Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I've got the Google Re-direct Virus & DCOM Server Shutdown Virus


  • This topic is locked This topic is locked
31 replies to this topic

#1 toolman605

toolman605

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:09:53 AM

Posted 21 January 2010 - 06:56 PM

Hi,

I've been living with the Google re-direct virus for about 2 weeks now and just yesterday I got the DCOm server process shutdown virus. I've been able to stop the rebooting and keep the computer running using the shutdown -a trick but enough is enough!
Help!

Thanks!
Dave

Here is my DSS and Kaspersky scans....

DDS (Ver_09-12-01.01) - NTFSx86
Run by David XXXX at 18:11:59.96 on Thu 01/21/2010
Internet Explorer: 7.0.5730.11
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============


============== Pseudo HJT Report ===============

uStart Page = hxxp://www6.comcast.net/a/
uSearch Page = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
uDefault_Page_URL = hxxp://smbusiness.dellnet.com/
uSearch Bar = hxxp://www.comcast.net/toolbar2.0/search/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/bin/search?p={searchTerms}
mDefault_Page_URL = hxxp://www.yahoo.com
mDefault_Search_URL = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
mSearch Page =
mStart Page = hxxp://www.yahoo.com
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
uInternet Settings,ProxyServer = actsvr.comcastonline.com:8100
uInternet Settings,ProxyOverride = actsvr.comcastonline.com;*.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
mSearchAssistant = hxxp://www.comcast.net/toolbar2.0/search/
BHO: AutorunsDisabled - No File
BHO: {089fd14d-132b-48fc-8861-0048ae113215} - c:\program files\siteadvisor\6261\SiteAdv.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common

files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Comcast Toolbar: {4e7bd74f-2b8d-469e-93be-be2df4d9ae29} - c:\progra~1\comcas~1\COMCAS~1.DLL
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
TB: McAfee SiteAdvisor: {0bf43445-2f28-4351-9252-17fe6e806aa0} - c:\program files\siteadvisor\6261\SiteAdv.dll
TB: Comcast Toolbar: {4e7bd74f-2b8d-469e-93be-be2df4d9ae29} - c:\progra~1\comcas~1\COMCAS~1.DLL
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
EB: {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [EasyLinkAdvisor] "c:\program files\linksys easylink advisor\LinksysAgent.exe" /startup
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [HostManager] c:\program files\common files\aol\1129368448\ee\AOLSoftware.exe
mRun: [SiteAdvisor] c:\program files\siteadvisor\6253\SiteAdv.exe
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\progra~1.lnk - c:\program files\citrix\ica client\pnagent.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program

files\java\jre1.6.0_07\bin\ssv.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.6.4/GarminAxControl.CAB
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700}
DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A}
DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68}
DPF: {41F17733-B041-4099-A042-B518BB6A408C} -

hxxp://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe
DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - hxxp://207.188.7.150/1006b278b6b044d74923/netzip/RdxIE601.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -

hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389}
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - c:\program files\siteadvisor\6261\SiteAdv.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - No File
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll

============= SERVICES / DRIVERS ===============


=============== Created Last 30 ================

2010-01-21 04:06:28 0 d-----w- c:\docume~1\davidt~1\applic~1\AVG8
2010-01-12 23:55:43 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
2010-01-03 14:35:12 0 d-----w- c:\windows\pss
2009-12-28 13:27:32 578560 ----a-w- c:\windows\system32\dllcache\user32.dll
2009-12-28 13:12:17 0 d-----w- c:\windows\ERUNT
2009-12-28 12:56:07 0 d-----w- C:\SDFix

==================== Find3M ====================

2010-01-14 16:12:06 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-07 21:07:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-01 13:52:48 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2010-01-01 13:52:48 96512 ----a-w- c:\windows\system32\dllcache\atapi.sys
2009-12-14 19:15:14 2146304 ----a-w- c:\windows\system32\GPhotos.scr
2009-11-22 14:22:16 77080 ---ha-w- c:\windows\system32\mlfcache.dat
2009-11-13 22:57:16 922112 ------w- c:\windows\system32\imapi2fs.dll
2009-11-13 22:57:16 922112 ------w- c:\windows\system32\dllcache\imapi2fs.dll
2009-11-13 22:57:16 62592 ------w- c:\windows\system32\dllcache\cdrom.sys
2009-11-13 22:57:16 426496 ------w- c:\windows\system32\imapi2.dll
2009-11-13 22:57:16 426496 ------w- c:\windows\system32\dllcache\imapi2.dll
2009-10-28 14:36:11 70656 ------w- c:\windows\system32\dllcache\ie4uinit.exe
2009-10-28 14:36:11 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
2009-10-28 06:54:16 634632 ------w- c:\windows\system32\dllcache\iexplore.exe
2009-10-28 06:52:46 161792 ------w- c:\windows\system32\dllcache\ieakui.dll
2008-08-11 19:43:29 80 --sh--r- c:\windows\system32\07DDA0E9A7.dll

============= FINISH: 18:15:01.06 ===============


--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Thursday, January 21, 2010
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Thursday, January 21, 2010 04:49:32
Records in database: 3352190
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
G:\

Scan statistics:
Objects scanned: 139274
Threats found: 2
Infected objects found: 2
Suspicious objects found: 0
Scan duration: 03:39:43


File name / Infected: / Infected:
C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\ASP12F.tmp\aspapp\setup.exe Infected: Trojan.Win32.Agent.dfsm 1
C:\Documents and Settings\Susan XXXX\Application Data\Sun\Java\Deployment\cache\6.0\38\16f48da6-789178a0-DGT1225 Infected: Trojan-Downloader.Java.Agent.ab 1

Selected area has been scanned.

Attached Files



BC AdBot (Login to Remove)

 


#2 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:53 AM

Posted 27 January 2010 - 06:34 PM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.


Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Also, please subscribe to this topic, so you are notified when someone replies. Please continue to check manually on occasion, as every now and then the email may be caught by your spam filter.
To enable topic notifications you should do the following:
  1. Click on the My Controls link at the top of the page to enter your control panel.
  2. Scroll down to the Options category in the left hand side menu bar and click on the Email Settings link.
  3. Put a checkmark in the checkbox labeled Enable 'Email Notification' by default?.
  4. Set the If ticked, choose default type: menu option to Immediate Email Notification to have an email sent immediately when someone replied.

Information on A/V control HERE


If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 


#3 toolman605

toolman605
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:09:53 AM

Posted 28 January 2010 - 06:59 PM

Hi,

1st - thanks for the help! Nothing new to update - still having redirect problem and the NT shutdown/Dcom problem. 1 new thing though I forgot abot. I tried to connect my Ipod and now Itunes wouldn't load.

Here is the latest DDS log;


DDS (Ver_09-12-01.01) - NTFSx86
Run by David XXXXX at 18:47:57.84 on Thu 01/28/2010
Internet Explorer: 7.0.5730.11
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============


============== Pseudo HJT Report ===============

uStart Page = hxxp://www6.comcast.net/a/
uSearch Page = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
uDefault_Page_URL = hxxp://smbusiness.dellnet.com/
uSearch Bar = hxxp://www.comcast.net/toolbar2.0/search/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/bin/search?p={searchTerms}
mDefault_Page_URL = hxxp://www.yahoo.com
mDefault_Search_URL = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
mSearch Page =
mStart Page = hxxp://www.yahoo.com
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
uInternet Settings,ProxyServer = actsvr.comcastonline.com:8100
uInternet Settings,ProxyOverride = actsvr.comcastonline.com;*.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
mSearchAssistant = hxxp://www.comcast.net/toolbar2.0/search/
BHO: AutorunsDisabled - No File
BHO: {089fd14d-132b-48fc-8861-0048ae113215} - c:\program files\siteadvisor\6261\SiteAdv.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common

files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Comcast Toolbar: {4e7bd74f-2b8d-469e-93be-be2df4d9ae29} - c:\progra~1\comcas~1\COMCAS~1.DLL
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
TB: McAfee SiteAdvisor: {0bf43445-2f28-4351-9252-17fe6e806aa0} - c:\program files\siteadvisor\6261\SiteAdv.dll
TB: Comcast Toolbar: {4e7bd74f-2b8d-469e-93be-be2df4d9ae29} - c:\progra~1\comcas~1\COMCAS~1.DLL
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
EB: {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [EasyLinkAdvisor] "c:\program files\linksys easylink advisor\LinksysAgent.exe" /startup
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [HostManager] c:\program files\common files\aol\1129368448\ee\AOLSoftware.exe
mRun: [SiteAdvisor] c:\program files\siteadvisor\6253\SiteAdv.exe
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\progra~1.lnk - c:\program files\citrix\ica client\pnagent.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program

files\java\jre1.6.0_07\bin\ssv.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.6.4/GarminAxControl.CAB
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700}
DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A}
DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68}
DPF: {41F17733-B041-4099-A042-B518BB6A408C} -

hxxp://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe
DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - hxxp://207.188.7.150/1006b278b6b044d74923/netzip/RdxIE601.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -

hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389}
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - c:\program files\siteadvisor\6261\SiteAdv.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - No File
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll

============= SERVICES / DRIVERS ===============


=============== Created Last 30 ================

2010-01-27 01:21:57 8832 ----a-w- c:\windows\system32\dllcache\wmiacpi.sys
2010-01-27 01:20:58 525568 ----a-w- c:\windows\system32\dllcache\tridxp.dll
2010-01-27 01:19:59 30208 ----a-w- c:\windows\system32\dllcache\sm87w.dll
2010-01-27 01:18:59 899146 ----a-w- c:\windows\system32\dllcache\r2mdkxga.sys
2010-01-27 01:17:59 28672 ----a-w- c:\windows\system32\dllcache\nscirda.sys
2010-01-27 01:16:57 16128 ----a-w- c:\windows\system32\dllcache\modemcsa.sys
2010-01-27 01:15:59 6144 ----a-w- c:\windows\system32\dllcache\kbd101a.dll
2010-01-27 01:14:59 57471 ----a-w- c:\windows\system32\dllcache\hsf_samp.sys
2010-01-27 01:13:59 442240 ----a-w- c:\windows\system32\dllcache\fpnpbase.sys
2010-01-27 01:12:57 28062 ----a-w- c:\windows\system32\dllcache\dp83820.sys
2010-01-27 01:11:59 93952 ----a-w- c:\windows\system32\dllcache\cwcwdm.sys
2010-01-27 01:10:59 121856 ----a-w- c:\windows\system32\dllcache\camext30.dll
2010-01-27 01:09:59 2944 ----a-w- c:\windows\system32\dllcache\brfilt.sys
2010-01-27 01:08:45 24576 ----a-w- c:\windows\system32\dllcache\agcgauge.ax
2010-01-27 01:07:59 66048 ----a-w- c:\windows\system32\dllcache\s3legacy.dll
2010-01-27 01:07:42 19968 ----a-w- c:\windows\system32\dllcache\inetsloc.dll
2010-01-27 01:07:41 7680 ----a-w- c:\windows\system32\dllcache\inetmgr.exe
2010-01-27 01:07:40 169984 ----a-w- c:\windows\system32\dllcache\iisui.dll
2010-01-27 01:07:39 5632 ----a-w- c:\windows\system32\dllcache\iisrstap.dll
2010-01-27 01:07:39 14336 ----a-w- c:\windows\system32\dllcache\iisreset.exe
2010-01-27 01:07:37 6144 ----a-w- c:\windows\system32\dllcache\ftpsapi2.dll
2010-01-27 01:07:27 94720 ----a-w- c:\windows\system32\dllcache\certmap.ocx
2010-01-24 15:01:05 0 d-----w- c:\program files\ESET
2010-01-21 23:17:33 0 ----a-w- c:\documents and settings\david tobbe\settings.dat
2010-01-21 04:06:28 0 d-----w- c:\docume~1\davidt~1\applic~1\AVG8
2010-01-03 14:35:12 0 d-----w- c:\windows\pss

