVG…i-Rootkit.shtml
- Install it, and follow the prompts to restart your computer.
- Run the program and select Perform in-depth search.
- When it has finished, click Save result to file
- Post the contents of the results in your reply.
techmut
Thanks LDTate,
Here are the AVG in-depth results:
C:\WINDOWS\system32\SecMon.sys,Hidden driver file
c:\Documents and Settings\Bubba\SecMon.sys,Hidden File
c:\WINDOWS\system32\SecMon.sys,Hidden File
LDTate
Please do the following:
STEP 1.
======
GMER
Please create a new subfolder in the Program Files folder called GMER. If you have an older version of GMER installed, you must delete it.
STEP 2.
======
Combofix
Please post the GMER results, the ComboFix log and a new hijackthis log.
STEP 1.
======
GMER
Please create a new subfolder in the Program Files folder called GMER. If you have an older version of GMER installed, you must delete it.
- Download GMER and extract it to the C:\program files\GMER folder.
- Please rename the GMER file
Note: You can rename gmer.exe to anything you like as long as you keep the .exe ending.
Run the Gmer.exe renamed program by double-clicking the executable file (gmer.exe) in Windows Explorer.
You may be prompted to scan immediately if GMER detects rootkit activity. - If you are prompted to scan your system click "yes" to begin the scan.
- If you are not prompted, Click the "Rootkit" tab, then click "Scan".
STEP 2.
======
Combofix
- Download this file - combofix.exe
- Double click combofix.exe & follow the prompts.
- When finished, it shall produce a log for you. Post that log in your next reply
Please post the GMER results, the ComboFix log and a new hijackthis log.
techmut
Thanks LDTate,
GMER results:
GMER 1.0.12.12244 - http://www.gmer.net
Rootkit scan 2007-05-03 20:47:12
Windows 5.1.2600 Service Pack 2
—- System - GMER 1.0.12 —-
SSDT \??\C:\WINDOWS\system32\SecMon.sys ZwEnumerateKey
SSDT \??\C:\WINDOWS\system32\SecMon.sys ZwEnumerateValueKey
SSDT \??\C:\WINDOWS\system32\SecMon.sys ZwQueryDirectoryFile
Code \SystemRoot\system32\drivers\mfehidk.sys ZwCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys ZwCreateKey
Code \SystemRoot\system32\drivers\mfehidk.sys ZwCreateProcess
Code \SystemRoot\system32\drivers\mfehidk.sys ZwDeleteKey
Code \SystemRoot\system32\drivers\mfehidk.sys ZwDeleteValueKey
Code \SystemRoot\system32\drivers\mfehidk.sys ZwMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys ZwOpenKey
Code \SystemRoot\system32\drivers\mfehidk.sys ZwProtectVirtualMemory
Code \SystemRoot\system32\drivers\mfehidk.sys ZwRenameKey
Code \SystemRoot\system32\drivers\mfehidk.sys ZwSetValueKey
Code \SystemRoot\system32\drivers\mfehidk.sys ZwTerminateProcess
Code \SystemRoot\system32\drivers\mfehidk.sys ZwUnmapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys ZwYieldExecution
Code \SystemRoot\system32\drivers\mfehidk.sys NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys NtMapViewOfSection
—- Kernel code sections - GMER 1.0.12 —-
.text ntoskrnl.exe!_abnormal_termination + 171 804E27CD 3 Bytes [ A3, 9D, F7 ]
.text ntoskrnl.exe!ZwYieldExecution 804F8B8D 7 Bytes JMP B95555BD \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!ZwOpenKey 80567CFB 5 Bytes JMP B95554EB \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!ZwCreateKey 8056E7A9 5 Bytes JMP B95554FF \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!NtCreateFile 8056FBF8 5 Bytes JMP B955557F \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!ZwUnmapViewOfSection 80571EF1 5 Bytes JMP B95555E9 \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!NtMapViewOfSection 8057236C 7 Bytes JMP B95555D3 \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!ZwProtectVirtualMemory 805730B5 7 Bytes JMP B9555593 \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!ZwSetValueKey 80573C8D 7 Bytes JMP B9555555 \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!ZwTerminateProcess 80584740 5 Bytes JMP B955556B \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!ZwDeleteValueKey 80593AAC 7 Bytes JMP B955553F \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!ZwDeleteKey 80595136 7 Bytes JMP B9555513 \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!ZwCreateProcess 805B0AA4 5 Bytes JMP B95555A9 \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!ZwRenameKey 8064D029 7 Bytes JMP B9555529 \SystemRoot\system32\drivers\mfehidk.sys
? C:\WINDOWS\system32\DRIVERS\update.sys
—- User code sections - GMER 1.0.12 —-
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00DF0FEF
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00DF0F41
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00DF0F66
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00DF0F83
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00DF0F94
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00DF0025
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00DF0F13
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00DF0F24
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00DF0091
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00DF0080
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00DF0EE7
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00DF0036
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00DF0FD4
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00DF005B
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00DF0FB9
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00DF000A
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00DF0F02
.text C:\WINDOWS\system32\services.exe[492] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00960FCA
.text C:\WINDOWS\system32\services.exe[492] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00960058
.text C:\WINDOWS\system32\services.exe[492] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 0096001B
.text C:\WINDOWS\system32\services.exe[492] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00960000
.text C:\WINDOWS\system32\services.exe[492] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00960FA5
.text C:\WINDOWS\system32\services.exe[492] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00960047
.text C:\WINDOWS\system32\services.exe[492] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00960FEF
.text C:\WINDOWS\system32\services.exe[492] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00960036
.text C:\WINDOWS\system32\services.exe[492] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00930FEF
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 007B0000
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 007B0064
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 007B0F6F
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 007B0F80
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 007B003D
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 007B0FB6
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 007B0086
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 007B0075
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 007B00B2
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 007B0F19
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 007B0F08
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 007B0FA5
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 007B0FE5
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 007B0F54
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 007B0022
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 007B0011
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 007B0097
.text C:\WINDOWS\system32\svchost.exe[668] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 007A0FD4
.text C:\WINDOWS\system32\svchost.exe[668] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 007A0FA8
.text C:\WINDOWS\system32\svchost.exe[668] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 007A0FEF
.text C:\WINDOWS\system32\svchost.exe[668] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 007A001B
.text C:\WINDOWS\system32\svchost.exe[668] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 007A0065
.text C:\WINDOWS\system32\svchost.exe[668] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 007A004A
.text C:\WINDOWS\system32\svchost.exe[668] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 007A000A
.text C:\WINDOWS\system32\svchost.exe[668] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 007A0FC3
.text C:\WINDOWS\system32\svchost.exe[668] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00780000
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00900FEF
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 009000A2
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 0090007D
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 0090006C
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 0090005B
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00900025
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 009000C4
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 009000B3
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00900F50
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 009000E9
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00900104
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00900040
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00900FD4
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00900F92
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00900FB9
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 0090000A
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00900F61
.text C:\WINDOWS\system32\svchost.exe[724] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 008F002F
.text C:\WINDOWS\system32\svchost.exe[724] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 008F0FB2
.text C:\WINDOWS\system32\svchost.exe[724] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 008F0FD4
.text C:\WINDOWS\system32\svchost.exe[724] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 008F000A
.text C:\WINDOWS\system32\svchost.exe[724] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 008F0FC3
.text C:\WINDOWS\system32\svchost.exe[724] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 008F005B
.text C:\WINDOWS\system32\svchost.exe[724] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 008F0FEF
.text C:\WINDOWS\system32\svchost.exe[724] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 008F004A
.text C:\WINDOWS\system32\svchost.exe[724] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 008D0000
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 018A0FEF
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 018A006B
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 018A0F76
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 018A0F91
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 018A004E
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 018A002C
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 018A0086
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 018A0F4A
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 018A0EFE
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 018A0F19
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 018A0EED
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 018A003D
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 018A0000
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 018A0F65
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 018A0FCA
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 018A001B
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 018A0097
.text C:\WINDOWS\system32\svchost.exe[788] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 0189001B
.text C:\WINDOWS\system32\svchost.exe[788] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 01890F8D
.text C:\WINDOWS\system32\svchost.exe[788] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 01890FCA
.text C:\WINDOWS\system32\svchost.exe[788] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 01890FE5
.text C:\WINDOWS\system32\svchost.exe[788] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 0189004A
.text C:\WINDOWS\system32\svchost.exe[788] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 01890F9E
.text C:\WINDOWS\system32\svchost.exe[788] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 01890000
.text C:\WINDOWS\system32\svchost.exe[788] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 01890FAF
.text C:\WINDOWS\system32\svchost.exe[788] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 01480000
.text C:\WINDOWS\system32\svchost.exe[788] WININET.dll!InternetOpenA 771CC859 5 Bytes JMP 0187000A
.text C:\WINDOWS\system32\svchost.exe[788] WININET.dll!InternetOpenW 771CCE91 5 Bytes JMP 01870FEF
.text C:\WINDOWS\system32\svchost.exe[788] WININET.dll!InternetOpenUrlA 771D06CD 5 Bytes JMP 01870025
.text C:\WINDOWS\system32\svchost.exe[788] WININET.dll!InternetOpenUrlW 7721A881 5 Bytes JMP 01870036
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00760FEF
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 0076007D
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00760062
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00760F94
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00760051
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00760040
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00760F3C
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00760F57
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 007600C4
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00760F21
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 007600D5
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00760FB9
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 0076000A
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 0076008E
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00760FD4
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00760025
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 0076009F
.text C:\WINDOWS\system32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 0075002C
.text C:\WINDOWS\system32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00750073
.text C:\WINDOWS\system32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 0075001B
.text C:\WINDOWS\system32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00750FEF
.text C:\WINDOWS\system32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00750062
.text C:\WINDOWS\system32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00750051
.text C:\WINDOWS\system32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 0075000A
.text C:\WINDOWS\system32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00750FCA
.text C:\WINDOWS\system32\svchost.exe[840] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00730FEF
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00720000
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 0072007F
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 0072006E
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00720F94
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00720051
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00720036
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00720F41
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00720F5E
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00720EFA
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00720F15
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 007200AE
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00720FA5
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00720FE5
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00720F6F
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00720FCA
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00720025
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00720F30
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00710FCA
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 0071006C
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00710011
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00710000
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00710051
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00710040
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00710FE5
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00710FB9
.text C:\WINDOWS\system32\svchost.exe[888] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 006F0FE5
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00C50000
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00C50075
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00C50F80
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00C5005A
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00C50F9B
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00C5002C
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00C500C1
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00C50F6F
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00C50F39
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00C500D2
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00C50F28
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00C5003D
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00C50011
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00C5009A
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00C50FC0
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00C50FD1
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00C50F54
.text C:\WINDOWS\system32\svchost.exe[1352] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00C40FC3
.text C:\WINDOWS\system32\svchost.exe[1352] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00C4005E
.text C:\WINDOWS\system32\svchost.exe[1352] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00C40FD4
.text C:\WINDOWS\system32\svchost.exe[1352] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00C4000A
.text C:\WINDOWS\system32\svchost.exe[1352] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00C40F97
.text C:\WINDOWS\system32\svchost.exe[1352] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00C4002F
.text C:\WINDOWS\system32\svchost.exe[1352] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00C40FEF
.text C:\WINDOWS\system32\svchost.exe[1352] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00C40FB2
.text C:\WINDOWS\system32\svchost.exe[1352] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00C20FEF
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 001A000A
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001A0084
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 001A0F8F
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 001A0073
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 001A0FB6
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 001A004E
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 001A00D7
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 001A00BC
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001A0F52
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 001A0F63
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 001A00FC
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 001A0FC7
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 001A001B
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 001A0095
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 001A003D
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 001A002C
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 001A0F74
.text C:\WINDOWS\explorer.exe[2236] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00290040
.text C:\WINDOWS\explorer.exe[2236] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00290076
.text C:\WINDOWS\explorer.exe[2236] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00290025
.text C:\WINDOWS\explorer.exe[2236] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00290FE5
.text C:\WINDOWS\explorer.exe[2236] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00290FC3
.text C:\WINDOWS\explorer.exe[2236] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 0029005B
.text C:\WINDOWS\explorer.exe[2236] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00290000
.text C:\WINDOWS\explorer.exe[2236] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00290FD4
.text C:\WINDOWS\explorer.exe[2236] WININET.dll!InternetOpenA 771CC859 5 Bytes JMP 002B0000
.text C:\WINDOWS\explorer.exe[2236] WININET.dll!InternetOpenW 771CCE91 5 Bytes JMP 002B0FE5
.text C:\WINDOWS\explorer.exe[2236] WININET.dll!InternetOpenUrlA 771D06CD 5 Bytes JMP 002B0FCA
.text C:\WINDOWS\explorer.exe[2236] WININET.dll!InternetOpenUrlW 7721A881 5 Bytes JMP 002B001B
.text C:\WINDOWS\explorer.exe[2236] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 01D20000
