Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

IE redirecting via ohtgnoenriga.com + getting pop ups

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

IE redirecting via ohtgnoenriga.com + getting pop ups

Unread postby bonsers » September 3rd, 2010, 6:20 pm

Hello.

My computer has significantly slowed down, is mostly redirecting me to a blank page via "www.ohtgnoenriga.com..." and has also started getting pop ups. Please can you help.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:15:59, on 03/09/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\Explorer.EXE
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\robert\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Dell Support Center\gs_agent\dsc.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Users\robert\Desktop\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/USCON/2
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [Conime] %windir%\system32\conime.exe
O4 - HKLM\..\Run: [EKIJ5000StatusMonitor] C:\Windows\system32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\robert\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [XA5RJ9EADJ] C:\Users\robert\AppData\Local\Temp\Ifh.exe
O4 - HKCU\..\Run: [Esqxqdrpan] rundll32 "C:\Users\robert\AppData\Roaming\fr-FRW.dll",UZVSEJTHIU
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com.edgesuite.net ... plugin.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\aestsrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Kodak AiO Network Discovery Service - Eastman Kodak Company - C:\Program Files\Kodak\AiO\Center\EKDiscovery.exe
O23 - Service: Kodak AiO Device Service (KodakSvc) - Eastman Kodak Company - C:\Program Files\Kodak\AiO\center\KodakSvc.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE

--
End of file - 11824 bytes



Acrobat.com
Acrobat.com
Adobe AIR
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.3
Advanced Audio FX Engine
aiofw
aioprnt
aioscnnr
Bonjour
center
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
Dell DataSafe Online
Dell Dock
Dell Edoc Viewer
Dell Getting Started Guide
Dell Support Center (Support Software)
Dell Touchpad
Dell Video Chat
Dell Webcam Central
Dell Wireless WLAN Card Utility
Driving Test Success 2007/8
Freecorder 2.3 (with Skype Call Recording)
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
Google Update Helper
GoToAssist 8.0.0.514
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Integrated Webcam Driver (1.00.04.0310)
Intel® Matrix Storage Manager
Java(TM) 6 Update 13
Junk Mail filter update
KODAK AiO Home Centre
ksDIP
Live! Cam Avatar Creator
McAfee SecurityCenter
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Client Profile
Microsoft Choice Guard
Microsoft Default Manager
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
PowerDVD DX
PreReq
QuickSet
Replay AV 8
Replay Screencast 1.21
Roxio Creator Audio
Roxio Creator Copy
Roxio Creator Data
Roxio Creator DE
Roxio Creator DE
Roxio Creator Tools
Roxio Express Labeler 3
Roxio Update Manager
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for 2007 Microsoft Office System (KB982312)
Security Update for 2007 Microsoft Office System (KB982331)
Security Update for Microsoft Office Excel 2007 (KB982308)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB982135)
Security Update for Windows Media Encoder (KB979332)
Skype™ 4.1
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Toolbar
Windows Live Upload Tool
Windows Live Writer
Windows Media Encoder 9 Series
Windows Media Encoder 9 Series
Windows Media Player Firefox Plugin
WinRAR archiver
bonsers
Regular Member
 
Posts: 15
Joined: July 26th, 2010, 2:02 pm
Advertisement
Register to Remove

Re: IE redirecting via ohtgnoenriga.com + getting pop ups

Unread postby peku006 » September 5th, 2010, 4:02 am

Hello and welcome to Malware Removal.

My name is peku006 and I will be helping you to remove any infection(s) that you may have.
I will be giving you a series of instructions that need to be followed in the order in which I give them to you.

Please observe these rules while we work:

  • If you don't know or understand something please don't hesitate to ask
  • Please DO NOT run any other tools or scans whilst I am helping you.
  • It is important that you reply to this thread. Do not start a new topic.
  • DO NOT attach logs unless requested to. Please copy/paste all requested logs into your replies.
  • Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
  • Absence of symptoms does not mean that everything is clear.

We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:
This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
If you need help to disable your protection programs see here.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply

Thanks peku006
User avatar
peku006
MRU Emeritus
MRU Emeritus
 
Posts: 3357
Joined: May 14th, 2007, 2:18 pm
Location: Norway

Re: IE redirecting via ohtgnoenriga.com + getting pop ups

Unread postby bonsers » September 6th, 2010, 11:11 am

Thanks for the reply. Here is ComboFix.txt

ComboFix 10-09-04.06 - robert 06/09/2010 15:55:55.1.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.44.1033.18.3032.1758 [GMT 1:00]
Running from: c:\users\robert\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job

.
((((((((((((((((((((((((( Files Created from 2010-08-06 to 2010-09-06 )))))))))))))))))))))))))))))))
.

2010-09-06 15:03 . 2010-09-06 15:03 -------- d-----w- c:\users\Default\AppData\Local\temp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-06 14:39 . 2010-02-15 20:59 -------- d-----w- c:\users\robert\AppData\Roaming\Skype
2010-09-06 14:35 . 2010-02-15 21:12 -------- d-----w- c:\users\robert\AppData\Roaming\skypePM
2010-07-26 17:54 . 2009-10-18 16:08 -------- d-----w- c:\program files\McAfee
2010-07-26 15:26 . 2010-07-26 15:25 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-25 00:42 . 2010-07-25 00:42 102400 --sha-r- c:\users\robert\AppData\Roaming\fr-FRW.dll
2010-07-25 00:42 . 2010-07-25 00:42 102400 --sha-r- c:\users\robert\AppData\Roaming\fr-FRW.dll
2010-07-25 00:42 . 2010-07-25 00:40 -------- d-----w- c:\program files\Replay Screencast
2010-07-25 00:40 . 2010-07-25 00:40 -------- d-----w- c:\program files\Windows Media Components
2010-07-25 00:39 . 2010-07-19 17:52 737280 ----a-w- c:\windows\iun6002.exe
2010-07-19 18:03 . 2010-07-19 18:01 -------- d-----w- c:\program files\Replay AV 8
2010-07-19 17:56 . 2010-07-19 17:52 -------- d-----w- c:\program files\Freecorder
2010-07-15 14:18 . 2009-10-18 16:09 130424 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2010-07-15 02:03 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-07-08 20:32 . 2009-10-22 22:07 -------- d-----w- c:\programdata\CyberLink
2010-07-07 12:57 . 2009-10-22 10:02 59464 ----a-w- c:\users\robert\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-27 11:59 . 2010-06-27 11:59 501936 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtb5A80.tmp.exe
2009-12-06 16:22 . 2009-12-06 16:22 6 ----a-w- c:\program files\Common Files\UnInstallCompleted.tmp
2009-10-18 16:05 . 2009-10-18 16:05 75 --sh--r- c:\windows\CT4CET.bin
2005-07-14 18:31 . 2006-05-24 16:37 27648 --sha-w- c:\windows\System32\AVSredirect.dll
2009-10-18 17:53 . 2009-04-11 19:01 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"Google Update"="c:\users\robert\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-10-22 133104]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-10-22 39408]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"Esqxqdrpan"="c:\users\robert\AppData\Roaming\fr-FRW.dll" [2010-07-25 102400]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-05-08 1516840]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-05-10 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-05-10 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-05-10 150552]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-12-21 3810304]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-06-15 178712]
"Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline.exe" [2009-07-07 1779952]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-02-05 128232]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2009-06-24 409744]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-06-03 206064]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-10-22 122880]
"Conime"="c:\windows\system32\conime.exe" [2009-04-11 69120]
"EKIJ5000StatusMonitor"="c:\windows\system32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2009-04-07 1511424]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-05-11 483428]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

c:\users\robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-6-30 1316192]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-6-30 1316192]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2009-10-18 15:53 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):38,c0,8a,56,97,58,ca,01

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 135664]
R3 CryptOSD;Phoenix CryptOSD Device Driver;c:\windows\system32\DRIVERS\CryptOSD.sys [x]
R3 CtAudDrv;Provides advanced audio effects for audio devices.;c:\windows\system32\Drivers\CtAudDrv.sys [2009-05-28 134144]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\aestsrv.exe [2009-05-11 81920]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-12-18 155648]
S2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\Kodak\AiO\Center\EKDiscovery.exe [2009-05-04 279960]
S2 KodakSvc;Kodak AiO Device Service;c:\program files\Kodak\AiO\center\KodakSvc.exe [2009-04-17 32768]
S2 yksvc;Marvell Yukon Service;c:\windows\System32\svchost.exe [2008-01-21 21504]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2009-06-15 143968]
S3 OA013Ufd;Creative Camera OA013 Upper Filter Driver;c:\windows\system32\DRIVERS\OA013Ufd.sys [2009-03-06 133632]
S3 OA013Vid;Creative Camera OA013 Function Driver;c:\windows\system32\DRIVERS\OA013Vid.sys [2009-03-09 271712]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
yksvcs REG_MULTI_SZ yksvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-09-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 13:13]

2010-09-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 13:13]

2010-07-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-98094027-3536932928-684913470-1000Core.job
- c:\users\robert\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-22 11:08]

2010-09-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-98094027-3536932928-684913470-1000UA.job
- c:\users\robert\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-22 11:08]

2010-09-06 c:\windows\Tasks\User_Feed_Synchronization-{ECBAEE84-55A1-4CE5-9EC0-70635EAC9938}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-06 16:04
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-09-06 16:06:52
ComboFix-quarantined-files.txt 2010-09-06 15:06

Pre-Run: 89,468,694,528 bytes free
Post-Run: 89,751,322,624 bytes free

- - End Of File - - 18FA5F388FF5139A09BCF610DCF56694
bonsers
Regular Member
 
Posts: 15
Joined: July 26th, 2010, 2:02 pm

Re: IE redirecting via ohtgnoenriga.com + getting pop ups

Unread postby peku006 » September 6th, 2010, 12:40 pm

Hi bonsers

Download and Run Malwarebytes' Anti-Malware

Please save any items you were working on... close any open programs. You may be asked to reboot your machine.
Please download Malwarebytes Anti-Malware and save it to your desktop. If needed...Tutorial w/screenshots
Alternate download sites available here or here.
  1. Make sure you are connected to the Internet.
  2. Double-click on mbam-setup.exe to install the application.
  3. When the installation begins, follow the prompts and do not make any changes to default settings.
  4. When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
    • Then click Finish.
    MBAM will automatically start and you will be asked to update the program before performing a scan.
    • If an update is found, the program will automatically update itself.
    • Press the OK button to close that box and continue.
    • Problems downloading the updates? Manually download them from here and double-click on "mbam-rules.exe" to install.
On the Scanner tab:
  1. Make sure the "Perform full scan" option is selected.
  2. Then click on the Scan button.
  3. If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  4. The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  5. When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  6. Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  1. Click on the Show Results button to see a list of any malware that was found.
  2. Check all items except items in the C:\System Volume Information folder... then click on Remove Selected.
    We will take care of the System Volume Information items later.
  3. When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  4. The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  5. Copy and paste the contents of that report in your next reply and exit MBAM.

Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.


Please reply with

the Malwarebytes' Anti-Malware Log
a fresh HijackThis log

Thanks peku006
User avatar
peku006
MRU Emeritus
MRU Emeritus
 
Posts: 3357
Joined: May 14th, 2007, 2:18 pm
Location: Norway

Re: IE redirecting via ohtgnoenriga.com + getting pop ups

Unread postby bonsers » September 6th, 2010, 2:47 pm

Hi. Thanks again. Quick question: 2 infections have been found, do i delete these? or do i need to save any?