==================== Find3M ====================

2010-01-14 16:12:06 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-07 21:07:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-01 13:52:48 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2010-01-01 13:52:48 96512 ----a-w- c:\windows\system32\dllcache\atapi.sys
2009-12-31 15:33:06 70656 ----a-w- c:\windows\system32\dllcache\ie4uinit.exe
2009-12-31 15:33:06 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
2009-12-18 13:05:43 634648 ----a-w- c:\windows\system32\dllcache\iexplore.exe
2009-12-18 13:04:09 161792 ----a-w- c:\windows\system32\dllcache\ieakui.dll
2009-12-14 19:15:14 2146304 ----a-w- c:\windows\system32\GPhotos.scr
2009-11-22 14:22:16 77080 ---ha-w- c:\windows\system32\mlfcache.dat
2009-11-21 15:51:04 471552 ----a-w- c:\windows\system32\dllcache\aclayers.dll
2009-11-13 22:57:16 922112 ------w- c:\windows\system32\imapi2fs.dll
2009-11-13 22:57:16 922112 ------w- c:\windows\system32\dllcache\imapi2fs.dll
2009-11-13 22:57:16 426496 ------w- c:\windows\system32\imapi2.dll
2009-11-13 22:57:16 426496 ------w- c:\windows\system32\dllcache\imapi2.dll
2008-08-11 19:43:29 80 --sh--r- c:\windows\system32\07DDA0E9A7.dll

============= FINISH: 18:51:06.98 ===============


#4 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:53 AM

Posted 28 January 2010 - 07:05 PM

Hi toolman605,

The services/drivers and running process sections are blank. Did you delete the information there intentionally or was it blank? Those are very critical sections to diagnose and fix malware.


If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 


#5 toolman605

toolman605
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:09:53 AM

Posted 28 January 2010 - 07:25 PM

No I copied and pasted right from Notepad.

Want me to try and run it again? I didn't turn off Antivirus or Spybot - does that matter?

#6 toolman605

toolman605
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:09:53 AM

Posted 28 January 2010 - 08:32 PM

I turned off McAfee antivirus and Spybot and here is a better log file with the running processes and services/drivers sections....


DDS (Ver_09-12-01.01) - NTFSx86
Run by David XXXX at 20:07:01.34 on Thu 01/28/2010
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.121 [GMT -5:00]

AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\Citrix\ICA Client\pnagent.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Common Files\ICWM\Printer\RDIConverterService.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\David Tobbe\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www6.comcast.net/a/
uSearch Page = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
uDefault_Page_URL = hxxp://smbusiness.dellnet.com/
uSearch Bar = hxxp://www.comcast.net/toolbar2.0/search/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/bin/search?p={searchTerms}
mDefault_Page_URL = hxxp://www.yahoo.com
mDefault_Search_URL = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
mSearch Page =
mStart Page = hxxp://www.yahoo.com
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
uInternet Settings,ProxyServer = actsvr.comcastonline.com:8100
uInternet Settings,ProxyOverride = actsvr.comcastonline.com;*.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
mSearchAssistant = hxxp://www.comcast.net/toolbar2.0/search/
BHO: AutorunsDisabled - No File
BHO: {089fd14d-132b-48fc-8861-0048ae113215} - c:\program files\siteadvisor\6261\SiteAdv.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Comcast Toolbar: {4e7bd74f-2b8d-469e-93be-be2df4d9ae29} - c:\progra~1\comcas~1\COMCAS~1.DLL
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
TB: McAfee SiteAdvisor: {0bf43445-2f28-4351-9252-17fe6e806aa0} - c:\program files\siteadvisor\6261\SiteAdv.dll
TB: Comcast Toolbar: {4e7bd74f-2b8d-469e-93be-be2df4d9ae29} - c:\progra~1\comcas~1\COMCAS~1.DLL
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
EB: {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [EasyLinkAdvisor] "c:\program files\linksys easylink advisor\LinksysAgent.exe" /startup
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [HostManager] c:\program files\common files\aol\1129368448\ee\AOLSoftware.exe
mRun: [SiteAdvisor] c:\program files\siteadvisor\6253\SiteAdv.exe
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\progra~1.lnk - c:\program files\citrix\ica client\pnagent.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.6.4/GarminAxControl.CAB
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700}
DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A}
DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68}
DPF: {41F17733-B041-4099-A042-B518BB6A408C} - hxxp://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe
DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - hxxp://207.188.7.150/1006b278b6b044d74923/netzip/RdxIE601.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389}
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - c:\program files\siteadvisor\6261\SiteAdv.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - No File
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll

============= SERVICES / DRIVERS ===============

R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2006-7-30 214664]
R2 ASFAgent;ASF Agent;c:\program files\intel\asf agent\ASFAgent.exe [2002-8-7 221184]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2008-5-23 359952]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2006-7-30 144704]
R2 NetAlrt;NetAlrt;c:\windows\system32\drivers\Netalrt.sys [2002-5-7 39680]
R2 PlatAlrt;PlatAlrt;c:\windows\system32\drivers\platalrt.sys [2002-5-7 23744]
R2 RDIConverterPrintHelper;RDI Document Conversion Helper;c:\program files\common files\icwm\printer\RDIConverterService.exe [2008-10-1 64888]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2006-7-30 79816]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2006-7-30 35272]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2006-7-30 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2006-7-30 40552]
S3 vsdatant;vsdatant;\??\c:\windows\system32\vsdatant.sys --> c:\windows\system32\vsdatant.sys [?]
S4 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2006-7-30 606736]

=============== Created Last 30 ================

2010-01-27 01:21:57 8832 ----a-w- c:\windows\system32\dllcache\wmiacpi.sys
2010-01-27 01:20:58 525568 ----a-w- c:\windows\system32\dllcache\tridxp.dll
2010-01-27 01:19:59 30208 ----a-w- c:\windows\system32\dllcache\sm87w.dll
2010-01-27 01:18:59 899146 ----a-w- c:\windows\system32\dllcache\r2mdkxga.sys
2010-01-27 01:17:59 28672 ----a-w- c:\windows\system32\dllcache\nscirda.sys
2010-01-27 01:16:57 16128 ----a-w- c:\windows\system32\dllcache\modemcsa.sys
2010-01-27 01:15:59 6144 ----a-w- c:\windows\system32\dllcache\kbd101a.dll
2010-01-27 01:14:59 57471 ----a-w- c:\windows\system32\dllcache\hsf_samp.sys
2010-01-27 01:13:59 442240 ----a-w- c:\windows\system32\dllcache\fpnpbase.sys
2010-01-27 01:12:57 28062 ----a-w- c:\windows\system32\dllcache\dp83820.sys
2010-01-27 01:11:59 93952 ----a-w- c:\windows\system32\dllcache\cwcwdm.sys
2010-01-27 01:10:59 121856 ----a-w- c:\windows\system32\dllcache\camext30.dll
2010-01-27 01:09:59 2944 ----a-w- c:\windows\system32\dllcache\brfilt.sys
2010-01-27 01:08:45 24576 ----a-w- c:\windows\system32\dllcache\agcgauge.ax
2010-01-27 01:07:59 66048 ----a-w- c:\windows\system32\dllcache\s3legacy.dll
2010-01-27 01:07:42 19968 ----a-w- c:\windows\system32\dllcache\inetsloc.dll
2010-01-27 01:07:41 7680 ----a-w- c:\windows\system32\dllcache\inetmgr.exe
2010-01-27 01:07:40 169984 ----a-w- c:\windows\system32\dllcache\iisui.dll
2010-01-27 01:07:39 5632 ----a-w- c:\windows\system32\dllcache\iisrstap.dll
2010-01-27 01:07:39 14336 ----a-w- c:\windows\system32\dllcache\iisreset.exe
2010-01-27 01:07:37 6144 ----a-w- c:\windows\system32\dllcache\ftpsapi2.dll
2010-01-27 01:07:27 94720 ----a-w- c:\windows\system32\dllcache\certmap.ocx
2010-01-24 15:01:05 0 d-----w- c:\program files\ESET
2010-01-21 23:17:33 0 ----a-w- c:\documents and settings\david tobbe\settings.dat
2010-01-21 04:06:28 0 d-----w- c:\docume~1\davidt~1\applic~1\AVG8
2010-01-03 14:35:12 0 d-----w- c:\windows\pss

==================== Find3M ====================

2010-01-14 16:12:06 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-07 21:07:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-01 13:52:48 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2010-01-01 13:52:48 96512 ----a-w- c:\windows\system32\dllcache\atapi.sys
2009-12-31 15:33:06 70656 ----a-w- c:\windows\system32\dllcache\ie4uinit.exe
2009-12-31 15:33:06 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
2009-12-18 13:05:43 634648 ----a-w- c:\windows\system32\dllcache\iexplore.exe
2009-12-18 13:04:09 161792 ----a-w- c:\windows\system32\dllcache\ieakui.dll
2009-12-14 19:15:14 2146304 ----a-w- c:\windows\system32\GPhotos.scr
2009-11-22 14:22:16 77080 ---ha-w- c:\windows\system32\mlfcache.dat
2009-11-21 15:51:04 471552 ----a-w- c:\windows\system32\dllcache\aclayers.dll
2009-11-13 22:57:16 922112 ------w- c:\windows\system32\imapi2fs.dll
2009-11-13 22:57:16 922112 ------w- c:\windows\system32\dllcache\imapi2fs.dll
2009-11-13 22:57:16 426496 ------w- c:\windows\system32\imapi2.dll
2009-11-13 22:57:16 426496 ------w- c:\windows\system32\dllcache\imapi2.dll
2008-08-11 19:43:29 80 --sh--r- c:\windows\system32\07DDA0E9A7.dll

============= FINISH: 20:09:34.01 ===============


#7 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:53 AM

Posted 28 January 2010 - 08:34 PM

Ok, Please give me some time to go through this. Thanks for updating.

In the meantime, here are some guidelines to ensure we are able to get your machine back under your control.
  • Please do not run any unsupervised scans, fixes, etc. We can work against each other and end up in a worse place.
  • Please subscribe to this topic if you have not already done so. Please check back just in case, as the email system can fail at times.
  • Just because your machine is running better does not mean it is completely cleaned. Please wait for the 'all clear' from me to say when we are done.
  • Please reply within 3 days to be fair to other people asking for help.
  • When in doubt, please stop and ask first. There's no harm in asking questions!

I am a senior trainee, so my fix will be checked by a staff member. This may result in an extra day before I can reply.



If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 


#8 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:53 AM

Posted 29 January 2010 - 07:01 AM

Hello, toolman605.
OK, now we need to take a slightly deeper look.

1. We need to disable Spybot S&D's "TeaTimer"
TeaTimer works by preventing ANY changes to the system. It will attempt to undo any fixes we run, because it blocks these fixes from running.

In order to safeguard your system from problems that can be brought on by a half finished fix, we need to disable TeaTimer. We can reenable it when we're done if you like.
  1. Open SpyBot Search and Destroy by going to Start -> All Programs -> Spybot Search and Destroy -> Spybot Search and Destroy.
  2. If prompted with a legal dialog, accept the warning.
  3. Click and then on "Advanced Mode"
  4. You may be presented with a warning dialog. If so, press
  5. Click on
  6. Click on
  7. Uncheck this checkbox:
  8. Close/Exit Spybot Search and Destroy



Step 1

Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.


  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.
-- If you encounter any problems, try running GMER in Safe Mode.



Step 2

for this step, you may need to change your settings to allow you to view system and hidden files. Please let me know if you need instructions.

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

How to see hidden files in Windows

Please click this link-->Jotti

When the jotti page has finished loading, click the Browse button and navigate to the following file and click Submit.

c:\windows\system32\07DDA0E9A7.dll

Please post back the results of the scan in your next post.

If Jotti is busy, try the same at Virustotal: http://www.virustotal.com/



Step 3

In your reply, please post:
  • GMER log
  • Virus scan results of that file


If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 


#9 toolman605

toolman605
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:09:53 AM

Posted 29 January 2010 - 11:47 PM

Wow! I had to run GMER twice and it took 3 hrs to scan! Here is the log file from GMER:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-29 23:28:10
Windows 5.1.2600 Service Pack 3
Running: me8u4txf.exe; Driver: C:\DOCUME~1\DAVIDT~1\LOCALS~1\Temp\pgloapow.sys


---- System - GMER 1.0.15 ----

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xED56378A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xED563738]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xED56374C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xED5637CA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xED563710]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xED563724]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xED56379E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xED563776]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xED563762]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xED5637F9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xED5637E0]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xED5637B4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess

---- Kernel code sections - GMER 1.0.15 ----

.text ntoskrnl.exe!ZwYieldExecution 804F0EA6 7 Bytes JMP ED5637B8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtCreateFile 8056F600 5 Bytes JMP ED56378E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtSetInformationProcess 80570441 5 Bytes JMP ED563766 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenProcess 805741D0 5 Bytes JMP ED563714 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwProtectVirtualMemory 8057457F 7 Bytes JMP ED5637A2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnmapViewOfSection 80578606 5 Bytes JMP ED5637E4 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtMapViewOfSection 80578A81 7 Bytes JMP ED5637CE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcessEx 80581030 7 Bytes JMP ED563750 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwTerminateProcess 805836B0 5 Bytes JMP ED5637FD \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenThread 8058B58D 5 Bytes JMP ED563728 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcess 805B136A 5 Bytes JMP ED56373C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwSetContextThread 8062DD47 5 Bytes JMP ED56377A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
.rsrc C:\WINDOWS\system32\drivers\atapi.sys entry point in ".rsrc" section [0xF84CF7A4]
init C:\WINDOWS\System32\drivers\NetAlrt.sys entry point in "init" section [0xB5D942A0]
init C:\WINDOWS\System32\drivers\PlatAlrt.sys entry point in "init" section [0xB4FCE2A0]

---- User code sections - GMER 1.0.15 ----

.text C:\WINDOWS\System32\svchost.exe[288] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 006C0FEF
.text C:\WINDOWS\System32\svchost.exe[288] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 006C0085
.text C:\WINDOWS\System32\svchost.exe[288] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 006C006A
.text C:\WINDOWS\System32\svchost.exe[288] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 006C0059
.text C:\WINDOWS\System32\svchost.exe[288] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 006C0F90
.text C:\WINDOWS\System32\svchost.exe[288] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 006C0FB2
.text C:\WINDOWS\System32\svchost.exe[288] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 006C0F5D
.text C:\WINDOWS\System32\svchost.exe[288] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 006C0F6E
.text C:\WINDOWS\System32\svchost.exe[288] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 006C0F42
.text C:\WINDOWS\System32\svchost.exe[288] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 006C00DB
.text C:\WINDOWS\System32\svchost.exe[288] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 006C0F27
.text C:\WINDOWS\System32\svchost.exe[288] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 006C0FA1
.text C:\WINDOWS\System32\svchost.exe[288] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 006C0FDE
.text C:\WINDOWS\System32\svchost.exe[288] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 006C0F7F
.text C:\WINDOWS\System32\svchost.exe[288] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 006C001E
.text C:\WINDOWS\System32\svchost.exe[288] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 006C0FCD
.text C:\WINDOWS\System32\svchost.exe[288] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 006C00C0
.text C:\WINDOWS\System32\svchost.exe[288] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00680011
.text C:\WINDOWS\System32\svchost.exe[288] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00680F5B
.text C:\WINDOWS\System32\svchost.exe[288] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00680000
.text C:\WINDOWS\System32\svchost.exe[288] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00680FD4
.text C:\WINDOWS\System32\svchost.exe[288] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00680F80
.text C:\WINDOWS\System32\svchost.exe[288] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00680FEF
.text C:\WINDOWS\System32\svchost.exe[288] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00680F91
.text C:\WINDOWS\System32\svchost.exe[288] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [88, 88]
.text C:\WINDOWS\System32\svchost.exe[288] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00680022
.text C:\WINDOWS\System32\svchost.exe[288] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0067004B
.text C:\WINDOWS\System32\svchost.exe[288] msvcrt.dll!system 77C293C7 5 Bytes JMP 0067003A
.text C:\WINDOWS\System32\svchost.exe[288] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00670FEF
.text C:\WINDOWS\System32\svchost.exe[288] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0067000C
.text C:\WINDOWS\System32\svchost.exe[288] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00670FD4
.text C:\WINDOWS\System32\svchost.exe[288] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0067001D
.text C:\WINDOWS\System32\svchost.exe[288] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 00650000
.text C:\WINDOWS\System32\svchost.exe[288] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 00650011
.text C:\WINDOWS\System32\svchost.exe[288] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 00650FDB
.text C:\WINDOWS\System32\svchost.exe[288] WININET.dll!InternetOpenUrlW 3D998439 5 Bytes JMP 0065002C
.text C:\WINDOWS\System32\svchost.exe[288] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00660FEF
.text C:\WINDOWS\system32\services.exe[816] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01380000
.text C:\WINDOWS\system32\services.exe[816] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01380F74
.text C:\WINDOWS\system32\services.exe[816] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01380F85
.text C:\WINDOWS\system32\services.exe[816] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01380069
.text C:\WINDOWS\system32\services.exe[816] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01380058
.text C:\WINDOWS\system32\services.exe[816] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0138002C
.text C:\WINDOWS\system32\services.exe[816] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01380F37
.text C:\WINDOWS\system32\services.exe[816] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01380F48
.text C:\WINDOWS\system32\services.exe[816] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01380F12
.text C:\WINDOWS\system32\services.exe[816] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 013800AB
.text C:\WINDOWS\system32\services.exe[816] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 013800C6
.text C:\WINDOWS\system32\services.exe[816] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01380047
.text C:\WINDOWS\system32\services.exe[816] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01380011
.text C:\WINDOWS\system32\services.exe[816] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01380F63
.text C:\WINDOWS\system32\services.exe[816] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01380FC0
.text C:\WINDOWS\system32\services.exe[816] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01380FDB
.text C:\WINDOWS\system32\services.exe[816] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01380090
.text C:\WINDOWS\system32\services.exe[816] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0137002F
.text C:\WINDOWS\system32\services.exe[816] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01370F9E
.text C:\WINDOWS\system32\services.exe[816] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0137000A
.text C:\WINDOWS\system32\services.exe[816] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01370FDE
.text C:\WINDOWS\system32\services.exe[816] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 0137005B
.text C:\WINDOWS\system32\services.exe[816] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01370FEF
.text C:\WINDOWS\system32\services.exe[816] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 0137004A
.text C:\WINDOWS\system32\services.exe[816] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01370FB9
.text C:\WINDOWS\system32\services.exe[816] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01360036
.text C:\WINDOWS\system32\services.exe[816] msvcrt.dll!system 77C293C7 5 Bytes JMP 01360FAB
.text C:\WINDOWS\system32\services.exe[816] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01360FC6
.text C:\WINDOWS\system32\services.exe[816] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01360000
.text C:\WINDOWS\system32\services.exe[816] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0136001B
.text C:\WINDOWS\system32\services.exe[816] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01360FD7
.text C:\WINDOWS\system32\services.exe[816] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 00FE0FE5
.text C:\WINDOWS\system32\services.exe[816] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 00FE0000
.text C:\WINDOWS\system32\services.exe[816] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 00FE001B
.text C:\WINDOWS\system32\services.exe[816] WININET.dll!InternetOpenUrlW 3D998439 5 Bytes JMP 00FE002C
.text C:\WINDOWS\system32\services.exe[816] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FF0FE5
.text C:\WINDOWS\system32\lsass.exe[828] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01020000
.text C:\WINDOWS\system32\lsass.exe[828] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 0102006F
.text C:\WINDOWS\system32\lsass.exe[828] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 0102005E
.text C:\WINDOWS\system32\lsass.exe[828] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01020F7A
.text C:\WINDOWS\system32\lsass.exe[828] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01020F97
.text C:\WINDOWS\system32\lsass.exe[828] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0102002F
.text C:\WINDOWS\system32\lsass.exe[828] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01020F5F
.text C:\WINDOWS\system32\lsass.exe[828] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 010200B1
.text C:\WINDOWS\system32\lsass.exe[828] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01020F22
.text C:\WINDOWS\system32\lsass.exe[828] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01020F33
.text C:\WINDOWS\system32\lsass.exe[828] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 010200D6
.text C:\WINDOWS\system32\lsass.exe[828] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01020FA8
.text C:\WINDOWS\system32\lsass.exe[828] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01020FE5
.text C:\WINDOWS\system32\lsass.exe[828] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01020094
.text C:\WINDOWS\system32\lsass.exe[828] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01020FC3
.text C:\WINDOWS\system32\lsass.exe[828] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01020FD4
.text C:\WINDOWS\system32\lsass.exe[828] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01020F4E
.text C:\WINDOWS\system32\lsass.exe[828] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00CE0FA8
.text C:\WINDOWS\system32\lsass.exe[828] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00CE0F83
.text C:\WINDOWS\system32\lsass.exe[828] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00CE0FC3
.text C:\WINDOWS\system32\lsass.exe[828] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00CE0FD4
.text C:\WINDOWS\system32\lsass.exe[828] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00CE0040
.text C:\WINDOWS\system32\lsass.exe[828] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00CE0FE5
.text C:\WINDOWS\system32\lsass.exe[828] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00CE002F
.text C:\WINDOWS\system32\lsass.exe[828] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00CE0014
.text C:\WINDOWS\system32\lsass.exe[828] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00CD0049
.text C:\WINDOWS\system32\lsass.exe[828] msvcrt.dll!system 77C293C7 5 Bytes JMP 00CD0FBE
.text C:\WINDOWS\system32\lsass.exe[828] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00CD0FE3
.text C:\WINDOWS\system32\lsass.exe[828] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00CD0000
.text C:\WINDOWS\system32\lsass.exe[828] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00CD002E
.text C:\WINDOWS\system32\lsass.exe[828] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00CD0011
.text C:\WINDOWS\system32\lsass.exe[828] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00CC0FEF
.text C:\WINDOWS\system32\lsass.exe[828] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 00CB0FEF
.text C:\WINDOWS\system32\lsass.exe[828] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 00CB0FDE
.text C:\WINDOWS\system32\lsass.exe[828] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 00CB0FCD
.text C:\WINDOWS\system32\lsass.exe[828] WININET.dll!InternetOpenUrlW 3D998439 5 Bytes JMP 00CB001E
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F00000
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F00F5A
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F00F75
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F00F86
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F00043
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F00FB2
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F00F18
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F00060
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F00096
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F0007B
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F000A7
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F00FA1
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F00FEF
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F00F35
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F00FCD
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F00FDE
.text C:\WINDOWS\system32\svchost.exe[992] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F00EFD
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00EF0FC3
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00EF0FA8
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00EF0FDE
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00EF000A
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00EF005B
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00EF0FEF
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00EF004A
.text C:\WINDOWS\system32\svchost.exe[992] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00EF002F
.text C:\WINDOWS\system32\svchost.exe[992] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 0094000A
.text C:\WINDOWS\system32\svchost.exe[992] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00EE0FDE
.text C:\WINDOWS\system32\svchost.exe[992] msvcrt.dll!system 77C293C7 5 Bytes JMP 00EE0FEF
.text C:\WINDOWS\system32\svchost.exe[992] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00EE0044
.text C:\WINDOWS\system32\svchost.exe[992] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00EE000C
.text C:\WINDOWS\system32\svchost.exe[992] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00EE0055
.text C:\WINDOWS\system32\svchost.exe[992] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00EE001D
.text C:\WINDOWS\system32\svchost.exe[992] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 00EC000A
.text C:\WINDOWS\system32\svchost.exe[992] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 00EC0FEF
.text C:\WINDOWS\system32\svchost.exe[992] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 00EC002F
.text C:\WINDOWS\system32\svchost.exe[992] WININET.dll!InternetOpenUrlW 3D998439 5 Bytes JMP 00EC0FD4
.text C:\WINDOWS\system32\svchost.exe[992] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00ED0FEF
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00FA0FEF
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00FA0F9E
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00FA0093
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00FA006C
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00FA005B
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00FA0025
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00FA0F68
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00FA0F79
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FA00ED
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FA00DC
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00FA00FE
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00FA004A
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00FA0FDE
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00FA00A4
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00FA0014
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00FA0FCD
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00FA00C1
.text C:\WINDOWS\system32\svchost.exe[1048] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00F9000A
.text C:\WINDOWS\system32\svchost.exe[1048] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00F90F72
.text C:\WINDOWS\system32\svchost.exe[1048] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00F90FB9
.text C:\WINDOWS\system32\svchost.exe[1048] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00F90FD4
.text C:\WINDOWS\system32\svchost.exe[1048] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00F9002F
.text C:\WINDOWS\system32\svchost.exe[1048] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00F90FE5
.text C:\WINDOWS\system32\svchost.exe[1048] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00F90F8D
.text C:\WINDOWS\system32\svchost.exe[1048] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [19, 89]
.text C:\WINDOWS\system32\svchost.exe[1048] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00F90F9E
.text C:\WINDOWS\system32\svchost.exe[1048] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00F80055
.text C:\WINDOWS\system32\svchost.exe[1048] msvcrt.dll!system 77C293C7 5 Bytes JMP 00F80FCA
.text C:\WINDOWS\system32\svchost.exe[1048] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00F80044
.text C:\WINDOWS\system32\svchost.exe[1048] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00F8000C
.text C:\WINDOWS\system32\svchost.exe[1048] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00F80FE5
.text C:\WINDOWS\system32\svchost.exe[1048] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00F80029
.text C:\WINDOWS\system32\svchost.exe[1048] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 00F60FEF
.text C:\WINDOWS\system32\svchost.exe[1048] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 00F6000A
.text C:\WINDOWS\system32\svchost.exe[1048] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 00F6001B
.text C:\WINDOWS\system32\svchost.exe[1048] WININET.dll!InternetOpenUrlW 3D998439 5 Bytes JMP 00F60FCA
.text C:\WINDOWS\system32\svchost.exe[1048] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00F70000
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02820FEF
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02820F77
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02820076
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02820065
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02820054
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0282002F
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02820F30
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02820F4B
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 028200A4
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 02820093
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02820EFA
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02820FA8
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02820FDE
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02820F5C
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 0282001E
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02820FCD
.text C:\WINDOWS\System32\svchost.exe[1248] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 02820F1F
.text C:\WINDOWS\System32\svchost.exe[1248] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 02810FCA
.text C:\WINDOWS\System32\svchost.exe[1248] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 0281006C
.text C:\WINDOWS\System32\svchost.exe[1248] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0281001B
.text C:\WINDOWS\System32\svchost.exe[1248] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 0281000A
.text C:\WINDOWS\System32\svchost.exe[1248] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 02810051
.text C:\WINDOWS\System32\svchost.exe[1248] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 02810FEF
.text C:\WINDOWS\System32\svchost.exe[1248] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 02810040
.text C:\WINDOWS\System32\svchost.exe[1248] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 02810FAF
.text C:\WINDOWS\System32\svchost.exe[1248] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 02800031
.text C:\WINDOWS\System32\svchost.exe[1248] msvcrt.dll!system 77C293C7 5 Bytes JMP 02800FA6
.text C:\WINDOWS\System32\svchost.exe[1248] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 02800FD2
.text C:\WINDOWS\System32\svchost.exe[1248] msvcrt.dll!_open 77C2F566 5 Bytes JMP 02800000
.text C:\WINDOWS\System32\svchost.exe[1248] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 02800FB7
.text C:\WINDOWS\System32\svchost.exe[1248] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 02800FE3
.text C:\WINDOWS\System32\svchost.exe[1248] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 027E0000
.text C:\WINDOWS\System32\svchost.exe[1248] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 027E0025
.text C:\WINDOWS\System32\svchost.exe[1248] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 027E0FEF
.text C:\WINDOWS\System32\svchost.exe[1248] WININET.dll!InternetOpenUrlW 3D998439 5 Bytes JMP 027E0FD4
.text C:\WINDOWS\System32\svchost.exe[1248] WS2_32.dll!socket 71AB4211 5 Bytes JMP 027F0FEF
.text C:\WINDOWS\System32\svchost.exe[1512] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C90000
.text C:\WINDOWS\System32\svchost.exe[1512] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C90064
.text C:\WINDOWS\System32\svchost.exe[1512] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C90F6F
.text C:\WINDOWS\System32\svchost.exe[1512] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C90053
.text C:\WINDOWS\System32\svchost.exe[1512] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C90F8A
.text C:\WINDOWS\System32\svchost.exe[1512] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C9002C
.text C:\WINDOWS\System32\svchost.exe[1512] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C90F39
.text C:\WINDOWS\System32\svchost.exe[1512] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C90F54
.text C:\WINDOWS\System32\svchost.exe[1512] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C90F03
.text C:\WINDOWS\System32\svchost.exe[1512] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C90F14
.text C:\WINDOWS\System32\svchost.exe[1512] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00C900B7
.text C:\WINDOWS\System32\svchost.exe[1512] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00C90FA5
.text C:\WINDOWS\System32\svchost.exe[1512] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00C90011
.text C:\WINDOWS\System32\svchost.exe[1512] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00C9007F
.text C:\WINDOWS\System32\svchost.exe[1512] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00C90FC0
.text C:\WINDOWS\System32\svchost.exe[1512] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00C90FDB
.text C:\WINDOWS\System32\svchost.exe[1512] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00C9009C
.text C:\WINDOWS\System32\svchost.exe[1512] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00C40014
.text C:\WINDOWS\System32\svchost.exe[1512] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00C4002F
.text C:\WINDOWS\System32\svchost.exe[1512] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00C40FC3
.text C:\WINDOWS\System32\svchost.exe[1512] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00C40FD4
.text C:\WINDOWS\System32\svchost.exe[1512] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00C40F7C
.text C:\WINDOWS\System32\svchost.exe[1512] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00C40FEF
.text C:\WINDOWS\System32\svchost.exe[1512] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00C40F97
.text C:\WINDOWS\System32\svchost.exe[1512] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [E4, 88] {IN AL, 0x88}
.text C:\WINDOWS\System32\svchost.exe[1512] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00C40FA8
.text C:\WINDOWS\System32\svchost.exe[1512] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00C30FDB
.text C:\WINDOWS\System32\svchost.exe[1512] msvcrt.dll!system 77C293C7 5 Bytes JMP 00C30066
.text C:\WINDOWS\System32\svchost.exe[1512] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00C3003A
.text C:\WINDOWS\System32\svchost.exe[1512] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00C30000
.text C:\WINDOWS\System32\svchost.exe[1512] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00C3004B
.text C:\WINDOWS\System32\svchost.exe[1512] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00C30029
.text C:\WINDOWS\System32\svchost.exe[1512] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 00C1000A
.text C:\WINDOWS\System32\svchost.exe[1512] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 00C10025
.text C:\WINDOWS\System32\svchost.exe[1512] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 00C10FEF
.text C:\WINDOWS\System32\svchost.exe[1512] WININET.dll!InternetOpenUrlW 3D998439 5 Bytes JMP 00C10FD4
.text C:\WINDOWS\System32\svchost.exe[1512] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00C20FEF
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[1528] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0041C130 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[1528] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0041C1B0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\System32\svchost.exe[2464] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00D10FEF
.text C:\WINDOWS\System32\svchost.exe[2464] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00D10F36
.text C:\WINDOWS\System32\svchost.exe[2464] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00D10F47
.text C:\WINDOWS\System32\svchost.exe[2464] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00D10F58
.text C:\WINDOWS\System32\svchost.exe[2464] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00D10F75
.text C:\WINDOWS\System32\svchost.exe[2464] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00D10FA1
.text C:\WINDOWS\System32\svchost.exe[2464] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00D10063
.text C:\WINDOWS\System32\svchost.exe[2464] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00D10048
.text C:\WINDOWS\System32\svchost.exe[2464] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D1008F
.text C:\WINDOWS\System32\svchost.exe[2464] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D10074
.text C:\WINDOWS\System32\svchost.exe[2464] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00D10EDB
.text C:\WINDOWS\System32\svchost.exe[2464] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00D10F86
.text C:\WINDOWS\System32\svchost.exe[2464] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00D10FDE
.text C:\WINDOWS\System32\svchost.exe[2464] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00D10F11
.text C:\WINDOWS\System32\svchost.exe[2464] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00D10FB2
.text C:\WINDOWS\System32\svchost.exe[2464] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00D10FCD
.text C:\WINDOWS\System32\svchost.exe[2464] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00D10F00
.text C:\WINDOWS\System32\svchost.exe[2464] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 006C0FB9
.text C:\WINDOWS\System32\svchost.exe[2464] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 006C0F94
.text C:\WINDOWS\System32\svchost.exe[2464] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 006C0FD4
.text C:\WINDOWS\System32\svchost.exe[2464] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 006C000A
.text C:\WINDOWS\System32\svchost.exe[2464] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 006C0051
.text C:\WINDOWS\System32\svchost.exe[2464] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 006C0FE5
.text C:\WINDOWS\System32\svchost.exe[2464] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 006C0036
.text C:\WINDOWS\System32\svchost.exe[2464] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 006C0025
.text C:\WINDOWS\System32\svchost.exe[2464] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 006B0040
.text C:\WINDOWS\System32\svchost.exe[2464] msvcrt.dll!system 77C293C7 5 Bytes JMP 006B0FAB
.text C:\WINDOWS\System32\svchost.exe[2464] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 006B0FD7
.text C:\WINDOWS\System32\svchost.exe[2464] msvcrt.dll!_open 77C2F566 5 Bytes JMP 006B0000
.text C:\WINDOWS\System32\svchost.exe[2464] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 006B0FC6
.text C:\WINDOWS\System32\svchost.exe[2464] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 006B0011
.text C:\WINDOWS\System32\svchost.exe[2464] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 006A0000
.text C:\WINDOWS\System32\svchost.exe[2464] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 006A0011
.text C:\WINDOWS\System32\svchost.exe[2464] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 006A0FDB
.text C:\WINDOWS\System32\svchost.exe[2464] WININET.dll!InternetOpenUrlW 3D998439 5 Bytes JMP 006A0FCA
.text C:\WINDOWS\system32\wuauclt.exe[3716] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001D0000
.text C:\WINDOWS\system32\wuauclt.exe[3716] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001D0054
.text C:\WINDOWS\system32\wuauclt.exe[3716] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001D0F55
.text C:\WINDOWS\system32\wuauclt.exe[3716] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001D0F72
.text C:\WINDOWS\system32\wuauclt.exe[3716] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001D0F83
.text C:\WINDOWS\system32\wuauclt.exe[3716] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001D0FB9
.text C:\WINDOWS\system32\wuauclt.exe[3716] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001D0F29
.text C:\WINDOWS\system32\wuauclt.exe[3716] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001D0F3A
.text C:\WINDOWS\system32\wuauclt.exe[3716] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001D0EE2
.text C:\WINDOWS\system32\wuauclt.exe[3716] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001D0EF3
.text C:\WINDOWS\system32\wuauclt.exe[3716] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 001D0096
.text C:\WINDOWS\system32\wuauclt.exe[3716] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 001D0FA8
.text C:\WINDOWS\system32\wuauclt.exe[3716] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 001D0FE5
.text C:\WINDOWS\system32\wuauclt.exe[3716] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 001D0065
.text C:\WINDOWS\system32\wuauclt.exe[3716] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 001D0FD4
.text C:\WINDOWS\system32\wuauclt.exe[3716] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 001D0025
.text C:\WINDOWS\system32\wuauclt.exe[3716] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 001D0F0E
.text C:\WINDOWS\system32\wuauclt.exe[3716] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 002C0027
.text C:\WINDOWS\system32\wuauclt.exe[3716] msvcrt.dll!system 77C293C7 5 Bytes JMP 002C0F92
.text C:\WINDOWS\system32\wuauclt.exe[3716] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 002C0FB7
.text C:\WINDOWS\system32\wuauclt.exe[3716] msvcrt.dll!_open 77C2F566 5 Bytes JMP 002C0FEF
.text C:\WINDOWS\system32\wuauclt.exe[3716] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 002C000C
.text C:\WINDOWS\system32\wuauclt.exe[3716] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 002C0FD2
.text C:\WINDOWS\system32\wuauclt.exe[3716] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 002D002C
.text C:\WINDOWS\system32\wuauclt.exe[3716] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 002D0F9B
.text C:\WINDOWS\system32\wuauclt.exe[3716] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 002D0FD1
.text C:\WINDOWS\system32\wuauclt.exe[3716] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 002D0011
.text C:\WINDOWS\system32\wuauclt.exe[3716] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 002D0058
.text C:\WINDOWS\system32\wuauclt.exe[3716] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 002D0000
.text C:\WINDOWS\system32\wuauclt.exe[3716] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 002D003D
.text C:\WINDOWS\system32\wuauclt.exe[3716] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 002D0FB6
.text C:\WINDOWS\system32\wuauclt.exe[3716] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 00710FEF
.text C:\WINDOWS\system32\wuauclt.exe[3716] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 00710000
.text C:\WINDOWS\system32\wuauclt.exe[3716] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 0071001B
.text C:\WINDOWS\system32\wuauclt.exe[3716] WININET.dll!InternetOpenUrlW 3D998439 5 Bytes JMP 00710FC0
.text C:\WINDOWS\system32\wuauclt.exe[3716] WS2_32.dll!socket 71AB4211 5 Bytes JMP 001C000A

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\MSVCRT.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\MSVCRT.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\user32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\user32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\user32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\user32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe[528] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs symsnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 symsnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 symsnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 symsnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 symsnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume5 symsnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat symsnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

Device -> \Driver\atapi \Device\Harddisk0\DR0 82B59618

---- Files - GMER 1.0.15 ----

File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

---- EOF - GMER 1.0.15 ----


Jotti didn't find anything.

Jotti's malware scan
Filename: 07DDA0E9A7.dll
Status: Scan finished. 0 out of 20 scanners reported malware.
Scan taken on: Sat 30 Jan 2010 05:43:23 (CET)




#10 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:53 AM

Posted 30 January 2010 - 07:33 AM

Hello, toolman605.
Sorry GMER took so long, but it did identiy the infection for us. We'll need to run Combofix. Please ensure you disable all your anti-malware programs (e.g. Spybot S+D's Teatimer, antivirus, etc.) when running it so they don't interefere.

One or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and download and execute files.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall

We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do. If you do decide to proceed, please continue with the fix below.



Step 1

Next, please download ComboFix from one of these locations:* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply, along with any symptoms that are present after it runs.


If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 


#11 toolman605

toolman605
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:09:53 AM

Posted 30 January 2010 - 04:22 PM

Hi,

Well - so far so good! Thank you so much for your help!!!!!!

Combofix crashed the 1st time and seems to have run fine the 2nd time. The Dcom/NT restart problem apears to be gone but something new has popped up. Its an error box that pops up and says at the top "Network Connections" then on the next line "Cannot load dialog" and then inside the box it says, "Error 623: The system could not find the phone book entry for this connection." Is this a remnant of one of the viruses trying to send info out?

Also, the processes in task manager are down to 41 from 43 so we did kill two but I thought there would be more?

Here is the Combofix log:

ComboFix 10-01-29.09 - David xxxx 01/30/2010 10:05:54.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.119 [GMT -5:00]
Running from: c:\documents and settings\David xxxx\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\David xxxx\My Documents\ZbThumbnail.info
c:\windows\Downloaded Program Files\RdxIE.dll
c:\windows\MailSwitch.ocx
c:\windows\patch.exe
c:\windows\system32\logs

Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it tongue.gif
.
((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-30 )))))))))))))))))))))))))))))))
.

2010-01-30 05:38 . 2010-01-30 05:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-01-30 05:38 . 2010-01-30 05:38 -------- d-----w- c:\documents and settings\David xxxx\Application Data\Office Genuine Advantage
2010-01-27 01:22 . 2002-08-29 10:00 13894 ----a-w- c:\windows\system32\dllcache\zonelibm.dll
2010-01-27 01:21 . 2008-04-13 19:36 8832 ----a-w- c:\windows\system32\dllcache\wmiacpi.sys
2010-01-27 01:20 . 2001-08-18 03:36 525568 ----a-w- c:\windows\system32\dllcache\tridxp.dll
2010-01-27 01:19 . 2002-08-29 10:00 30208 ----a-w- c:\windows\system32\dllcache\sm87w.dll
2010-01-27 01:18 . 2001-08-17 18:28 899146 ----a-w- c:\windows\system32\dllcache\r2mdkxga.sys
2010-01-27 01:17 . 2008-04-13 19:54 28672 ----a-w- c:\windows\system32\dllcache\nscirda.sys
2010-01-27 01:16 . 2001-08-17 18:57 16128 ----a-w- c:\windows\system32\dllcache\modemcsa.sys
2010-01-27 01:15 . 2002-08-29 10:00 6144 ----a-w- c:\windows\system32\dllcache\kbd101a.dll
2010-01-27 01:14 . 2001-08-17 18:28 57471 ----a-w- c:\windows\system32\dllcache\hsf_samp.sys
2010-01-27 01:13 . 2001-08-17 17:15 442240 ----a-w- c:\windows\system32\dllcache\fpnpbase.sys
2010-01-27 01:12 . 2001-08-17 18:47 23808 ----a-w- c:\windows\system32\dllcache\dot4usb.sys
2010-01-27 01:11 . 2004-08-04 06:32 48640 ----a-w- c:\windows\system32\dllcache\cwrwdm.sys
2010-01-27 01:10 . 2008-04-14 01:11 121856 ----a-w- c:\windows\system32\dllcache\camext30.dll
2010-01-27 01:09 . 2001-08-18 03:36 12800 ----a-w- c:\windows\system32\dllcache\brevif.dll
2010-01-27 01:08 . 2002-08-29 10:00 49664 ----a-w- c:\windows\system32\dllcache\adrot.dll
2010-01-27 01:07 . 2001-08-17 19:56 66048 ----a-w- c:\windows\system32\dllcache\s3legacy.dll
2010-01-27 01:07 . 2002-08-29 10:00 19968 ----a-w- c:\windows\system32\dllcache\inetsloc.dll
2010-01-27 01:07 . 2002-08-29 10:00 7680 ----a-w- c:\windows\system32\dllcache\inetmgr.exe
2010-01-27 01:07 . 2002-08-29 10:00 169984 ----a-w- c:\windows\system32\dllcache\iisui.dll
2010-01-27 01:07 . 2002-08-29 10:00 5632 ----a-w- c:\windows\system32\dllcache\iisrstap.dll
2010-01-27 01:07 . 2002-08-29 10:00 14336 ----a-w- c:\windows\system32\dllcache\iisreset.exe
2010-01-27 01:07 . 2002-08-29 10:00 6144 ----a-w- c:\windows\system32\dllcache\ftpsapi2.dll
2010-01-24 15:01 . 2010-01-24 15:01 -------- d-----w- c:\program files\ESET
2010-01-23 14:07 . 2010-01-23 14:07 -------- d-----w- c:\program files\NOS
2010-01-21 23:17 . 2010-01-21 23:17 0 ----a-w- c:\documents and settings\David xxxx\settings.dat
2010-01-21 04:06 . 2010-01-21 04:06 -------- d-----w- c:\documents and settings\David xxxx\Application Data\AVG8
2010-01-18 15:07 . 2010-01-18 15:07 -------- d-----w- c:\program files\Google
2010-01-17 23:20 . 2010-01-17 23:20 5115824 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-03 15:51 . 2009-11-20 11:08 38784 ----a-w- c:\documents and settings\David xxxx\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-01-03 15:35 . 2010-01-03 15:35 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-03 15:32 . 2010-01-03 15:32 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-01-03 15:31 . 2010-01-23 14:08 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-30 10:30 . 2007-12-01 10:32 -------- d-----w- c:\documents and settings\Susan Tobbe\Application Data\COMCASTTOOLBAR
2010-01-20 19:35 . 2009-12-16 01:02 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-20 01:11 . 2006-10-03 09:30 -------- d-----w- c:\documents and settings\LocalService\Application Data\SiteAdvisor
2010-01-19 23:57 . 2003-12-06 14:19 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2010-01-18 12:45 . 2004-10-13 01:51 -------- d-----w- c:\program files\Java
2010-01-18 12:43 . 2003-07-19 17:28 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-17 23:21 . 2009-12-09 00:04 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-17 22:52 . 2007-01-13 10:12 -------- d-----w- c:\documents and settings\Susan Tobbe\Application Data\Apple Computer
2010-01-14 16:12 . 2009-10-02 17:51 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-13 10:17 . 2006-08-24 21:27 -------- d-----w- c:\documents and settings\Susan Tobbe\Application Data\SiteAdvisor
2010-01-07 21:07 . 2009-12-09 00:04 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2009-12-09 00:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-06 00:05 . 2009-04-04 14:02 -------- d-----w- c:\program files\Windows Live Safety Center
2010-01-05 10:00 . 2004-02-06 22:05 832512 ----a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2004-08-04 07:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2002-08-29 10:00 17408 ----a-w- c:\windows\system32\corpol.dll
2010-01-01 13:52 . 2002-08-29 06:27 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2010-01-01 13:52 . 2002-08-29 06:27 96512 ----a-w- c:\windows\system32\drivers\atapi.svs
2009-12-25 14:12 . 2009-12-24 19:49 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-21 14:24 . 2009-12-21 14:24 -------- d-----w- c:\program files\Autoruns
2009-12-21 13:24 . 2009-12-21 13:05 -------- d-----w- c:\documents and settings\David xxxx\Application Data\ImgBurn
2009-12-21 13:04 . 2009-12-21 13:04 -------- d-----w- c:\program files\ImgBurn
2009-12-21 12:15 . 2006-07-30 12:28 -------- d-----w- c:\documents and settings\David xxxx\Application Data\SiteAdvisor
2009-12-14 19:15 . 2009-12-14 19:15 2146304 ----a-w- c:\windows\system32\GPhotos.scr
2009-12-09 09:59 . 2009-12-09 09:59 -------- d-----w- c:\documents and settings\Susan Tobbe\Application Data\Malwarebytes
2009-12-09 00:13 . 2009-12-09 00:13 -------- d-----w- c:\program files\Garmin GPS Plugin
2009-12-09 00:05 . 2009-12-09 00:05 -------- d-----w- c:\documents and settings\David xxxx\Application Data\Malwarebytes
2009-12-09 00:04 . 2009-12-09 00:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-07 09:45 . 2004-03-04 20:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-22 14:22 . 2009-11-22 14:22 77080 ---ha-w- c:\windows\system32\mlfcache.dat
2009-11-22 14:16 . 2009-11-22 14:16 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-21 15:51 . 2002-08-29 10:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-13 22:57 . 2009-11-13 22:57 922112 ------w- c:\windows\system32\imapi2fs.dll
2009-11-13 22:57 . 2009-11-13 22:57 426496 ------w- c:\windows\system32\imapi2.dll
2008-08-11 19:43 . 2008-08-11 15:00 80 --sh--r- c:\windows\SYSTEM32\07DDA0E9A7.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 454784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2002-09-20 290816]
"HostManager"="c:\program files\Common Files\AOL\1129368448\ee\AOLSoftware.exe" [2007-10-08 41824]
"SiteAdvisor"="c:\program files\SiteAdvisor\6253\SiteAdv.exe" [2006-07-24 35992]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

c:\documents and settings\Susan Tobbe\Start Menu\Programs\Startup\
DSL Connection.lnk - c:\windows\SYSTEM32\rasphone.exe [2002-8-29 56832]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Program Neighborhood Agent.lnk - c:\program files\Citrix\ICA Client\pnagent.exe [2005-11-29 233744]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\America Online 9.0a\\waol.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\1129368448\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R2 ASFAgent;ASF Agent;c:\program files\Intel\ASF Agent\ASFAgent.exe [8/7/2002 5:34 AM 221184]
R2 NetAlrt;NetAlrt;c:\windows\SYSTEM32\DRIVERS\Netalrt.sys [5/7/2002 4:05 PM 39680]
R2 PlatAlrt;PlatAlrt;c:\windows\SYSTEM32\DRIVERS\platalrt.sys [5/7/2002 4:06 PM 23744]
R2 RDIConverterPrintHelper;RDI Document Conversion Helper;c:\program files\Common Files\ICWM\Printer\RDIConverterService.exe [10/1/2008 3:13 PM 64888]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder

2010-01-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-11-15 c:\windows\Tasks\McDefragTask.job
- c:\windows\system32\defrag.exe [2002-08-29 00:12]

2009-12-01 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2006-07-30 16:22]

2010-01-30 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]

2010-01-30 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 20:07]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www6.comcast.net/a/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/bin/search?p={searchTerms}
mStart Page = hxxp://www.yahoo.com
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
uInternet Settings,ProxyServer = actsvr.comcastonline.com:8100
uInternet Settings,ProxyOverride = actsvr.comcastonline.com;*.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.6.4/GarminAxControl.CAB
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A}
DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-30 10:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-01-30 10:23:38
ComboFix-quarantined-files.txt 2010-01-30 15:23

Pre-Run: 6,159,982,592 bytes free
Post-Run: 6,871,093,248 bytes free

- - End Of File - - 78EBFAAE21A425C33E897343351CD73E


#12 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:53 AM

Posted 31 January 2010 - 10:56 AM

Hello, toolman605.

Good to hear we're making progress. The main issue you had was a rootkit and would not show up in the process list since Windows can't see rootkits. The fewer processes are probably your security programs realtime protection being off at the time.

Let's clean up some remnants, run an A/V scan, and try to fix that error. If it looks good at that point, we'll close a few security holes and clean up our mess so you cant' get reinfected.





Step 1

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

QUOTE
File::
c:\windows\SYSTEM32\07DDA0E9A7.dll
DDS::
uSearch Page = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
mDefault_Search_URL = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - hxxp://207.188.7.150/1006b278b6b044d74923/netzip/RdxIE601.cab
BHO: AutorunsDisabled - No File
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
EB: {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - No File
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000000


Save this as CFScript.txt, in the same location as ComboFix.exe




Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.



Step 2

I'd like us to scan your machine with ESET OnlineScan
  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the icon on your desktop.
  4. Check
  5. Click the button.
  6. Accept any security warnings from your browser.
  7. Check
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
  11. Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the button.
  13. Push
Step 3

OK, now onto the phone book error. There are a few sources of this error. Do you use dial-up for internet? Or do you have a cable modem or DSL?

ONLY if you do NOT use a model to physically call a number, please try the following:
  1. Go to Start --> Control Panel
  2. Select Internet Options
  3. Select Connections
  4. ensure it is set to never dial a connection
DId that work? If not, what exactly are you doing when you get that error? Are you trying to use a VPN connection? Which browser are you using? What webpage are you trying to go to? Etc.



Step 4

In your reply, please post:
  • Combofix log
  • ESET log
  • Info about the Phone Book error
  • A fresh DDS log

Edited by etavares, 31 January 2010 - 10:56 AM.


If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 


#13 toolman605

toolman605
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:09:53 AM

Posted 01 February 2010 - 07:35 AM

Ok,

Here are that latest result. I didn't expect a reply on Sunday - you are simply amazing!!! (but you need to take a day off) busy.gif

Quick summary;
1. Combofix ran with the script you provided - log below

2. ESET found 1 problem - log below

3. I think the phone book error is relaed to my wife's Citrix server link to her office - it only happens on her side of the computer (under her log in). It didn't occur to me until you said VPN connection. I use a VPN connection under my log in to connect remotely to my office. I went to Internet Options in Control Panel and it is set to "never dial a connection" but its greyed out. I think this is a Citrix problem and I'll try and solve it myself and save your valuable time with what you are good at - finding and killing viruses!!

4. I'm doing this from work so I'll have to run you a fresh DDS log tonight when I get home.

Combofix log:

ComboFix 10-01-31.03 - David XXXX 01/31/2010 22:13:45.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.125 [GMT -5:00]
Running from: c:\documents and settings\David XXXX\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\David XXXX\Desktop\CFscript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

FILE ::
"c:\windows\SYSTEM32\07DDA0E9A7.dll"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\SYSTEM32\07DDA0E9A7.dll

.
((((((((((((((((((((((((( Files Created from 2010-01-01 to 2010-02-01 )))))))))))))))))))))))))))))))
.

2010-01-30 21:36 . 2010-01-30 21:36 -------- d-----w- c:\documents and settings\Susan XXXX\Application Data\Office Genuine Advantage
2010-01-30 05:38 . 2010-01-30 05:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-01-30 05:38 . 2010-01-30 05:38 -------- d-----w- c:\documents and settings\David XXXX\Application Data\Office Genuine Advantage
2010-01-27 01:22 . 2002-08-29 10:00 13894 ----a-w- c:\windows\system32\dllcache\zonelibm.dll
2010-01-27 01:21 . 2008-04-13 19:36 8832 ----a-w- c:\windows\system32\dllcache\wmiacpi.sys
2010-01-27 01:20 . 2001-08-18 03:36 525568 ----a-w- c:\windows\system32\dllcache\tridxp.dll
2010-01-27 01:19 . 2002-08-29 10:00 30208 ----a-w- c:\windows\system32\dllcache\sm87w.dll
2010-01-27 01:18 . 2001-08-17 18:28 899146 ----a-w- c:\windows\system32\dllcache\r2mdkxga.sys
2010-01-27 01:17 . 2008-04-13 19:54 28672 ----a-w- c:\windows\system32\dllcache\nscirda.sys
2010-01-27 01:16 . 2001-08-17 18:57 16128 ----a-w- c:\windows\system32\dllcache\modemcsa.sys
2010-01-27 01:15 . 2002-08-29 10:00 6144 ----a-w- c:\windows\system32\dllcache\kbd101a.dll
2010-01-27 01:14 . 2001-08-17 18:28 57471 ----a-w- c:\windows\system32\dllcache\hsf_samp.sys
2010-01-27 01:13 . 2001-08-17 17:15 442240 ----a-w- c:\windows\system32\dllcache\fpnpbase.sys
2010-01-27 01:12 . 2001-08-17 18:47 23808 ----a-w- c:\windows\system32\dllcache\dot4usb.sys
2010-01-27 01:11 . 2004-08-04 06:32 48640 ----a-w- c:\windows\system32\dllcache\cwrwdm.sys
2010-01-27 01:10 . 2008-04-14 01:11 121856 ----a-w- c:\windows\system32\dllcache\camext30.dll
2010-01-27 01:09 . 2001-08-18 03:36 12800 ----a-w- c:\windows\system32\dllcache\brevif.dll
2010-01-27 01:08 . 2002-08-29 10:00 49664 ----a-w- c:\windows\system32\dllcache\adrot.dll
2010-01-27 01:07 . 2001-08-17 19:56 66048 ----a-w- c:\windows\system32\dllcache\s3legacy.dll
2010-01-27 01:07 . 2002-08-29 10:00 19968 ----a-w- c:\windows\system32\dllcache\inetsloc.dll
2010-01-27 01:07 . 2002-08-29 10:00 7680 ----a-w- c:\windows\system32\dllcache\inetmgr.exe
2010-01-27 01:07 . 2002-08-29 10:00 169984 ----a-w- c:\windows\system32\dllcache\iisui.dll
2010-01-27 01:07 . 2002-08-29 10:00 5632 ----a-w- c:\windows\system32\dllcache\iisrstap.dll
2010-01-27 01:07 . 2002-08-29 10:00 14336 ----a-w- c:\windows\system32\dllcache\iisreset.exe
2010-01-27 01:07 . 2002-08-29 10:00 6144 ----a-w- c:\windows\system32\dllcache\ftpsapi2.dll
2010-01-24 15:01 . 2010-01-24 15:01 -------- d-----w- c:\program files\ESET
2010-01-23 14:07 . 2010-01-23 14:07 -------- d-----w- c:\program files\NOS
2010-01-21 23:17 . 2010-01-21 23:17 0 ----a-w- c:\documents and settings\David XXXX\settings.dat
2010-01-21 04:06 . 2010-01-21 04:06 -------- d-----w- c:\documents and settings\David XXXX\Application Data\AVG8
2010-01-18 15:07 . 2010-01-18 15:07 -------- d-----w- c:\program files\Google
2010-01-03 15:35 . 2010-01-03 15:35 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-03 15:31 . 2010-01-23 14:08 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-31 21:35 . 2007-12-01 10:32 -------- d-----w- c:\documents and settings\Susan XXXX\Application Data\COMCASTTOOLBAR
2010-01-20 19:35 . 2009-12-16 01:02 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-20 01:11 . 2006-10-03 09:30 -------- d-----w- c:\documents and settings\LocalService\Application Data\SiteAdvisor
2010-01-19 23:57 . 2003-12-06 14:19 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2010-01-18 12:45 . 2004-10-13 01:51 -------- d-----w- c:\program files\Java
2010-01-18 12:43 . 2003-07-19 17:28 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-17 23:21 . 2009-12-09 00:04 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-17 23:20 . 2010-01-17 23:20 5115824 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-17 22:52 . 2007-01-13 10:12 -------- d-----w- c:\documents and settings\Susan XXXX\Application Data\Apple Computer
2010-01-14 16:12 . 2009-10-02 17:51 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-13 10:17 . 2006-08-24 21:27 -------- d-----w- c:\documents and settings\Susan XXXX\Application Data\SiteAdvisor
2010-01-07 21:07 . 2009-12-09 00:04 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2009-12-09 00:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-06 00:05 . 2009-04-04 14:02 -------- d-----w- c:\program files\Windows Live Safety Center
2010-01-05 10:00 . 2004-02-06 22:05 832512 ------w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2004-08-04 07:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2002-08-29 10:00 17408 ----a-w- c:\windows\system32\corpol.dll
2010-01-03 15:32 . 2010-01-03 15:32 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-01-01 13:52 . 2002-08-29 06:27 96512 ----a-w- c:\windows\system32\drivers\atapi.svs
2010-01-01 13:52 . 2002-08-29 06:27 96512 ------w- c:\windows\system32\drivers\atapi.sys
2009-12-26 15:38 . 2008-05-23 09:00 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\SiteAdvisor
2009-12-25 14:12 . 2009-12-24 19:49 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-21 14:24 . 2009-12-21 14:24 -------- d-----w- c:\program files\Autoruns
2009-12-21 13:24 . 2009-12-21 13:05 -------- d-----w- c:\documents and settings\David XXXX\Application Data\ImgBurn
2009-12-21 13:04 . 2009-12-21 13:04 -------- d-----w- c:\program files\ImgBurn
2009-12-21 12:15 . 2006-07-30 12:28 -------- d-----w- c:\documents and settings\David XXXX\Application Data\SiteAdvisor
2009-12-14 19:15 . 2009-12-14 19:15 2146304 ----a-w- c:\windows\system32\GPhotos.scr
2009-12-09 09:59 . 2009-12-09 09:59 -------- d-----w- c:\documents and settings\Susan XXXX\Application Data\Malwarebytes
2009-12-09 00:13 . 2009-12-09 00:13 -------- d-----w- c:\program files\Garmin GPS Plugin
2009-12-09 00:05 . 2009-12-09 00:05 -------- d-----w- c:\documents and settings\David XXXX\Application Data\Malwarebytes
2009-12-09 00:04 . 2009-12-09 00:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-07 09:45 . 2004-03-04 20:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-22 14:22 . 2009-11-22 14:22 77080 ---ha-w- c:\windows\system32\mlfcache.dat
2009-11-22 14:16 . 2009-11-22 14:16 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-21 15:51 . 2002-08-29 10:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-20 11:08 . 2010-01-03 15:51 38784 ----a-w- c:\documents and settings\David XXXX\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-13 22:57 . 2009-11-13 22:57 922112 ------w- c:\windows\system32\imapi2fs.dll
2009-11-13 22:57 . 2009-11-13 22:57 426496 ------w- c:\windows\system32\imapi2.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-01-30_15.19.06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-02-01 03:09 . 2010-02-01 03:09 16384 c:\windows\Temp\Perflib_Perfdata_77c.dat
+ 2002-09-03 18:45 . 2010-02-01 01:34 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
- 2002-09-03 18:45 . 2010-01-30 15:07 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
+ 2002-09-03 18:45 . 2010-02-01 01:34 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
- 2002-09-03 18:45 . 2010-01-30 15:07 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
+ 2002-09-03 18:45 . 2010-02-01 01:34 737280 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT
- 2002-09-03 18:45 . 2010-01-30 15:07 737280 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 454784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2002-09-20 290816]
"HostManager"="c:\program files\Common Files\AOL\1129368448\ee\AOLSoftware.exe" [2007-10-08 41824]
"SiteAdvisor"="c:\program files\SiteAdvisor\6253\SiteAdv.exe" [2006-07-24 35992]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

c:\documents and settings\Susan XXXX\Start Menu\Programs\Startup\
DSL Connection.lnk - c:\windows\SYSTEM32\rasphone.exe [2002-8-29 56832]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Program Neighborhood Agent.lnk - c:\program files\Citrix\ICA Client\pnagent.exe [2005-11-29 233744]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\America Online 9.0a\\waol.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\1129368448\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R2 ASFAgent;ASF Agent;c:\program files\Intel\ASF Agent\ASFAgent.exe [8/7/2002 5:34 AM 221184]
R2 NetAlrt;NetAlrt;c:\windows\SYSTEM32\DRIVERS\Netalrt.sys [5/7/2002 4:05 PM 39680]
R2 PlatAlrt;PlatAlrt;c:\windows\SYSTEM32\DRIVERS\platalrt.sys [5/7/2002 4:06 PM 23744]
R2 RDIConverterPrintHelper;RDI Document Conversion Helper;c:\program files\Common Files\ICWM\Printer\RDIConverterService.exe [10/1/2008 3:13 PM 64888]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder

2010-01-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-11-15 c:\windows\Tasks\McDefragTask.job
- c:\windows\system32\defrag.exe [2002-08-29 00:12]

2009-12-01 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2006-07-30 16:22]

2010-02-01 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]

2010-02-01 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 20:07]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www6.comcast.net/a/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/bin/search?p={searchTerms}
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyServer = actsvr.comcastonline.com:8100
uInternet Settings,ProxyOverride = actsvr.comcastonline.com;*.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.6.4/GarminAxControl.CAB
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A}
DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-31 22:22
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-01-31 22:27:52
ComboFix-quarantined-files.txt 2010-02-01 03:27
ComboFix2.txt 2010-01-30 15:23

Pre-Run: 6,693,355,520 bytes free
Post-Run: 6,724,132,864 bytes free

- - End Of File - - 8B789374C22CF38E24ECEA9DFF83FD01


ESET Log:

C:\Documents and Settings\Susan XXXX\Application Data\Sun\Java\Deployment\cache\6.0\38\16f48da6-789178a0-DGT1225 probably a variant of Java/TrojanDownloader.Agent.AB trojan

#14 toolman605

toolman605
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:09:53 AM

Posted 01 February 2010 - 06:16 PM

and a copy of the DDS log as promised.
Thanks!


DDS (Ver_09-12-01.01) - NTFSx86
Run by David XXXX at 18:11:47.06 on Mon 02/01/2010
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.103 [GMT -5:00]

AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\AOL\1129368448\ee\AOLSoftware.exe
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Citrix\ICA Client\pnagent.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Common Files\ICWM\Printer\RDIConverterService.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\David XXXX\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www6.comcast.net/a/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/bin/search?p={searchTerms}
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyServer = actsvr.comcastonline.com:8100
uInternet Settings,ProxyOverride = actsvr.comcastonline.com;*.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
BHO: AutorunsDisabled - No File
BHO: {089fd14d-132b-48fc-8861-0048ae113215} - c:\program files\siteadvisor\6261\SiteAdv.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Comcast Toolbar: {4e7bd74f-2b8d-469e-93be-be2df4d9ae29} - c:\progra~1\comcas~1\COMCAS~1.DLL
BHO: {53707962-6F74-2D53-2644-206D7942484F} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
TB: McAfee SiteAdvisor: {0bf43445-2f28-4351-9252-17fe6e806aa0} - c:\program files\siteadvisor\6261\SiteAdv.dll
TB: Comcast Toolbar: {4e7bd74f-2b8d-469e-93be-be2df4d9ae29} - c:\progra~1\comcas~1\COMCAS~1.DLL
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [EasyLinkAdvisor] "c:\program files\linksys easylink advisor\LinksysAgent.exe" /startup
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [HostManager] c:\program files\common files\aol\1129368448\ee\AOLSoftware.exe
mRun: [SiteAdvisor] c:\program files\siteadvisor\6253\SiteAdv.exe
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\progra~1.lnk - c:\program files\citrix\ica client\pnagent.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.6.4/GarminAxControl.CAB
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700}
DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A}
DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68}
DPF: {41F17733-B041-4099-A042-B518BB6A408C} - hxxp://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389}
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - c:\program files\siteadvisor\6261\SiteAdv.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - No File
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll

============= SERVICES / DRIVERS ===============

R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2006-7-30 214664]
R2 ASFAgent;ASF Agent;c:\program files\intel\asf agent\ASFAgent.exe [2002-8-7 221184]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2008-5-23 359952]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2006-7-30 144704]
R2 NetAlrt;NetAlrt;c:\windows\system32\drivers\Netalrt.sys [2002-5-7 39680]
R2 PlatAlrt;PlatAlrt;c:\windows\system32\drivers\platalrt.sys [2002-5-7 23744]
R2 RDIConverterPrintHelper;RDI Document Conversion Helper;c:\program files\common files\icwm\printer\RDIConverterService.exe [2008-10-1 64888]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2006-7-30 606736]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2006-7-30 79816]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2006-7-30 35272]
R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2006-7-30 40552]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2006-7-30 34248]
S3 vsdatant;vsdatant;\??\c:\windows\system32\vsdatant.sys --> c:\windows\system32\vsdatant.sys [?]

=============== Created Last 30 ================

2010-01-30 14:41:38 0 d-sha-r- C:\cmdcons
2010-01-30 14:38:46 98816 ----a-w- c:\windows\sed.exe
2010-01-30 14:38:46 77312 ----a-w- c:\windows\MBR.exe
2010-01-30 14:38:46 261632 ----a-w- c:\windows\PEV.exe
2010-01-30 14:38:46 161792 ----a-w- c:\windows\SWREG.exe
2010-01-30 05:38:11 0 d-----w- c:\docume~1\davidt~1\applic~1\Office Genuine Advantage
2010-01-27 01:22:44 13894 ----a-w- c:\windows\system32\dllcache\zonelibm.dll
2010-01-27 01:21:57 8832 ----a-w- c:\windows\system32\dllcache\wmiacpi.sys
2010-01-27 01:20:58 525568 ----a-w- c:\windows\system32\dllcache\tridxp.dll
2010-01-27 01:19:59 30208 ----a-w- c:\windows\system32\dllcache\sm87w.dll
2010-01-27 01:18:59 899146 ----a-w- c:\windows\system32\dllcache\r2mdkxga.sys
2010-01-27 01:17:59 28672 ----a-w- c:\windows\system32\dllcache\nscirda.sys
2010-01-27 01:16:57 16128 ----a-w- c:\windows\system32\dllcache\modemcsa.sys
2010-01-27 01:15:59 6144 ----a-w- c:\windows\system32\dllcache\kbd101a.dll
2010-01-27 01:14:59 57471 ----a-w- c:\windows\system32\dllcache\hsf_samp.sys
2010-01-27 01:13:59 442240 ----a-w- c:\windows\system32\dllcache\fpnpbase.sys
2010-01-27 01:12:57 28062 ----a-w- c:\windows\system32\dllcache\dp83820.sys
2010-01-27 01:11:59 93952 ----a-w- c:\windows\system32\dllcache\cwcwdm.sys
2010-01-27 01:10:59 121856 ----a-w- c:\windows\system32\dllcache\camext30.dll
2010-01-27 01:09:59 2944 ----a-w- c:\windows\system32\dllcache\brfilt.sys
2010-01-27 01:08:45 24576 ----a-w- c:\windows\system32\dllcache\agcgauge.ax
2010-01-27 01:07:59 66048 ----a-w- c:\windows\system32\dllcache\s3legacy.dll
2010-01-27 01:07:42 19968 ----a-w- c:\windows\system32\dllcache\inetsloc.dll
2010-01-27 01:07:41 7680 ----a-w- c:\windows\system32\dllcache\inetmgr.exe
2010-01-27 01:07:40 169984 ----a-w- c:\windows\system32\dllcache\iisui.dll
2010-01-27 01:07:39 5632 ----a-w- c:\windows\system32\dllcache\iisrstap.dll
2010-01-27 01:07:39 14336 ----a-w- c:\windows\system32\dllcache\iisreset.exe
2010-01-27 01:07:37 6144 ----a-w- c:\windows\system32\dllcache\ftpsapi2.dll
2010-01-27 01:07:27 94720 ----a-w- c:\windows\system32\dllcache\certmap.ocx
2010-01-24 15:01:05 0 d-----w- c:\program files\ESET
2010-01-21 23:17:33 0 ----a-w- c:\documents and settings\David XXXX\settings.dat
2010-01-21 04:06:28 0 d-----w- c:\docume~1\davidt~1\applic~1\AVG8
2010-01-03 14:35:12 0 d-----w- c:\windows\pss

==================== Find3M ====================

2010-01-14 16:12:06 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-07 21:07:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-01 13:52:48 96512 ----a-w- c:\windows\system32\drivers\atapi.svs
2010-01-01 13:52:48 96512 ----a-w- c:\windows\system32\dllcache\atapi.sys
2010-01-01 13:52:48 96512 ------w- c:\windows\system32\drivers\atapi.sys
2009-12-31 15:33:06 70656 ----a-w- c:\windows\system32\dllcache\ie4uinit.exe
2009-12-31 15:33:06 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
2009-12-18 13:05:43 634648 ----a-w- c:\windows\system32\dllcache\iexplore.exe
2009-12-18 13:04:09 161792 ----a-w- c:\windows\system32\dllcache\ieakui.dll
2009-12-14 19:15:14 2146304 ----a-w- c:\windows\system32\GPhotos.scr
2009-11-22 14:22:16 77080 ---ha-w- c:\windows\system32\mlfcache.dat
2009-11-21 15:51:04 471552 ----a-w- c:\windows\system32\dllcache\aclayers.dll
2009-11-13 22:57:16 922112 ------w- c:\windows\system32\imapi2fs.dll
2009-11-13 22:57:16 922112 ------w- c:\windows\system32\dllcache\imapi2fs.dll
2009-11-13 22:57:16 426496 ------w- c:\windows\system32\imapi2.dll
2009-11-13 22:57:16 426496 ------w- c:\windows\system32\dllcache\imapi2.dll

============= FINISH: 18:13:32.32 ===============


#15 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:53 AM

Posted 02 February 2010 - 07:05 AM

Hello, toolman605.
Thanks, toolman605. I was doing some work around the house so it was a nice interruption. smile.gif

Overall, we're looking better, but still have some maintenace work to do. I noticed the ESET threat wasn't deleted. We'll uninstall Java anyway in this step so it should take care of the issue, but I"ll have you look to delete a file or folder just in case.

Also, did you have ZoneAlarm firewall installed at some point? I see something that looks like a leftover from it. It looks like you use McAfee?

Good to know about the Citrix issue. We have other forums I can refer you to here at BC that can probably help better than I can. When we're done..if you still have that issue, just let me know and I'll give you a link to another BC forum.



Step 1
  • Open notepad.
  • Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
  • Save it to your desktop (click file, save as) as "fixit.reg" with the quotes.

CODE
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer]
"SearchURL"="http://www.yahoo.com"
[-HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\AutorunsDisabled]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{53707962-6F74-2D53-2644-206D7942484F}]
[-HKEY_CLASSES_ROOT\CLSID\{53707962-6F74-2D53-2644-206D7942484F}]


NOTICE: This file was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Locate fixit.reg on your Desktop and double-click on it.
You will receive a prompt similar to: "Do you wish to merge the information into the registry?".
Answer "Yes" and wait for a message to appear similar to "Merged Successfully".

Please reply back letting me know if it merged correctly.




Step 2

Next, we need to update Java.
Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 18 and save it to your desktop.
  • Scroll down to where it says "JDK 6 Update 18 (JDK or JRE)...allows end-users to run Java applications".
  • Click the "Download JRE" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u18-windows-i586-p.exe to install the newest version.



Step 3

OK, let's delete the virus that ESET found. With uninstalling and reinstalling Java, it may be gone now.

Use Windows Explorer to find and delete these item(s) if they are still present.

Files:
C:\Documents and Settings\Susan XXXX\Application Data\Sun\Java\Deployment\cache\6.0\38\16f48da6-789178a0-DGT1225



As an example:
To delete C:\WINDOWS\badfile.dll
Double click the My Computer icon on your Desktop. Or click on the Windows KEY + E.
Double click on Local Disc (C:\)
Double click on the Windows folder,
Right click on badfile.dll and then from the menu that appears, click on Delete




Step 4

In your reply, please post:
  • confirmation that Step 1 merged successfully.
  • That you could/could not delete the file/folder in Step 3.
  • If you had ZoneAlarm installed in the past.
  • A fresh DDS log.

Almost done!



If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users