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 001A0FE5
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001A0F43
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 001A0038
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 001A0F5E
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 001A0F79
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 001A000A
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 001A0F17
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 001A005F
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001A0EFC
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 001A008B
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 001A00B0
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 001A001B
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 001A0FD4
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 001A0F28
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 001A0F9E
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 001A0FB9
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 001A007A
.text C:\Program Files\Messenger\msmsgs.exe[3144] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00290FC3
.text C:\Program Files\Messenger\msmsgs.exe[3144] ADVAPI32.dll!RegCreateKeyExW 77DD7535 1 Byte [ E9 ]
.text C:\Program Files\Messenger\msmsgs.exe[3144] ADVAPI32.dll!RegCreateKeyExW + 2 77DD7537 3 Bytes [ 8A, 4B, 88 ]
.text C:\Program Files\Messenger\msmsgs.exe[3144] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00290FDE
.text C:\Program Files\Messenger\msmsgs.exe[3144] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00290014
.text C:\Program Files\Messenger\msmsgs.exe[3144] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00290F86
.text C:\Program Files\Messenger\msmsgs.exe[3144] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00290F97
.text C:\Program Files\Messenger\msmsgs.exe[3144] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00290FEF
.text C:\Program Files\Messenger\msmsgs.exe[3144] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00290FA8
.text C:\Program Files\Messenger\msmsgs.exe[3144] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 002A0FEF
.text C:\Program Files\Messenger\msmsgs.exe[3144] WININET.dll!InternetOpenA 771CC859 5 Bytes JMP 002B000A
.text C:\Program Files\Messenger\msmsgs.exe[3144] WININET.dll!InternetOpenW 771CCE91 5 Bytes JMP 002B001B
.text C:\Program Files\Messenger\msmsgs.exe[3144] WININET.dll!InternetOpenUrlA 771D06CD 5 Bytes JMP 002B0FE5
.text C:\Program Files\Messenger\msmsgs.exe[3144] WININET.dll!InternetOpenUrlW 7721A881 5 Bytes JMP 002B0040
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 0664000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 06640067
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 06640F7C
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 06640F8D
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 06640040
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 06640FAF
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 06640F44
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 0664008C
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 06640F07
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 06640F22
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 066400BB
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 06640F9E
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 06640FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 06640F61
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 06640025
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 06640FD4
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 06640F33
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 06630025
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 0663005B
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 0663000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 06630FDE
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 06630040
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 06630FA8
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 06630FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 06630FB9
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] USER32.dll!SetWindowLongA 7E41D60D 5 Bytes JMP 00B5FFBA C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] USER32.dll!SetWindowLongW 7E41D62B 5 Bytes JMP 00B5FFEB C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] USER32.dll!DialogBoxParamW 7E42555F 5 Bytes JMP 009CF205 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] USER32.dll!DialogBoxIndirectParamW 7E432032 5 Bytes JMP 00B5FEBF C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] USER32.dll!MessageBoxIndirectA 7E43A04A 5 Bytes JMP 00B5FE40 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] USER32.dll!DialogBoxParamA 7E43B10C 5 Bytes JMP 00B5FE84 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] USER32.dll!MessageBoxExW 7E4505D8 5 Bytes JMP 00B5FDCC C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] USER32.dll!MessageBoxExA 7E4505FC 5 Bytes JMP 00B5FE06 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] USER32.dll!DialogBoxIndirectParamA 7E456B50 5 Bytes JMP 00B5FEFA C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 009F15DA C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] WININET.dll!InternetOpenA 771CC859 5 Bytes JMP 06610000
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] WININET.dll!InternetOpenW 771CCE91 5 Bytes JMP 06610011
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] WININET.dll!InternetOpenUrlA 771D06CD 5 Bytes JMP 06610FDB
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] WININET.dll!InternetOpenUrlW 7721A881 5 Bytes JMP 06610022
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] ws2_32.dll!socket 71AB3B91 5 Bytes JMP 06600000
—- Devices - GMER 1.0.12 —-
Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE B6B54C8A
Device \FileSystem\Fastfat \Fat IRP_MJ_CLOSE B6B517C8
Device \FileSystem\Fastfat \Fat IRP_MJ_READ B6B4D60A
Device \FileSystem\Fastfat \Fat IRP_MJ_WRITE B6B4DAED
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION B6B58958
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION B6B5B821
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA B6B6438A
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_EA B6B63D49
Device \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS B6B5DBBE
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION B6B5E331
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION B6B6C4F4
Device \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL B6B54B37
Device \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL B6B50948
Device \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL B6B5A46B
Device \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN B6B6B79D
Device \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL B6B6AC4A
Device \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP B6B512FD
Device \FileSystem\Fastfat \Fat IRP_MJ_PNP B6B6B1DB
Device \FileSystem\Fastfat \Fat FastIoCheckIfPossible B6B661F9
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [BA4DE701] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [BA4DE701] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [BA4DE701] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [BA4DE701] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [BA4DE701] tfsnifs.sys
Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL [BA4DE89D] tfsnifs.sys
—- Registry - GMER 1.0.12 —-
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run@RunAppBk C:\WINDOWS\system32\tmpnt.exe
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run@runner1 C:\WINDOWS\updater.exe 61A847B5BBF72810329B385576F901F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run@RunAppBk C:\WINDOWS\system32\tmpnt.exe
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run@runner1 C:\WINDOWS\updater.exe 61A847B5BBF72810329B385576F901F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
—- Files - GMER 1.0.12 —-
File C:\Documents and Settings\Bubba\SecMon.sys
File C:\WINDOWS\system32\SecMon.sys <– ROOTKIT !!!
—- Services - GMER 1.0.12 —-
Service C:\WINDOWS\system32\SecMon.sys [SYSTEM] SecurityMonitoringDriver <– ROOTKIT !!!
—- EOF - GMER 1.0.12 —-
Hijack log:
Logfile of HijackThis v1.99.1
Scan saved at 8:54:25 PM, on 5/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\SiteAdvisor\6028\SAService.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\SiteAdvisor\6028\SiteAdv.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\GMER\merchant.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.optonline.net/Home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {1E93AC48-1C87-4C55-F64F-1AE34B90F9CE} - C:\WINDOWS\system32\vix.dll
O2 - BHO: (no name) - {30000273-8230-4dd4-be4f-6889d1e74167} - (no file)
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: (no name) - {7F5A2699-38CD-4B98-B193-5916D6566B01} - (no file)
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {90051074-A0DF-49B4-94E8-E6A212240E89} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {c9e3f918-b62d-4859-8335-6c31f9576fc0} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {D38439EC-4A7F-42b4-90C2-D810D7778FDD} - (no file)
O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} - (no file)
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [gwiz] C:\WINDOWS\system32\ntsystem.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AntiVirusUpdateExe] C:\WINDOWS\gsvpm.exe
O4 - HKLM\..\RunServices: [E30A8607] C:\WINDOWS\system32\rsbmsc.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [freestyle] lockx.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = C:\Program Files\Dell Wireless\PRISMCFG.exe
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…arch.jhtml?p=ZS
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Bubba\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.howstuffworks.com
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://amiuptodate.mcafee.com/vsc/bin/2,0,…pdatePortal.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1150937271991
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1151184111625
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…008/mcfscan.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: lfpdsg - lfpdsg.dll (file missing)
O20 - Winlogon Notify: p4reg - C:\WINDOWS\SYSTEM32\p432.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: carbinyl - {8d8c2387-7f80-4022-9be6-43630a969558} - (no file)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6028\SAService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Windows Genuine Advantage Validation (wgav) - Unknown owner - C:\WINDOWS\system32\wgav.exe (file missing)
Would not let me download the ComboFix file……kept getting " 404 Not Found "
GMER results:
GMER 1.0.12.12244 - http://www.gmer.net
Rootkit scan 2007-05-03 20:47:12
Windows 5.1.2600 Service Pack 2
—- System - GMER 1.0.12 —-
SSDT \??\C:\WINDOWS\system32\SecMon.sys ZwEnumerateKey
SSDT \??\C:\WINDOWS\system32\SecMon.sys ZwEnumerateValueKey
SSDT \??\C:\WINDOWS\system32\SecMon.sys ZwQueryDirectoryFile
Code \SystemRoot\system32\drivers\mfehidk.sys ZwCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys ZwCreateKey
Code \SystemRoot\system32\drivers\mfehidk.sys ZwCreateProcess
Code \SystemRoot\system32\drivers\mfehidk.sys ZwDeleteKey
Code \SystemRoot\system32\drivers\mfehidk.sys ZwDeleteValueKey
Code \SystemRoot\system32\drivers\mfehidk.sys ZwMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys ZwOpenKey
Code \SystemRoot\system32\drivers\mfehidk.sys ZwProtectVirtualMemory
Code \SystemRoot\system32\drivers\mfehidk.sys ZwRenameKey
Code \SystemRoot\system32\drivers\mfehidk.sys ZwSetValueKey
Code \SystemRoot\system32\drivers\mfehidk.sys ZwTerminateProcess
Code \SystemRoot\system32\drivers\mfehidk.sys ZwUnmapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys ZwYieldExecution
Code \SystemRoot\system32\drivers\mfehidk.sys NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys NtMapViewOfSection
—- Kernel code sections - GMER 1.0.12 —-
.text ntoskrnl.exe!_abnormal_termination + 171 804E27CD 3 Bytes [ A3, 9D, F7 ]
.text ntoskrnl.exe!ZwYieldExecution 804F8B8D 7 Bytes JMP B95555BD \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!ZwOpenKey 80567CFB 5 Bytes JMP B95554EB \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!ZwCreateKey 8056E7A9 5 Bytes JMP B95554FF \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!NtCreateFile 8056FBF8 5 Bytes JMP B955557F \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!ZwUnmapViewOfSection 80571EF1 5 Bytes JMP B95555E9 \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!NtMapViewOfSection 8057236C 7 Bytes JMP B95555D3 \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!ZwProtectVirtualMemory 805730B5 7 Bytes JMP B9555593 \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!ZwSetValueKey 80573C8D 7 Bytes JMP B9555555 \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!ZwTerminateProcess 80584740 5 Bytes JMP B955556B \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!ZwDeleteValueKey 80593AAC 7 Bytes JMP B955553F \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!ZwDeleteKey 80595136 7 Bytes JMP B9555513 \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!ZwCreateProcess 805B0AA4 5 Bytes JMP B95555A9 \SystemRoot\system32\drivers\mfehidk.sys
PAGE ntoskrnl.exe!ZwRenameKey 8064D029 7 Bytes JMP B9555529 \SystemRoot\system32\drivers\mfehidk.sys
? C:\WINDOWS\system32\DRIVERS\update.sys
—- User code sections - GMER 1.0.12 —-
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00DF0FEF
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00DF0F41
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00DF0F66
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00DF0F83
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00DF0F94
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00DF0025
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00DF0F13
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00DF0F24
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00DF0091
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00DF0080
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00DF0EE7
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00DF0036
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00DF0FD4
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00DF005B
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00DF0FB9
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00DF000A
.text C:\WINDOWS\system32\services.exe[492] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00DF0F02
.text C:\WINDOWS\system32\services.exe[492] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00960FCA
.text C:\WINDOWS\system32\services.exe[492] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00960058
.text C:\WINDOWS\system32\services.exe[492] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 0096001B
.text C:\WINDOWS\system32\services.exe[492] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00960000
.text C:\WINDOWS\system32\services.exe[492] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00960FA5
.text C:\WINDOWS\system32\services.exe[492] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00960047
.text C:\WINDOWS\system32\services.exe[492] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00960FEF
.text C:\WINDOWS\system32\services.exe[492] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00960036
.text C:\WINDOWS\system32\services.exe[492] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00930FEF
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 007B0000
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 007B0064
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 007B0F6F
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 007B0F80
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 007B003D
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 007B0FB6
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 007B0086
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 007B0075
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 007B00B2
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 007B0F19
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 007B0F08
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 007B0FA5
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 007B0FE5
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 007B0F54
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 007B0022
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 007B0011
.text C:\WINDOWS\system32\svchost.exe[668] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 007B0097
.text C:\WINDOWS\system32\svchost.exe[668] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 007A0FD4
.text C:\WINDOWS\system32\svchost.exe[668] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 007A0FA8
.text C:\WINDOWS\system32\svchost.exe[668] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 007A0FEF
.text C:\WINDOWS\system32\svchost.exe[668] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 007A001B
.text C:\WINDOWS\system32\svchost.exe[668] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 007A0065
.text C:\WINDOWS\system32\svchost.exe[668] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 007A004A
.text C:\WINDOWS\system32\svchost.exe[668] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 007A000A
.text C:\WINDOWS\system32\svchost.exe[668] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 007A0FC3
.text C:\WINDOWS\system32\svchost.exe[668] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00780000
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00900FEF
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 009000A2
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 0090007D
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 0090006C
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 0090005B
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00900025
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 009000C4
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 009000B3
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00900F50
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 009000E9
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00900104
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00900040
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00900FD4
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00900F92
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00900FB9
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 0090000A
.text C:\WINDOWS\system32\svchost.exe[724] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00900F61
.text C:\WINDOWS\system32\svchost.exe[724] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 008F002F
.text C:\WINDOWS\system32\svchost.exe[724] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 008F0FB2
.text C:\WINDOWS\system32\svchost.exe[724] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 008F0FD4
.text C:\WINDOWS\system32\svchost.exe[724] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 008F000A
.text C:\WINDOWS\system32\svchost.exe[724] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 008F0FC3
.text C:\WINDOWS\system32\svchost.exe[724] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 008F005B
.text C:\WINDOWS\system32\svchost.exe[724] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 008F0FEF
.text C:\WINDOWS\system32\svchost.exe[724] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 008F004A
.text C:\WINDOWS\system32\svchost.exe[724] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 008D0000
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 018A0FEF
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 018A006B
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 018A0F76
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 018A0F91
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 018A004E
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 018A002C
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 018A0086
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 018A0F4A
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 018A0EFE
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 018A0F19
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 018A0EED
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 018A003D
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 018A0000
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 018A0F65
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 018A0FCA
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 018A001B
.text C:\WINDOWS\system32\svchost.exe[788] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 018A0097
.text C:\WINDOWS\system32\svchost.exe[788] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 0189001B
.text C:\WINDOWS\system32\svchost.exe[788] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 01890F8D
.text C:\WINDOWS\system32\svchost.exe[788] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 01890FCA
.text C:\WINDOWS\system32\svchost.exe[788] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 01890FE5
.text C:\WINDOWS\system32\svchost.exe[788] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 0189004A
.text C:\WINDOWS\system32\svchost.exe[788] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 01890F9E
.text C:\WINDOWS\system32\svchost.exe[788] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 01890000
.text C:\WINDOWS\system32\svchost.exe[788] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 01890FAF
.text C:\WINDOWS\system32\svchost.exe[788] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 01480000
.text C:\WINDOWS\system32\svchost.exe[788] WININET.dll!InternetOpenA 771CC859 5 Bytes JMP 0187000A
.text C:\WINDOWS\system32\svchost.exe[788] WININET.dll!InternetOpenW 771CCE91 5 Bytes JMP 01870FEF
.text C:\WINDOWS\system32\svchost.exe[788] WININET.dll!InternetOpenUrlA 771D06CD 5 Bytes JMP 01870025
.text C:\WINDOWS\system32\svchost.exe[788] WININET.dll!InternetOpenUrlW 7721A881 5 Bytes JMP 01870036
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00760FEF
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 0076007D
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00760062
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00760F94
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00760051
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00760040
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00760F3C
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00760F57
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 007600C4
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00760F21
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 007600D5
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00760FB9
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 0076000A
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 0076008E
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00760FD4
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00760025
.text C:\WINDOWS\system32\svchost.exe[840] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 0076009F
.text C:\WINDOWS\system32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 0075002C
.text C:\WINDOWS\system32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00750073
.text C:\WINDOWS\system32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 0075001B
.text C:\WINDOWS\system32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00750FEF
.text C:\WINDOWS\system32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00750062
.text C:\WINDOWS\system32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00750051
.text C:\WINDOWS\system32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 0075000A
.text C:\WINDOWS\system32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00750FCA
.text C:\WINDOWS\system32\svchost.exe[840] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00730FEF
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00720000
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 0072007F
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 0072006E
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00720F94
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00720051
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00720036
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00720F41
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00720F5E
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00720EFA
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00720F15
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 007200AE
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00720FA5
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00720FE5
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00720F6F
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00720FCA
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00720025
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00720F30
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00710FCA
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 0071006C
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00710011
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00710000
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00710051
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00710040
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00710FE5
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00710FB9
.text C:\WINDOWS\system32\svchost.exe[888] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 006F0FE5
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00C50000
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00C50075
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00C50F80
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00C5005A
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00C50F9B
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00C5002C
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00C500C1
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00C50F6F
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00C50F39
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00C500D2
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00C50F28
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00C5003D
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00C50011
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00C5009A
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00C50FC0
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00C50FD1
.text C:\WINDOWS\system32\svchost.exe[1352] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00C50F54
.text C:\WINDOWS\system32\svchost.exe[1352] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00C40FC3
.text C:\WINDOWS\system32\svchost.exe[1352] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00C4005E
.text C:\WINDOWS\system32\svchost.exe[1352] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00C40FD4
.text C:\WINDOWS\system32\svchost.exe[1352] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00C4000A
.text C:\WINDOWS\system32\svchost.exe[1352] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00C40F97
.text C:\WINDOWS\system32\svchost.exe[1352] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00C4002F
.text C:\WINDOWS\system32\svchost.exe[1352] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00C40FEF
.text C:\WINDOWS\system32\svchost.exe[1352] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00C40FB2
.text C:\WINDOWS\system32\svchost.exe[1352] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00C20FEF
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 001A000A
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001A0084
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 001A0F8F
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 001A0073
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 001A0FB6
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 001A004E
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 001A00D7
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 001A00BC
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001A0F52
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 001A0F63
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 001A00FC
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 001A0FC7
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 001A001B
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 001A0095
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 001A003D
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 001A002C
.text C:\WINDOWS\explorer.exe[2236] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 001A0F74
.text C:\WINDOWS\explorer.exe[2236] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00290040
.text C:\WINDOWS\explorer.exe[2236] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00290076
.text C:\WINDOWS\explorer.exe[2236] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00290025
.text C:\WINDOWS\explorer.exe[2236] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00290FE5
.text C:\WINDOWS\explorer.exe[2236] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00290FC3
.text C:\WINDOWS\explorer.exe[2236] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 0029005B
.text C:\WINDOWS\explorer.exe[2236] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00290000
.text C:\WINDOWS\explorer.exe[2236] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00290FD4
.text C:\WINDOWS\explorer.exe[2236] WININET.dll!InternetOpenA 771CC859 5 Bytes JMP 002B0000
.text C:\WINDOWS\explorer.exe[2236] WININET.dll!InternetOpenW 771CCE91 5 Bytes JMP 002B0FE5
.text C:\WINDOWS\explorer.exe[2236] WININET.dll!InternetOpenUrlA 771D06CD 5 Bytes JMP 002B0FCA
.text C:\WINDOWS\explorer.exe[2236] WININET.dll!InternetOpenUrlW 7721A881 5 Bytes JMP 002B001B
.text C:\WINDOWS\explorer.exe[2236] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 01D20000
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 001A0FE5
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001A0F43
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 001A0038
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 001A0F5E
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 001A0F79
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 001A000A
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 001A0F17
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 001A005F
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001A0EFC
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 001A008B
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 001A00B0
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 001A001B
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 001A0FD4
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 001A0F28
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 001A0F9E
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 001A0FB9
.text C:\Program Files\Messenger\msmsgs.exe[3144] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 001A007A
.text C:\Program Files\Messenger\msmsgs.exe[3144] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00290FC3
.text C:\Program Files\Messenger\msmsgs.exe[3144] ADVAPI32.dll!RegCreateKeyExW 77DD7535 1 Byte [ E9 ]
.text C:\Program Files\Messenger\msmsgs.exe[3144] ADVAPI32.dll!RegCreateKeyExW + 2 77DD7537 3 Bytes [ 8A, 4B, 88 ]
.text C:\Program Files\Messenger\msmsgs.exe[3144] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00290FDE
.text C:\Program Files\Messenger\msmsgs.exe[3144] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00290014
.text C:\Program Files\Messenger\msmsgs.exe[3144] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00290F86
.text C:\Program Files\Messenger\msmsgs.exe[3144] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00290F97
.text C:\Program Files\Messenger\msmsgs.exe[3144] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00290FEF
.text C:\Program Files\Messenger\msmsgs.exe[3144] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00290FA8
.text C:\Program Files\Messenger\msmsgs.exe[3144] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 002A0FEF
.text C:\Program Files\Messenger\msmsgs.exe[3144] WININET.dll!InternetOpenA 771CC859 5 Bytes JMP 002B000A
.text C:\Program Files\Messenger\msmsgs.exe[3144] WININET.dll!InternetOpenW 771CCE91 5 Bytes JMP 002B001B
.text C:\Program Files\Messenger\msmsgs.exe[3144] WININET.dll!InternetOpenUrlA 771D06CD 5 Bytes JMP 002B0FE5
.text C:\Program Files\Messenger\msmsgs.exe[3144] WININET.dll!InternetOpenUrlW 7721A881 5 Bytes JMP 002B0040
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 0664000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 06640067
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 06640F7C
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 06640F8D
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 06640040
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 06640FAF
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 06640F44
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 0664008C
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 06640F07
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 06640F22
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 066400BB
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 06640F9E
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 06640FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 06640F61
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 06640025
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 06640FD4
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 06640F33
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 06630025
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 0663005B
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 0663000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 06630FDE
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 06630040
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 06630FA8
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 06630FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 06630FB9
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] USER32.dll!SetWindowLongA 7E41D60D 5 Bytes JMP 00B5FFBA C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] USER32.dll!SetWindowLongW 7E41D62B 5 Bytes JMP 00B5FFEB C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] USER32.dll!DialogBoxParamW 7E42555F 5 Bytes JMP 009CF205 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] USER32.dll!DialogBoxIndirectParamW 7E432032 5 Bytes JMP 00B5FEBF C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] USER32.dll!MessageBoxIndirectA 7E43A04A 5 Bytes JMP 00B5FE40 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] USER32.dll!DialogBoxParamA 7E43B10C 5 Bytes JMP 00B5FE84 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] USER32.dll!MessageBoxExW 7E4505D8 5 Bytes JMP 00B5FDCC C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] USER32.dll!MessageBoxExA 7E4505FC 5 Bytes JMP 00B5FE06 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] USER32.dll!DialogBoxIndirectParamA 7E456B50 5 Bytes JMP 00B5FEFA C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 009F15DA C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] WININET.dll!InternetOpenA 771CC859 5 Bytes JMP 06610000
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] WININET.dll!InternetOpenW 771CCE91 5 Bytes JMP 06610011
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] WININET.dll!InternetOpenUrlA 771D06CD 5 Bytes JMP 06610FDB
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] WININET.dll!InternetOpenUrlW 7721A881 5 Bytes JMP 06610022
.text C:\Program Files\Internet Explorer\iexplore.exe[3252] ws2_32.dll!socket 71AB3B91 5 Bytes JMP 06600000
—- Devices - GMER 1.0.12 —-
Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE B6B54C8A
Device \FileSystem\Fastfat \Fat IRP_MJ_CLOSE B6B517C8
Device \FileSystem\Fastfat \Fat IRP_MJ_READ B6B4D60A
Device \FileSystem\Fastfat \Fat IRP_MJ_WRITE B6B4DAED
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION B6B58958
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION B6B5B821
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA B6B6438A
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_EA B6B63D49
Device \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS B6B5DBBE
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION B6B5E331
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION B6B6C4F4
Device \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL B6B54B37
Device \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL B6B50948
Device \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL B6B5A46B
Device \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN B6B6B79D
Device \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL B6B6AC4A
Device \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP B6B512FD
Device \FileSystem\Fastfat \Fat IRP_MJ_PNP B6B6B1DB
Device \FileSystem\Fastfat \Fat FastIoCheckIfPossible B6B661F9
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [BA4DE701] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [BA4DE701] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [BA4DE701] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [BA4DE701] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [BA4DE701] tfsnifs.sys
Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL [BA4DE89D] tfsnifs.sys
—- Registry - GMER 1.0.12 —-
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run@RunAppBk C:\WINDOWS\system32\tmpnt.exe
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run@runner1 C:\WINDOWS\updater.exe 61A847B5BBF72810329B385576F901F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run@RunAppBk C:\WINDOWS\system32\tmpnt.exe
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run@runner1 C:\WINDOWS\updater.exe 61A847B5BBF72810329B385576F901F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
—- Files - GMER 1.0.12 —-
File C:\Documents and Settings\Bubba\SecMon.sys
File C:\WINDOWS\system32\SecMon.sys <– ROOTKIT !!!
—- Services - GMER 1.0.12 —-
Service C:\WINDOWS\system32\SecMon.sys [SYSTEM] SecurityMonitoringDriver <– ROOTKIT !!!
—- EOF - GMER 1.0.12 —-
Hijack log:
Logfile of HijackThis v1.99.1
Scan saved at 8:54:25 PM, on 5/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\SiteAdvisor\6028\SAService.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\SiteAdvisor\6028\SiteAdv.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\GMER\merchant.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.optonline.net/Home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {1E93AC48-1C87-4C55-F64F-1AE34B90F9CE} - C:\WINDOWS\system32\vix.dll
O2 - BHO: (no name) - {30000273-8230-4dd4-be4f-6889d1e74167} - (no file)
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: (no name) - {7F5A2699-38CD-4B98-B193-5916D6566B01} - (no file)
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {90051074-A0DF-49B4-94E8-E6A212240E89} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {c9e3f918-b62d-4859-8335-6c31f9576fc0} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {D38439EC-4A7F-42b4-90C2-D810D7778FDD} - (no file)
O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} - (no file)
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [gwiz] C:\WINDOWS\system32\ntsystem.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AntiVirusUpdateExe] C:\WINDOWS\gsvpm.exe
O4 - HKLM\..\RunServices: [E30A8607] C:\WINDOWS\system32\rsbmsc.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [freestyle] lockx.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = C:\Program Files\Dell Wireless\PRISMCFG.exe
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…arch.jhtml?p=ZS
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Bubba\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.howstuffworks.com
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://amiuptodate.mcafee.com/vsc/bin/2,0,…pdatePortal.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1150937271991
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1151184111625
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…008/mcfscan.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: lfpdsg - lfpdsg.dll (file missing)
O20 - Winlogon Notify: p4reg - C:\WINDOWS\SYSTEM32\p432.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: carbinyl - {8d8c2387-7f80-4022-9be6-43630a969558} - (no file)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6028\SAService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Windows Genuine Advantage Validation (wgav) - Unknown owner - C:\WINDOWS\system32\wgav.exe (file missing)
Would not let me download the ComboFix file……kept getting " 404 Not Found "
LDTate
Download ComboFix from Here or Here to your Desktop.
- Double click combofix.exe and follow the prompts.
- When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
techmut
Thanks LDTate,
CombFix ran weird but apparently worked. FYI while we're doing all this, every time I run something and the comp reboots I can't get online and have to run the WinsockxpFix prog I downloaded. Then it gets right online.
ComboFix results:
"Bubba" - 07-05-03 21:40:33 Service Pack 2
ComboFix 07-04-25.4V - Running from: "C:\Documents and Settings\Bubba\Desktop\"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\uninstall_nmon.vbs
C:\WINDOWS\764.exe
C:\Program Files\outerinfo\OiUninstaller.exe
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\outerinfo\Terms.rtf
C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon\domains.txt
C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon\log.txt
C:\DOCUME~1\Bubba\Desktop\internet.lnk
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\wintsvit.exe
C:\WINDOWS\stat
C:\Program Files\inetget2
C:\Program Files\ipwindows
C:\Program Files\outerinfo
C:\deluxecommunications
C:\Program Files\webhancer
C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon
C:\Program Files\Common Files\{34F33~1
C:\Program Files\Common Files\{84F33~1
C:\Program Files\Common Files\{84F33~2
C:\WINDOWS\system32\msvcrl.dll
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\C\DOCUME~1
C:\qoobox\purity\C\DOCUME~1\Bubba
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1\cmd.exe
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1\??mantec
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1\??mantec\ctxad-552.0000
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
——-\Network Monitor
——-\nm
——-\LEGACY_CMDSERVICE
——-\LEGACY_NETWORK_MONITOR
((((((((((((((((((((((((((((((( Files Created from 2007-04-03 to 2007-05-03 ))))))))))))))))))))))))))))))))))
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\uninstall_nmon.vbs
C:\WINDOWS\764.exe
C:\Program Files\outerinfo\OiUninstaller.exe
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\outerinfo\Terms.rtf
C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon\domains.txt
C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon\log.txt
C:\DOCUME~1\Bubba\Desktop\internet.lnk
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\wintsvit.exe
C:\WINDOWS\stat
C:\Program Files\inetget2
C:\Program Files\ipwindows
C:\Program Files\outerinfo
C:\deluxecommunications
C:\Program Files\webhancer
C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon
C:\Program Files\Common Files\{34F33~1
C:\Program Files\Common Files\{84F33~1
C:\Program Files\Common Files\{84F33~2
C:\WINDOWS\system32\msvcrl.dll
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\C\DOCUME~1
C:\qoobox\purity\C\DOCUME~1\Bubba
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1\cmd.exe
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1\??mantec
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1\??mantec\ctxad-552.0000
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\C\DOCUME~1
C:\qoobox\purity\C\DOCUME~1\Bubba
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1\cmd.exe
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1\??mantec
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1\??mantec\ctxad-552.0000
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
——-\Network Monitor
——-\nm
——-\LEGACY_CMDSERVICE
——-\LEGACY_NETWORK_MONITOR
((((((((((((((((((((((((((((((( Files Created from 2007-04-03 to 2007-05-03 ))))))))))))))))))))))))))))))))))
2007-05-03 20:24 d——– C:\Program Files\GMER
2007-05-03 19:45 3,968 –a—— C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-05-03 19:45 3,968 –a—— C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-05-02 19:24 d——– C:\regbakup050207
2007-05-02 19:24 d——– C:\regbakup050207
2007-05-02 18:22 380,416 –a—— C:\WINDOWS\system32\rstrui.exe
2007-05-02 18:22 380,416 –a—— C:\WINDOWS\system32\rstrui.exe
2007-04-24 20:42 d——– C:\DOCUME~1\Dad\APPLIC~1\Google
2007-04-24 20:19 d——– C:\DOCUME~1\Dad\APPLIC~1\Lavasoft
2007-04-22 07:29 d——– C:\WINDOWS\system32\Logs
2007-04-22 07:29 d——– C:\WINDOWS\system32\Logs
2007-04-19 20:04 d——– C:\DOCUME~1\LOCALS~1\APPLIC~1\Google
2007-04-19 18:38 d——– C:\WINDOWS\oozi
2007-04-19 18:38 d——– C:\WINDOWS\oozi
2007-04-19 18:38 d——– C:\Program Files\Common Files\oozi
2007-04-19 18:38 d——– C:\Program Files\Common Files\oozi
2007-04-19 18:24 60,928 –a—— C:\WINDOWS\system32\vix.dll
2007-04-19 18:24 60,928 –a—— C:\WINDOWS\system32\vix.dll
2007-04-19 18:24 d——– C:\Program Files\àdobe
2007-04-19 18:08 d–hs—- C:\WINDOWS\QnViYmE
2007-04-19 18:08 d–hs—- C:\WINDOWS\QnViYmE
2007-04-19 17:53 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-04-15 11:24 d——– C:\Program Files\DellSupport
2007-04-14 19:03 d——– C:\Mypictures
2007-04-14 19:03 d——– C:\Mypictures
2007-04-13 19:55 d——– C:\DOCUME~1\Bubba\APPLIC~1\Ventrilo
2007-04-13 19:54 d——– C:\Program Files\Ventrilo
2007-04-13 17:09 d——– C:\WINDOWS\9580813D94B14C289426A441E2BB29A5.TMP
2007-04-13 17:09 d——– C:\WINDOWS\9580813D94B14C289426A441E2BB29A5.TMP
2007-04-10 16:58 d–h—– C:\WINDOWS\PIF
2007-04-10 16:58 d–h—– C:\WINDOWS\PIF
2007-04-10 16:58 d——– C:\Program Files\VentSrv
2007-04-10 16:57 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-04-10 16:57 d——– C:\Program Files\Common Files\Wise Installation Wizard
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-03 20:02 ——– d——– C:\Program Files\steam
2007-04-29 20:58 ——– d——– C:\DOCUME~1\Bubba\APPLIC~1\xfire
2007-04-29 17:14 ——– d—s—- C:\Program Files\xfire
2007-04-26 21:44 ——– d——– C:\DOCUME~1\Bubba\APPLIC~1\siteadvisor
2007-04-21 16:28 576 –a—— C:\DOCUME~1\Bubba\APPLIC~1\wklnhst.dat
2007-04-20 06:34 ——– d——– C:\Program Files\google
2007-03-22 12:08 ——– d——– C:\Program Files\mcafee
2007-03-21 07:12 14445 –a—— C:\WINDOWS\system32\svchpd1.exe
2007-03-17 09:43 292864 –a—— C:\WINDOWS\system32\winsrv.dll
2007-03-14 22:26 1130417 —hs—- C:\WINDOWS\system32\ehhkj.ini2
2007-03-14 20:46 1130181 —hs—- C:\WINDOWS\system32\ehhkj.bak2
2007-03-14 20:46 1129667 —hs—- C:\WINDOWS\system32\ehhkj.bak1
2007-03-13 19:04 32000 –a—— C:\WINDOWS\susp.exe
2007-03-13 19:04 30976 –a—— C:\WINDOWS\wml.exe
2007-03-13 19:04 30208 –a—— C:\WINDOWS\vxddsk.exe
2007-03-13 19:04 13312 –a—— C:\WINDOWS\system32\vxddsk.exe
2007-03-13 19:04 11520 –a—— C:\WINDOWS\system32\wml.exe
2007-03-13 19:04 11008 –a—— C:\WINDOWS\satmat.exe
2007-03-13 19:03 28672 –a—— C:\WINDOWS\pbar.dll
2007-03-13 19:03 12288 –a—— C:\WINDOWS\flt.dll
2007-03-13 19:03 11008 –a—— C:\WINDOWS\7search.dll
2007-03-13 19:02 32256 –a—— C:\WINDOWS\bokja.exe
2007-03-13 19:02 25600 –a—— C:\WINDOWS\voiceip.dll
2007-03-13 19:02 22016 –a—— C:\WINDOWS\cdsm32.dll
2007-03-13 19:02 19968 –a—— C:\WINDOWS\stcloader.exe
2007-03-13 19:02 13312 –a—— C:\WINDOWS\swin32.dll
2007-03-13 19:01 9984 –a—— C:\WINDOWS\mspphe.dll
2007-03-13 19:01 8448 –a—— C:\WINDOWS\system32\msixu.dll
2007-03-13 19:01 29952 –a—— C:\WINDOWS\updatetc.exe
2007-03-13 19:01 24320 –a—— C:\WINDOWS\180ax.exe
2007-03-13 19:01 24064 –a—— C:\WINDOWS\bjam.dll
2007-03-13 19:01 20992 –a—— C:\WINDOWS\salm.exe
2007-03-13 19:01 18432 –a—— C:\WINDOWS\system32\wer8274.dll
2007-03-13 19:01 14592 –a—— C:\WINDOWS\saiemod.dll
2007-03-13 18:59 19968 –a—— C:\WINDOWS\system32\cdromdrv32.dll
2007-03-13 18:58 12 –a—— C:\WINDOWS\system32\gtv_sd.bin
2007-03-13 12:54 72704 ——— C:\WINDOWS\system32\p432.dll
2007-03-12 20:46 20480 –a—— C:\WINDOWS\system32\eohugi.exe
2007-03-12 19:08 20480 –a—— C:\WINDOWS\system32\tispbvhz.exe
2007-03-12 18:41 20480 –a—— C:\WINDOWS\system32\kogbz.exe
2007-03-12 18:40 ——– d——– C:\Program Files\mcafee.com
2007-03-12 18:09 ——– d——– C:\Program Files\siteadvisor
2007-03-11 16:30 ——– d——– C:\Program Files\mywebsearch
2007-03-08 11:36 577536 –a—— C:\WINDOWS\system32\user32.dll
2007-03-08 11:36 40960 –a—— C:\WINDOWS\system32\mf3216.dll
2007-03-08 11:36 281600 –a—— C:\WINDOWS\system32\gdi32.dll
2007-03-08 09:47 1843584 –a—— C:\WINDOWS\system32\win32k.sys
2007-03-05 14:29 ——– d–h—– C:\Program Files\installshield installation information
2007-03-05 14:29 ——– d——– C:\Program Files\panasonic
2007-03-05 14:29 ——– d——– C:\Program Files\Common Files\panasonic
2007-02-05 16:17 185344 –a—— C:\WINDOWS\system32\upnphost.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
No new files created in this timespan
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4EFB-9B51-7695ECA05670} C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
{089FD14D-132B-48FC-8861-0048AE113215} C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
{1E93AC48-1C87-4C55-F64F-1AE34B90F9CE} C:\WINDOWS\system32\vix.dll
{53707962-6F74-2D53-2644-206D7942484F} C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
{5CA3D70E-1895-11CF-8E15-001234567890} C:\WINDOWS\system32\dla\tfswshx.dll
{7C554162-8CB7-45A4-B8F4-8EA1C75885F9} C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
{7DB2D5A0-7241-4E79-B68D-6309F01C5231} c:\program files\mcafee\virusscan\scriptcl.dll
{AA58ED58-01DD-4d91-8333-CF10577473F7} c:\program files\google\googletoolbar2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SoundMAXPnP"="C:\\Program Files\\Analog Devices\\Core\\smax4pnp.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_03\\bin\\jusched.exe"
"DVDLauncher"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"RealTray"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"ISUSPM Startup"="C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\ISUSPM.exe -startup"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"HPHUPD08"="c:\\Program Files\\HP\\Digital Imaging\\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\\hphupd08.exe"
"HP Software Update"="c:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"igfxtray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"igfxhkcmd"="C:\\WINDOWS\\system32\\hkcmd.exe"
"igfxpers"="C:\\WINDOWS\\system32\\igfxpers.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"AntiVirusUpdateExe"="C:\\WINDOWS\\gsvpm.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"freestyle"="lockx.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Aim6"="\"C:\\Program Files\\AIM6\\aim6.exe\" /d locale=en-US ee://aol/imApp"
"Steam"="\"C:\\Program Files\\Steam\\Steam.exe\" -silent"
"DellSupport"="\"C:\\Program Files\\DellSupport\\DSAgnt.exe\" /startup"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"E30A8607"="C:\\WINDOWS\\system32\\rsbmsc.exe"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Memt"="\"C:\\DOCUME~1\\Bubba\\APPLIC~1\\MANTEC~1\\cmd.exe\" -vt yazb"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"Wallpaper"=""
2007-05-03 21:45 ——– d——– C:\Program Files\steam
2007-04-29 20:58 ——– d——– C:\DOCUME~1\Bubba\APPLIC~1\xfire
2007-04-29 17:14 ——– d—s—- C:\Program Files\xfire
2007-04-26 21:44 ——– d——– C:\DOCUME~1\Bubba\APPLIC~1\siteadvisor
2007-04-21 16:28 576 –a—— C:\DOCUME~1\Bubba\APPLIC~1\wklnhst.dat
2007-04-20 06:34 ——– d——– C:\Program Files\google
2007-03-22 12:08 ——– d——– C:\Program Files\mcafee
2007-03-21 07:12 14445 –a—— C:\WINDOWS\system32\svchpd1.exe
2007-03-17 09:43 292864 –a—— C:\WINDOWS\system32\winsrv.dll
2007-03-14 22:26 1130417 —hs—- C:\WINDOWS\system32\ehhkj.ini2
2007-03-14 20:46 1130181 —hs—- C:\WINDOWS\system32\ehhkj.bak2
2007-03-14 20:46 1129667 —hs—- C:\WINDOWS\system32\ehhkj.bak1
2007-03-13 19:04 32000 –a—— C:\WINDOWS\susp.exe
2007-03-13 19:04 30976 –a—— C:\WINDOWS\wml.exe
2007-03-13 19:04 30208 –a—— C:\WINDOWS\vxddsk.exe
2007-03-13 19:04 13312 –a—— C:\WINDOWS\system32\vxddsk.exe
2007-03-13 19:04 11520 –a—— C:\WINDOWS\system32\wml.exe
2007-03-13 19:04 11008 –a—— C:\WINDOWS\satmat.exe
2007-03-13 19:03 28672 –a—— C:\WINDOWS\pbar.dll
2007-03-13 19:03 12288 –a—— C:\WINDOWS\flt.dll
2007-03-13 19:03 11008 –a—— C:\WINDOWS\7search.dll
2007-03-13 19:02 32256 –a—— C:\WINDOWS\bokja.exe
2007-03-13 19:02 25600 –a—— C:\WINDOWS\voiceip.dll
2007-03-13 19:02 22016 –a—— C:\WINDOWS\cdsm32.dll
2007-03-13 19:02 19968 –a—— C:\WINDOWS\stcloader.exe
2007-03-13 19:02 13312 –a—— C:\WINDOWS\swin32.dll
2007-03-13 19:01 9984 –a—— C:\WINDOWS\mspphe.dll
2007-03-13 19:01 8448 –a—— C:\WINDOWS\system32\msixu.dll
2007-03-13 19:01 29952 –a—— C:\WINDOWS\updatetc.exe
2007-03-13 19:01 24320 –a—— C:\WINDOWS\180ax.exe
2007-03-13 19:01 24064 –a—— C:\WINDOWS\bjam.dll
2007-03-13 19:01 20992 –a—— C:\WINDOWS\salm.exe
2007-03-13 19:01 18432 –a—— C:\WINDOWS\system32\wer8274.dll
2007-03-13 19:01 14592 –a—— C:\WINDOWS\saiemod.dll
2007-03-13 18:59 19968 –a—— C:\WINDOWS\system32\cdromdrv32.dll
2007-03-13 18:58 12 –a—— C:\WINDOWS\system32\gtv_sd.bin
2007-03-13 12:54 72704 ——— C:\WINDOWS\system32\p432.dll
2007-03-12 20:46 20480 –a—— C:\WINDOWS\system32\eohugi.exe
2007-03-12 19:08 20480 –a—— C:\WINDOWS\system32\tispbvhz.exe
2007-03-12 18:41 20480 –a—— C:\WINDOWS\system32\kogbz.exe
2007-03-12 18:40 ——– d——– C:\Program Files\mcafee.com
2007-03-12 18:09 ——– d——– C:\Program Files\siteadvisor
2007-03-11 16:30 ——– d——– C:\Program Files\mywebsearch
2007-03-08 11:36 577536 –a—— C:\WINDOWS\system32\user32.dll
2007-03-08 11:36 40960 –a—— C:\WINDOWS\system32\mf3216.dll
2007-03-08 11:36 281600 –a—— C:\WINDOWS\system32\gdi32.dll
2007-03-08 09:47 1843584 –a—— C:\WINDOWS\system32\win32k.sys
2007-03-05 14:29 ——– d–h—– C:\Program Files\installshield installation information
2007-03-05 14:29 ——– d——– C:\Program Files\panasonic
2007-03-05 14:29 ——– d——– C:\Program Files\Common Files\panasonic
2007-02-05 16:17 185344 –a—— C:\WINDOWS\system32\upnphost.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktop"=dword:00000000
"ForceActiveDesktopOn"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{8d8c2387-7f80-4022-9be6-43630a969558}"="carbinyl"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{7F5A2699-38CD-4B98-B193-5916D6566B01}"=""
"{1FFB1A32-1D58-46CF-BE8B-237586AF7F2F}"=""
"{F57D8DBE-5520-46F3-8A0A-484F4E6F8F71}"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"carbinyl"="{8d8c2387-7f80-4022-9be6-43630a969558}"
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\lfpdsg
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\p4reg
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\
Security Packages REG_MULTI_SZ kerberosmsv1_0schannelwdigest\
Notification Packages REG_MULTI_SZ scecli\
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\MCODS
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\
LocalService REG_MULTI_SZ AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV\
NetworkService REG_MULTI_SZ DnsCache\
DcomLaunch REG_MULTI_SZ DcomLaunchTermService\
rpcss REG_MULTI_SZ RpcSs\
imgsvc REG_MULTI_SZ StiSvc\
termsvcs REG_MULTI_SZ TermService\
WudfServiceGroup REG_MULTI_SZ WUDFSvc\
p2psvc REG_MULTI_SZ p2psvcp2pimsvcp2pgasvcPNRPSvc\
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Memt"="\"C:\\DOCUME~1\\Bubba\\APPLIC~1\\MANTEC~1\\cmd.exe\" -vt yazb"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"Wallpaper"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktop"=dword:00000000
"ForceActiveDesktopOn"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\McDefragTask.job
********************************************************************
********************************************************************
Completion time: 07-05-03 21:47:07 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 07-05-03 21:47
Completion time: 07-05-03 21:47:07 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 07-05-03 21:47
ComboFix Quarantined Log ??:
Hijack Log:
Logfile of HijackThis v1.99.1
Scan saved at 10:02:56 PM, on 5/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\SiteAdvisor\6028\SAService.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\SiteAdvisor\6028\SiteAdv.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.optonline.net/Home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {1E93AC48-1C87-4C55-F64F-1AE34B90F9CE} - C:\WINDOWS\system32\vix.dll
O2 - BHO: (no name) - {30000273-8230-4dd4-be4f-6889d1e74167} - (no file)
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: (no name) - {7F5A2699-38CD-4B98-B193-5916D6566B01} - (no file)
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {90051074-A0DF-49B4-94E8-E6A212240E89} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {c9e3f918-b62d-4859-8335-6c31f9576fc0} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {D38439EC-4A7F-42b4-90C2-D810D7778FDD} - (no file)
O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} - (no file)
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AntiVirusUpdateExe] C:\WINDOWS\gsvpm.exe
O4 - HKLM\..\RunServices: [E30A8607] C:\WINDOWS\system32\rsbmsc.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [freestyle] lockx.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = C:\Program Files\Dell Wireless\PRISMCFG.exe
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…arch.jhtml?p=ZS
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Bubba\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.howstuffworks.com
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://amiuptodate.mcafee.com/vsc/bin/2,0,…pdatePortal.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1150937271991
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1151184111625
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…008/mcfscan.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: lfpdsg - lfpdsg.dll (file missing)
O20 - Winlogon Notify: p4reg - C:\WINDOWS\SYSTEM32\p432.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: carbinyl - {8d8c2387-7f80-4022-9be6-43630a969558} - (no file)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6028\SAService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Windows Genuine Advantage Validation (wgav) - Unknown owner - C:\WINDOWS\system32\wgav.exe (file missing)
Last process I can run tonight. Son wants to go to bed. Look forward to resuming tomorrow.
CombFix ran weird but apparently worked. FYI while we're doing all this, every time I run something and the comp reboots I can't get online and have to run the WinsockxpFix prog I downloaded. Then it gets right online.
ComboFix results:
"Bubba" - 07-05-03 21:40:33 Service Pack 2
ComboFix 07-04-25.4V - Running from: "C:\Documents and Settings\Bubba\Desktop\"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\uninstall_nmon.vbs
C:\WINDOWS\764.exe
C:\Program Files\outerinfo\OiUninstaller.exe
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\outerinfo\Terms.rtf
C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon\domains.txt
C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon\log.txt
C:\DOCUME~1\Bubba\Desktop\internet.lnk
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\wintsvit.exe
C:\WINDOWS\stat
C:\Program Files\inetget2
C:\Program Files\ipwindows
C:\Program Files\outerinfo
C:\deluxecommunications
C:\Program Files\webhancer
C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon
C:\Program Files\Common Files\{34F33~1
C:\Program Files\Common Files\{84F33~1
C:\Program Files\Common Files\{84F33~2
C:\WINDOWS\system32\msvcrl.dll
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\C\DOCUME~1
C:\qoobox\purity\C\DOCUME~1\Bubba
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1\cmd.exe
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1\??mantec
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1\??mantec\ctxad-552.0000
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
——-\Network Monitor
——-\nm
——-\LEGACY_CMDSERVICE
——-\LEGACY_NETWORK_MONITOR
((((((((((((((((((((((((((((((( Files Created from 2007-04-03 to 2007-05-03 ))))))))))))))))))))))))))))))))))
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\uninstall_nmon.vbs
C:\WINDOWS\764.exe
C:\Program Files\outerinfo\OiUninstaller.exe
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\outerinfo\Terms.rtf
C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon\domains.txt
C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon\log.txt
C:\DOCUME~1\Bubba\Desktop\internet.lnk
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\wintsvit.exe
C:\WINDOWS\stat
C:\Program Files\inetget2
C:\Program Files\ipwindows
C:\Program Files\outerinfo
C:\deluxecommunications
C:\Program Files\webhancer
C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon
C:\Program Files\Common Files\{34F33~1
C:\Program Files\Common Files\{84F33~1
C:\Program Files\Common Files\{84F33~2
C:\WINDOWS\system32\msvcrl.dll
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\C\DOCUME~1
C:\qoobox\purity\C\DOCUME~1\Bubba
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1\cmd.exe
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1\??mantec
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1\??mantec\ctxad-552.0000
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\C\DOCUME~1
C:\qoobox\purity\C\DOCUME~1\Bubba
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1\cmd.exe
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1\??mantec
C:\qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1\??mantec\ctxad-552.0000
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
——-\Network Monitor
——-\nm
——-\LEGACY_CMDSERVICE
——-\LEGACY_NETWORK_MONITOR
((((((((((((((((((((((((((((((( Files Created from 2007-04-03 to 2007-05-03 ))))))))))))))))))))))))))))))))))
2007-05-03 20:24 d——– C:\Program Files\GMER
2007-05-03 19:45 3,968 –a—— C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-05-03 19:45 3,968 –a—— C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-05-02 19:24 d——– C:\regbakup050207
2007-05-02 19:24 d——– C:\regbakup050207
2007-05-02 18:22 380,416 –a—— C:\WINDOWS\system32\rstrui.exe
2007-05-02 18:22 380,416 –a—— C:\WINDOWS\system32\rstrui.exe
2007-04-24 20:42 d——– C:\DOCUME~1\Dad\APPLIC~1\Google
2007-04-24 20:19 d——– C:\DOCUME~1\Dad\APPLIC~1\Lavasoft
2007-04-22 07:29 d——– C:\WINDOWS\system32\Logs
2007-04-22 07:29 d——– C:\WINDOWS\system32\Logs
2007-04-19 20:04 d——– C:\DOCUME~1\LOCALS~1\APPLIC~1\Google
2007-04-19 18:38 d——– C:\WINDOWS\oozi
2007-04-19 18:38 d——– C:\WINDOWS\oozi
2007-04-19 18:38 d——– C:\Program Files\Common Files\oozi
2007-04-19 18:38 d——– C:\Program Files\Common Files\oozi
2007-04-19 18:24 60,928 –a—— C:\WINDOWS\system32\vix.dll
2007-04-19 18:24 60,928 –a—— C:\WINDOWS\system32\vix.dll
2007-04-19 18:24 d——– C:\Program Files\àdobe
2007-04-19 18:08 d–hs—- C:\WINDOWS\QnViYmE
2007-04-19 18:08 d–hs—- C:\WINDOWS\QnViYmE
2007-04-19 17:53 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-04-15 11:24 d——– C:\Program Files\DellSupport
2007-04-14 19:03 d——– C:\Mypictures
2007-04-14 19:03 d——– C:\Mypictures
2007-04-13 19:55 d——– C:\DOCUME~1\Bubba\APPLIC~1\Ventrilo
2007-04-13 19:54 d——– C:\Program Files\Ventrilo
2007-04-13 17:09 d——– C:\WINDOWS\9580813D94B14C289426A441E2BB29A5.TMP
2007-04-13 17:09 d——– C:\WINDOWS\9580813D94B14C289426A441E2BB29A5.TMP
2007-04-10 16:58 d–h—– C:\WINDOWS\PIF
2007-04-10 16:58 d–h—– C:\WINDOWS\PIF
2007-04-10 16:58 d——– C:\Program Files\VentSrv
2007-04-10 16:57 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-04-10 16:57 d——– C:\Program Files\Common Files\Wise Installation Wizard
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-03 20:02 ——– d——– C:\Program Files\steam
2007-04-29 20:58 ——– d——– C:\DOCUME~1\Bubba\APPLIC~1\xfire
2007-04-29 17:14 ——– d—s—- C:\Program Files\xfire
2007-04-26 21:44 ——– d——– C:\DOCUME~1\Bubba\APPLIC~1\siteadvisor
2007-04-21 16:28 576 –a—— C:\DOCUME~1\Bubba\APPLIC~1\wklnhst.dat
2007-04-20 06:34 ——– d——– C:\Program Files\google
2007-03-22 12:08 ——– d——– C:\Program Files\mcafee
2007-03-21 07:12 14445 –a—— C:\WINDOWS\system32\svchpd1.exe
2007-03-17 09:43 292864 –a—— C:\WINDOWS\system32\winsrv.dll
2007-03-14 22:26 1130417 —hs—- C:\WINDOWS\system32\ehhkj.ini2
2007-03-14 20:46 1130181 —hs—- C:\WINDOWS\system32\ehhkj.bak2
2007-03-14 20:46 1129667 —hs—- C:\WINDOWS\system32\ehhkj.bak1
2007-03-13 19:04 32000 –a—— C:\WINDOWS\susp.exe
2007-03-13 19:04 30976 –a—— C:\WINDOWS\wml.exe
2007-03-13 19:04 30208 –a—— C:\WINDOWS\vxddsk.exe
2007-03-13 19:04 13312 –a—— C:\WINDOWS\system32\vxddsk.exe
2007-03-13 19:04 11520 –a—— C:\WINDOWS\system32\wml.exe
2007-03-13 19:04 11008 –a—— C:\WINDOWS\satmat.exe
2007-03-13 19:03 28672 –a—— C:\WINDOWS\pbar.dll
2007-03-13 19:03 12288 –a—— C:\WINDOWS\flt.dll
2007-03-13 19:03 11008 –a—— C:\WINDOWS\7search.dll
2007-03-13 19:02 32256 –a—— C:\WINDOWS\bokja.exe
2007-03-13 19:02 25600 –a—— C:\WINDOWS\voiceip.dll
2007-03-13 19:02 22016 –a—— C:\WINDOWS\cdsm32.dll
2007-03-13 19:02 19968 –a—— C:\WINDOWS\stcloader.exe
2007-03-13 19:02 13312 –a—— C:\WINDOWS\swin32.dll
2007-03-13 19:01 9984 –a—— C:\WINDOWS\mspphe.dll
2007-03-13 19:01 8448 –a—— C:\WINDOWS\system32\msixu.dll
2007-03-13 19:01 29952 –a—— C:\WINDOWS\updatetc.exe
2007-03-13 19:01 24320 –a—— C:\WINDOWS\180ax.exe
2007-03-13 19:01 24064 –a—— C:\WINDOWS\bjam.dll
2007-03-13 19:01 20992 –a—— C:\WINDOWS\salm.exe
2007-03-13 19:01 18432 –a—— C:\WINDOWS\system32\wer8274.dll
2007-03-13 19:01 14592 –a—— C:\WINDOWS\saiemod.dll
2007-03-13 18:59 19968 –a—— C:\WINDOWS\system32\cdromdrv32.dll
2007-03-13 18:58 12 –a—— C:\WINDOWS\system32\gtv_sd.bin
2007-03-13 12:54 72704 ——— C:\WINDOWS\system32\p432.dll
2007-03-12 20:46 20480 –a—— C:\WINDOWS\system32\eohugi.exe
2007-03-12 19:08 20480 –a—— C:\WINDOWS\system32\tispbvhz.exe
2007-03-12 18:41 20480 –a—— C:\WINDOWS\system32\kogbz.exe
2007-03-12 18:40 ——– d——– C:\Program Files\mcafee.com
2007-03-12 18:09 ——– d——– C:\Program Files\siteadvisor
2007-03-11 16:30 ——– d——– C:\Program Files\mywebsearch
2007-03-08 11:36 577536 –a—— C:\WINDOWS\system32\user32.dll
2007-03-08 11:36 40960 –a—— C:\WINDOWS\system32\mf3216.dll
2007-03-08 11:36 281600 –a—— C:\WINDOWS\system32\gdi32.dll
2007-03-08 09:47 1843584 –a—— C:\WINDOWS\system32\win32k.sys
2007-03-05 14:29 ——– d–h—– C:\Program Files\installshield installation information
2007-03-05 14:29 ——– d——– C:\Program Files\panasonic
2007-03-05 14:29 ——– d——– C:\Program Files\Common Files\panasonic
2007-02-05 16:17 185344 –a—— C:\WINDOWS\system32\upnphost.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
No new files created in this timespan
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4EFB-9B51-7695ECA05670} C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
{089FD14D-132B-48FC-8861-0048AE113215} C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
{1E93AC48-1C87-4C55-F64F-1AE34B90F9CE} C:\WINDOWS\system32\vix.dll
{53707962-6F74-2D53-2644-206D7942484F} C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
{5CA3D70E-1895-11CF-8E15-001234567890} C:\WINDOWS\system32\dla\tfswshx.dll
{7C554162-8CB7-45A4-B8F4-8EA1C75885F9} C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
{7DB2D5A0-7241-4E79-B68D-6309F01C5231} c:\program files\mcafee\virusscan\scriptcl.dll
{AA58ED58-01DD-4d91-8333-CF10577473F7} c:\program files\google\googletoolbar2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SoundMAXPnP"="C:\\Program Files\\Analog Devices\\Core\\smax4pnp.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_03\\bin\\jusched.exe"
"DVDLauncher"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"RealTray"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"ISUSPM Startup"="C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\ISUSPM.exe -startup"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"HPHUPD08"="c:\\Program Files\\HP\\Digital Imaging\\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\\hphupd08.exe"
"HP Software Update"="c:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"igfxtray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"igfxhkcmd"="C:\\WINDOWS\\system32\\hkcmd.exe"
"igfxpers"="C:\\WINDOWS\\system32\\igfxpers.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"AntiVirusUpdateExe"="C:\\WINDOWS\\gsvpm.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"freestyle"="lockx.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Aim6"="\"C:\\Program Files\\AIM6\\aim6.exe\" /d locale=en-US ee://aol/imApp"
"Steam"="\"C:\\Program Files\\Steam\\Steam.exe\" -silent"
"DellSupport"="\"C:\\Program Files\\DellSupport\\DSAgnt.exe\" /startup"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"E30A8607"="C:\\WINDOWS\\system32\\rsbmsc.exe"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Memt"="\"C:\\DOCUME~1\\Bubba\\APPLIC~1\\MANTEC~1\\cmd.exe\" -vt yazb"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"Wallpaper"=""
2007-05-03 21:45 ——– d——– C:\Program Files\steam
2007-04-29 20:58 ——– d——– C:\DOCUME~1\Bubba\APPLIC~1\xfire
2007-04-29 17:14 ——– d—s—- C:\Program Files\xfire
2007-04-26 21:44 ——– d——– C:\DOCUME~1\Bubba\APPLIC~1\siteadvisor
2007-04-21 16:28 576 –a—— C:\DOCUME~1\Bubba\APPLIC~1\wklnhst.dat
2007-04-20 06:34 ——– d——– C:\Program Files\google
2007-03-22 12:08 ——– d——– C:\Program Files\mcafee
2007-03-21 07:12 14445 –a—— C:\WINDOWS\system32\svchpd1.exe
2007-03-17 09:43 292864 –a—— C:\WINDOWS\system32\winsrv.dll
2007-03-14 22:26 1130417 —hs—- C:\WINDOWS\system32\ehhkj.ini2
2007-03-14 20:46 1130181 —hs—- C:\WINDOWS\system32\ehhkj.bak2
2007-03-14 20:46 1129667 —hs—- C:\WINDOWS\system32\ehhkj.bak1
2007-03-13 19:04 32000 –a—— C:\WINDOWS\susp.exe
2007-03-13 19:04 30976 –a—— C:\WINDOWS\wml.exe
2007-03-13 19:04 30208 –a—— C:\WINDOWS\vxddsk.exe
2007-03-13 19:04 13312 –a—— C:\WINDOWS\system32\vxddsk.exe
2007-03-13 19:04 11520 –a—— C:\WINDOWS\system32\wml.exe
2007-03-13 19:04 11008 –a—— C:\WINDOWS\satmat.exe
2007-03-13 19:03 28672 –a—— C:\WINDOWS\pbar.dll
2007-03-13 19:03 12288 –a—— C:\WINDOWS\flt.dll
2007-03-13 19:03 11008 –a—— C:\WINDOWS\7search.dll
2007-03-13 19:02 32256 –a—— C:\WINDOWS\bokja.exe
2007-03-13 19:02 25600 –a—— C:\WINDOWS\voiceip.dll
2007-03-13 19:02 22016 –a—— C:\WINDOWS\cdsm32.dll
2007-03-13 19:02 19968 –a—— C:\WINDOWS\stcloader.exe
2007-03-13 19:02 13312 –a—— C:\WINDOWS\swin32.dll
2007-03-13 19:01 9984 –a—— C:\WINDOWS\mspphe.dll
2007-03-13 19:01 8448 –a—— C:\WINDOWS\system32\msixu.dll
2007-03-13 19:01 29952 –a—— C:\WINDOWS\updatetc.exe
2007-03-13 19:01 24320 –a—— C:\WINDOWS\180ax.exe
2007-03-13 19:01 24064 –a—— C:\WINDOWS\bjam.dll
2007-03-13 19:01 20992 –a—— C:\WINDOWS\salm.exe
2007-03-13 19:01 18432 –a—— C:\WINDOWS\system32\wer8274.dll
2007-03-13 19:01 14592 –a—— C:\WINDOWS\saiemod.dll
2007-03-13 18:59 19968 –a—— C:\WINDOWS\system32\cdromdrv32.dll
2007-03-13 18:58 12 –a—— C:\WINDOWS\system32\gtv_sd.bin
2007-03-13 12:54 72704 ——— C:\WINDOWS\system32\p432.dll
2007-03-12 20:46 20480 –a—— C:\WINDOWS\system32\eohugi.exe
2007-03-12 19:08 20480 –a—— C:\WINDOWS\system32\tispbvhz.exe
2007-03-12 18:41 20480 –a—— C:\WINDOWS\system32\kogbz.exe
2007-03-12 18:40 ——– d——– C:\Program Files\mcafee.com
2007-03-12 18:09 ——– d——– C:\Program Files\siteadvisor
2007-03-11 16:30 ——– d——– C:\Program Files\mywebsearch
2007-03-08 11:36 577536 –a—— C:\WINDOWS\system32\user32.dll
2007-03-08 11:36 40960 –a—— C:\WINDOWS\system32\mf3216.dll
2007-03-08 11:36 281600 –a—— C:\WINDOWS\system32\gdi32.dll
2007-03-08 09:47 1843584 –a—— C:\WINDOWS\system32\win32k.sys
2007-03-05 14:29 ——– d–h—– C:\Program Files\installshield installation information
2007-03-05 14:29 ——– d——– C:\Program Files\panasonic
2007-03-05 14:29 ——– d——– C:\Program Files\Common Files\panasonic
2007-02-05 16:17 185344 –a—— C:\WINDOWS\system32\upnphost.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktop"=dword:00000000
"ForceActiveDesktopOn"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{8d8c2387-7f80-4022-9be6-43630a969558}"="carbinyl"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{7F5A2699-38CD-4B98-B193-5916D6566B01}"=""
"{1FFB1A32-1D58-46CF-BE8B-237586AF7F2F}"=""
"{F57D8DBE-5520-46F3-8A0A-484F4E6F8F71}"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"carbinyl"="{8d8c2387-7f80-4022-9be6-43630a969558}"
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\lfpdsg
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\p4reg
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\
Security Packages REG_MULTI_SZ kerberosmsv1_0schannelwdigest\
Notification Packages REG_MULTI_SZ scecli\
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\MCODS
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\
LocalService REG_MULTI_SZ AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV\
NetworkService REG_MULTI_SZ DnsCache\
DcomLaunch REG_MULTI_SZ DcomLaunchTermService\
rpcss REG_MULTI_SZ RpcSs\
imgsvc REG_MULTI_SZ StiSvc\
termsvcs REG_MULTI_SZ TermService\
WudfServiceGroup REG_MULTI_SZ WUDFSvc\
p2psvc REG_MULTI_SZ p2psvcp2pimsvcp2pgasvcPNRPSvc\
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Memt"="\"C:\\DOCUME~1\\Bubba\\APPLIC~1\\MANTEC~1\\cmd.exe\" -vt yazb"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"Wallpaper"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktop"=dword:00000000
"ForceActiveDesktopOn"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\McDefragTask.job
********************************************************************
********************************************************************
Completion time: 07-05-03 21:47:07 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 07-05-03 21:47
Completion time: 07-05-03 21:47:07 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 07-05-03 21:47
ComboFix Quarantined Log ??:
00-10-27 18:23 50688 –a—— C:\Qoobox\Quarantine\C\WINDOWS\system32\BSZIP.DLL.vir 06-01-03 17:45 1989 –a—— C:\Qoobox\Quarantine\C\WINDOWS\uninstall_nmon.vbs.vir 07-01-12 16:00 18031 –a—— C:\Qoobox\Quarantine\C\Program Files\Outerinfo\Terms.rtf.vir 07-01-16 15:57 104 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\Bubba\Desktop\Internet.lnk.vir 07-01-29 10:01 44032 –a—— C:\Qoobox\Quarantine\C\WINDOWS\system32\msvcrl.dll.vir 07-03-06 11:59 34494 –a—— C:\Qoobox\Quarantine\C\Program Files\Outerinfo\outerinfo.ico.vir 07-03-13 18:58 1 –a—— C:\Qoobox\Quarantine\C\WINDOWS\stat.vir 07-03-13 19:03 29440 –a—— C:\Qoobox\Quarantine\C\WINDOWS\764.exe.vir 07-03-19 14:31 111896 –a—— C:\Qoobox\Quarantine\C\Program Files\Outerinfo\OiUninstaller.exe.vir 07-04-19 18:23 70144 –a—— C:\Qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1\cmd.exe 07-04-19 18:24 2 –a—— C:\Qoobox\Quarantine\C\WINDOWS\system32\wintsvit.exe.vir 07-04-19 22:28 60000 –a—— C:\Qoobox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1\??mantec\ctxad-552.0000 07-04-23 10:57 131020 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\LOCALS~1\APPLIC~1\NetMon\log.txt.vir 07-04-23 10:57 73 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\LOCALS~1\APPLIC~1\NetMon\domains.txt.vir 07-05-03 21:42 2830 –a—— C:\Qoobox\Quarantine\Registry_backups\services_Network Monitor.reg.cf 07-05-03 21:42 360 –a—— C:\Qoobox\Quarantine\Registry_backups\services_nm.reg.cf 07-05-03 21:42 840 –a—— C:\Qoobox\Quarantine\Registry_backups\LEGACY_CMDSERVICE.reg.cf 07-05-03 21:42 870 –a—— C:\Qoobox\Quarantine\Registry_backups\LEGACY_NETWORK_MONITOR.reg.cf Folder PATH listing Volume serial number is 84F3-3D0D C:\QOOBOX +—purity | \—C | \—DOCUME~1 | \—Bubba | \—APPLIC~1 | \—MANTEC~1 | | cmd.exe | | | \—??mantec | ctxad-552.0000 | \—Quarantine +—C | +—DOCUME~1 | | +—Bubba | | | \—Desktop | | | Internet.lnk.vir | | | | | \—LOCALS~1 | | \—APPLIC~1 | | \—NetMon | | domains.txt.vir | | log.txt.vir | | | +—Program Files | | \—Outerinfo | | OiUninstaller.exe.vir | | outerinfo.ico.vir | | Terms.rtf.vir | | | \—WINDOWS | | 764.exe.vir | | stat.vir | | uninstall_nmon.vbs.vir | | | \—system32 | BSZIP.DLL.vir | msvcrl.dll.vir | wintsvit.exe.vir | \—Registry_backups LEGACY_CMDSERVICE.reg.cf LEGACY_NETWORK_MONITOR.reg.cf services_Network Monitor.reg.cf services_nm.reg.cf
Hijack Log:
Logfile of HijackThis v1.99.1
Scan saved at 10:02:56 PM, on 5/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\SiteAdvisor\6028\SAService.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\SiteAdvisor\6028\SiteAdv.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.optonline.net/Home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {1E93AC48-1C87-4C55-F64F-1AE34B90F9CE} - C:\WINDOWS\system32\vix.dll
O2 - BHO: (no name) - {30000273-8230-4dd4-be4f-6889d1e74167} - (no file)
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: (no name) - {7F5A2699-38CD-4B98-B193-5916D6566B01} - (no file)
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {90051074-A0DF-49B4-94E8-E6A212240E89} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {c9e3f918-b62d-4859-8335-6c31f9576fc0} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {D38439EC-4A7F-42b4-90C2-D810D7778FDD} - (no file)
O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} - (no file)
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AntiVirusUpdateExe] C:\WINDOWS\gsvpm.exe
O4 - HKLM\..\RunServices: [E30A8607] C:\WINDOWS\system32\rsbmsc.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [freestyle] lockx.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = C:\Program Files\Dell Wireless\PRISMCFG.exe
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…arch.jhtml?p=ZS
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Bubba\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.howstuffworks.com
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://amiuptodate.mcafee.com/vsc/bin/2,0,…pdatePortal.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1150937271991
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1151184111625
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…008/mcfscan.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: lfpdsg - lfpdsg.dll (file missing)
O20 - Winlogon Notify: p4reg - C:\WINDOWS\SYSTEM32\p432.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: carbinyl - {8d8c2387-7f80-4022-9be6-43630a969558} - (no file)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6028\SAService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Windows Genuine Advantage Validation (wgav) - Unknown owner - C:\WINDOWS\system32\wgav.exe (file missing)
Last process I can run tonight. Son wants to go to bed. Look forward to resuming tomorrow.
LDTate
This PC is so bad I can't beleive it's running.
We'll try and clean it.
First thing I want you to do is from a clean PC, change any financial and other personal online passwords.
Next:
Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)
It's normal after running ATF cleaner that the PC will be slower to boot the first time.
Next:
Download AVG Anti-Spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
We'll try and clean it.
First thing I want you to do is from a clean PC, change any financial and other personal online passwords.
Next:
Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)
It's normal after running ATF cleaner that the PC will be slower to boot the first time.
Next:
Download AVG Anti-Spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
- Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop
and double-click it to launch the set up program. - Once the setup is complete you will need run ewido and update the definition
files. - On the main screen select the icon "Update" then select the "
Update now" link.- Next select the "Start Update" button, the update will start and a
progress bar will show the updates being installed.
- Next select the "Start Update" button, the update will start and a
- Once the update has completed select the "Scanner" icon at the top of
the screen, then select the "Settings" tab. - Once in the Settings screen click on "Recommended actions" and then
select " "Quarantine" .". - Under "Reports"
- Select "Automatically generate report after every scan"
- Un-Select "Only if threats were found"
- Reboot your computer into SafeMode. You can do this by restarting
your computer and continually tapping the F8 key until a menu appears.
Use your up arrow key to highlight SafeMode then hit enter.
IMPORTANT: Do not open any other windows or
programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess: - Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
- Select the "Scanner" icon at the top and then the "Scan" tab
then click on "Complete System Scan". - ewido will now begin the scanning process, be patient this may take a little
time.
Once the scan is complete do the following: - If you have any infections you will prompted, then select "Apply all
actions" - Next select the "Reports" icon at the top.
- Select the "Save report as" button in the lower left hand of the
screen and save it to a text file on your system (make sure to remember where
you saved that file, this is important). - Close AVG Anti-Spyware and reboot your system back into Normal Mode and post the
results of the AVG Anti-Spyware report scan along with a new HijackThis log.
techmut
gotta laugh……..
wait til we get to my daughter's pc!!!
Want to understand what you refer to as a "clean pc".
And as far as passwords, this being my son's computer I believe he only has online gaming, IM and Outl Expr email (I know…cringe, cringe) passwords. Nothing financial.
Should he change all those?
Will all existing passwords on his pc be deleted by the ATF Cleaner?
What is the reason for needing to change the passwords?
Want to understand what you refer to as a "clean pc".
And as far as passwords, this being my son's computer I believe he only has online gaming, IM and Outl Expr email (I know…cringe, cringe) passwords. Nothing financial.
Should he change all those?
Will all existing passwords on his pc be deleted by the ATF Cleaner?
What is the reason for needing to change the passwords?
LDTate
If you want you can do a google search on Rootkits. There any many different flavor's of Rootkits though.
They steal login names / passwords / account numbers etc.
They steal login names / passwords / account numbers etc.
On that isn't infected.Want to understand what you refer to as a "clean pc".
Yes, I would.And as far as passwords, this being my son's computer I believe he only has online gaming, IM and Outl Expr email (I know…cringe, cringe) passwords. Nothing financial.
Should he change all those?
No.Will all existing passwords on his pc be deleted by the ATF Cleaner?
techmut
Thanks LDTate,
Back at it……
AVG Spyware results:
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————
+ Created at: 7:47:34 PM 5/5/2007
+ Scan result:
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024024.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024025.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024026.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} -> Adware.Generic : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Antispyware Soldier_is1 -> Adware.Generic : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929CD6E-2062-44A4-B2C5-2C7E78FBAB38} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929CD6E-2062-44A4-B2C5-2C7E78FBAB38} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-291091202-288067208-300698780-1006\Software\Microsoft\Active Setup\Installed Components\{Y479C6D0-OTRW-U5GH-S1EE-E0AC10B4E666} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-291091202-288067208-300698780-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-291091202-288067208-300698780-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929CD6E-2062-44A4-B2C5-2C7E78FBAB38} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-291091202-288067208-300698780-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} -> Adware.Generic : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Public Messenger ver 2.03 -> Adware.IntCodec : Cleaned with backup (quarantined).
C:\Program Files\PestCapture -> Adware.PestCapture : Cleaned with backup (quarantined).
C:\Program Files\PestCapture\PestCapture.lic -> Adware.PestCapture : Cleaned with backup (quarantined).
C:\Program Files\PestCapture\Uninstall.exe -> Adware.PestCapture : Cleaned with backup (quarantined).
C:\Program Files\Αdobe\wυauboot.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Outerinfo\OiUninstaller.exe.vir -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP52\A0024287.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\vix.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareSheriff_is1 -> Adware.SpywareSheriff : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\BrowserSearch -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\BrowserSearch\BrowserSearch.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\BrowserSearch\BrowserSearch.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Configurator -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Configurator\ConfiguratorOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Configurator\ConfiguratorOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ErrorSearch -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Games -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Games\GamesOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Games\GamesOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Layouts -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Layouts\PreferencesLayout.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Layouts\PreferencesLayout.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Layouts\ToolbarLayout.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Layouts\ToolbarLayout.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Manager -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Manager\ManagerOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Manager\ManagerOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Movies -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Movies\MoviesOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Movies\MoviesOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\PopupBlocker -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\PopupBlocker\PopupBlockerOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\PopupBlocker\PopupBlockerOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Reference -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Reference\ReferenceOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Reference\ReferenceOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\RelatedSearch -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\RelatedSearch\RelatedSearchOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\RelatedSearch\RelatedSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ScreenSavers -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ScreenSavers\ScreenSaversOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ScreenSavers\ScreenSaversOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ScreensaversMarketingSitePager -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\SearchAssistPlus -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\SearchAssistPlus\SearchAssistPlusOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\SearchAssistPlus\SearchAssistPlusOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\SearchMatch -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\SearchMatch\SearchMatchOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\SearchMatch\SearchMatchOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\SmileyTown -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\SmileyTown\SmileyTownOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\SmileyTown\SmileyTownOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Toolbar -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ToolbarLogo -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ToolbarSearch -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Toolbar\TBProductsOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Toolbar\TBProductsOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\TravelSearch -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\TravelSearch\TravelSearchOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\TravelSearch\TravelSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Weather -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Weather\WeatherOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Weather\WeatherOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
HKU\S-1-5-21-291091202-288067208-300698780-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA356D79-679B-4B4C-8E49-5AF97014F4C1} -> Adware.Starware : Cleaned with backup (quarantined).
HKU\S-1-5-21-291091202-288067208-300698780-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D49E9D35-254C-4C6A-9D17-95018D228FF5} -> Adware.Starware : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024020.exe -> Adware.WebBuying : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024027.exe -> Adware.WebBuying : Cleaned with backup (quarantined).
C:\WINDOWS\b129.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\WINDOWS\system32\p432.dll -> Backdoor.Agent.akj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024007.exe -> Backdoor.PoeBot.o : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024017.exe -> Backdoor.PoeBot.o : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024006.exe -> Backdoor.SdBot.aad : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024014.exe -> Backdoor.SdBot.aad : Cleaned with backup (quarantined).
C:\QooBox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1\cmd.exe -> Downloader.Age : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP52\A0024294.exe -> Downloader.Age : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0011457.exe -> Downloader.Agent.bdr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP25\A0013146.exe -> Downloader.Agent.bdr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP38\A0017364.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024008.dll -> Downloader.Small.cyn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024028.dll -> Downloader.Small.cyn : Cleaned with backup (quarantined).
C:\Program Files\Common Files\oozi\oozid\vocabulary -> Downloader.TSUpdate.j : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP38\A0017355.exe -> Downloader.TSUpdate.o : Cleaned with backup (quarantined).
C:\WINDOWS\system32\cdromdrv32.dll -> Downloader.VB.apq : Cleaned with backup (quarantined).
C:\Documents and Settings\Bubba\Desktop\WinRAR Unplugged\Launch WinRAR.exe -> Heuristic.Win32.AVKiller : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\msvcrl.dll.vir -> Logger.Goldun.ox : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP52\A0024297.dll -> Logger.Goldun.ox : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP16\A0011507.exe -> Not-A-Virus.HackTool.Win32.Delf.bw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18\A0011900.exe -> Not-A-Virus.HackTool.Win32.Delf.bw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP52\A0024353.exe -> Not-A-Virus.HackTool.Win32.Delf.bw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP52\A0024358.exe -> Not-A-Virus.HackTool.Win32.Delf.bw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP52\A0024377.exe -> Not-A-Virus.HackTool.Win32.Delf.bw : Cleaned with backup (quarantined).
C:\WINDOWS\system32\eohugi.exe -> Proxy.Agent.mf : Cleaned with backup (quarantined).
C:\WINDOWS\system32\kogbz.exe -> Proxy.Agent.mf : Cleaned with backup (quarantined).
C:\WINDOWS\system32\tispbvhz.exe -> Proxy.Agent.mf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024217.exe -> Trojan.LdPinch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP52\A0024341.exe -> Trojan.LdPinch : Cleaned with backup (quarantined).
C:\Documents and Settings\Bubba\Desktop\HellBot_V4.3B\HellBot V4.3B\HellBot V4.3B\HFinal.DLL -> Trojan.Small : Cleaned with backup (quarantined).
C:\Documents and Settings\Bubba\Desktop\Zombies_hack\XxX.dll -> Trojan.Small : Cleaned with backup (quarantined).
C:\Documents and Settings\Bubba\Desktop\[-RxP-] Clan Hack\[-RxP-] Clan Hack\[-RxP-].DLL -> Trojan.Small : Cleaned with backup (quarantined).
C:\Documents and Settings\Bubba\Desktop\new_h4l_hack\new h4l hack\Scratch Hack v1.0-a.dll -> Trojan.Small : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\wintsvit.exe.vir -> Trojan.Small : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\uninstall_nmon.vbs.vir -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18\A0011896.DLL -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP38\A0017362.vbs -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP52\A0024285.vbs -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP52\A0024291.exe -> Trojan.Small : Cleaned with backup (quarantined).
::Report end
Hijack Log:
Logfile of HijackThis v1.99.1
Scan saved at 8:06:53 PM, on 5/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\SiteAdvisor\6028\SAService.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\SiteAdvisor\6028\SiteAdv.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.optonline.net/Home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {1E93AC48-1C87-4C55-F64F-1AE34B90F9CE} - C:\WINDOWS\system32\vix.dll (file missing)
O2 - BHO: (no name) - {30000273-8230-4dd4-be4f-6889d1e74167} - (no file)
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: (no name) - {7F5A2699-38CD-4B98-B193-5916D6566B01} - (no file)
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {90051074-A0DF-49B4-94E8-E6A212240E89} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {c9e3f918-b62d-4859-8335-6c31f9576fc0} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {D38439EC-4A7F-42b4-90C2-D810D7778FDD} - (no file)
O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AntiVirusUpdateExe] C:\WINDOWS\gsvpm.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunServices: [E30A8607] C:\WINDOWS\system32\rsbmsc.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [freestyle] lockx.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = C:\Program Files\Dell Wireless\PRISMCFG.exe
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…arch.jhtml?p=ZS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Bubba\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.howstuffworks.com
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://amiuptodate.mcafee.com/vsc/bin/2,0,…pdatePortal.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1150937271991
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1151184111625
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…008/mcfscan.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: lfpdsg - lfpdsg.dll (file missing)
O20 - Winlogon Notify: p4reg - p432.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: carbinyl - {8d8c2387-7f80-4022-9be6-43630a969558} - (no file)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6028\SAService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Windows Genuine Advantage Validation (wgav) - Unknown owner - C:\WINDOWS\system32\wgav.exe (file missing)
Fingers crossed
Back at it……
AVG Spyware results:
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————
+ Created at: 7:47:34 PM 5/5/2007
+ Scan result:
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024024.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024025.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024026.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} -> Adware.Generic : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Antispyware Soldier_is1 -> Adware.Generic : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929CD6E-2062-44A4-B2C5-2C7E78FBAB38} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929CD6E-2062-44A4-B2C5-2C7E78FBAB38} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-291091202-288067208-300698780-1006\Software\Microsoft\Active Setup\Installed Components\{Y479C6D0-OTRW-U5GH-S1EE-E0AC10B4E666} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-291091202-288067208-300698780-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-291091202-288067208-300698780-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929CD6E-2062-44A4-B2C5-2C7E78FBAB38} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-291091202-288067208-300698780-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} -> Adware.Generic : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Public Messenger ver 2.03 -> Adware.IntCodec : Cleaned with backup (quarantined).
C:\Program Files\PestCapture -> Adware.PestCapture : Cleaned with backup (quarantined).
C:\Program Files\PestCapture\PestCapture.lic -> Adware.PestCapture : Cleaned with backup (quarantined).
C:\Program Files\PestCapture\Uninstall.exe -> Adware.PestCapture : Cleaned with backup (quarantined).
C:\Program Files\Αdobe\wυauboot.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Outerinfo\OiUninstaller.exe.vir -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP52\A0024287.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\vix.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareSheriff_is1 -> Adware.SpywareSheriff : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\BrowserSearch -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\BrowserSearch\BrowserSearch.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\BrowserSearch\BrowserSearch.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Configurator -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Configurator\ConfiguratorOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Configurator\ConfiguratorOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ErrorSearch -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Games -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Games\GamesOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Games\GamesOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Layouts -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Layouts\PreferencesLayout.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Layouts\PreferencesLayout.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Layouts\ToolbarLayout.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Layouts\ToolbarLayout.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Manager -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Manager\ManagerOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Manager\ManagerOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Movies -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Movies\MoviesOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Movies\MoviesOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\PopupBlocker -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\PopupBlocker\PopupBlockerOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\PopupBlocker\PopupBlockerOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Reference -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Reference\ReferenceOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Reference\ReferenceOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\RelatedSearch -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\RelatedSearch\RelatedSearchOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\RelatedSearch\RelatedSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ScreenSavers -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ScreenSavers\ScreenSaversOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ScreenSavers\ScreenSaversOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ScreensaversMarketingSitePager -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\SearchAssistPlus -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\SearchAssistPlus\SearchAssistPlusOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\SearchAssistPlus\SearchAssistPlusOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\SearchMatch -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\SearchMatch\SearchMatchOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\SearchMatch\SearchMatchOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\SmileyTown -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\SmileyTown\SmileyTownOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\SmileyTown\SmileyTownOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Toolbar -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ToolbarLogo -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ToolbarSearch -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Toolbar\TBProductsOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Toolbar\TBProductsOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\TravelSearch -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\TravelSearch\TravelSearchOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\TravelSearch\TravelSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Weather -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Weather\WeatherOptions.xml -> Adware.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Application Data\Starware\Weather\WeatherOptions.xml.backup -> Adware.Starware : Cleaned with backup (quarantined).
HKU\S-1-5-21-291091202-288067208-300698780-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA356D79-679B-4B4C-8E49-5AF97014F4C1} -> Adware.Starware : Cleaned with backup (quarantined).
HKU\S-1-5-21-291091202-288067208-300698780-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D49E9D35-254C-4C6A-9D17-95018D228FF5} -> Adware.Starware : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024020.exe -> Adware.WebBuying : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024027.exe -> Adware.WebBuying : Cleaned with backup (quarantined).
C:\WINDOWS\b129.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\WINDOWS\system32\p432.dll -> Backdoor.Agent.akj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024007.exe -> Backdoor.PoeBot.o : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024017.exe -> Backdoor.PoeBot.o : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024006.exe -> Backdoor.SdBot.aad : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024014.exe -> Backdoor.SdBot.aad : Cleaned with backup (quarantined).
C:\QooBox\purity\C\DOCUME~1\Bubba\APPLIC~1\MANTEC~1\cmd.exe -> Downloader.Age : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP52\A0024294.exe -> Downloader.Age : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP15\A0011457.exe -> Downloader.Agent.bdr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP25\A0013146.exe -> Downloader.Agent.bdr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP38\A0017364.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024008.dll -> Downloader.Small.cyn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024028.dll -> Downloader.Small.cyn : Cleaned with backup (quarantined).
C:\Program Files\Common Files\oozi\oozid\vocabulary -> Downloader.TSUpdate.j : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP38\A0017355.exe -> Downloader.TSUpdate.o : Cleaned with backup (quarantined).
C:\WINDOWS\system32\cdromdrv32.dll -> Downloader.VB.apq : Cleaned with backup (quarantined).
C:\Documents and Settings\Bubba\Desktop\WinRAR Unplugged\Launch WinRAR.exe -> Heuristic.Win32.AVKiller : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\msvcrl.dll.vir -> Logger.Goldun.ox : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP52\A0024297.dll -> Logger.Goldun.ox : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP16\A0011507.exe -> Not-A-Virus.HackTool.Win32.Delf.bw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18\A0011900.exe -> Not-A-Virus.HackTool.Win32.Delf.bw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP52\A0024353.exe -> Not-A-Virus.HackTool.Win32.Delf.bw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP52\A0024358.exe -> Not-A-Virus.HackTool.Win32.Delf.bw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP52\A0024377.exe -> Not-A-Virus.HackTool.Win32.Delf.bw : Cleaned with backup (quarantined).
C:\WINDOWS\system32\eohugi.exe -> Proxy.Agent.mf : Cleaned with backup (quarantined).
C:\WINDOWS\system32\kogbz.exe -> Proxy.Agent.mf : Cleaned with backup (quarantined).
C:\WINDOWS\system32\tispbvhz.exe -> Proxy.Agent.mf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP51\A0024217.exe -> Trojan.LdPinch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP52\A0024341.exe -> Trojan.LdPinch : Cleaned with backup (quarantined).
C:\Documents and Settings\Bubba\Desktop\HellBot_V4.3B\HellBot V4.3B\HellBot V4.3B\HFinal.DLL -> Trojan.Small : Cleaned with backup (quarantined).
C:\Documents and Settings\Bubba\Desktop\Zombies_hack\XxX.dll -> Trojan.Small : Cleaned with backup (quarantined).
C:\Documents and Settings\Bubba\Desktop\[-RxP-] Clan Hack\[-RxP-] Clan Hack\[-RxP-].DLL -> Trojan.Small : Cleaned with backup (quarantined).
C:\Documents and Settings\Bubba\Desktop\new_h4l_hack\new h4l hack\Scratch Hack v1.0-a.dll -> Trojan.Small : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\wintsvit.exe.vir -> Trojan.Small : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\uninstall_nmon.vbs.vir -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP18\A0011896.DLL -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP38\A0017362.vbs -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP52\A0024285.vbs -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP52\A0024291.exe -> Trojan.Small : Cleaned with backup (quarantined).
::Report end
Hijack Log:
Logfile of HijackThis v1.99.1
Scan saved at 8:06:53 PM, on 5/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\SiteAdvisor\6028\SAService.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\SiteAdvisor\6028\SiteAdv.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.optonline.net/Home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {1E93AC48-1C87-4C55-F64F-1AE34B90F9CE} - C:\WINDOWS\system32\vix.dll (file missing)
O2 - BHO: (no name) - {30000273-8230-4dd4-be4f-6889d1e74167} - (no file)
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: (no name) - {7F5A2699-38CD-4B98-B193-5916D6566B01} - (no file)
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {90051074-A0DF-49B4-94E8-E6A212240E89} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {c9e3f918-b62d-4859-8335-6c31f9576fc0} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {D38439EC-4A7F-42b4-90C2-D810D7778FDD} - (no file)
O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AntiVirusUpdateExe] C:\WINDOWS\gsvpm.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunServices: [E30A8607] C:\WINDOWS\system32\rsbmsc.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [freestyle] lockx.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = C:\Program Files\Dell Wireless\PRISMCFG.exe
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…arch.jhtml?p=ZS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Bubba\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.howstuffworks.com
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://amiuptodate.mcafee.com/vsc/bin/2,0,…pdatePortal.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1150937271991
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1151184111625
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…008/mcfscan.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: lfpdsg - lfpdsg.dll (file missing)
O20 - Winlogon Notify: p4reg - p432.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: carbinyl - {8d8c2387-7f80-4022-9be6-43630a969558} - (no file)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6028\SAService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Windows Genuine Advantage Validation (wgav) - Unknown owner - C:\WINDOWS\system32\wgav.exe (file missing)
Fingers crossed
LDTate
I suggest you do this:
Please go to http://virusscan.jotti.org , click on Browse, and upload the following file for analysis:
C:\WINDOWS\gsvpm.exe
Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If Jotti is too busy you can try these.
http://www.kaspersky.com/scanforvirus.html
http://www.virustotal.com/en/indexf.html
With AVG Anti-Spyware, if you click on the Infections icon, then it will show you all the items in Quarrantine and you can remove them that way. Just click Select All then Remove Finally
Please do not delete anything unless instructed to.
1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:
Viewpoint
Viewpoint Manager
Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {1E93AC48-1C87-4C55-F64F-1AE34B90F9CE} - C:\WINDOWS\system32\vix.dll (file missing)
O2 - BHO: (no name) - {30000273-8230-4dd4-be4f-6889d1e74167} - (no file)
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {7F5A2699-38CD-4B98-B193-5916D6566B01} - (no file)
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {90051074-A0DF-49B4-94E8-E6A212240E89} - (no file)
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {c9e3f918-b62d-4859-8335-6c31f9576fc0} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {D38439EC-4A7F-42b4-90C2-D810D7778FDD} - (no file)
O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - (no file)
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: PowerReg Scheduler.exe
O15 - Trusted Zone: http://www.howstuffworks.com
O20 - Winlogon Notify: lfpdsg - lfpdsg.dll (file missing)
O20 - Winlogon Notify: p4reg - p432.dll (file missing)
O21 - SSODL: carbinyl - {8d8c2387-7f80-4022-9be6-43630a969558} - (no file)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Close ALL windows and browsers except HijackThis and click "Fix checked"
Empty Recycle Bin
Reboot and "copy/paste" a new HijackThis log file into this thread.
Also please describe how your computer behaves at the moment.
Please go to http://virusscan.jotti.org , click on Browse, and upload the following file for analysis:
C:\WINDOWS\gsvpm.exe
Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If Jotti is too busy you can try these.
http://www.kaspersky.com/scanforvirus.html
http://www.virustotal.com/en/indexf.html
With AVG Anti-Spyware, if you click on the Infections icon, then it will show you all the items in Quarrantine and you can remove them that way. Just click Select All then Remove Finally
Please do not delete anything unless instructed to.
1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:
Viewpoint
Viewpoint Manager
Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {1E93AC48-1C87-4C55-F64F-1AE34B90F9CE} - C:\WINDOWS\system32\vix.dll (file missing)
O2 - BHO: (no name) - {30000273-8230-4dd4-be4f-6889d1e74167} - (no file)
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {7F5A2699-38CD-4B98-B193-5916D6566B01} - (no file)
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {90051074-A0DF-49B4-94E8-E6A212240E89} - (no file)
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {c9e3f918-b62d-4859-8335-6c31f9576fc0} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {D38439EC-4A7F-42b4-90C2-D810D7778FDD} - (no file)
O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - (no file)
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: PowerReg Scheduler.exe
O15 - Trusted Zone: http://www.howstuffworks.com
O20 - Winlogon Notify: lfpdsg - lfpdsg.dll (file missing)
O20 - Winlogon Notify: p4reg - p432.dll (file missing)
O21 - SSODL: carbinyl - {8d8c2387-7f80-4022-9be6-43630a969558} - (no file)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Close ALL windows and browsers except HijackThis and click "Fix checked"
Empty Recycle Bin
Reboot and "copy/paste" a new HijackThis log file into this thread.
Also please describe how your computer behaves at the moment.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI