Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Blue screen/Malware


  • Please log in to reply
28 replies to this topic

#1 peanutsnana

peanutsnana

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:06:07 PM

Posted 21 July 2011 - 12:20 AM

I have been having issues with a blue screen popping up and telling me that my computer is preparing for a crash dump and thenit shuts down. I have been receiving help from Allan for the blue screen. He had me to a dump list from the blue screen text, look at the device manager for yellow and red symbols, run chkdsk/r, then check Vista for the service pack 2. Also ran a full scan with AVG and MalwareBytes. AVG said the only problem was a broken digital signature. Allan said it shouldn't be a problem. MalwareBytes said I have something like 60 infections. Told it to clean it and it cleaned part of them and then said the rest couldn't be removed.

Allan suggested I post here and let you help me.

Also ran Memtest and am now at 185% coverage with 2 errors.

Can you help?

Thank You,

Sherry

BC AdBot (Login to Remove)

 


#2 jntkwx

jntkwx

  • Malware Response Team
  • 4,339 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New England, U.S.A.
  • Local time:06:07 PM

Posted 21 July 2011 - 11:09 AM

Hi Sherry,

:welcome: to BleepingComputer.

My name is Jason and I'll be helping you with your computer problems. You can call me by my screename jntkwx or Jason is fine.

Some things to remember while we are working together.

  • Do not run any other tool untill instructed to do so!
  • Please do not attach logs or put logs in code boxes.
  • Tell me about any problems that have occurred during the fix.
  • Tell me of any other symptoms you may be having as these can also help.
  • Do not run anything while running a fix.
  • If you don't understand a step, please ask for clarification before continuing with any future steps.

Click on the Watch Topic button and select Immediate Notification and click on proceed, this will help you to get notified faster when I have replied and make the cleaning process faster.

:step1: Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt.
  • Please post the contents of that document.

:step2: Please download MiniToolBox and run it.

Checkmark following boxes:
  • Report IE Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List last 10 Event Viewer log
  • List Users, Partitions and Memory size
Click Go and post the result.

:step3: Let's try rebooting into Safe Mode.
This can be done tapping the F8 key as soon as you start your computer
You will be brought to a menu with several options. Press the down arrow key on your keyboard until Safe Mode with Networking is selected. Press Enter. Please see here for additional details.

:step4: Once in Safe Mode with Networking, download Rkill

Run Rkill (renamed iExplore.exe).

Please be patient while Rkill looks for various malware programs and ends them. When it has finished, the black window will automatically close and you can continue with the next step. If it appears like Rkill did not stop the malware from running, please try running RKill again until the malware is no longer running.

If you are unable to download or run rkill from the main download, try these alternate download locations:

1. http://download.bleepingcomputer.com/grinler/rkill.com
2. http://download.bleepingcomputer.com/grinler/rkill.pif
3. http://download.bleepingcomputer.com/grinler/rkill.scr
4. http://download.bleepingcomputer.com/grinler/eXplorer.exe
5. http://download.bleepingcomputer.com/grinler/iExplore.exe
6. http://download.bleepingcomputer.com/grinler/uSeRiNiT.exe
7. http://download.bleepingcomputer.com/grinler/WiNlOgOn.exe
8. http://www.boredomsoft.org/hosted/rkill.exe
9. http://www.boredomsoft.org/hosted/rkill.com
10. http://www.boredomsoft.org/hosted/rkill.scr
11. http://www.boredomsoft.org/hosted/eXplorer.exe
12. http://www.boredomsoft.org/hosted/iExplore.exe


Do not reboot your computer after running RKill as the malware programs will start again!

:step5: Still in Safe Mode with Networking, open Malwarebytes, click on the Update tab, and click the check for Updates button.
  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Full Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

Troubleshoot Malwarebytes' Anti-Malware


:step6: Reboot into Normal mode. Next run Superantisypware (SAS):

Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download them from http://www.superantispyware.com/downloads/SASDEFINITIONS.EXE (copy and paste that website address) and save SASDEFINITIONS.EXE to your desktop. Then double-click on SASDEFINITIONS.EXE to install the definitions.)
  • In the Main Menu, click the Preferences... button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.
If you have a problem downloading, installing or getting SAS to run, try downloading and using the SUPERAntiSpyware Portable Scanner instead. Save the randomly named file (i.e. SAS_1710895.COM) to a USB drive or CD and transfer to the infected computer. Then double-click on it to launch and scan. The file is randomly named to help keep malware from blocking the scanner.

:step7: Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

    Posted Image
  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and be sure to re-enable your anti-virus, Firewall and any other security programs you had disabled.

IMPORTANT! If for some reason GMER refuses to run, try again.
If it still fails, try to UN-check "Devices" in right pane.
If still no joy, try to run it from Safe Mode.


In your next reply, please include:
  • SecurityCheck's checkup.txt file
  • MiniToolbox's Result.txt file
  • Malwarebytes' log file
  • SuperAntiSpyware log file
  • GMER log file
  • How's the computer running now? Please include a detailed description of anything out of the ordinary, including any error messages.

Regards,
Jason

 

Simple and easy ways to keep your computer safe and secure on the Internet

If I am helping you and have not returned in 48 hours, please feel free to send me a PM with a link to the topic.
My help is free... however, if you wish to show appreciation and support me personally fighting against malware, please consider a donation: btn_donate_SM.gif


#3 peanutsnana

peanutsnana
  • Topic Starter

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:06:07 PM

Posted 21 July 2011 - 11:40 AM

Jason,

Tried running the Security check. Lots of stuff going on in the lil black box, but once Notepad popped open, it was completely blank. I have Vista on my computer, will that make a difference?

#4 jntkwx

jntkwx

  • Malware Response Team
  • 4,339 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New England, U.S.A.
  • Local time:06:07 PM

Posted 21 July 2011 - 11:43 AM

No, having Vista installed shouldn't make a difference. Try running SecurityCheck in Safe Mode with Networking.
Regards,
Jason

 

Simple and easy ways to keep your computer safe and secure on the Internet

If I am helping you and have not returned in 48 hours, please feel free to send me a PM with a link to the topic.
My help is free... however, if you wish to show appreciation and support me personally fighting against malware, please consider a donation: btn_donate_SM.gif


#5 peanutsnana

peanutsnana
  • Topic Starter

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:06:07 PM

Posted 21 July 2011 - 11:59 AM

Just ran it in Safe Mode with Networking. Same response, lots going on in the black box but nothing popping up in notepad.

#6 jntkwx

jntkwx

  • Malware Response Team
  • 4,339 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New England, U.S.A.
  • Local time:06:07 PM

Posted 21 July 2011 - 12:12 PM

That's odd. Let's skip it and move on to step 2.
Regards,
Jason

 

Simple and easy ways to keep your computer safe and secure on the Internet

If I am helping you and have not returned in 48 hours, please feel free to send me a PM with a link to the topic.
My help is free... however, if you wish to show appreciation and support me personally fighting against malware, please consider a donation: btn_donate_SM.gif


#7 peanutsnana

peanutsnana
  • Topic Starter

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:06:07 PM

Posted 21 July 2011 - 12:15 PM

Should I stay in safe mode?

#8 peanutsnana

peanutsnana
  • Topic Starter

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:06:07 PM

Posted 21 July 2011 - 12:22 PM

MiniToolBox by Farbar
Ran by Roger & Sherry (administrator) on 21-07-2011 at 13:19:50
Windows Vista ™ Home Basic Service Pack 2 (X86)

***************************************************************************

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.
========================= Hosts content: =================================

::1 localhost

127.0.0.1 localhost

========================= IP Configuration: ================================

# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled


popd
# End of IPv4 configuration



Windows IP Configuration

Host Name . . . . . . . . . . . . : Home-PC
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No

Wireless LAN adapter Wireless Network Connection:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter
Physical Address. . . . . . . . . : 00-22-5F-BD-FA-A3
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes

Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Realtek PCIe FE Family Controller
Physical Address. . . . . . . . . : 00-1E-33-CC-7B-08
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::80f8:34e2:bb72:fb%10(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.1.64(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : Thursday, July 21, 2011 12:51:59 PM
Lease Expires . . . . . . . . . . : Friday, July 22, 2011 12:52:00 PM
Default Gateway . . . . . . . . . : 192.168.1.254
DHCP Server . . . . . . . . . . . : 192.168.1.254
DHCPv6 IAID . . . . . . . . . . . : 167779891
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-11-D3-86-30-00-1E-33-CB-37-66
DNS Servers . . . . . . . . . . . : 192.168.1.254
NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter Local Area Connection* 6:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : isatap.{0913D5A8-EAAD-4D04-821E-DF2C6404AAB0}
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 12:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : isatap.{D78AB608-BA18-49FB-B58E-A1044727D2B6}
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 13:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 02-00-54-55-4E-01
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 15:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : isatap.{D78AB608-BA18-49FB-B58E-A1044727D2B6}
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Server: dsldevice
Address: 192.168.1.254

Name: google.com
Addresses: 74.125.225.51
74.125.225.50
74.125.225.49
74.125.225.48
74.125.225.52



Pinging google.com [74.125.225.52] with 32 bytes of data:

Reply from 74.125.225.52: bytes=32 time=17ms TTL=55

Reply from 74.125.225.52: bytes=32 time=18ms TTL=55



Ping statistics for 74.125.225.52:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 17ms, Maximum = 18ms, Average = 17ms

Server: dsldevice
Address: 192.168.1.254

Name: yahoo.com
Addresses: 209.191.122.70
67.195.160.76
69.147.125.65
72.30.2.43
98.137.149.56



Pinging yahoo.com [209.191.122.70] with 32 bytes of data:

Reply from 209.191.122.70: bytes=32 time=64ms TTL=55

Reply from 209.191.122.70: bytes=32 time=63ms TTL=55



Ping statistics for 209.191.122.70:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 63ms, Maximum = 64ms, Average = 63ms



Pinging 127.0.0.1 with 32 bytes of data:

Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Reply from 127.0.0.1: bytes=32 time<1ms TTL=128



Ping statistics for 127.0.0.1:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 0ms, Maximum = 0ms, Average = 0ms

===========================================================================
Interface List
11 ...00 22 5f bd fa a3 ...... Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter
10 ...00 1e 33 cc 7b 08 ...... Realtek PCIe FE Family Controller
1 ........................... Software Loopback Interface 1
17 ...00 00 00 00 00 00 00 e0 isatap.{0913D5A8-EAAD-4D04-821E-DF2C6404AAB0}
16 ...00 00 00 00 00 00 00 e0 isatap.{D78AB608-BA18-49FB-B58E-A1044727D2B6}
12 ...02 00 54 55 4e 01 ...... Teredo Tunneling Pseudo-Interface
18 ...00 00 00 00 00 00 00 e0 isatap.{D78AB608-BA18-49FB-B58E-A1044727D2B6}
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.1.254 192.168.1.64 20
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
192.168.1.0 255.255.255.0 On-link 192.168.1.64 276
192.168.1.64 255.255.255.255 On-link 192.168.1.64 276
192.168.1.255 255.255.255.255 On-link 192.168.1.64 276
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 192.168.1.64 276
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 192.168.1.64 276
===========================================================================
Persistent Routes:
None

IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
1 306 ::1/128 On-link
10 276 fe80::/64 On-link
10 276 fe80::80f8:34e2:bb72:fb/128
On-link
1 306 ff00::/8 On-link
10 276 ff00::/8 On-link
===========================================================================
Persistent Routes:
None

========================= Event log errors: ===============================

Application errors:
==================
Error: (07/21/2011 00:53:25 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/21/2011 00:52:35 PM) (Source: EventSystem) (User: )
Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c

Error: (07/21/2011 00:08:55 PM) (Source: Application Error) (User: )
Description: Faulting application YahooMessenger.exe, version 10.0.0.1251, time stamp 0x4b8ed4b4, faulting module ntdll.dll, version 6.0.6002.18327, time stamp 0x4cb73436, exception code 0xc000012f, fault offset 0x00009f7d,
process id 0xb60, application start time 0xYahooMessenger.exe0.

Error: (07/21/2011 11:03:28 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/21/2011 10:03:13 AM) (Source: Application Error) (User: )
Description: Faulting application YahooMessenger.exe, version 10.0.0.1251, time stamp 0x4b8ed4b4, faulting module ntdll.dll, version 6.0.6002.18327, time stamp 0x4cb73436, exception code 0xc000012f, fault offset 0x00009f7d,
process id 0xb30, application start time 0xYahooMessenger.exe0.

Error: (07/21/2011 10:02:33 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/21/2011 00:34:21 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/21/2011 00:33:43 AM) (Source: Application Error) (User: )
Description: Faulting application YahooMessenger.exe, version 10.0.0.1251, time stamp 0x4b8ed4b4, faulting module ntdll.dll, version 6.0.6002.18327, time stamp 0x4cb73436, exception code 0xc000012f, fault offset 0x00009f7d,
process id 0xfd0, application start time 0xYahooMessenger.exe0.

Error: (07/21/2011 00:16:21 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/21/2011 00:15:57 AM) (Source: Application Error) (User: )
Description: Faulting application YahooMessenger.exe, version 10.0.0.1251, time stamp 0x4b8ed4b4, faulting module ntdll.dll, version 6.0.6002.18327, time stamp 0x4cb73436, exception code 0xc000012f, fault offset 0x00009f7d,
process id 0x9b8, application start time 0xYahooMessenger.exe0.


System errors:
=============
Error: (07/21/2011 00:56:38 PM) (Source: DCOM) (User: )
Description: 1084WSearch{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

Error: (07/21/2011 00:53:25 PM) (Source: Service Control Manager) (User: )
Description: Avgldx86
Avgmfx86
spldr
Wanarpv6

Error: (07/21/2011 00:53:25 PM) (Source: Service Control Manager) (User: )
Description: Computer BrowserServer%%1068

Error: (07/21/2011 00:52:50 PM) (Source: DCOM) (User: )
Description: 1084WSearch{9E175B6D-F52A-11D8-B9A5-505054503030}

Error: (07/21/2011 00:52:35 PM) (Source: DCOM) (User: )
Description: 1084EventSystem{1BE1F766-5536-11D1-B726-00C04FB926AF}

Error: (07/21/2011 00:52:27 PM) (Source: DCOM) (User: )
Description: 1084ShellHWDetection{DD522ACC-F821-461A-A407-50B198B896DC}

Error: (07/21/2011 00:51:58 PM) (Source: EventLog) (User: )
Description: The previous system shutdown at 12:50:08 PM on 7/21/2011 was unexpected.

Error: (07/21/2011 11:02:07 AM) (Source: EventLog) (User: )
Description: The previous system shutdown at 10:50:56 AM on 7/21/2011 was unexpected.

Error: (07/21/2011 10:01:19 AM) (Source: EventLog) (User: )
Description: The previous system shutdown at 9:51:13 AM on 7/21/2011 was unexpected.

Error: (07/21/2011 00:32:58 AM) (Source: EventLog) (User: )
Description: The previous system shutdown at 12:21:42 AM on 7/21/2011 was unexpected.


Microsoft Office Sessions:
=========================

========================= Memory info: ===================================

Percentage of memory in use: 27%
Total physical RAM: 1915.26 MB
Available physical RAM: 1396.42 MB
Total Pagefile: 4071.8 MB
Available Pagefile: 3694.38 MB
Total Virtual: 2047.88 MB
Available Virtual: 1979.2 MB

========================= Partitions: =====================================

1 Drive c: (SQ004981V02) (Fixed) (Total:140.37 GB) (Free:77.42 GB) NTFS

========================= Users: ========================================

User accounts for \\HOME-PC

Administrator Guest Roger & Sherry


== End of log ==

#9 jntkwx

jntkwx

  • Malware Response Team
  • 4,339 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New England, U.S.A.
  • Local time:06:07 PM

Posted 21 July 2011 - 12:29 PM

:thumbup2: Looking good so far. Yes, you can stay in Safe Mode with Networking for both Rkill and Malwarebytes. However, SuperAntiSpyware cannot install in Safe Mode, so reboot into Normal Mode when you get to that step.
Regards,
Jason

 

Simple and easy ways to keep your computer safe and secure on the Internet

If I am helping you and have not returned in 48 hours, please feel free to send me a PM with a link to the topic.
My help is free... however, if you wish to show appreciation and support me personally fighting against malware, please consider a donation: btn_donate_SM.gif


#10 peanutsnana

peanutsnana
  • Topic Starter

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:06:07 PM

Posted 21 July 2011 - 01:24 PM

Jason,

This is all I will be able to do today. Have to go to work, but will continue tomorrow when I get home.

Thanx so much for your help and your patience.

Sherry


Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 7223

Windows 6.0.6002 Service Pack 2 (Safe Mode)
Internet Explorer 9.0.8112.16421

7/21/2011 2:22:37 PM
mbam-log-2011-07-21 (14-22-37).txt

Scan type: Full scan (C:\|)
Objects scanned: 321514
Time elapsed: 45 minute(s), 51 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\APPID\MightyMagooText.DLL (PUP.MightyMagoo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\AppDataLow\mmagootl (PUP.MightyMagoo) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

#11 jntkwx

jntkwx

  • Malware Response Team
  • 4,339 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New England, U.S.A.
  • Local time:06:07 PM

Posted 21 July 2011 - 02:06 PM

When you get back, please continue with steps 6 and 7 from my first post.
Regards,
Jason

 

Simple and easy ways to keep your computer safe and secure on the Internet

If I am helping you and have not returned in 48 hours, please feel free to send me a PM with a link to the topic.
My help is free... however, if you wish to show appreciation and support me personally fighting against malware, please consider a donation: btn_donate_SM.gif


#12 peanutsnana

peanutsnana
  • Topic Starter

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:06:07 PM

Posted 22 July 2011 - 02:47 PM

Jason,

Wow, those 2 steps took forever! Hope I'm posting right.

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/22/2011 at 11:37 AM

Application Version : 4.55.1000

Core Rules Database Version : 7443
Trace Rules Database Version: 5255

Scan type : Complete Scan
Total Scan Time : 03:22:48

Memory items scanned : 677
Memory threats detected : 0
Registry items scanned : 8327
Registry threats detected : 23
File items scanned : 165433
File threats detected : 75

Adware.IWinGames
HKLM\Software\Classes\CLSID\{8CA5ED52-F3FB-4414-A105-2E3491156990}
HKCR\CLSID\{8CA5ED52-F3FB-4414-A105-2E3491156990}
HKCR\CLSID\{8CA5ED52-F3FB-4414-A105-2E3491156990}
HKCR\CLSID\{8CA5ED52-F3FB-4414-A105-2E3491156990}\InprocServer32
HKCR\CLSID\{8CA5ED52-F3FB-4414-A105-2E3491156990}\InprocServer32#ThreadingModel
HKCR\CLSID\{8CA5ED52-F3FB-4414-A105-2E3491156990}\ProgID
HKCR\CLSID\{8CA5ED52-F3FB-4414-A105-2E3491156990}\Programmable
HKCR\CLSID\{8CA5ED52-F3FB-4414-A105-2E3491156990}\VersionIndependentProgID
HKCR\IEHlprObj.IEHlprObj.1
HKCR\IEHlprObj.IEHlprObj.1\CLSID
HKCR\IEHlprObj.IEHlprObj
C:\PROGRA~1\IWINGA~1\IWINGA~1.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8CA5ED52-F3FB-4414-A105-2E3491156990}
HKU\S-1-5-21-748510194-217282370-3783705229-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8CA5ED52-F3FB-4414-A105-2E3491156990}
C:\PROGRAM FILES\IWIN GAMES\IWINGAMESHOOKIE.DLL

Adware.Tracking Cookie
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\roger_&_sherry@collective-media[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\roger_&_sherry@invitemedia[2].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\roger_&_sherry@ad.yieldmanager[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\roger_&_sherry@content.yieldmanager[2].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\roger_&_sherry@ad.wsod[2].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\roger_&_sherry@bs.serving-sys[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\roger_&_sherry@advertising[2].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\roger_&_sherry@content.yieldmanager[3].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\roger_&_sherry@doubleclick[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\roger_&_sherry@serving-sys[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\roger_&_sherry@questionmarket[2].txt
static.xxxmatch.com [ C:\Users\Roger & Sherry\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\XQQZLCM8 ]
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@ad.wsod[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@ad.wsod[2].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@ad.wsod[3].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@ad.wsod[4].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@ad.yieldmanager[2].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@adbrite[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@ads.bleepingcomputer[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@ads.crakmedia[2].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@advertising[2].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@advertising[3].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@advertising[4].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@adxpose[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@apmebf[2].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@atdmt[2].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@bizrate[2].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@bs.serving-sys[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@casalemedia[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@collective-media[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@collective-media[2].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@content.yieldmanager[2].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@content.yieldmanager[3].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@content.yieldmanager[4].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@doubleclick[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@fastclick[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@imrworldwide[2].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@in.getclicky[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@invitemedia[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@invitemedia[2].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@invitemedia[3].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@legolas-media[2].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@lfstmedia[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@lfstmedia[2].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@media6degrees[2].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@media6degrees[3].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@mediabrandsww[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@mediaplex[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@nextag[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@questionmarket[2].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@questionmarket[3].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@questionmarket[4].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@questionmarket[5].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@ru4[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@serving-sys[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@statcounter[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@trafficmp[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@tribalfusion[2].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@wt.xxxmatch[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@www.googleadservices[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@www.googleadservices[2].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@www.googleadservices[3].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@www.googleadservices[4].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@www.googleadservices[5].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@www.xxxmatch[2].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@xxxmatch[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@yieldmanager[1].txt
C:\Users\Roger & Sherry\AppData\Roaming\Microsoft\Windows\Cookies\Low\roger_&_sherry@zedo[1].txt
.doubleclick.net [ C:\Windows\System32\config\systemprofile\AppData\Roaming\Mozilla\Firefox\Profiles\cydk8n1v.default\cookies.sqlite ]
.adserver.adtechus.com [ C:\Windows\System32\config\systemprofile\AppData\Roaming\Mozilla\Firefox\Profiles\cydk8n1v.default\cookies.sqlite ]
.serving-sys.com [ C:\Windows\System32\config\systemprofile\AppData\Roaming\Mozilla\Firefox\Profiles\cydk8n1v.default\cookies.sqlite ]
.serving-sys.com [ C:\Windows\System32\config\systemprofile\AppData\Roaming\Mozilla\Firefox\Profiles\cydk8n1v.default\cookies.sqlite ]

Adware.MyWebSearch/FunWebProducts
HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid
HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid32
HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib
HKCR\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib#Version
HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid
HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid32
HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib
HKCR\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib#Version

Trojan.Downloader-IExplore/Fake
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\DOWNLOADS\IEXPLORE.EXE





GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-07-22 15:38:55
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 TOSHIBA_ rev.FG01
Running: gmer.exe; Driver: C:\Users\ROGER&~1\AppData\Local\Temp\pwtdipow.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xA82017A0]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS ZwTerminateProcess [0x8D398620]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xA82018E4]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xA8201980]

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!KeSetEvent + 3F1 826F3B74 4 Bytes [A0, 17, 20, A8]
.text ntkrnlpa.exe!KeSetEvent + 621 826F3DA4 8 Bytes [20, 86, 39, 8D, E4, 18, 20, ...]
.text ntkrnlpa.exe!KeSetEvent + 681 826F3E04 4 Bytes [80, 19, 20, A8]
.text C:\Windows\system32\DRIVERS\tos_sps32.sys section is writeable [0x88355480, 0x3C939, 0xE8000020]
.dsrt C:\Windows\system32\DRIVERS\tos_sps32.sys unknown last section [0x88396900, 0x3CA, 0x48000040]
? C:\Users\ROGER&~1\AppData\Local\Temp\pwtdipow.sys The system cannot find the file specified. !

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Internet Explorer\iexplore.exe[1424] USER32.dll!EnableWindow 76BECD8B 5 Bytes JMP 708198BC C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1424] USER32.dll!DialogBoxParamW 76C110B0 5 Bytes JMP 707715E3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1424] USER32.dll!DialogBoxIndirectParamW 76C12EF5 5 Bytes JMP 70965E86 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1424] USER32.dll!DialogBoxParamA 76C28152 5 Bytes JMP 70965E21 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1424] USER32.dll!DialogBoxIndirectParamA 76C2847D 5 Bytes JMP 70965EEB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1424] USER32.dll!MessageBoxIndirectA 76C3D4D9 5 Bytes JMP 70965DA8 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1424] USER32.dll!MessageBoxIndirectW 76C3D5D3 5 Bytes JMP 70965D2F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1424] USER32.dll!MessageBoxExA 76C3D639 5 Bytes JMP 70965CCB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1424] USER32.dll!MessageBoxExW 76C3D65D 5 Bytes JMP 70965C67 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] kernel32.dll!CreateThread 76A1CB2E 5 Bytes JMP 707D71CB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!CreateDialogParamW 76BE72A2 5 Bytes JMP 709661F0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!GetAsyncKeyState 76BE863C 5 Bytes JMP 707BDC69 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!SetWindowsHookExW 76BE87AD 5 Bytes JMP 7081204C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!CallNextHookEx 76BE8E3B 1 Byte [E9]
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!CallNextHookEx 76BE8E3B 5 Bytes JMP 70837A3F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!UnhookWindowsHookEx 76BE98DB 5 Bytes JMP 7085E9F8 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!EnableWindow 76BECD8B 5 Bytes JMP 708198BC C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!DefWindowProcA 76BEDB88 7 Bytes JMP 707D93F5 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!CreateWindowExA 76BEDC2A 2 Bytes JMP 707E3223 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!CreateWindowExA + 3 76BEDC2D 2 Bytes [BF, F9]
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!CreateWindowExW 76BF1305 5 Bytes JMP 7083FE1F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!GetKeyState 76BF8CB1 5 Bytes JMP 707BDB43 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!DefWindowProcW 76C003B4 7 Bytes JMP 70837AA2 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!IsDialogMessageW 76C00745 5 Bytes JMP 70966964 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!CreateDialogParamA 76C017AA 5 Bytes JMP 709661B8 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!IsDialogMessage 76C01847 5 Bytes JMP 7096693C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!CreateDialogIndirectParamA 76C026F1 5 Bytes JMP 70966228 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!CreateDialogIndirectParamW 76C09A62 5 Bytes JMP 70966260 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!SetKeyboardState 76C10987 5 Bytes JMP 7096722D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!DialogBoxParamW 76C110B0 5 Bytes JMP 707715E3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!DialogBoxIndirectParamW 76C12EF5 5 Bytes JMP 70965E86 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!SendInput 76C12F75 5 Bytes JMP 709671D5 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!EndDialog 76C1326E 5 Bytes JMP 70966C10 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!SetCursorPos 76C26FB2 5 Bytes JMP 709672AE C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!DialogBoxParamA 76C28152 5 Bytes JMP 70965E21 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!DialogBoxIndirectParamA 76C2847D 5 Bytes JMP 70965EEB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!MessageBoxIndirectA 76C3D4D9 5 Bytes JMP 70965DA8 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!MessageBoxIndirectW 76C3D5D3 5 Bytes JMP 70965D2F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!MessageBoxExA 76C3D639 5 Bytes JMP 70965CCB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!MessageBoxExW 76C3D65D 5 Bytes JMP 70965C67 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] USER32.dll!keybd_event 76C3D972 5 Bytes JMP 70967192 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] SHELL32.dll!SHRestricted + D95 75DC89A8 4 Bytes [37, 01, E9, 65]
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] SHELL32.dll!SHRestricted + D9D 75DC89B0 8 Bytes CALL 5ED36B1A
.text C:\Program Files\Internet Explorer\iexplore.exe[3556] ole32.dll!OleLoadFromStream 76D21E80 5 Bytes JMP 7096666E C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [65E84743] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [65E84743] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SearchPathW] [65E90206] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [65E85E47] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CopyFileW] [65E9BBBD] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!MoveFileW] [65E9DFF5] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!DeleteFileW] [65E9C77D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [65E97EBA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetCurrentDirectoryW] [65E9F46C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindClose] [65E9F8B9] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindNextFileW] [65EA0736] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindFirstFileW] [65E9FC5F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [65E86CA2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateFileW] [65E86367] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!WritePrivateProfileStringW] [65E9B4D7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [65E84DAB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [65E84743] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetPrivateProfileStringW] [65E9AB47] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryInfoKeyW] [65E914BD] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegEnumValueW] [65E90D90] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegOpenKeyExW] [65E86035] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryValueExW] [65E871F8] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegDeleteKeyW] [65EA332D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCreateKeyExW] [65E91932] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCloseKey] [65E86612] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [65E85E47] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [65E86CA2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CopyFileW] [65E9BBBD] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [65E84743] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [65E84DAB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CreateFileW] [65E86367] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SearchPathW] [65E90206] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!DeleteFileW] [65E9C77D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindClose] [65E9F8B9] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileA] [65E9F90C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindNextFileA] [65EA0697] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileW] [65E9FC5F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindNextFileW] [65EA0736] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesA] [65E90A47] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetCurrentDirectoryA] [65E9EF43] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFileAttributesA] [65E99195] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateDirectoryA] [65E9E6AB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!RemoveDirectoryA] [65E9EC67] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DeleteFileA] [65E9C61D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesW] [65E85EE2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetCurrentDirectoryW] [65E9F46C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFileAttributesW] [65E99307] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateDirectoryW] [65E86211] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DeleteFileW] [65E9C77D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!MoveFileW] [65E9DFF5] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!RemoveDirectoryW] [65E9EDD3] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!MoveFileA] [65E9DF29] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [65E84743] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [65E86CA2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [65E97B50] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [65E97EBA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileA] [65E8F159] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileW] [65E86367] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryW] [65E84DAB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [65E84DAB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!ReplaceFileW] [65E9E3C3] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!WritePrivateProfileStringW] [65E9B4D7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringW] [65E9AB47] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringA] [65E9A9A3] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW] [65E9C77D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [65E85E47] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesW] [65E99307] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileW] [65E86367] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileW] [65E9FC5F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileW] [65EA0736] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathW] [65E90206] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesW] [65E85EE2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesA] [65E99195] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileA] [65E8F159] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileA] [65E9F90C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileA] [65EA0697] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindClose] [65E9F8B9] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathA] [65E9F229] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesA] [65E90A47] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [65E86CA2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [65E84743] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpW] [65E9D62B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpA] [65E9D4C3] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCloseKey] [65E86612] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExA] [65EA2F1D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyA] [65EA31E5] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyA] [65EA3A97] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExA] [65E8EE25] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExW] [65E91932] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExW] [65E86035] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExW] [65E907C1] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueW] [65EA38EB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyW] [65EA332D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyW] [65E914BD] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExW] [65E871F8] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueW] [65E90D90] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyW] [65EA3DF1] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExA] [65E8F273] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueA] [65EA3F57] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyA] [65EA3C8F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExA] [65E8FC2D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionW] [65E9A4D9] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindNextFileW] [65EA0736] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!ReplaceFileW] [65E9E3C3] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionNamesW] [65E9A80B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileSectionW] [65E9B1B1] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileStringW] [65E9B4D7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateHardLinkW] [65E9C409] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetCurrentDirectoryW] [65E9F46C] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CopyFileW] [65E9BBBD] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetBinaryTypeW] [65E99EB7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [65E85E47] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [65E97EBA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileW] [65E9DFF5] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindFirstFileW] [65E9FC5F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindClose] [65E9F8B9] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameA] [65E99A5F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesA] [65E90A47] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SearchPathW] [65E90206] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileIntW] [65E9A1B5] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileStringW] [65E9AB47] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!RemoveDirectoryW] [65E9EDD3] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateDirectoryW] [65E86211] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!DeleteFileW] [65E9C77D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetFileAttributesW] [65E99307] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesW] [65E85EE2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW] [65E9E02D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameW] [65E99BD5] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [65E84DAB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateFileW] [65E86367] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesExW] [65E995FB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [65E86CA2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetLongPathNameW] [65E998EB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [USER32.dll!LoadImageW] [65E9CA7B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [USER32.dll!WinHelpW] [65E9D62B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [USER32.dll!PrivateExtractIconsW] [65E9D08B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!AssocQueryStringByKeyW] [65EA0D67] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHCreateStreamOnFileW] [65E8F68D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!AssocQueryKeyW] [65E8F77F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!AssocQueryStringW] [65EA0CB3] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHDeleteKeyA] [65EA1E9E] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathCombineW] [65EA1001] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHOpenRegStream2W] [65E8FA8D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsDirectoryW] [65EA123E] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsURLW] [65E8F9E1] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsRootA] [65EA14AE] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsRootW] [65EA14FC] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathStripToRootW] [65EA1BCA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathFindOnPathW] [65EA10FD] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathStripPathW] [65EA1B32] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathRemoveArgsW] [65EA195A] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegGetBoolUSValueW] [65E8E1CD] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathSkipRootW] [65EA1A9A] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsDirectoryEmptyW] [65EA12DA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsSystemFolderW] [65EA159B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsDirectoryA] [65EA11F0] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathRelativePathToW] [65EA18B6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathBuildRootA] [65EA0EBA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegGetPathW] [65EA26D5] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegSetPathW] [65EA28A3] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegGetUSValueW] [65E873B0] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathCreateFromUrlW] [65E900E0] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHQueryValueExW] [65E8FB73] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHRegGetValueW] [65E84904] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsNetworkPathW] [65EA1376] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsUNCServerShareW] [65EA1724] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsUNCServerW] [65EA1688] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathUnExpandEnvStringsW] [65EA1C18] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathMakeSystemFolderW] [65EA180E] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsUNCW] [65E8F993] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathIsRelativeW] [65E85C88] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHGetValueW] [65E848A7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathBuildRootW] [65EA0F0B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHDeleteValueW] [65EA1F94] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHSetValueW] [65EA2ACE] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHEnumKeyExW] [65EA203F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHEnumValueW] [65EA20F6] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!PathFileExistsW] [65E9008B] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [SHLWAPI.dll!SHDeleteKeyW] [65EA1EEF] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] [65E98B86] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindClose] [65E9F8B9] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW] [65E9FC5F] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [65E85E47] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SearchPathW] [65E90206] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [65E97EBA] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DeleteFileW] [65E9C77D] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetShortPathNameW] [65E99BD5] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesExW] [65E995FB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW] [65E86367] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [65E84DAB] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesW] [65E85EE2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [65E86CA2] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!PathUnExpandEnvStringsA] [65E8F639] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHDeleteKeyA] [65EA1E9E] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHDeleteValueW] [65EA1F94] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHSetValueA] [65EA2A71] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHSetValueW] [65EA2ACE] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!PathCreateFromUrlW] [65E900E0] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHRegGetUSValueA] [65E86445] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHGetValueA] [65E84C2A] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHGetValueW] [65E848A7] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHRegGetValueW] [65E84904] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\WININET.dll [SHLWAPI.dll!SHRegGetValueA] [65E864A8] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [65E84743] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [65E84743] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [65E84743] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [65E84743] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [65E84743] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [65E84743] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\SAMLIB.dll [KERNEL32.dll!GetProcAddress] [65E84743] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3556] @ C:\Windows\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [65E84743] C:\Program Files\Internet Explorer\IEShims.dll (Internet Explorer Compatibility Shims/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----

#13 jntkwx

jntkwx

  • Malware Response Team
  • 4,339 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New England, U.S.A.
  • Local time:06:07 PM

Posted 22 July 2011 - 04:06 PM

Yes, you did post correctly. :thumbup2:

Looks like SuperAntiSpyware got rid of several things. How's the computer running now?

:step1: Let's try running SecurityCheck again.
Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt.
  • Please post the contents of that document.

:step2: Rerun Malwarebytes (in Normal Mode this time)
Open Malwarebytes, click on the Update tab, and click the check for Updates button.
  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Full Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

:step3: I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on this link to open ESET OnlineScan in a new window.
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image
      icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.


In your next reply, please include:
  • SecurityCheck log file
  • Malwarebytes' log file
  • ESET log file
  • How's the computer running now?

Regards,
Jason

 

Simple and easy ways to keep your computer safe and secure on the Internet

If I am helping you and have not returned in 48 hours, please feel free to send me a PM with a link to the topic.
My help is free... however, if you wish to show appreciation and support me personally fighting against malware, please consider a donation: btn_donate_SM.gif


#14 peanutsnana

peanutsnana
  • Topic Starter

  • Members
  • 57 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:06:07 PM

Posted 25 July 2011 - 01:46 PM

Ran MalwareBytes again this morning. Halfway thru a box popped up that said it had stopped working and needed to close. So I went on to the next step.

This is what came up with ESET:


C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application cleaned by deleting - quarantined
C:\Users\Roger & Sherry\AppData\Local\Temp\PageRage-SilentInstaller.exe Win32/Adware.Yontoo.A application cleaned by deleting - quarantined
C:\Users\Roger & Sherry\AppData\Local\Temp\mia3C16.tmp\data\OFFLINE\D038292B\DBD9B16A\Launcher.exe Win32/RegistryBooster application cleaned by deleting - quarantined
C:\Users\Roger & Sherry\AppData\Local\Temp\mia3C16.tmp\data\OFFLINE\D038292B\DBD9B16A\rbmonitor.exe Win32/RegistryBooster application cleaned by deleting - quarantined
C:\Users\Roger & Sherry\AppData\Local\Temp\mia3C16.tmp\data\OFFLINE\D038292B\DBD9B16A\rbnotifier.exe Win32/RegistryBooster application cleaned by deleting - quarantined
C:\Users\Roger & Sherry\AppData\Local\Temp\mia3C16.tmp\data\OFFLINE\D038292B\DBD9B16A\rb_move_serial.exe Win32/RegistryBooster application cleaned by deleting - quarantined
C:\Users\Roger & Sherry\AppData\Local\Temp\mia3C16.tmp\data\OFFLINE\D038292B\DBD9B16A\rb_ubm.exe Win32/RegistryBooster application cleaned by deleting - quarantined
C:\Users\Roger & Sherry\AppData\Local\Temp\mia3C16.tmp\data\OFFLINE\D038292B\DBD9B16A\registrybooster.exe Win32/RegistryBooster application cleaned by deleting - quarantined
C:\Users\Roger & Sherry\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\126cbbd9-6cba2db9 a variant of Java/TrojanDownloader.OpenStream.NBF trojan deleted - quarantined
C:\Users\Roger & Sherry\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\359030a3-2e8df0a7 multiple threats deleted - quarantined

#15 jntkwx

jntkwx

  • Malware Response Team
  • 4,339 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New England, U.S.A.
  • Local time:06:07 PM

Posted 25 July 2011 - 01:56 PM

Hi peanutsnana,

:step1: Clear Cache/Temp Files
Download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.

:step2: Rerun Security Check
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt.
  • Please post the contents of that document.

:step2: Rerun Malwarebytes
Open Malwarebytes, click on the Update tab, and click the check for Updates button.
  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

If you have trouble updating, troubleshoot Malwarebytes' Anti-Malware

In your next reply, please include:
  • Security Check log file
  • Malwarebytes log file
  • How's the computer running now? Please provide a detailed description any remainging problems, detailed word-for-word error messages that you are receiving, and/or screenshots of strange behavior.

Edited by jntkwx, 25 July 2011 - 01:56 PM.

Regards,
Jason

 

Simple and easy ways to keep your computer safe and secure on the Internet

If I am helping you and have not returned in 48 hours, please feel free to send me a PM with a link to the topic.
My help is free... however, if you wish to show appreciation and support me personally fighting against malware, please consider a donation: btn_donate_SM.gif





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users