Image
bonsers
Regular Member
 
Posts: 15
Joined: July 26th, 2010, 2:02 pm

Re: IE redirecting via ohtgnoenriga.com + getting pop ups

Unread postby peku006 » September 7th, 2010, 3:06 am

Hi bonsers

remove them.......
User avatar
peku006
MRU Emeritus
MRU Emeritus
 
Posts: 3357
Joined: May 14th, 2007, 2:18 pm
Location: Norway

Re: IE redirecting via ohtgnoenriga.com + getting pop ups

Unread postby bonsers » September 7th, 2010, 7:13 am

Malwarebytes' Anti-Malware 1.46
http://www.malwarebytes.org

Database version: 4556

Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

07/09/2010 12:07:39
mbam-log-2010-09-07 (12-07-39).txt

Scan type: Full scan (C:\|E:\|F:\|)
Objects scanned: 253801
Time elapsed: 1 hour(s), 28 minute(s), 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\TG0PTF86JH (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XA5RJ9EADJ (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:10:23, on 07/09/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\explorer.exe
C:\Windows\System32\mobsync.exe
C:\Users\robert\Desktop\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [Conime] %windir%\system32\conime.exe
O4 - HKLM\..\Run: [EKIJ5000StatusMonitor] C:\Windows\system32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\robert\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Esqxqdrpan] rundll32 "C:\Users\robert\AppData\Roaming\fr-FRW.dll",UZVSEJTHIU
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com.edgesuite.net ... plugin.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: McAfee Application Installer Cleanup (0259751283794023) (0259751283794023mcinstcleanup) - McAfee, Inc. - C:\Windows\TEMP\025975~1.EXE
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\aestsrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Kodak AiO Network Discovery Service - Eastman Kodak Company - C:\Program Files\Kodak\AiO\Center\EKDiscovery.exe
O23 - Service: Kodak AiO Device Service (KodakSvc) - Eastman Kodak Company - C:\Program Files\Kodak\AiO\center\KodakSvc.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE

--
End of file - 10840 bytes
bonsers
Regular Member
 
Posts: 15
Joined: July 26th, 2010, 2:02 pm

Re: IE redirecting via ohtgnoenriga.com + getting pop ups

Unread postby peku006 » September 7th, 2010, 7:50 am

Hi bonsers

Download and Run Gmer

Please download gmer.zip from Gmer and save it to your desktop.

***Please close any open programs ***

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any "<--- ROOTKIT" entries unless advised by a trained Security Analyst


If possible rootkit activity is found, you will be asked if you would like to perform a full scan. Click No.

If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure that the 'Sections' button is ticked and the 'Show All' button is unticked.
  • Click the Scan button and let the program do its work. GMER will produce a log.
  • Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the Save button, and save the log as gmer.txt somewhere you can easily find it, such as your desktop.

DO NOT touch the PC at ALL for Whatever reason/s until it has 100% completed its scan, or attempted scan in case of some error etc !

Please post the results from the GMER scan in your reply.

Thanks peku006
User avatar
peku006
MRU Emeritus
MRU Emeritus
 
Posts: 3357
Joined: May 14th, 2007, 2:18 pm
Location: Norway

Re: IE redirecting via ohtgnoenriga.com + getting pop ups

Unread postby bonsers » September 7th, 2010, 8:19 am

hello, i ran "gmer.exe" and no "ROOTKIT" entries came up so i clicked "scan". it finished scanning and i tried to save the log and a blue screen appeared with white writing and then my computer just restarted. i tried scanning again, however the blue screen appeared and it restarted again, however it happened halfway the scan this time. what do you recommend i do?
bonsers
Regular Member
 
Posts: 15
Joined: July 26th, 2010, 2:02 pm

Re: IE redirecting via ohtgnoenriga.com + getting pop ups

Unread postby peku006 » September 7th, 2010, 10:59 am

Hi bonsers

Let`s try this

Download OTC by Old Timer and save it to your Desktop.

  • Double-click OTC.exe
  • Click the CleanUp! button
  • Select Yes when the Begin cleanup Process? Prompt appears
  • If you are prompted to Reboot during the cleanup, select Yes
  • The tool will delete itself once it finishes, if not delete it by yourself

Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so.

The downloaded file will have a random name... this prevents malware from detecting and blocking it.
Please download GMER... random file name.exe by GMER. An alternate (zip file) download site.
Note: Do not run any programs while Gmer is running.
**Caution** Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries
  1. Double click on the random named.exe to execute. If asked, allow the gmer.sys driver load.
    If using Vista, you must right click random named.exe and choose "Run As Administrator".
  2. If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO <--- Important!
  3. On the right side panel, several boxes have been checked. Please UNCHECK the following: (see image below)
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All <-- don't miss this one

    Image
    Click on image to enlarge
  4. If you don't get a warning then... Click the Rootkit/Malware tab at the top of the GMER window.
  5. Click the Scan button.
  6. Once the scan has finished... click Save. The Save... window will open.
  7. Save the scan results as gmerroot.log, save it to your Desktop.
  8. Double click on the desktop "gmerroot.log" file, to open in Notepad.
  9. Copy and paste the contents of the file gmerroot.log in your next reply.

Thanks peku006
User avatar
peku006
MRU Emeritus
MRU Emeritus
 
Posts: 3357
Joined: May 14th, 2007, 2:18 pm
Location: Norway

Re: IE redirecting via ohtgnoenriga.com + getting pop ups

Unread postby bonsers » September 7th, 2010, 12:20 pm

i have downloaded OTC and ran the cleanup etc, but this time when i run the gmer (randon file name.exe) it will scan for a while, but then close down so im just left with the desktop open. i then have tried to start random file name.exe again and the blue screen reappears and my computer is rebooted.
bonsers
Regular Member
 
Posts: 15
Joined: July 26th, 2010, 2:02 pm

Re: IE redirecting via ohtgnoenriga.com + getting pop ups

Unread postby peku006 » September 7th, 2010, 1:04 pm

Hi

Ok.......I hope this works......

RootRepeal
Please download RootRepeal.zip.
Save it to your Desktop. Alternate download links here or here.
Please print these instructions, you will not have an Internet connection!
RootRepeal site wrote:RootRepeal is currently in public beta. Whereas every effort has been made to ensure compatibility with every system configuration on Windows 2000, XP, 2003 and Vista, it cannot be guaranteed. There is always some risk when scanning for rootkits. Before running RootRepeal, please make sure you have backups of all important data and have saved all open documents.
If you have a 3rd party "unzipping" program...use it to open the zipped file...then skip to Step 5. Otherwise...
  1. Right click on RootRepeal.zip and select "Extract All"....
  2. Click Next on the "Welcome to the Compressed (zipped) Folders Extraction Wizard."
  3. Click on the Browse...button, then click on Desktop, then click OK.
  4. Once done, check (tick) the Show extracted files box and click Finish.
  5. Before running RootRepeal:
      Disconnect from the Internet as your system will be unprotected while using this tool.
      Close all programs and temporarily disable your anti-virus, Firewall and any anti-malware real-time protection before performing a scan.
      */ Insert instructions to disable specific user's protection programs */
  6. Open the RootRepeal folder and double-click on RootRepeal.exe to launch it.
  7. When the program opens, click the Report tab at the bottom, then click the Scan button.
  8. In the Select Scan, dialog which asks What do you want to include in the scan?, check ALL the boxes.
    Image
  9. Click OK.
  10. In the Select Drives, dialog Please select drives to scan: select all drives showing, then click OK.
    The scan can take some time to finish. Do not use the computer while the scan is running.
    When the scan has completed, a list of files will be generated in the RootRepeal window.
  11. Click on the Save Report button and save it as "rootrepeal.txt" to your desktop.
  12. Close and exit RootRepeal
  13. Double-click on the file rootrepeal.txt... Notepad will open... copy/paste the file contents in your next reply.

Make sure to enable your anti-virus, Firewall and any other security programs you disabled.
Note: If RootRepeal cannot complete a scan and results in a crash report, try repeating the scan in "safe mode".

Thanks peku006
User avatar
peku006
MRU Emeritus
MRU Emeritus
 
Posts: 3357
Joined: May 14th, 2007, 2:18 pm
Location: Norway

Re: IE redirecting via ohtgnoenriga.com + getting pop ups

Unread postby bonsers » September 7th, 2010, 3:01 pm

hello, it turns out that a gmer log file (that i tried earlier today) survived before one of the times it rebooted. here it is. what shall i do now? shall i forget rootrepeal.zip?

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-09-07 14:27:09
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\robert\AppData\Local\Temp\awlcapog.sys


---- System - GMER 1.0.15 ----

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0x8E9C679E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0x8E9C6738]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0x8E9C674C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0x8E9C67DC]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0x8E9C681F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0x8E9C6710]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0x8E9C6724]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0x8E9C67B2]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0x8E9C6847]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0x8E9C6833]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0x8E9C678A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0x8E9C6776]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0x8E9C680B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0x8E9C67F2]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0x8E9C67C8]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateUserProcess [0x8E9C6762]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!ZwYieldExecution 81A689D2 5 Bytes JMP 8E9C67CC \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwNotifyChangeKey 81BFC5B5 5 Bytes JMP 8E9C6823 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateUserProcess 81C06B82 5 Bytes JMP 8E9C6766 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 81C2DDA3 5 Bytes JMP 8E9C680F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 81C4D4FA 7 Bytes JMP 8E9C67E0 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 81C4D7BD 5 Bytes JMP 8E9C67F6 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetInformationProcess 81C51528 5 Bytes JMP 8E9C677A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 81C56F3D 7 Bytes JMP 8E9C67B6 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 81C5915A 5 Bytes JMP 8E9C6728 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess 81C5DC08 5 Bytes JMP 8E9C6714 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtCreateFile 81C7EE19 5 Bytes JMP 8E9C67A2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRestoreKey 81C8F892 5 Bytes JMP 8E9C6837 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwReplaceKey 81C90A96 5 Bytes JMP 8E9C684B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcess 81CCE847 5 Bytes JMP 8E9C673C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 81CCE892 7 Bytes JMP 8E9C6750 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetContextThread 81CCF34F 5 Bytes JMP 8E9C678E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

---- User code sections - GMER 1.0.15 ----

.text C:\Windows\system32\services.exe[648] kernel32.dll!GetStartupInfoW 75E61929 5 Bytes JMP 009500AE
.text C:\Windows\system32\services.exe[648] kernel32.dll!GetStartupInfoA 75E619C9 5 Bytes JMP 0095009D
.text C:\Windows\system32\services.exe[648] kernel32.dll!CreateProcessW 75E61BF3 5 Bytes JMP 009500E4
.text C:\Windows\system32\services.exe[648] kernel32.dll!CreateProcessA 75E61C28 5 Bytes JMP 00950F43
.text C:\Windows\system32\services.exe[648] kernel32.dll!VirtualProtect 75E61DC3 5 Bytes JMP 00950067
.text C:\Windows\system32\services.exe[648] kernel32.dll!CreateNamedPipeA 75E62EF5 5 Bytes JMP 0095001B
.text C:\Windows\system32\services.exe[648] kernel32.dll!CreateNamedPipeW 75E65C0C 5 Bytes JMP 0095002C
.text C:\Windows\system32\services.exe[648] kernel32.dll!CreatePipe 75E88E6E 5 Bytes JMP 0095008C
.text C:\Windows\system32\services.exe[648] kernel32.dll!LoadLibraryExW 75E89109 5 Bytes JMP 00950F8D
.text C:\Windows\system32\services.exe[648] kernel32.dll!LoadLibraryW 75E89362 5 Bytes JMP 00950FAF
.text C:\Windows\system32\services.exe[648] kernel32.dll!LoadLibraryExA 75E894B4 5 Bytes JMP 00950F9E
.text C:\Windows\system32\services.exe[648] kernel32.dll!LoadLibraryA 75E894DC 5 Bytes JMP 00950FC0
.text C:\Windows\system32\services.exe[648] kernel32.dll!VirtualProtectEx 75E8DBDA 5 Bytes JMP 00950F72
.text C:\Windows\system32\services.exe[648] kernel32.dll!GetProcAddress 75EA903B 5 Bytes JMP 009500F5
.text C:\Windows\system32\services.exe[648] kernel32.dll!CreateFileW 75EAAECB 5 Bytes JMP 00950FE5
.text C:\Windows\system32\services.exe[648] kernel32.dll!CreateFileA 75EACE5F 5 Bytes JMP 00950000
.text C:\Windows\system32\services.exe[648] kernel32.dll!WinExec 75EF5CF7 5 Bytes JMP 009500BF
.text C:\Windows\system32\services.exe[648] ADVAPI32.dll!RegCreateKeyExA 762E39AB 1 Byte [E9]
.text C:\Windows\system32\services.exe[648] ADVAPI32.dll!RegCreateKeyExA 762E39AB 5 Bytes JMP 009C0FAF
.text C:\Windows\system32\services.exe[648] ADVAPI32.dll!RegCreateKeyA 762E3BA9 5 Bytes JMP 009C0047
.text C:\Windows\system32\services.exe[648] ADVAPI32.dll!RegOpenKeyA 762E89C7 5 Bytes JMP 009C0000
.text C:\Windows\system32\services.exe[648] ADVAPI32.dll!RegCreateKeyW 762F391E 5 Bytes JMP 009C0FC0
.text C:\Windows\system32\services.exe[648] ADVAPI32.dll!RegCreateKeyExW 762F41F1 5 Bytes JMP 009C0F9E
.text C:\Windows\system32\services.exe[648] ADVAPI32.dll!RegOpenKeyExA 762F7C42 5 Bytes JMP 009C0036
.text C:\Windows\system32\services.exe[648] ADVAPI32.dll!RegOpenKeyW 762FE2B5 5 Bytes JMP 009C001B
.text C:\Windows\system32\services.exe[648] ADVAPI32.dll!RegOpenKeyExW 76307BA1 5 Bytes JMP 009C0FE5
.text C:\Windows\system32\services.exe[648] msvcrt.dll!_wsystem 761E7F2F 5 Bytes JMP 009B0F95
.text C:\Windows\system32\services.exe[648] msvcrt.dll!system 761E804B 5 Bytes JMP 009B0FA6
.text C:\Windows\system32\services.exe[648] msvcrt.dll!_creat 761EBBE1 5 Bytes JMP 009B0FD2
.text C:\Windows\system32\services.exe[648] msvcrt.dll!_open 761ED106 5 Bytes JMP 009B0FEF
.text C:\Windows\system32\services.exe[648] msvcrt.dll!_wcreat 761ED326 5 Bytes JMP 009B0FB7
.text C:\Windows\system32\services.exe[648] msvcrt.dll!_wopen 761ED501 5 Bytes JMP 009B0000
.text C:\Windows\system32\services.exe[648] WS2_32.dll!socket 775B36D1 5 Bytes JMP 009D0FE5
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!GetStartupInfoW 75E61929 5 Bytes JMP 00190F6F
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!GetStartupInfoA 75E619C9 5 Bytes JMP 001900B5
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!CreateProcessW 75E61BF3 5 Bytes JMP 001900E8
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!CreateProcessA 75E61C28 5 Bytes JMP 001900D7
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!VirtualProtect 75E61DC3 5 Bytes JMP 0019007F
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!CreateNamedPipeA 75E62EF5 5 Bytes JMP 00190011
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!CreateNamedPipeW 75E65C0C 5 Bytes JMP 0019002C
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!CreatePipe 75E88E6E 5 Bytes JMP 0019009A
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!LoadLibraryExW 75E89109 5 Bytes JMP 00190062
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!LoadLibraryW 75E89362 5 Bytes JMP 00190FB6
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!LoadLibraryExA 75E894B4 5 Bytes JMP 00190FA5
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!LoadLibraryA 75E894DC 5 Bytes JMP 0019003D
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!VirtualProtectEx 75E8DBDA 5 Bytes JMP 00190F80
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!GetProcAddress 75EA903B 5 Bytes JMP 00190F36
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!CreateFileW 75EAAECB 5 Bytes JMP 00190FE5
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!CreateFileA 75EACE5F 5 Bytes JMP 00190000
.text C:\Windows\system32\lsass.exe[688] kernel32.dll!WinExec 75EF5CF7 5 Bytes JMP 001900C6
.text C:\Windows\system32\lsass.exe[688] ADVAPI32.dll!RegCreateKeyExA 762E39AB 5 Bytes JMP 001B0F94
.text C:\Windows\system32\lsass.exe[688] ADVAPI32.dll!RegCreateKeyA 762E3BA9 5 Bytes JMP 001B0025
.text C:\Windows\system32\lsass.exe[688] ADVAPI32.dll!RegOpenKeyA 762E89C7 5 Bytes JMP 001B0000
.text C:\Windows\system32\lsass.exe[688] ADVAPI32.dll!RegCreateKeyW 762F391E 5 Bytes JMP 001B0036
.text C:\Windows\system32\lsass.exe[688] ADVAPI32.dll!RegCreateKeyExW 762F41F1 5 Bytes JMP 001B005B
.text C:\Windows\system32\lsass.exe[688] ADVAPI32.dll!RegOpenKeyExA 762F7C42 5 Bytes JMP 001B0FD4
.text C:\Windows\system32\lsass.exe[688] ADVAPI32.dll!RegOpenKeyW 762FE2B5 5 Bytes JMP 001B0FE5
.text C:\Windows\system32\lsass.exe[688] ADVAPI32.dll!RegOpenKeyExW 76307BA1 5 Bytes JMP 001B0FC3
.text C:\Windows\system32\lsass.exe[688] msvcrt.dll!_wsystem 761E7F2F 5 Bytes JMP 001A0FAA
.text C:\Windows\system32\lsass.exe[688] msvcrt.dll!system 761E804B 5 Bytes JMP 001A003F
.text C:\Windows\system32\lsass.exe[688] msvcrt.dll!_creat 761EBBE1 5 Bytes JMP 001A0FE3
.text C:\Windows\system32\lsass.exe[688] msvcrt.dll!_open 761ED106 5 Bytes JMP 001A000C
.text C:\Windows\system32\lsass.exe[688] msvcrt.dll!_wcreat 761ED326 5 Bytes JMP 001A002E
.text C:\Windows\system32\lsass.exe[688] msvcrt.dll!_wopen 761ED501 5 Bytes JMP 001A001D
.text C:\Windows\system32\lsass.exe[688] WS2_32.dll!socket 775B36D1 5 Bytes JMP 00510000
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!GetStartupInfoW 75E61929 5 Bytes JMP 00610F48
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!GetStartupInfoA 75E619C9 5 Bytes JMP 0061008E
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!CreateProcessW 75E61BF3 5 Bytes JMP 00610F15
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!CreateProcessA 75E61C28 5 Bytes JMP 00610F26
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!VirtualProtect 75E61DC3 5 Bytes JMP 00610062
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!CreateNamedPipeA 75E62EF5 5 Bytes JMP 00610FB9
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!CreateNamedPipeW 75E65C0C 5 Bytes JMP 0061000A
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!CreatePipe 75E88E6E 5 Bytes JMP 00610F63
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!LoadLibraryExW 75E89109 5 Bytes JMP 00610051
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!LoadLibraryW 75E89362 5 Bytes JMP 00610F94
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!LoadLibraryExA 75E894B4 5 Bytes JMP 00610036
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!LoadLibraryA 75E894DC 5 Bytes JMP 0061001B
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!VirtualProtectEx 75E8DBDA 5 Bytes JMP 00610073
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!GetProcAddress 75EA903B 5 Bytes JMP 006100C7
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!CreateFileW 75EAAECB 5 Bytes JMP 00610FD4
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!CreateFileA 75EACE5F 5 Bytes JMP 00610FE5
.text C:\Windows\system32\svchost.exe[864] kernel32.dll!WinExec 75EF5CF7 5 Bytes JMP 00610F37
.text C:\Windows\system32\svchost.exe[864] msvcrt.dll!_wsystem 761E7F2F 5 Bytes JMP 0066007A
.text C:\Windows\system32\svchost.exe[864] msvcrt.dll!system 761E804B 5 Bytes JMP 00660069
.text C:\Windows\system32\svchost.exe[864] msvcrt.dll!_creat 761EBBE1 5 Bytes JMP 00660029
.text C:\Windows\system32\svchost.exe[864] msvcrt.dll!_open 761ED106 5 Bytes JMP 00660FEF
.text C:\Windows\system32\svchost.exe[864] msvcrt.dll!_wcreat 761ED326 5 Bytes JMP 0066004E
.text C:\Windows\system32\svchost.exe[864] msvcrt.dll!_wopen 761ED501 5 Bytes JMP 0066000C
.text C:\Windows\system32\svchost.exe[864] ADVAPI32.dll!RegCreateKeyExA 762E39AB 5 Bytes JMP 00670F8A
.text C:\Windows\system32\svchost.exe[864] ADVAPI32.dll!RegCreateKeyA 762E3BA9 5 Bytes JMP 0067001B
.text C:\Windows\system32\svchost.exe[864] ADVAPI32.dll!RegOpenKeyA 762E89C7 5 Bytes JMP 00670FE5
.text C:\Windows\system32\svchost.exe[864] ADVAPI32.dll!RegCreateKeyW 762F391E 5 Bytes JMP 0067002C
.text C:\Windows\system32\svchost.exe[864] ADVAPI32.dll!RegCreateKeyExW 762F41F1 5 Bytes JMP 00670F79
.text C:\Windows\system32\svchost.exe[864] ADVAPI32.dll!RegOpenKeyExA 762F7C42 5 Bytes JMP 00670000
.text C:\Windows\system32\svchost.exe[864] ADVAPI32.dll!RegOpenKeyW 762FE2B5 5 Bytes JMP 00670FCA
.text C:\Windows\system32\svchost.exe[864] ADVAPI32.dll!RegOpenKeyExW 76307BA1 5 Bytes JMP 00670FAF
.text C:\Windows\system32\svchost.exe[864] WS2_32.dll!socket 775B36D1 5 Bytes JMP 0068000A
.text C:\Windows\system32\svchost.exe[928] kernel32.dll!GetStartupInfoW 75E61929 5 Bytes JMP 000F0F0D
.text C:\Windows\system32\svchost.exe[928] kernel32.dll!GetStartupInfoA 75E619C9 5 Bytes JMP 000F0F28
.text C:\Windows\system32\svchost.exe[928] kernel32.dll!CreateProcessW 75E61BF3 5 Bytes JMP 000F0EF2
.text C:\Windows\system32\svchost.exe[928] kernel32.dll!CreateProcessA 75E61C28 5 Bytes JMP 000F007F
.text C:\Windows\system32\svchost.exe[928] kernel32.dll!VirtualProtect 75E61DC3 5 Bytes JMP 000F0F5E
.text C:\Windows\system32\svchost.exe[928] kernel32.dll!CreateNamedPipeA 75E62EF5 5 Bytes JMP 000F0FC0
.text C:\Windows\system32\svchost.exe[928] kernel32.dll!CreateNamedPipeW 75E65C0C 5 Bytes JMP 000F0FAF
.text C:\Windows\system32\svchost.exe[928] kernel32.dll!CreatePipe 75E88E6E 5 Bytes JMP 000F0053
.text C:\Windows\system32\svchost.exe[928] kernel32.dll!LoadLibraryExW 75E89109 5 Bytes JMP 000F0038
.text C:\Windows\system32\svchost.exe[928] kernel32.dll!LoadLibraryW 75E89362 5 Bytes JMP 000F001B
.text C:\Windows\system32\svchost.exe[928] kernel32.dll!LoadLibraryExA 75E894B4 5 Bytes JMP 000F0F79
.text C:\Windows\system32\svchost.exe[928] kernel32.dll!LoadLibraryA 75E894DC 5 Bytes JMP 000F0F9E
.text C:\Windows\system32\svchost.exe[928] kernel32.dll!VirtualProtectEx 75E8DBDA 5 Bytes JMP 000F0F43
.text C:\Windows\system32\svchost.exe[928] kernel32.dll!GetProcAddress 75EA903B 5 Bytes JMP 000F0ECD
.text C:\Windows\system32\svchost.exe[928] kernel32.dll!CreateFileW 75EAAECB 5 Bytes JMP 000F0FE5
.text C:\Windows\system32\svchost.exe[928] kernel32.dll!CreateFileA 75EACE5F 5 Bytes JMP 000F0000
.text C:\Windows\system32\svchost.exe[928] kernel32.dll!WinExec 75EF5CF7 5 Bytes JMP 000F006E
.text C:\Windows\system32\svchost.exe[928] msvcrt.dll!_wsystem 761E7F2F 5 Bytes JMP 00140069
.text C:\Windows\system32\svchost.exe[928] msvcrt.dll!system 761E804B 5 Bytes JMP 00140FD4
.text C:\Windows\system32\svchost.exe[928] msvcrt.dll!_creat 761EBBE1 5 Bytes JMP 00140033
.text C:\Windows\system32\svchost.exe[928] msvcrt.dll!_open 761ED106 5 Bytes JMP 0014000C
.text C:\Windows\system32\svchost.exe[928] msvcrt.dll!_wcreat 761ED326 5 Bytes JMP 00140044
.text C:\Windows\system32\svchost.exe[928] msvcrt.dll!_wopen 761ED501 5 Bytes JMP 00140FEF
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!RegCreateKeyExA 762E39AB 5 Bytes JMP 0015004A
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!RegCreateKeyA 762E3BA9 5 Bytes JMP 00150FB9
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!RegOpenKeyA 762E89C7 5 Bytes JMP 00150FEF
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!RegCreateKeyW 762F391E 5 Bytes JMP 00150FA8
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!RegCreateKeyExW 762F41F1 5 Bytes JMP 00150065
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!RegOpenKeyExA 762F7C42 5 Bytes JMP 0015000A
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!RegOpenKeyW 762FE2B5 5 Bytes JMP 00150FD4
.text C:\Windows\system32\svchost.exe[928] ADVAPI32.dll!RegOpenKeyExW 76307BA1 5 Bytes JMP 00150025
.text C:\Windows\system32\svchost.exe[928] WS2_32.dll!socket 775B36D1 5 Bytes JMP 0016000A
.text C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe[980] kernel32.dll!LoadLibraryW 75E89362 5 Bytes JMP 0041C1B0 C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe[980] kernel32.dll!LoadLibraryA 75E894DC 5 Bytes JMP 0041C130 C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Windows\System32\svchost.exe[1068] kernel32.dll!GetStartupInfoW 75E61929 5 Bytes JMP 00130F6F
.text C:\Windows\System32\svchost.exe[1068] kernel32.dll!GetStartupInfoA 75E619C9 5 Bytes JMP 001300BF
.text C:\Windows\System32\svchost.exe[1068] kernel32.dll!CreateProcessW 75E61BF3 5 Bytes JMP 00130F43
.text C:\Windows\System32\svchost.exe[1068] kernel32.dll!CreateProcessA 75E61C28 5 Bytes JMP 00130F54
.text C:\Windows\System32\svchost.exe[1068] kernel32.dll!VirtualProtect 75E61DC3 5 Bytes JMP 00130078
.text C:\Windows\System32\svchost.exe[1068] kernel32.dll!CreateNamedPipeA 75E62EF5 5 Bytes JMP 0013001B
.text C:\Windows\System32\svchost.exe[1068] kernel32.dll!CreateNamedPipeW 75E65C0C 5 Bytes JMP 00130036
.text C:\Windows\System32\svchost.exe[1068] kernel32.dll!CreatePipe 75E88E6E 5 Bytes JMP 001300A4
.text C:\Windows\System32\svchost.exe[1068] kernel32.dll!LoadLibraryExW 75E89109 5 Bytes JMP 00130067
.text C:\Windows\System32\svchost.exe[1068] kernel32.dll!LoadLibraryW 75E89362 5 Bytes JMP 00130FB9
.text C:\Windows\System32\svchost.exe[1068] kernel32.dll!LoadLibraryExA 75E894B4 5 Bytes JMP 00130F9E
.text C:\Windows\System32\svchost.exe[1068] kernel32.dll!LoadLibraryA 75E894DC 5 Bytes JMP 00130FCA
.text C:\Windows\System32\svchost.exe[1068] kernel32.dll!VirtualProtectEx 75E8DBDA 5 Bytes JMP 00130093
.text C:\Windows\System32\svchost.exe[1068] kernel32.dll!GetProcAddress 75EA903B 5 Bytes JMP 001300FF
.text C:\Windows\System32\svchost.exe[1068] kernel32.dll!CreateFileW 75EAAECB 5 Bytes JMP 0013000A
.text C:\Windows\System32\svchost.exe[1068] kernel32.dll!CreateFileA 75EACE5F 5 Bytes JMP 00130FEF
.text C:\Windows\System32\svchost.exe[1068] kernel32.dll!WinExec 75EF5CF7 5 Bytes JMP 001300DA
.text C:\Windows\System32\svchost.exe[1068] msvcrt.dll!_wsystem 761E7F2F 5 Bytes JMP 00150049
.text C:\Windows\System32\svchost.exe[1068] msvcrt.dll!system 761E804B 5 Bytes JMP 00150FBE
.text C:\Windows\System32\svchost.exe[1068] msvcrt.dll!_creat 761EBBE1 5 Bytes JMP 0015002E
.text C:\Windows\System32\svchost.exe[1068] msvcrt.dll!_open 761ED106 5 Bytes JMP 00150000
.text C:\Windows\System32\svchost.exe[1068] msvcrt.dll!_wcreat 761ED326 5 Bytes JMP 00150FCF
.text C:\Windows\System32\svchost.exe[1068] msvcrt.dll!_wopen 761ED501 5 Bytes JMP 00150011
.text C:\Windows\System32\svchost.exe[1068] ADVAPI32.dll!RegCreateKeyExA 762E39AB 5 Bytes JMP 00A00FA5
.text C:\Windows\System32\svchost.exe[1068] ADVAPI32.dll!RegCreateKeyA 762E3BA9 5 Bytes JMP 00A00036
.text C:\Windows\System32\svchost.exe[1068] ADVAPI32.dll!RegOpenKeyA 762E89C7 5 Bytes JMP 00A00FEF
.text C:\Windows\System32\svchost.exe[1068] ADVAPI32.dll!RegCreateKeyW 762F391E 5 Bytes JMP 00A00047
.text C:\Windows\System32\svchost.exe[1068] ADVAPI32.dll!RegCreateKeyExW 762F41F1 5 Bytes JMP 00A00062
.text C:\Windows\System32\svchost.exe[1068] ADVAPI32.dll!RegOpenKeyExA 762F7C42 5 Bytes JMP 00A00FD4
.text C:\Windows\System32\svchost.exe[1068] ADVAPI32.dll!RegOpenKeyW 762FE2B5 5 Bytes JMP 00A0000A
.text C:\Windows\System32\svchost.exe[1068] ADVAPI32.dll!RegOpenKeyExW 76307BA1 5 Bytes JMP 00A00025
.text C:\Windows\System32\svchost.exe[1068] WS2_32.dll!socket 775B36D1 5 Bytes JMP 00A60000
.text C:\Windows\System32\svchost.exe[1096] kernel32.dll!GetStartupInfoW 75E61929 5 Bytes JMP 01120F40
.text C:\Windows\System32\svchost.exe[1096] kernel32.dll!GetStartupInfoA 75E619C9 5 Bytes JMP 01120F5B
.text C:\Windows\System32\svchost.exe[1096] kernel32.dll!CreateProcessW 75E61BF3 5 Bytes JMP 011200CD
.text C:\Windows\System32\svchost.exe[1096] kernel32.dll!CreateProcessA 75E61C28 5 Bytes JMP 011200BC
.text C:\Windows\System32\svchost.exe[1096] kernel32.dll!VirtualProtect 75E61DC3 5 Bytes JMP 0112006B
.text C:\Windows\System32\svchost.exe[1096] kernel32.dll!CreateNamedPipeA 75E62EF5 5 Bytes JMP 01120011
.text C:\Windows\System32\svchost.exe[1096] kernel32.dll!CreateNamedPipeW 75E65C0C 5 Bytes JMP 01120022
.text C:\Windows\System32\svchost.exe[1096] kernel32.dll!CreatePipe 75E88E6E 5 Bytes JMP 01120086
.text C:\Windows\System32\svchost.exe[1096] kernel32.dll!LoadLibraryExW 75E89109 5 Bytes JMP 0112004E
.text C:\Windows\System32\svchost.exe[1096] kernel32.dll!LoadLibraryW 75E89362 5 Bytes JMP 01120FB6
.text C:\Windows\System32\svchost.exe[1096] kernel32.dll!LoadLibraryExA 75E894B4 5 Bytes JMP 01120F9B
.text C:\Windows\System32\svchost.exe[1096] kernel32.dll!LoadLibraryA 75E894DC 5 Bytes JMP 0112003D
.text C:\Windows\System32\svchost.exe[1096] kernel32.dll!VirtualProtectEx 75E8DBDA 5 Bytes JMP 01120F76
.text C:\Windows\System32\svchost.exe[1096] kernel32.dll!GetProcAddress 75EA903B 5 Bytes JMP 01120F25
.text C:\Windows\System32\svchost.exe[1096] kernel32.dll!CreateFileW 75EAAECB 5 Bytes JMP 01120FE5
.text C:\Windows\System32\svchost.exe[1096] kernel32.dll!CreateFileA 75EACE5F 5 Bytes JMP 01120000
.text C:\Windows\System32\svchost.exe[1096] kernel32.dll!WinExec 75EF5CF7 5 Bytes JMP 011200AB
.text C:\Windows\System32\svchost.exe[1096] msvcrt.dll!_wsystem 761E7F2F 5 Bytes JMP 01610FB7
.text C:\Windows\System32\svchost.exe[1096] msvcrt.dll!system 761E804B 5 Bytes JMP 01610042
.text C:\Windows\System32\svchost.exe[1096] msvcrt.dll!_creat 761EBBE1 5 Bytes JMP 01610016
.text C:\Windows\System32\svchost.exe[1096] msvcrt.dll!_open 761ED106 5 Bytes JMP 01610FE3
.text C:\Windows\System32\svchost.exe[1096] msvcrt.dll!_wcreat 761ED326 5 Bytes JMP 01610027
.text C:\Windows\System32\svchost.exe[1096] msvcrt.dll!_wopen 761ED501 5 Bytes JMP 01610FD2
.text C:\Windows\System32\svchost.exe[1096] ADVAPI32.dll!RegCreateKeyExA 762E39AB 5 Bytes JMP 01620054
.text C:\Windows\System32\svchost.exe[1096] ADVAPI32.dll!RegCreateKeyA 762E3BA9 5 Bytes JMP 01620FCD
.text C:\Windows\System32\svchost.exe[1096] ADVAPI32.dll!RegOpenKeyA 762E89C7 5 Bytes JMP 0162000A
.text C:\Windows\System32\svchost.exe[1096] ADVAPI32.dll!RegCreateKeyW 762F391E 5 Bytes JMP 01620FB2
.text C:\Windows\System32\svchost.exe[1096] ADVAPI32.dll!RegCreateKeyExW 762F41F1 5 Bytes JMP 01620F97
.text C:\Windows\System32\svchost.exe[1096] ADVAPI32.dll!RegOpenKeyExA 762F7C42 5 Bytes JMP 01620FEF
.text C:\Windows\System32\svchost.exe[1096] ADVAPI32.dll!RegOpenKeyW 762FE2B5 5 Bytes JMP 01620025
.text C:\Windows\System32\svchost.exe[1096] ADVAPI32.dll!RegOpenKeyExW 76307BA1 5 Bytes JMP 01620FDE
.text C:\Windows\System32\svchost.exe[1096] WS2_32.dll!socket 775B36D1 5 Bytes JMP 01630000
.text C:\Windows\system32\svchost.exe[1120] kernel32.dll!GetStartupInfoW 75E61929 5 Bytes JMP 00CB0096
.text C:\Windows\system32\svchost.exe[1120] kernel32.dll!GetStartupInfoA 75E619C9 5 Bytes JMP 00CB0F46
.text C:\Windows\system32\svchost.exe[1120] kernel32.dll!CreateProcessW 75E61BF3 5 Bytes JMP 00CB0F24
.text C:\Windows\system32\svchost.exe[1120] kernel32.dll!CreateProcessA 75E61C28 5 Bytes JMP 00CB0F35
.text C:\Windows\system32\svchost.exe[1120] kernel32.dll!VirtualProtect 75E61DC3 5 Bytes JMP 00CB0F86
.text C:\Windows\system32\svchost.exe[1120] kernel32.dll!CreateNamedPipeA 75E62EF5 5 Bytes JMP 00CB0FD4
.text C:\Windows\system32\svchost.exe[1120] kernel32.dll!CreateNamedPipeW 75E65C0C 5 Bytes JMP 00CB0025
.text C:\Windows\system32\svchost.exe[1120] kernel32.dll!CreatePipe 75E88E6E 5 Bytes JMP 00CB007B
.text C:\Windows\system32\svchost.exe[1120] kernel32.dll!LoadLibraryExW 75E89109 5 Bytes JMP 00CB0F97
.text C:\Windows\system32\svchost.exe[1120] kernel32.dll!LoadLibraryW 75E89362 5 Bytes JMP 00CB004A
.text C:\Windows\system32\svchost.exe[1120] kernel32.dll!LoadLibraryExA 75E894B4 5 Bytes JMP 00CB0FA8
.text C:\Windows\system32\svchost.exe[1120] kernel32.dll!LoadLibraryA 75E894DC 5 Bytes JMP 00CB0FB9
