System is windows XP Media Center Edition SP3 and I believe it is reasonably updated because Automatic Updated was turned on and functional after I fixed the first problem which was that the system would not connect to the internet - no way no how no browsers nothing. System belongs to an old man friend of mine and he just clicks on everything and installs everything. IE8 was so loaded with toolbars it would hardly launch.
I restored the system back to 1 week prior (sucessfully - amazingly) and connectivity to the internet was fixed. Now is when I started seeing Automatic Updates icon appearing in the System Tray.
Proceeded to disable and delete toolbars as much as possible. Finally had to reset IE8 to the defaults and it worked much better. Continued to uninstall toolbars as much as possible.
Downloaded and installed Malwarebytes Free Edition, updated it and deep, thorough scanned. It found loads of stuff and I cleaned it all.
Downloaded and installed Superantispyware, updated it and deep thorough scanned. It too found more stuff and I cleaned it all.
Downloaded and installed Spybot Search n Destroy (no Tea Times or SD Helper), updated it and scanned. It found more stuff. Went to the BHO section in Advanced Mode and cleared out 2 obvious crap remnants of BHO's.
Manually deleted everything out of Owner's Temp files, Temporary Internet Files and Windows Prefetch (except the .ini file there.
I have scanned with TDSSKiller and Panda's Anti-Rootkit scanners but none of them find anything.
NOW - Symptoms include:
Unable to install ActiveX control for Windows Update in IE8 - therefore cannot do manual/custom Windows Update using IE8. The ActiveX Install window (with Install button) appears but when I click it to install it, IE8 freezes for a while and then displays a page saying: "Internet Explorer has closed this webpage to help protect your computer.
Windows Data Execution Prevention detected an add-on trying to use system memory incorrectly. This can be caused by a malfunction or a malicious add-on."
Unable to install Qualys Browser Check ActiveX Control. Browser gets stuck in a loop to install it over and over again but it never installs and Qualys never scans.
Unable to scan with ESET online scanner. When launched from the website, the 1/3 size window appeart but the thing will not Start. I suspect this window is ActiveX involved/related somehow too. Yep it is. Just tried it on another system and it requires the installation of an ActiveX control.
GMER and HijackThis suggest to me that SOMETHING STEALTHY IS STILL GOING ON. A file named pxtdqpog.sys is listed in the Temp files folder but when I navigate there is is not visible in Windows Explorer.
Twice, when I first ran GMER successfully, but then closed it and then ran it a second time - I got the BSOD.
MBAM LOG:
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.09.02.04
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
GERALD WERBIN :: CAROL [administrator]
9/2/2012 12:55:28 PM
mbam-log-2012-09-02 (12-55-28).txt
Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 328631
Time elapsed: 1 hour(s), 22 minute(s), 4 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 67
HKCR\CLSID\{032416f0-0007-481b-9df8-9bcd1bf357f0} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{696d3b4f-71ef-41cc-96ff-342317e644de} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{0270C2C5-40BD-4CFF-B0DF-79AD2E283AD3} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{045c5f24-9e13-4ea8-ab93-fddab34f3fa5} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{23f28f6b-50a2-4327-9450-7d3d2f33daae} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{4de8b15e-e379-482a-81c5-cd99eb8cef40} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{6DDD8F3F-3774-484C-938C-4D9AB3A5F575} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{272143f8-3dbe-424c-949f-20acd11e5a6d} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{a436c6ec-9040-4322-ab62-bdb9e81e2f6c} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{7448C04F-A2EC-43F8-B42C-49001A49A199} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{272143F8-3DBE-424C-949F-20ACD11E5A6D} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{2c72f7a5-8160-4024-94d8-e0995d547bb0} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{3042df7a-e900-4389-9b94-923df0daa57e} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3042DF7A-E900-4389-9B94-923DF0DAA57E} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{488c2712-1482-42ad-bc4d-681e5832f0c2} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{d1479029-bacc-4c9a-8c15-d857a2974e27} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{8A44A538-73FC-4D86-83DB-68ACE71E5FE8} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{58376892-60e7-4f63-aca0-0f686af554d6} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{58376892-60E7-4F63-ACA0-0F686AF554D6} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{58376892-60E7-4F63-ACA0-0F686AF554D6} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{5b610696-32b6-416c-bf5c-ca4f60a345dd} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5B610696-32B6-416C-BF5C-CA4F60A345DD} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{6d0c6f55-e3eb-4d6b-8f52-996b4da196d9} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{a525b28e-04ee-455f-8c17-3a0273ebea2c} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{5BD5AE73-FDA3-469B-9358-D4EDA7123370} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6D0C6F55-E3EB-4D6B-8F52-996B4DA196D9} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{6eb534fb-2001-45c4-b860-bc904865a379} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{6EB534FB-2001-45C4-B860-BC904865A379} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6EB534FB-2001-45C4-B860-BC904865A379} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{715321aa-a1fc-4058-8ffa-668d687b6e32} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{73a7cce6-ff3a-4c7f-9a3e-db9bd92be292} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{82481cff-738f-4410-bffb-77595d5d9faa} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{9d14caf3-88c2-4c9a-ae73-fe77c2a5697d} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{BE9F4D06-3A23-4F1A-902F-D9E113793576} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{8eb0aaa0-2ffe-4326-8331-efe2d5d15ec7} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{1a033ae8-0d4d-4ec8-a4a9-47bbe0b6489b} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{264E97DD-7AD7-442B-87A8-F9EC4819E47B} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8EB0AAA0-2FFE-4326-8331-EFE2D5D15EC7} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{afed4702-7932-4426-aea4-9b248189c7a3} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{b4ea8204-ee81-4f73-a240-ec4aeb8ad3de} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{da08805b-ba32-426b-ad14-ecac8235a8aa} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{6c367b45-0824-419a-af7f-157665b56aba} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{08855E67-37D6-48CC-B59E-A010D658A7BB} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{e001b32e-5acb-4cce-9910-2d379ce0a6d6} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{220d75ad-0772-4c6c-a72f-8bf267c13cb5} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{317D0A60-985E-4C4D-BA9B-8D1026665EA9} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E001B32E-5ACB-4CCE-9910-2D379CE0A6D6} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{e7472076-ff9d-4325-8eaf-613572008758} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{E7472076-FF9D-4325-8EAF-613572008758} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E7472076-FF9D-4325-8EAF-613572008758} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{eb2049f6-9dfa-4e51-b2a1-fc5a6e596c80} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{9378167c-fac6-4dfb-bd4f-f7c195d2b1e4} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{19C920DF-88F9-44F8-A17E-A35A12D60525} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EB2049F6-9DFA-4E51-B2A1-FC5A6E596C80} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{F9A402FD-82C8-4743-991E-BC77E62DA0E5} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F9A402FD-82C8-4743-991E-BC77E62DA0E5} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2pInstaller.Start (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2pInstaller.Start.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (PUP.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Detected: 4
HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser|{3042DF7A-E900-4389-9B94-923DF0DAA57E} (PUP.MyWebSearch) -> Data: ???????? -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{3042DF7A-E900-4389-9B94-923DF0DAA57E} (PUP.MyWebSearch) -> Data: -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{3042DF7A-E900-4389-9B94-923DF0DAA57E} (PUP.MyWebSearch) -> Data: -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{3042df7a-e900-4389-9b94-923df0daa57e} (PUP.MyWebSearch) -> Data: -> Quarantined and deleted successfully.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 67
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4htmlmu.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\NPv4Stub.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4auxstb.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4bar.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4barsvc.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4brmon.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4brstub.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4datact.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4dlghk.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4dyn.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4feedmg.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4highin.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4hkstub.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4html.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4httpct.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4idle.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4ieovr.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4impipe.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4medint.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4mlbtn.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4msg.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4Plugin.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4radio.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4regfft.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4reghk.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4regiet.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4script.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4skin.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4skplay.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4SrcAs.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4SrchMn.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4tpinst.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4uabtn.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221221.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221204.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221205.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221206.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221207.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221208.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221209.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221210.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221211.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221212.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221213.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221214.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221215.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221216.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221217.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221218.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221219.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221220.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221222.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221223.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221224.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221225.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221226.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221227.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221229.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221230.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221231.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221232.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221234.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1842\A0221270.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1842\A0221271.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1842\A0221272.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1842\A0221273.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1849\A0221595.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
(end)
GMER LOG:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-09-04 17:02:36
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e ST3160828AS rev.8.03
Running: 9yy0kq8x.exe; Driver: C:\DOCUME~1\GERALD~1\LOCALS~1\Temp\pxtdqpog.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\drivers\dwprot.sys ZwAllocateVirtualMemory [0xA6AA72D2]
SSDT \SystemRoot\system32\drivers\dwprot.sys ZwCreateThread [0xA6AA8904]
SSDT \SystemRoot\system32\drivers\dwprot.sys ZwFreeVirtualMemory [0xA6AA755E]
SSDT \SystemRoot\system32\drivers\dwprot.sys ZwOpenSection [0xA6AA70F0]
SSDT \SystemRoot\system32\drivers\dwprot.sys ZwQueueApcThread [0xA6AA8A0C]
SSDT \SystemRoot\system32\drivers\dwprot.sys ZwSetContextThread [0xA6AA8A58]
SSDT \SystemRoot\system32\drivers\dwprot.sys ZwSystemDebugControl [0xA6AA7006]
SSDT \SystemRoot\system32\drivers\dwprot.sys ZwWriteVirtualMemory [0xA6AA766E]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xB9EAA594]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xB9EAA5A8]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ObfDereferenceObject 805266C2 7 Bytes [B8, 44, 98, 32, BA, FF, E0] {MOV EAX, 0xba329844; JMP EAX}
PAGE ntkrnlpa.exe!MmMapViewOfSection 805B1DFE 7 Bytes [B8, D0, 92, 32, BA, FF, E0] {MOV EAX, 0xba3292d0; JMP EAX}
PAGE ntkrnlpa.exe!ObCreateObject 805C13BC 7 Bytes [B8, 12, 92, 32, BA, FF, E0] {MOV EAX, 0xba329212; JMP EAX}
PAGE ntkrnlpa.exe!ObInsertObject 805C2FE2 7 Bytes [B8, E4, 96, 32, BA, FF, E0] {MOV EAX, 0xba3296e4; JMP EAX}
PAGE ntkrnlpa.exe!NtOpenProcess 805CB456 5 Bytes JMP B9EAA598 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 805CB6E2 5 Bytes JMP B9EAA5AC mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
? phooks.sys The system cannot find the file specified. !
init C:\WINDOWS\system32\DRIVERS\mohfilt.sys entry point in "init" section [0xBA493720]
? system32\drivers\dwprot.sys The system cannot find the path specified. !
? C:\DOCUME~1\GERALD~1\LOCALS~1\Temp\urj6OI3j.sys The system cannot find the file specified. !
? C:\WINDOWS\system32\Drivers\RKREVEAL150.SYS The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[1500] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 624199A1 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[1500] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 62419A63 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\system32\SearchIndexer.exe[2732] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA963D] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6BFA963D] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA963D] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [6BFA963D] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA963D] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6BFA963D] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
I restored the system back to 1 week prior (sucessfully - amazingly) and connectivity to the internet was fixed. Now is when I started seeing Automatic Updates icon appearing in the System Tray.
Proceeded to disable and delete toolbars as much as possible. Finally had to reset IE8 to the defaults and it worked much better. Continued to uninstall toolbars as much as possible.
Downloaded and installed Malwarebytes Free Edition, updated it and deep, thorough scanned. It found loads of stuff and I cleaned it all.
Downloaded and installed Superantispyware, updated it and deep thorough scanned. It too found more stuff and I cleaned it all.
Downloaded and installed Spybot Search n Destroy (no Tea Times or SD Helper), updated it and scanned. It found more stuff. Went to the BHO section in Advanced Mode and cleared out 2 obvious crap remnants of BHO's.
Manually deleted everything out of Owner's Temp files, Temporary Internet Files and Windows Prefetch (except the .ini file there.
I have scanned with TDSSKiller and Panda's Anti-Rootkit scanners but none of them find anything.
NOW - Symptoms include:
Unable to install ActiveX control for Windows Update in IE8 - therefore cannot do manual/custom Windows Update using IE8. The ActiveX Install window (with Install button) appears but when I click it to install it, IE8 freezes for a while and then displays a page saying: "Internet Explorer has closed this webpage to help protect your computer.
Windows Data Execution Prevention detected an add-on trying to use system memory incorrectly. This can be caused by a malfunction or a malicious add-on."
Unable to install Qualys Browser Check ActiveX Control. Browser gets stuck in a loop to install it over and over again but it never installs and Qualys never scans.
Unable to scan with ESET online scanner. When launched from the website, the 1/3 size window appeart but the thing will not Start. I suspect this window is ActiveX involved/related somehow too. Yep it is. Just tried it on another system and it requires the installation of an ActiveX control.
GMER and HijackThis suggest to me that SOMETHING STEALTHY IS STILL GOING ON. A file named pxtdqpog.sys is listed in the Temp files folder but when I navigate there is is not visible in Windows Explorer.
Twice, when I first ran GMER successfully, but then closed it and then ran it a second time - I got the BSOD.
MBAM LOG:
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.09.02.04
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
GERALD WERBIN :: CAROL [administrator]
9/2/2012 12:55:28 PM
mbam-log-2012-09-02 (12-55-28).txt
Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 328631
Time elapsed: 1 hour(s), 22 minute(s), 4 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 67
HKCR\CLSID\{032416f0-0007-481b-9df8-9bcd1bf357f0} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{696d3b4f-71ef-41cc-96ff-342317e644de} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{0270C2C5-40BD-4CFF-B0DF-79AD2E283AD3} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{045c5f24-9e13-4ea8-ab93-fddab34f3fa5} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{23f28f6b-50a2-4327-9450-7d3d2f33daae} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{4de8b15e-e379-482a-81c5-cd99eb8cef40} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{6DDD8F3F-3774-484C-938C-4D9AB3A5F575} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{272143f8-3dbe-424c-949f-20acd11e5a6d} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{a436c6ec-9040-4322-ab62-bdb9e81e2f6c} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{7448C04F-A2EC-43F8-B42C-49001A49A199} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{272143F8-3DBE-424C-949F-20ACD11E5A6D} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{2c72f7a5-8160-4024-94d8-e0995d547bb0} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{3042df7a-e900-4389-9b94-923df0daa57e} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3042DF7A-E900-4389-9B94-923DF0DAA57E} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{488c2712-1482-42ad-bc4d-681e5832f0c2} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{d1479029-bacc-4c9a-8c15-d857a2974e27} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{8A44A538-73FC-4D86-83DB-68ACE71E5FE8} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{58376892-60e7-4f63-aca0-0f686af554d6} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{58376892-60E7-4F63-ACA0-0F686AF554D6} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{58376892-60E7-4F63-ACA0-0F686AF554D6} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{5b610696-32b6-416c-bf5c-ca4f60a345dd} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5B610696-32B6-416C-BF5C-CA4F60A345DD} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{6d0c6f55-e3eb-4d6b-8f52-996b4da196d9} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{a525b28e-04ee-455f-8c17-3a0273ebea2c} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{5BD5AE73-FDA3-469B-9358-D4EDA7123370} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6D0C6F55-E3EB-4D6B-8F52-996B4DA196D9} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{6eb534fb-2001-45c4-b860-bc904865a379} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{6EB534FB-2001-45C4-B860-BC904865A379} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6EB534FB-2001-45C4-B860-BC904865A379} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{715321aa-a1fc-4058-8ffa-668d687b6e32} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{73a7cce6-ff3a-4c7f-9a3e-db9bd92be292} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{82481cff-738f-4410-bffb-77595d5d9faa} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{9d14caf3-88c2-4c9a-ae73-fe77c2a5697d} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{BE9F4D06-3A23-4F1A-902F-D9E113793576} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{8eb0aaa0-2ffe-4326-8331-efe2d5d15ec7} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{1a033ae8-0d4d-4ec8-a4a9-47bbe0b6489b} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{264E97DD-7AD7-442B-87A8-F9EC4819E47B} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8EB0AAA0-2FFE-4326-8331-EFE2D5D15EC7} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{afed4702-7932-4426-aea4-9b248189c7a3} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{b4ea8204-ee81-4f73-a240-ec4aeb8ad3de} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{da08805b-ba32-426b-ad14-ecac8235a8aa} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{6c367b45-0824-419a-af7f-157665b56aba} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{08855E67-37D6-48CC-B59E-A010D658A7BB} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{e001b32e-5acb-4cce-9910-2d379ce0a6d6} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{220d75ad-0772-4c6c-a72f-8bf267c13cb5} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{317D0A60-985E-4C4D-BA9B-8D1026665EA9} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E001B32E-5ACB-4CCE-9910-2D379CE0A6D6} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{e7472076-ff9d-4325-8eaf-613572008758} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{E7472076-FF9D-4325-8EAF-613572008758} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E7472076-FF9D-4325-8EAF-613572008758} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{eb2049f6-9dfa-4e51-b2a1-fc5a6e596c80} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{9378167c-fac6-4dfb-bd4f-f7c195d2b1e4} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{19C920DF-88F9-44F8-A17E-A35A12D60525} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EB2049F6-9DFA-4E51-B2A1-FC5A6E596C80} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{F9A402FD-82C8-4743-991E-BC77E62DA0E5} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F9A402FD-82C8-4743-991E-BC77E62DA0E5} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2pInstaller.Start (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CouponAlert_2pInstaller.Start.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (PUP.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Detected: 4
HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser|{3042DF7A-E900-4389-9B94-923DF0DAA57E} (PUP.MyWebSearch) -> Data: ???????? -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{3042DF7A-E900-4389-9B94-923DF0DAA57E} (PUP.MyWebSearch) -> Data: -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{3042DF7A-E900-4389-9B94-923DF0DAA57E} (PUP.MyWebSearch) -> Data: -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{3042df7a-e900-4389-9b94-923df0daa57e} (PUP.MyWebSearch) -> Data: -> Quarantined and deleted successfully.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 67
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4htmlmu.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\NPv4Stub.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4auxstb.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4bar.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4barsvc.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4brmon.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4brstub.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4datact.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4dlghk.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4dyn.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4feedmg.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4highin.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4hkstub.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4html.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4httpct.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4idle.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4ieovr.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4impipe.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4medint.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4mlbtn.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4msg.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4Plugin.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4radio.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4regfft.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4reghk.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4regiet.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4script.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4skin.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4skplay.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4SrcAs.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4SrchMn.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4tpinst.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-432067519-1997297027-1167191528-1005\Dc19.bin\v4uabtn.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221221.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221204.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221205.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221206.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221207.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221208.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221209.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221210.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221211.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221212.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221213.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221214.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221215.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221216.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221217.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221218.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221219.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221220.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221222.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221223.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221224.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221225.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221226.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221227.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221229.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221230.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221231.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221232.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1841\A0221234.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1842\A0221270.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1842\A0221271.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1842\A0221272.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1842\A0221273.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1849\A0221595.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
(end)
GMER LOG:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-09-04 17:02:36
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e ST3160828AS rev.8.03
Running: 9yy0kq8x.exe; Driver: C:\DOCUME~1\GERALD~1\LOCALS~1\Temp\pxtdqpog.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\drivers\dwprot.sys ZwAllocateVirtualMemory [0xA6AA72D2]
SSDT \SystemRoot\system32\drivers\dwprot.sys ZwCreateThread [0xA6AA8904]
SSDT \SystemRoot\system32\drivers\dwprot.sys ZwFreeVirtualMemory [0xA6AA755E]
SSDT \SystemRoot\system32\drivers\dwprot.sys ZwOpenSection [0xA6AA70F0]
SSDT \SystemRoot\system32\drivers\dwprot.sys ZwQueueApcThread [0xA6AA8A0C]
SSDT \SystemRoot\system32\drivers\dwprot.sys ZwSetContextThread [0xA6AA8A58]
SSDT \SystemRoot\system32\drivers\dwprot.sys ZwSystemDebugControl [0xA6AA7006]
SSDT \SystemRoot\system32\drivers\dwprot.sys ZwWriteVirtualMemory [0xA6AA766E]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xB9EAA594]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xB9EAA5A8]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ObfDereferenceObject 805266C2 7 Bytes [B8, 44, 98, 32, BA, FF, E0] {MOV EAX, 0xba329844; JMP EAX}
PAGE ntkrnlpa.exe!MmMapViewOfSection 805B1DFE 7 Bytes [B8, D0, 92, 32, BA, FF, E0] {MOV EAX, 0xba3292d0; JMP EAX}
PAGE ntkrnlpa.exe!ObCreateObject 805C13BC 7 Bytes [B8, 12, 92, 32, BA, FF, E0] {MOV EAX, 0xba329212; JMP EAX}
PAGE ntkrnlpa.exe!ObInsertObject 805C2FE2 7 Bytes [B8, E4, 96, 32, BA, FF, E0] {MOV EAX, 0xba3296e4; JMP EAX}
PAGE ntkrnlpa.exe!NtOpenProcess 805CB456 5 Bytes JMP B9EAA598 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 805CB6E2 5 Bytes JMP B9EAA5AC mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
? phooks.sys The system cannot find the file specified. !
init C:\WINDOWS\system32\DRIVERS\mohfilt.sys entry point in "init" section [0xBA493720]
? system32\drivers\dwprot.sys The system cannot find the path specified. !
? C:\DOCUME~1\GERALD~1\LOCALS~1\Temp\urj6OI3j.sys The system cannot find the file specified. !
? C:\WINDOWS\system32\Drivers\RKREVEAL150.SYS The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[1500] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 624199A1 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[1500] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 62419A63 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\system32\SearchIndexer.exe[2732] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA963D] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6BFA963D] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA963D] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryExA] [6BFA963D] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] [6BFA963D] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\1135344252\ee\AOLSoftware.exe[400] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA974B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6BFA963D] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6BFA96C4] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6BFA95BC] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)
IAT C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe[484] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [6BFA953B] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL Inc.)