.text C:\Windows\system32\svchost.exe[1120] kernel32.dll!VirtualProtectEx 75E8DBDA 5 Bytes JMP 00CB0F75
.text C:\Windows\system32\svchost.exe[1120] kernel32.dll!GetProcAddress 75EA903B 5 Bytes JMP 00CB0F13
.text C:\Windows\system32\svchost.exe[1120] kernel32.dll!CreateFileW 75EAAECB 5 Bytes JMP 00CB0000
.text C:\Windows\system32\svchost.exe[1120] kernel32.dll!CreateFileA 75EACE5F 5 Bytes JMP 00CB0FEF
.text C:\Windows\system32\svchost.exe[1120] kernel32.dll!WinExec 75EF5CF7 5 Bytes JMP 00CB00B1
.text C:\Windows\system32\svchost.exe[1120] msvcrt.dll!_wsystem 761E7F2F 5 Bytes JMP 00CC0FA6
.text C:\Windows\system32\svchost.exe[1120] msvcrt.dll!system 761E804B 5 Bytes JMP 00CC0027
.text C:\Windows\system32\svchost.exe[1120] msvcrt.dll!_creat 761EBBE1 5 Bytes JMP 00CC000C
.text C:\Windows\system32\svchost.exe[1120] msvcrt.dll!_open 761ED106 5 Bytes JMP 00CC0FEF
.text C:\Windows\system32\svchost.exe[1120] msvcrt.dll!_wcreat 761ED326 5 Bytes JMP 00CC0FB7
.text C:\Windows\system32\svchost.exe[1120] msvcrt.dll!_wopen 761ED501 5 Bytes JMP 00CC0FDE
.text C:\Windows\system32\svchost.exe[1120] ADVAPI32.dll!RegCreateKeyExA 762E39AB 5 Bytes JMP 00D60F97
.text C:\Windows\system32\svchost.exe[1120] ADVAPI32.dll!RegCreateKeyA 762E3BA9 5 Bytes JMP 00D60FA8
.text C:\Windows\system32\svchost.exe[1120] ADVAPI32.dll!RegOpenKeyA 762E89C7 5 Bytes JMP 00D60FEF
.text C:\Windows\system32\svchost.exe[1120] ADVAPI32.dll!RegCreateKeyW 762F391E 5 Bytes JMP 00D60039
.text C:\Windows\system32\svchost.exe[1120] ADVAPI32.dll!RegCreateKeyExW 762F41F1 5 Bytes JMP 00D60F7C
.text C:\Windows\system32\svchost.exe[1120] ADVAPI32.dll!RegOpenKeyExA 762F7C42 5 Bytes JMP 00D60014
.text C:\Windows\system32\svchost.exe[1120] ADVAPI32.dll!RegOpenKeyW 762FE2B5 5 Bytes JMP 00D60FDE
.text C:\Windows\system32\svchost.exe[1120] ADVAPI32.dll!RegOpenKeyExW 76307BA1 5 Bytes JMP 00D60FC3
.text C:\Windows\system32\svchost.exe[1120] WS2_32.dll!socket 775B36D1 5 Bytes JMP 01180000
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!GetStartupInfoW 75E61929 5 Bytes JMP 00D200A4
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!GetStartupInfoA 75E619C9 5 Bytes JMP 00D20F68
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreateProcessW 75E61BF3 5 Bytes JMP 00D20F32
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreateProcessA 75E61C28 5 Bytes JMP 00D200C9
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!VirtualProtect 75E61DC3 5 Bytes JMP 00D20F8D
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreateNamedPipeA 75E62EF5 5 Bytes JMP 00D2001B
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreateNamedPipeW 75E65C0C 5 Bytes JMP 00D20FCA
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreatePipe 75E88E6E 5 Bytes JMP 00D20093
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!LoadLibraryExW 75E89109 5 Bytes JMP 00D20F9E
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!LoadLibraryW 75E89362 5 Bytes JMP 00D20047
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!LoadLibraryExA 75E894B4 5 Bytes JMP 00D20FAF
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!LoadLibraryA 75E894DC 5 Bytes JMP 00D20036
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!VirtualProtectEx 75E8DBDA 5 Bytes JMP 00D20082
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!GetProcAddress 75EA903B 5 Bytes JMP 00D200DA
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreateFileW 75EAAECB 5 Bytes JMP 00D2000A
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreateFileA 75EACE5F 5 Bytes JMP 00D20FEF
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!WinExec 75EF5CF7 5 Bytes JMP 00D20F4D
.text C:\Windows\system32\svchost.exe[1400] msvcrt.dll!_wsystem 761E7F2F 5 Bytes JMP 00D80062
.text C:\Windows\system32\svchost.exe[1400] msvcrt.dll!system 761E804B 5 Bytes JMP 00D80FCD
.text C:\Windows\system32\svchost.exe[1400] msvcrt.dll!_creat 761EBBE1 5 Bytes JMP 00D80022
.text C:\Windows\system32\svchost.exe[1400] msvcrt.dll!_open 761ED106 5 Bytes JMP 00D80000
.text C:\Windows\system32\svchost.exe[1400] msvcrt.dll!_wcreat 761ED326 5 Bytes JMP 00D80047
.text C:\Windows\system32\svchost.exe[1400] msvcrt.dll!_wopen 761ED501 5 Bytes JMP 00D80011
.text C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyExA 762E39AB 5 Bytes JMP 00DA0F5E
.text C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyA 762E3BA9 5 Bytes JMP 00DA0000
.text C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyA 762E89C7 5 Bytes JMP 00DA0FEF
.text C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyW 762F391E 5 Bytes JMP 00DA0F6F
.text C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyExW 762F41F1 5 Bytes JMP 00DA0025
.text C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyExA 762F7C42 5 Bytes JMP 00DA0FB9
.text C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyW 762FE2B5 5 Bytes JMP 00DA0FCA
.text C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyExW 76307BA1 5 Bytes JMP 00DA0F94
.text C:\Windows\system32\svchost.exe[1400] WS2_32.dll!socket 775B36D1 5 Bytes JMP 00CD0FEF
.text C:\Windows\system32\svchost.exe[1400] WinInet.dll!InternetOpenA 771FD47D 5 Bytes JMP 00920FE5
.text C:\Windows\system32\svchost.exe[1400] WinInet.dll!InternetOpenW 771FD7DA 5 Bytes JMP 00920000
.text C:\Windows\system32\svchost.exe[1400] WinInet.dll!InternetOpenUrlA 771FFE4B 5 Bytes JMP 0092001B
.text C:\Windows\system32\svchost.exe[1400] WinInet.dll!InternetOpenUrlW 77249139 5 Bytes JMP 00920FD4
.text C:\Windows\system32\svchost.exe[1564] kernel32.dll!GetStartupInfoW 75E61929 5 Bytes JMP 00890093
.text C:\Windows\system32\svchost.exe[1564] kernel32.dll!GetStartupInfoA 75E619C9 5 Bytes JMP 00890F4D
.text C:\Windows\system32\svchost.exe[1564] kernel32.dll!CreateProcessW 75E61BF3 5 Bytes JMP 00890F21
.text C:\Windows\system32\svchost.exe[1564] kernel32.dll!CreateProcessA 75E61C28 5 Bytes JMP 00890F32
.text C:\Windows\system32\svchost.exe[1564] kernel32.dll!VirtualProtect 75E61DC3 5 Bytes JMP 00890F68
.text C:\Windows\system32\svchost.exe[1564] kernel32.dll!CreateNamedPipeA 75E62EF5 5 Bytes JMP 0089000A
.text C:\Windows\system32\svchost.exe[1564] kernel32.dll!CreateNamedPipeW 75E65C0C 5 Bytes JMP 00890FC3
.text C:\Windows\system32\svchost.exe[1564] kernel32.dll!CreatePipe 75E88E6E 5 Bytes JMP 00890078
.text C:\Windows\system32\svchost.exe[1564] kernel32.dll!LoadLibraryExW 75E89109 5 Bytes JMP 0089004C
.text C:\Windows\system32\svchost.exe[1564] kernel32.dll!LoadLibraryW 75E89362 5 Bytes JMP 00890025
.text C:\Windows\system32\svchost.exe[1564] kernel32.dll!LoadLibraryExA 75E894B4 5 Bytes JMP 00890F83
.text C:\Windows\system32\svchost.exe[1564] kernel32.dll!LoadLibraryA 75E894DC 5 Bytes JMP 00890F9E
.text C:\Windows\system32\svchost.exe[1564] kernel32.dll!VirtualProtectEx 75E8DBDA 5 Bytes JMP 0089005D
.text C:\Windows\system32\svchost.exe[1564] kernel32.dll!GetProcAddress 75EA903B 5 Bytes JMP 008900C9
.text C:\Windows\system32\svchost.exe[1564] kernel32.dll!CreateFileW 75EAAECB 5 Bytes JMP 00890FD4
.text C:\Windows\system32\svchost.exe[1564] kernel32.dll!CreateFileA 75EACE5F 5 Bytes JMP 00890FE5
.text C:\Windows\system32\svchost.exe[1564] kernel32.dll!WinExec 75EF5CF7 5 Bytes JMP 008900B8
.text C:\Windows\system32\svchost.exe[1564] msvcrt.dll!_wsystem 761E7F2F 5 Bytes JMP 008F0FA8
.text C:\Windows\system32\svchost.exe[1564] msvcrt.dll!system 761E804B 5 Bytes JMP 008F0FB9
.text C:\Windows\system32\svchost.exe[1564] msvcrt.dll!_creat 761EBBE1 5 Bytes JMP 008F0018
.text C:\Windows\system32\svchost.exe[1564] msvcrt.dll!_open 761ED106 5 Bytes JMP 008F0FEF
.text C:\Windows\system32\svchost.exe[1564] msvcrt.dll!_wcreat 761ED326 5 Bytes JMP 008F0029
.text C:\Windows\system32\svchost.exe[1564] msvcrt.dll!_wopen 761ED501 5 Bytes JMP 008F0FDE
.text C:\Windows\system32\svchost.exe[1564] ADVAPI32.dll!RegCreateKeyExA 762E39AB 5 Bytes JMP 00910F9E
.text C:\Windows\system32\svchost.exe[1564] ADVAPI32.dll!RegCreateKeyA 762E3BA9 5 Bytes JMP 00910FC0
.text C:\Windows\system32\svchost.exe[1564] ADVAPI32.dll!RegOpenKeyA 762E89C7 5 Bytes JMP 00910000
.text C:\Windows\system32\svchost.exe[1564] ADVAPI32.dll!RegCreateKeyW 762F391E 5 Bytes JMP 00910FAF
.text C:\Windows\system32\svchost.exe[1564] ADVAPI32.dll!RegCreateKeyExW 762F41F1 5 Bytes JMP 00910F8D
.text C:\Windows\system32\svchost.exe[1564] ADVAPI32.dll!RegOpenKeyExA 762F7C42 5 Bytes JMP 0091002C
.text C:\Windows\system32\svchost.exe[1564] ADVAPI32.dll!RegOpenKeyW 762FE2B5 5 Bytes JMP 00910011
.text C:\Windows\system32\svchost.exe[1564] ADVAPI32.dll!RegOpenKeyExW 76307BA1 5 Bytes JMP 00910FDB
.text C:\Windows\system32\svchost.exe[1564] WS2_32.dll!socket 775B36D1 5 Bytes JMP 00960FE5
.text C:\Windows\System32\svchost.exe[1600] kernel32.dll!GetStartupInfoW 75E61929 5 Bytes JMP 001F00C7
.text C:\Windows\System32\svchost.exe[1600] kernel32.dll!GetStartupInfoA 75E619C9 5 Bytes JMP 001F00AC
.text C:\Windows\System32\svchost.exe[1600] kernel32.dll!CreateProcessW 75E61BF3 5 Bytes JMP 001F010E
.text C:\Windows\System32\svchost.exe[1600] kernel32.dll!CreateProcessA 75E61C28 5 Bytes JMP 001F00FD
.text C:\Windows\System32\svchost.exe[1600] kernel32.dll!VirtualProtect 75E61DC3 5 Bytes JMP 001F0087
.text C:\Windows\System32\svchost.exe[1600] kernel32.dll!CreateNamedPipeA 75E62EF5 5 Bytes JMP 001F0FE5
.text C:\Windows\System32\svchost.exe[1600] kernel32.dll!CreateNamedPipeW 75E65C0C 5 Bytes JMP 001F0036
.text C:\Windows\System32\svchost.exe[1600] kernel32.dll!CreatePipe 75E88E6E 5 Bytes JMP 001F0F81
.text C:\Windows\System32\svchost.exe[1600] kernel32.dll!LoadLibraryExW 75E89109 5 Bytes JMP 001F0FAD
.text C:\Windows\System32\svchost.exe[1600] kernel32.dll!LoadLibraryW 75E89362 5 Bytes JMP 001F006C
.text C:\Windows\System32\svchost.exe[1600] kernel32.dll!LoadLibraryExA 75E894B4 5 Bytes JMP 001F0FCA
.text C:\Windows\System32\svchost.exe[1600] kernel32.dll!LoadLibraryA 75E894DC 5 Bytes JMP 001F0047
.text C:\Windows\System32\svchost.exe[1600] kernel32.dll!VirtualProtectEx 75E8DBDA 5 Bytes JMP 001F0F92
.text C:\Windows\System32\svchost.exe[1600] kernel32.dll!GetProcAddress 75EA903B 5 Bytes JMP 001F011F
.text C:\Windows\System32\svchost.exe[1600] kernel32.dll!CreateFileW 75EAAECB 5 Bytes JMP 001F001B
.text C:\Windows\System32\svchost.exe[1600] kernel32.dll!CreateFileA 75EACE5F 5 Bytes JMP 001F000A
.text C:\Windows\System32\svchost.exe[1600] kernel32.dll!WinExec 75EF5CF7 5 Bytes JMP 001F00EC
.text C:\Windows\System32\svchost.exe[1600] msvcrt.dll!_wsystem 761E7F2F 5 Bytes JMP 002D0FAF
.text C:\Windows\System32\svchost.exe[1600] msvcrt.dll!system 761E804B 5 Bytes JMP 002D0FCA
.text C:\Windows\System32\svchost.exe[1600] msvcrt.dll!_creat 761EBBE1 5 Bytes JMP 002D0029
.text C:\Windows\System32\svchost.exe[1600] msvcrt.dll!_open 761ED106 5 Bytes JMP 002D0FEF
.text C:\Windows\System32\svchost.exe[1600] msvcrt.dll!_wcreat 761ED326 5 Bytes JMP 002D003A
.text C:\Windows\System32\svchost.exe[1600] msvcrt.dll!_wopen 761ED501 5 Bytes JMP 002D0018
.text C:\Windows\System32\svchost.exe[1600] ADVAPI32.dll!RegCreateKeyExA 762E39AB 5 Bytes JMP 00C70F8A
.text C:\Windows\System32\svchost.exe[1600] ADVAPI32.dll!RegCreateKeyA 762E3BA9 5 Bytes JMP 00C70FA5
.text C:\Windows\System32\svchost.exe[1600] ADVAPI32.dll!RegOpenKeyA 762E89C7 5 Bytes JMP 00C70FEF
.text C:\Windows\System32\svchost.exe[1600] ADVAPI32.dll!RegCreateKeyW 762F391E 5 Bytes JMP 00C7002C
.text C:\Windows\System32\svchost.exe[1600] ADVAPI32.dll!RegCreateKeyExW 762F41F1 5 Bytes JMP 00C70047
.text C:\Windows\System32\svchost.exe[1600] ADVAPI32.dll!RegOpenKeyExA 762F7C42 5 Bytes JMP 00C7000A
.text C:\Windows\System32\svchost.exe[1600] ADVAPI32.dll!RegOpenKeyW 762FE2B5 5 Bytes JMP 00C70FDE
.text C:\Windows\System32\svchost.exe[1600] ADVAPI32.dll!RegOpenKeyExW 76307BA1 5 Bytes JMP 00C7001B
.text C:\Windows\System32\svchost.exe[1600] WS2_32.dll!socket 775B36D1 5 Bytes JMP 00C90000
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetStartupInfoW 75E61929 5 Bytes JMP 00240F63
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetStartupInfoA 75E619C9 5 Bytes JMP 002400B3
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateProcessW 75E61BF3 5 Bytes JMP 00240F30
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateProcessA 75E61C28 5 Bytes JMP 00240F41
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!VirtualProtect 75E61DC3 5 Bytes JMP 00240076
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateNamedPipeA 75E62EF5 5 Bytes JMP 00240FDB
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateNamedPipeW 75E65C0C 5 Bytes JMP 00240FCA
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreatePipe 75E88E6E 5 Bytes JMP 00240098
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!LoadLibraryExW 75E89109 5 Bytes JMP 00240F9E
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!LoadLibraryW 75E89362 5 Bytes JMP 00240051
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!LoadLibraryExA 75E894B4 5 Bytes JMP 00240FAF
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!LoadLibraryA 75E894DC 5 Bytes JMP 00240040
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!VirtualProtectEx 75E8DBDA 5 Bytes JMP 00240087
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!GetProcAddress 75EA903B 5 Bytes JMP 00240F1F
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateFileW 75EAAECB 5 Bytes JMP 00240011
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!CreateFileA 75EACE5F 5 Bytes JMP 00240000
.text C:\Windows\system32\svchost.exe[1836] kernel32.dll!WinExec 75EF5CF7 5 Bytes JMP 00240F52
.text C:\Windows\system32\svchost.exe[1836] msvcrt.dll!_wsystem 761E7F2F 5 Bytes JMP 00270F97
.text C:\Windows\system32\svchost.exe[1836] msvcrt.dll!system 761E804B 5 Bytes JMP 0027002C
.text C:\Windows\system32\svchost.exe[1836] msvcrt.dll!_creat 761EBBE1 5 Bytes JMP 00270011
.text C:\Windows\system32\svchost.exe[1836] msvcrt.dll!_open 761ED106 5 Bytes JMP 00270000
.text C:\Windows\system32\svchost.exe[1836] msvcrt.dll!_wcreat 761ED326 5 Bytes JMP 00270FBC
.text C:\Windows\system32\svchost.exe[1836] msvcrt.dll!_wopen 761ED501 5 Bytes JMP 00270FE3
.text C:\Windows\system32\svchost.exe[1836] ADVAPI32.dll!RegCreateKeyExA 762E39AB 5 Bytes JMP 00CE008E
.text C:\Windows\system32\svchost.exe[1836] ADVAPI32.dll!RegCreateKeyA 762E3BA9 5 Bytes JMP 00CE006C
.text C:\Windows\system32\svchost.exe[1836] ADVAPI32.dll!RegOpenKeyA 762E89C7 5 Bytes JMP 00CE0000
.text C:\Windows\system32\svchost.exe[1836] ADVAPI32.dll!RegCreateKeyW 762F391E 5 Bytes JMP 00CE007D
.text C:\Windows\system32\svchost.exe[1836] ADVAPI32.dll!RegCreateKeyExW 762F41F1 5 Bytes JMP 00CE0FD1
.text C:\Windows\system32\svchost.exe[1836] ADVAPI32.dll!RegOpenKeyExA 762F7C42 5 Bytes JMP 00CE0036
.text C:\Windows\system32\svchost.exe[1836] ADVAPI32.dll!RegOpenKeyW 762FE2B5 5 Bytes JMP 00CE001B
.text C:\Windows\system32\svchost.exe[1836] ADVAPI32.dll!RegOpenKeyExW 76307BA1 5 Bytes JMP 00CE0047
.text C:\Windows\system32\svchost.exe[1836] WS2_32.dll!socket 775B36D1 5 Bytes JMP 00CF0FEF
.text C:\Windows\system32\svchost.exe[2100] kernel32.dll!GetStartupInfoW 75E61929 5 Bytes JMP 00070F57
.text C:\Windows\system32\svchost.exe[2100] kernel32.dll!GetStartupInfoA 75E619C9 5 Bytes JMP 00070F68
.text C:\Windows\system32\svchost.exe[2100] kernel32.dll!CreateProcessW 75E61BF3 5 Bytes JMP 000700B8
.text C:\Windows\system32\svchost.exe[2100] kernel32.dll!CreateProcessA 75E61C28 5 Bytes JMP 00070F21
.text C:\Windows\system32\svchost.exe[2100] kernel32.dll!VirtualProtect 75E61DC3 5 Bytes JMP 0007006E
.text C:\Windows\system32\svchost.exe[2100] kernel32.dll!CreateNamedPipeA 75E62EF5 5 Bytes JMP 0007001B
.text C:\Windows\system32\svchost.exe[2100] kernel32.dll!CreateNamedPipeW 75E65C0C 5 Bytes JMP 00070FC0
.text C:\Windows\system32\svchost.exe[2100] kernel32.dll!CreatePipe 75E88E6E 5 Bytes JMP 00070093
.text C:\Windows\system32\svchost.exe[2100] kernel32.dll!LoadLibraryExW 75E89109 5 Bytes JMP 0007005D
.text C:\Windows\system32\svchost.exe[2100] kernel32.dll!LoadLibraryW 75E89362 5 Bytes JMP 00070FAF
.text C:\Windows\system32\svchost.exe[2100] kernel32.dll!LoadLibraryExA 75E894B4 5 Bytes JMP 00070F94
.text C:\Windows\system32\svchost.exe[2100] kernel32.dll!LoadLibraryA 75E894DC 5 Bytes JMP 0007002C
.text C:\Windows\system32\svchost.exe[2100] kernel32.dll!VirtualProtectEx 75E8DBDA 5 Bytes JMP 00070F83
.text C:\Windows\system32\svchost.exe[2100] kernel32.dll!GetProcAddress 75EA903B 5 Bytes JMP 000700C9
.text C:\Windows\system32\svchost.exe[2100] kernel32.dll!CreateFileW 75EAAECB 5 Bytes JMP 00070000
.text C:\Windows\system32\svchost.exe[2100] kernel32.dll!CreateFileA 75EACE5F 5 Bytes JMP 00070FEF
.text C:\Windows\system32\svchost.exe[2100] kernel32.dll!WinExec 75EF5CF7 5 Bytes JMP 00070F3C
.text C:\Windows\system32\svchost.exe[2100] msvcrt.dll!_wsystem 761E7F2F 5 Bytes JMP 001A002C
.text C:\Windows\system32\svchost.exe[2100] msvcrt.dll!system 761E804B 5 Bytes JMP 001A001B
.text C:\Windows\system32\svchost.exe[2100] msvcrt.dll!_creat 761EBBE1 5 Bytes JMP 001A0FBC
.text C:\Windows\system32\svchost.exe[2100] msvcrt.dll!_open 761ED106 5 Bytes JMP 001A0FE3
.text C:\Windows\system32\svchost.exe[2100] msvcrt.dll!_wcreat 761ED326 5 Bytes JMP 001A0FA1
.text C:\Windows\system32\svchost.exe[2100] msvcrt.dll!_wopen 761ED501 5 Bytes JMP 001A0000
.text C:\Windows\system32\svchost.exe[2100] ADVAPI32.dll!RegCreateKeyExA 762E39AB 5 Bytes JMP 0065006C
.text C:\Windows\system32\svchost.exe[2100] ADVAPI32.dll!RegCreateKeyA 762E3BA9 5 Bytes JMP 00650FD4
.text C:\Windows\system32\svchost.exe[2100] ADVAPI32.dll!RegOpenKeyA 762E89C7 5 Bytes JMP 00650000
.text C:\Windows\system32\svchost.exe[2100] ADVAPI32.dll!RegCreateKeyW 762F391E 5 Bytes JMP 0065005B
.text C:\Windows\system32\svchost.exe[2100] ADVAPI32.dll!RegCreateKeyExW 762F41F1 5 Bytes JMP 00650087
.text C:\Windows\system32\svchost.exe[2100] ADVAPI32.dll!RegOpenKeyExA 762F7C42 5 Bytes JMP 00650036
.text C:\Windows\system32\svchost.exe[2100] ADVAPI32.dll!RegOpenKeyW 762FE2B5 5 Bytes JMP 0065001B
.text C:\Windows\system32\svchost.exe[2100] ADVAPI32.dll!RegOpenKeyExW 76307BA1 5 Bytes JMP 00650FE5
.text C:\Windows\system32\svchost.exe[2100] WS2_32.dll!socket 775B36D1 5 Bytes JMP 00660000
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!GetStartupInfoW 75E61929 5 Bytes JMP 002E0F57
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!GetStartupInfoA 75E619C9 5 Bytes JMP 002E009D
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!CreateProcessW 75E61BF3 5 Bytes JMP 002E00C2
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!CreateProcessA 75E61C28 5 Bytes JMP 002E0F2B
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!VirtualProtect 75E61DC3 5 Bytes JMP 002E0F83
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!CreateNamedPipeA 75E62EF5 5 Bytes JMP 002E0FEF
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!CreateNamedPipeW 75E65C0C 5 Bytes JMP 002E0040
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!CreatePipe 75E88E6E 5 Bytes JMP 002E0F68
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!LoadLibraryExW 75E89109 5 Bytes JMP 002E0F94
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!LoadLibraryW 75E89362 5 Bytes JMP 002E0FAF
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!LoadLibraryExA 75E894B4 5 Bytes JMP 002E0051
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!LoadLibraryA 75E894DC 5 Bytes JMP 002E0FCA
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!VirtualProtectEx 75E8DBDA 5 Bytes JMP 002E0082
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!GetProcAddress 75EA903B 5 Bytes JMP 002E0F1A
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!CreateFileW 75EAAECB 5 Bytes JMP 002E001B
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!CreateFileA 75EACE5F 5 Bytes JMP 002E000A
.text C:\Windows\system32\svchost.exe[2392] kernel32.dll!WinExec 75EF5CF7 5 Bytes JMP 002E0F3C
.text C:\Windows\system32\svchost.exe[2392] msvcrt.dll!_wsystem 761E7F2F 5 Bytes JMP 00C20064
.text C:\Windows\system32\svchost.exe[2392] msvcrt.dll!system 761E804B 5 Bytes JMP 00C20049
.text C:\Windows\system32\svchost.exe[2392] msvcrt.dll!_creat 761EBBE1 5 Bytes JMP 00C2001D
.text C:\Windows\system32\svchost.exe[2392] msvcrt.dll!_open 761ED106 5 Bytes JMP 00C20FE3
.text C:\Windows\system32\svchost.exe[2392] msvcrt.dll!_wcreat 761ED326 5 Bytes JMP 00C2002E
.text C:\Windows\system32\svchost.exe[2392] msvcrt.dll!_wopen 761ED501 5 Bytes JMP 00C2000C
.text C:\Windows\system32\svchost.exe[2392] ADVAPI32.dll!RegCreateKeyExA 762E39AB 5 Bytes JMP 00C3005B
.text C:\Windows\system32\svchost.exe[2392] ADVAPI32.dll!RegCreateKeyA 762E3BA9 5 Bytes JMP 00C30039
.text C:\Windows\system32\svchost.exe[2392] ADVAPI32.dll!RegOpenKeyA 762E89C7 5 Bytes JMP 00C30FEF
.text C:\Windows\system32\svchost.exe[2392] ADVAPI32.dll!RegCreateKeyW 762F391E 5 Bytes JMP 00C3004A
.text C:\Windows\system32\svchost.exe[2392] ADVAPI32.dll!RegCreateKeyExW 762F41F1 5 Bytes JMP 00C30FA8
.text C:\Windows\system32\svchost.exe[2392] ADVAPI32.dll!RegOpenKeyExA 762F7C42 5 Bytes JMP 00C30014
.text C:\Windows\system32\svchost.exe[2392] ADVAPI32.dll!RegOpenKeyW 762FE2B5 5 Bytes JMP 00C30FDE
.text C:\Windows\system32\svchost.exe[2392] ADVAPI32.dll!RegOpenKeyExW 76307BA1 5 Bytes JMP 00C30FC3
.text C:\Windows\system32\svchost.exe[2392] WS2_32.dll!socket 775B36D1 5 Bytes JMP 00C40000
.text C:\Windows\System32\svchost.exe[2488] kernel32.dll!GetStartupInfoW 75E61929 5 Bytes JMP 00050F86
.text C:\Windows\System32\svchost.exe[2488] kernel32.dll!GetStartupInfoA 75E619C9 5 Bytes JMP 000500CC
.text C:\Windows\System32\svchost.exe[2488] kernel32.dll!CreateProcessW 75E61BF3 5 Bytes JMP 0005010C
.text C:\Windows\System32\svchost.exe[2488] kernel32.dll!CreateProcessA 75E61C28 5 Bytes JMP 000500F1
.text C:\Windows\System32\svchost.exe[2488] kernel32.dll!VirtualProtect 75E61DC3 5 Bytes JMP 0005009D
.text C:\Windows\System32\svchost.exe[2488] kernel32.dll!CreateNamedPipeA 75E62EF5 5 Bytes JMP 00050FDE
.text C:\Windows\System32\svchost.exe[2488] kernel32.dll!CreateNamedPipeW 75E65C0C 5 Bytes JMP 0005002F
.text C:\Windows\System32\svchost.exe[2488] kernel32.dll!CreatePipe 75E88E6E 5 Bytes JMP 00050F97
.text C:\Windows\System32\svchost.exe[2488] kernel32.dll!LoadLibraryExW 75E89109 5 Bytes JMP 00050076
.text C:\Windows\System32\svchost.exe[2488] kernel32.dll!LoadLibraryW 75E89362 5 Bytes JMP 00050051
.text C:\Windows\System32\svchost.exe[2488] kernel32.dll!LoadLibraryExA 75E894B4 5 Bytes JMP 00050FB9
.text C:\Windows\System32\svchost.exe[2488] kernel32.dll!LoadLibraryA 75E894DC 5 Bytes JMP 00050040
.text C:\Windows\System32\svchost.exe[2488] kernel32.dll!VirtualProtectEx 75E8DBDA 5 Bytes JMP 00050FA8
.text C:\Windows\System32\svchost.exe[2488] kernel32.dll!GetProcAddress 75EA903B 5 Bytes JMP 0005011D
.text C:\Windows\System32\svchost.exe[2488] kernel32.dll!CreateFileW 75EAAECB 5 Bytes JMP 0005000A
.text C:\Windows\System32\svchost.exe[2488] kernel32.dll!CreateFileA 75EACE5F 5 Bytes JMP 00050FEF
.text C:\Windows\System32\svchost.exe[2488] kernel32.dll!WinExec 75EF5CF7 5 Bytes JMP 00050F75
.text C:\Windows\System32\svchost.exe[2488] msvcrt.dll!_wsystem 761E7F2F 5 Bytes JMP 00060F97
.text C:\Windows\System32\svchost.exe[2488] msvcrt.dll!system 761E804B 5 Bytes JMP 00060FA8
.text C:\Windows\System32\svchost.exe[2488] msvcrt.dll!_creat 761EBBE1 5 Bytes JMP 00060018
.text C:\Windows\System32\svchost.exe[2488] msvcrt.dll!_open 761ED106 5 Bytes JMP 00060FEF
.text C:\Windows\System32\svchost.exe[2488] msvcrt.dll!_wcreat 761ED326 5 Bytes JMP 00060FC3
.text C:\Windows\System32\svchost.exe[2488] msvcrt.dll!_wopen 761ED501 5 Bytes JMP 00060FDE
.text C:\Windows\System32\svchost.exe[2488] ADVAPI32.dll!RegCreateKeyExA 762E39AB 5 Bytes JMP 00070058
.text C:\Windows\System32\svchost.exe[2488] ADVAPI32.dll!RegCreateKeyA 762E3BA9 5 Bytes JMP 00070FB6
.text C:\Windows\System32\svchost.exe[2488] ADVAPI32.dll!RegOpenKeyA 762E89C7 5 Bytes JMP 00070000
.text C:\Windows\System32\svchost.exe[2488] ADVAPI32.dll!RegCreateKeyW 762F391E 5 Bytes JMP 00070047
.text C:\Windows\System32\svchost.exe[2488] ADVAPI32.dll!RegCreateKeyExW 762F41F1 5 Bytes JMP 00070FA5
.text C:\Windows\System32\svchost.exe[2488] ADVAPI32.dll!RegOpenKeyExA 762F7C42 5 Bytes JMP 00070FDB
.text C:\Windows\System32\svchost.exe[2488] ADVAPI32.dll!RegOpenKeyW 762FE2B5 5 Bytes JMP 00070011
.text C:\Windows\System32\svchost.exe[2488] ADVAPI32.dll!RegOpenKeyExW 76307BA1 5 Bytes JMP 00070022
.text C:\Windows\Explorer.EXE[3292] kernel32.dll!GetStartupInfoW 75E61929 5 Bytes JMP 009A0F59
.text C:\Windows\Explorer.EXE[3292] kernel32.dll!GetStartupInfoA 75E619C9 5 Bytes JMP 009A009F
.text C:\Windows\Explorer.EXE[3292] kernel32.dll!CreateProcessW 75E61BF3 5 Bytes JMP 009A00E9
.text C:\Windows\Explorer.EXE[3292] kernel32.dll!CreateProcessA 75E61C28 5 Bytes JMP 009A00CE
.text C:\Windows\Explorer.EXE[3292] kernel32.dll!VirtualProtect 75E61DC3 5 Bytes JMP 009A006C
.text C:\Windows\Explorer.EXE[3292] kernel32.dll!CreateNamedPipeA 75E62EF5 5 Bytes JMP 009A0025
.text C:\Windows\Explorer.EXE[3292] kernel32.dll!CreateNamedPipeW 75E65C0C 5 Bytes JMP 009A0FD4
.text C:\Windows\Explorer.EXE[3292] kernel32.dll!CreatePipe 75E88E6E 5 Bytes JMP 009A008E
.text C:\Windows\Explorer.EXE[3292] kernel32.dll!LoadLibraryExW 75E89109 5 Bytes JMP 009A005B
.text C:\Windows\Explorer.EXE[3292] kernel32.dll!LoadLibraryW 75E89362 5 Bytes JMP 009A0040
.text C:\Windows\Explorer.EXE[3292] kernel32.dll!LoadLibraryExA 75E894B4 5 Bytes JMP 009A0FA8
.text C:\Windows\Explorer.EXE[3292] kernel32.dll!LoadLibraryA 75E894DC 5 Bytes JMP 009A0FB9
.text C:\Windows\Explorer.EXE[3292] kernel32.dll!VirtualProtectEx 75E8DBDA 5 Bytes JMP 009A007D
.text C:\Windows\Explorer.EXE[3292] kernel32.dll!GetProcAddress 75EA903B 5 Bytes JMP 009A0F37
.text C:\Windows\Explorer.EXE[3292] kernel32.dll!CreateFileW 75EAAECB 5 Bytes JMP 009A000A
.text C:\Windows\Explorer.EXE[3292] kernel32.dll!CreateFileA 75EACE5F 5 Bytes JMP 009A0FEF
.text C:\Windows\Explorer.EXE[3292] kernel32.dll!WinExec 75EF5CF7 5 Bytes JMP 009A0F48
.text C:\Windows\Explorer.EXE[3292] ADVAPI32.dll!RegCreateKeyExA 762E39AB 5 Bytes JMP 009C0FB6
.text C:\Windows\Explorer.EXE[3292] ADVAPI32.dll!RegCreateKeyA 762E3BA9 5 Bytes JMP 009C0051
.text C:\Windows\Explorer.EXE[3292] ADVAPI32.dll!RegOpenKeyA 762E89C7 5 Bytes JMP 009C0000
.text C:\Windows\Explorer.EXE[3292] ADVAPI32.dll!RegCreateKeyW 762F391E 5 Bytes JMP 009C0062
.text C:\Windows\Explorer.EXE[3292] ADVAPI32.dll!RegCreateKeyExW 762F41F1 5 Bytes JMP 009C0073
.text C:\Windows\Explorer.EXE[3292] ADVAPI32.dll!RegOpenKeyExA 762F7C42 5 Bytes JMP 009C002C
.text C:\Windows\Explorer.EXE[3292] ADVAPI32.dll!RegOpenKeyW 762FE2B5 5 Bytes JMP 009C0011
.text C:\Windows\Explorer.EXE[3292] ADVAPI32.dll!RegOpenKeyExW 76307BA1 5 Bytes JMP 009C0FDB
.text C:\Windows\Explorer.EXE[3292] msvcrt.dll!_wsystem 761E7F2F 5 Bytes JMP 009B0042
.text C:\Windows\Explorer.EXE[3292] msvcrt.dll!system 761E804B 5 Bytes JMP 009B0FAD
.text C:\Windows\Explorer.EXE[3292] msvcrt.dll!_creat 761EBBE1 5 Bytes JMP 009B0FE3
.text C:\Windows\Explorer.EXE[3292] msvcrt.dll!_open 761ED106 5 Bytes JMP 009B0000
.text C:\Windows\Explorer.EXE[3292] msvcrt.dll!_wcreat 761ED326 5 Bytes JMP 009B0FC8
.text C:\Windows\Explorer.EXE[3292] msvcrt.dll!_wopen 761ED501 5 Bytes JMP 009B0011
.text C:\Windows\Explorer.EXE[3292] WS2_32.dll!socket 775B36D1 5 Bytes JMP 02890000
.text C:\Windows\Explorer.EXE[3292] WININET.dll!InternetOpenA 771FD47D 5 Bytes JMP 03220000
.text C:\Windows\Explorer.EXE[3292] WININET.dll!InternetOpenW 771FD7DA 5 Bytes JMP 03220011
.text C:\Windows\Explorer.EXE[3292] WININET.dll!InternetOpenUrlA 771FFE4B 5 Bytes JMP 03220FE5
.text C:\Windows\Explorer.EXE[3292] WININET.dll!InternetOpenUrlW 77249139 5 Bytes JMP 03220040
.text C:\Windows\system32\wuauclt.exe[5964] kernel32.dll!GetStartupInfoW 75E61929 5 Bytes JMP 00010080
.text C:\Windows\system32\wuauclt.exe[5964] kernel32.dll!GetStartupInfoA 75E619C9 5 Bytes JMP 00010F3A
.text C:\Windows\system32\wuauclt.exe[5964] kernel32.dll!CreateProcessW 75E61BF3 5 Bytes JMP 00010F0E
.text C:\Windows\system32\wuauclt.exe[5964] kernel32.dll!CreateProcessA 75E61C28 5 Bytes JMP 00010F1F
.text C:\Windows\system32\wuauclt.exe[5964] kernel32.dll!VirtualProtect 75E61DC3 5 Bytes JMP 00010F55
.text C:\Windows\system32\wuauclt.exe[5964] kernel32.dll!CreateNamedPipeA 75E62EF5 5 Bytes JMP 00010FD4
.text C:\Windows\system32\wuauclt.exe[5964] kernel32.dll!CreateNamedPipeW 75E65C0C 5 Bytes JMP 0001001B
.text C:\Windows\system32\wuauclt.exe[5964] kernel32.dll!CreatePipe 75E88E6E 5 Bytes JMP 00010065
.text C:\Windows\system32\wuauclt.exe[5964] kernel32.dll!LoadLibraryExW 75E89109 5 Bytes JMP 00010F72
.text C:\Windows\system32\wuauclt.exe[5964] kernel32.dll!LoadLibraryW 75E89362 5 Bytes JMP 00010F94
.text C:\Windows\system32\wuauclt.exe[5964] kernel32.dll!LoadLibraryExA 75E894B4 5 Bytes JMP 00010F83
.text C:\Windows\system32\wuauclt.exe[5964] kernel32.dll!LoadLibraryA 75E894DC 5 Bytes JMP 00010FAF
.text C:\Windows\system32\wuauclt.exe[5964] kernel32.dll!VirtualProtectEx 75E8DBDA 5 Bytes JMP 00010054
.text C:\Windows\system32\wuauclt.exe[5964] kernel32.dll!GetProcAddress 75EA903B 5 Bytes JMP 000100C0
.text C:\Windows\system32\wuauclt.exe[5964] kernel32.dll!CreateFileW 75EAAECB 5 Bytes JMP 00010FE5
.text C:\Windows\system32\wuauclt.exe[5964] kernel32.dll!CreateFileA 75EACE5F 5 Bytes JMP 00010000
.text C:\Windows\system32\wuauclt.exe[5964] kernel32.dll!WinExec 75EF5CF7 5 Bytes JMP 00010091
.text C:\Windows\system32\wuauclt.exe[5964] msvcrt.dll!_wsystem 761E7F2F 5 Bytes JMP 00060F97
.text C:\Windows\system32\wuauclt.exe[5964] msvcrt.dll!system 761E804B 5 Bytes JMP 00060FB2
.text C:\Windows\system32\wuauclt.exe[5964] msvcrt.dll!_creat 761EBBE1 5 Bytes JMP 00060FCD
.text C:\Windows\system32\wuauclt.exe[5964] msvcrt.dll!_open 761ED106 5 Bytes JMP 00060FEF
.text C:\Windows\system32\wuauclt.exe[5964] msvcrt.dll!_wcreat 761ED326 5 Bytes JMP 00060022
.text C:\Windows\system32\wuauclt.exe[5964] msvcrt.dll!_wopen 761ED501 5 Bytes JMP 00060FDE
.text C:\Windows\system32\wuauclt.exe[5964] ADVAPI32.dll!RegCreateKeyExA 762E39AB 5 Bytes JMP 00070058
.text C:\Windows\system32\wuauclt.exe[5964] ADVAPI32.dll!RegCreateKeyA 762E3BA9 5 Bytes JMP 00070FC0
.text C:\Windows\system32\wuauclt.exe[5964] ADVAPI32.dll!RegOpenKeyA 762E89C7 5 Bytes JMP 00070FEF
.text C:\Windows\system32\wuauclt.exe[5964] ADVAPI32.dll!RegCreateKeyW 762F391E 5 Bytes JMP 00070047
.text C:\Windows\system32\wuauclt.exe[5964] ADVAPI32.dll!RegCreateKeyExW 762F41F1 5 Bytes JMP 00070F9B
.text C:\Windows\system32\wuauclt.exe[5964] ADVAPI32.dll!RegOpenKeyExA 762F7C42 5 Bytes JMP 0007001B
.text C:\Windows\system32\wuauclt.exe[5964] ADVAPI32.dll!RegOpenKeyW 762FE2B5 5 Bytes JMP 0007000A
.text C:\Windows\system32\wuauclt.exe[5964] ADVAPI32.dll!RegOpenKeyExW 76307BA1 5 Bytes JMP 0007002C

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

---- EOF - GMER 1.0.15 ----
bonsers
Regular Member
 
Posts: 15
Joined: July 26th, 2010, 2:02 pm

Re: IE redirecting via ohtgnoenriga.com + getting pop ups

Unread postby peku006 » September 7th, 2010, 3:29 pm

Hi bonsers
shall i forget rootrepeal.zip?

Yes

do not see anything suspicious in the Gmer log..........

Kaspersky Online Scan

You can use either Internet Explorer or Mozilla FireFox for this scan.

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • Hold down Control then click on the following link to open a new window to Kaspersky Online Scan
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
  • Click on My Computer under Scan. * This will take a while. Please be patient *.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

This online tutorial will help explain how to use the aforementioned online scan

Thanks peku006
User avatar
peku006
MRU Emeritus
MRU Emeritus
 
Posts: 3357
Joined: May 14th, 2007, 2:18 pm
Location: Norway

Re: IE redirecting via ohtgnoenriga.com + getting pop ups

Unread postby bonsers » September 7th, 2010, 6:47 pm

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Tuesday, September 7, 2010
Operating system: Microsoft Windows Vista Home Basic Edition, 32-bit Service Pack 2 (build 6002)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Tuesday, September 07, 2010 12:39:03
Records in database: 4202275
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
E:\
F:\

Scan statistics:
Objects scanned: 132386
Threats found: 4
Infected objects found: 6
Suspicious objects found: 0
Scan duration: 01:49:53


File name / Threat / Threats count
C:\Users\robert\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\2cc0dad0-5c4d838e Infected: Exploit.Java.CVE-2009-3867.h 1
C:\Users\robert\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\2cc0dad0-5c4d838e Infected: Exploit.Java.CVE-2009-3867.g 1
C:\Users\robert\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\2cc0dad0-5c4d838e Infected: Exploit.Java.CVE-2009-3867.f 1
C:\Users\robert\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\2eb73969-47e5bcdb Infected: Exploit.Java.Agent.ca 3

Selected area has been scanned.
bonsers
Regular Member
 
Posts: 15
Joined: July 26th, 2010, 2:02 pm
Advertisement
Register to Remove

Next

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 24 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware