stijpn2012
Posts: 39 +0
I'm having issues with a virus that causes a pop up ad when i start up my PC and has slowed the performance as well.
Malwarebytes Anti-Malware (Trial) 1.60.0.1800
www.malwarebytes.org
Database version: v2012.01.09.06
Windows 7 Service Pack 1 x86 NTFS (Safe Mode/Networking)
Internet Explorer 9.0.8112.16421
Protection: Disabled
1/10/2012 1:12:53 AM
mbam-log-2012-01-10 (01-12-53).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 213001
Time elapsed: 2 minute(s), 37 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 2
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|SystemBootNQtdP6TDS6cn0vSDlYFgIHWxSydqQbiS (Trojan.PMovie) -> Data: C:\Users\bbailey\UserProfile\SystemBoot.lnk -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|RegWriteNQtdP6TDS6cn0vSDlYFgIHWxSydqQbiS (Trojan.PMovie) -> Data: C:\Users\bbailey\SoftRecovery\RegWrite.lnk -> Quarantined and deleted successfully.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 2
C:\Users\bbailey\UserProfile\SystemBoot.lnk (Trojan.PMovie) -> Quarantined and deleted successfully.
C:\Users\bbailey\SoftRecovery\RegWrite.lnk (Trojan.PMovie) -> Quarantined and deleted successfully.
(end)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-01-10 01:55:31
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD25 rev.03.0
Running: gmer.exe; Driver: C:\Users\bbailey\AppData\Local\Temp\fwldrpod.sys
---- System - GMER 1.0.15 ----
SSDT 87CEB330 ZwAlertResumeThread
SSDT 87BEE7F0 ZwAlertThread
SSDT 87BF8FC0 ZwAllocateVirtualMemory
SSDT 87B66E60 ZwConnectPort
SSDT 87BE1CB0 ZwCreateMutant
SSDT 87CC93D0 ZwCreateThread
SSDT 87BEE3A0 ZwFreeVirtualMemory
SSDT 87BE1D80 ZwImpersonateAnonymousToken
SSDT 87C46728 ZwImpersonateThread
SSDT 87DB6C28 ZwMapViewOfSection
SSDT 87BE1BD0 ZwOpenEvent
SSDT 87C4DC10 ZwOpenProcessToken
SSDT 87D5C340 ZwOpenThreadToken
SSDT \??\C:\windows\system32\drivers\wpsdrvnt.sys ZwProtectVirtualMemory [0x91628880]
SSDT 87C3E6D8 ZwResumeThread
SSDT 87CE8350 ZwSetContextThread
SSDT 87CE8388 ZwSetInformationProcess
SSDT 87BE1638 ZwSetInformationThread
SSDT 87BE1AF0 ZwSuspendProcess
SSDT 87CEB8E0 ZwSuspendThread
SSDT 87CE2E80 ZwTerminateProcess
SSDT 87CEB9A0 ZwTerminateThread
SSDT 87BE8E98 ZwUnmapViewOfSection
SSDT 87BD3C88 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13D1 82E91369 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82ECAD52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10DB 82ED1D90 8 Bytes [30, B3, CE, 87, F0, E7, BE, ...]
.text ntkrnlpa.exe!KeRemoveQueueEx + 10F3 82ED1DA8 4 Bytes [C0, 8F, BF, 87]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1193 82ED1E48 4 Bytes [60, 6E, B6, 87] {PUSHA ; OUTSB ; MOV DH, 0x87}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11CF 82ED1E84 4 Bytes [B0, 1C, BE, 87]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1203 82ED1EB8 4 Bytes [D0, 93, CC, 87]
.text ...
? System32\drivers\ghacxari.sys The system cannot find the path specified. !
? C:\windows\System32\Drivers\SafeBoot.sys The process cannot access the file because it is being used by another process.
.text peauth.sys BB636C9D 28 Bytes [55, 2F, BC, 71, E9, C7, 2B, ...]
.text peauth.sys BB636CC1 28 Bytes [55, 2F, BC, 71, E9, C7, 2B, ...]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Internet Explorer\iexplore.exe[2064] USER32.dll!EnableWindow 76228D02 5 Bytes JMP 68459A14 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2064] USER32.dll!DialogBoxParamW 76243B9B 5 Bytes JMP 683B170B C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2064] USER32.dll!DialogBoxIndirectParamW 76253B7F 5 Bytes JMP 685A62BE C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2064] USER32.dll!DialogBoxParamA 7626CF42 5 Bytes JMP 685A6259 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2064] USER32.dll!DialogBoxIndirectParamA 7626D274 5 Bytes JMP 685A6323 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2064] USER32.dll!MessageBoxIndirectA 7627E869 5 Bytes JMP 685A61E0 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2064] USER32.dll!MessageBoxIndirectW 7627E963 1 Byte [E9]
.text C:\Program Files\Internet Explorer\iexplore.exe[2064] USER32.dll!MessageBoxIndirectW 7627E963 5 Bytes JMP 685A6167 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2064] USER32.dll!MessageBoxExA 7627E9C9 5 Bytes JMP 685A6103 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2064] USER32.dll!MessageBoxExW 7627E9ED 5 Bytes JMP 685A609F C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] kernel32.dll!CreateThread 771DDCC2 5 Bytes JMP 68417303 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!EnableWindow 76228D02 5 Bytes JMP 68459A14 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!CallNextHookEx 7622ABE1 5 Bytes JMP 68477BB7 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!UnhookWindowsHookEx 7622ADF9 5 Bytes JMP 6849EB74 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!DefWindowProcA 7622BB1C 7 Bytes JMP 6841952D C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!CreateWindowExA 7622BF40 5 Bytes JMP 68423363 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!SetWindowsHookExW 7622E30C 5 Bytes JMP 68452194 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!CreateWindowExW 7622EC7C 5 Bytes JMP 6847FF8F C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!DefWindowProcW 7623507D 7 Bytes JMP 68477C1A C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!DialogBoxParamW 76243B9B 5 Bytes JMP 683B170B C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!DialogBoxIndirectParamW 76253B7F 5 Bytes JMP 685A62BE C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!DialogBoxParamA 7626CF42 5 Bytes JMP 685A6259 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!DialogBoxIndirectParamA 7626D274 5 Bytes JMP 685A6323 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!MessageBoxIndirectA 7627E869 5 Bytes JMP 685A61E0 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!MessageBoxIndirectW 7627E963 1 Byte [E9]
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!MessageBoxIndirectW 7627E963 5 Bytes JMP 685A6167 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!MessageBoxExA 7627E9C9 5 Bytes JMP 685A6103 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!MessageBoxExW 7627E9ED 5 Bytes JMP 685A609F C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] ole32.dll!OleLoadFromStream 77766143 5 Bytes JMP 685A6A8C C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] WININET.dll!InternetCloseHandle 7601B7C4 5 Bytes JMP 736843D0 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] WININET.dll!InternetReadFile 7601EA3A 5 Bytes JMP 736844F0 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] WININET.dll!InternetConnectA 76045556 5 Bytes JMP 73684790 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] WININET.dll!HttpOpenRequestA 76045639 5 Bytes JMP 73684690 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] kernel32.dll!CreateThread 771DDCC2 5 Bytes JMP 68417303 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!EnableWindow 76228D02 5 Bytes JMP 68459A14 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!CallNextHookEx 7622ABE1 5 Bytes JMP 68477BB7 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!UnhookWindowsHookEx 7622ADF9 5 Bytes JMP 6849EB74 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!DefWindowProcA 7622BB1C 7 Bytes JMP 6841952D C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!CreateWindowExA 7622BF40 5 Bytes JMP 68423363 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!SetWindowsHookExW 7622E30C 5 Bytes JMP 68452194 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!CreateWindowExW 7622EC7C 5 Bytes JMP 6847FF8F C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!DefWindowProcW 7623507D 7 Bytes JMP 68477C1A C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!DialogBoxParamW 76243B9B 5 Bytes JMP 683B170B C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!DialogBoxIndirectParamW 76253B7F 5 Bytes JMP 685A62BE C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!DialogBoxParamA 7626CF42 5 Bytes JMP 685A6259 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!DialogBoxIndirectParamA 7626D274 5 Bytes JMP 685A6323 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!MessageBoxIndirectA 7627E869 5 Bytes JMP 685A61E0 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!MessageBoxIndirectW 7627E963 1 Byte [E9]
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!MessageBoxIndirectW 7627E963 5 Bytes JMP 685A6167 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!MessageBoxExA 7627E9C9 5 Bytes JMP 685A6103 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!MessageBoxExW 7627E9ED 5 Bytes JMP 685A609F C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] ole32.dll!OleLoadFromStream 77766143 5 Bytes JMP 685A6A8C C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] WININET.dll!InternetCloseHandle 7601B7C4 5 Bytes JMP 736843D0 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] WININET.dll!InternetReadFile 7601EA3A 5 Bytes JMP 736844F0 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] WININET.dll!InternetConnectA 76045556 5 Bytes JMP 73684790 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] WININET.dll!HttpOpenRequestA 76045639 5 Bytes JMP 73684690 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] kernel32.dll!CreateThread 771DDCC2 5 Bytes JMP 68417303 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!EnableWindow 76228D02 5 Bytes JMP 68459A14 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!CallNextHookEx 7622ABE1 5 Bytes JMP 68477BB7 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!UnhookWindowsHookEx 7622ADF9 5 Bytes JMP 6849EB74 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!DefWindowProcA 7622BB1C 7 Bytes JMP 6841952D C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!CreateWindowExA 7622BF40 5 Bytes JMP 68423363 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!SetWindowsHookExW 7622E30C 5 Bytes JMP 68452194 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!CreateWindowExW 7622EC7C 5 Bytes JMP 6847FF8F C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!DefWindowProcW 7623507D 7 Bytes JMP 68477C1A C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!DialogBoxParamW 76243B9B 5 Bytes JMP 683B170B C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!DialogBoxIndirectParamW 76253B7F 5 Bytes JMP 685A62BE C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!DialogBoxParamA 7626CF42 5 Bytes JMP 685A6259 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!DialogBoxIndirectParamA 7626D274 5 Bytes JMP 685A6323 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!MessageBoxIndirectA 7627E869 5 Bytes JMP 685A61E0 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!MessageBoxIndirectW 7627E963 1 Byte [E9]
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!MessageBoxIndirectW 7627E963 5 Bytes JMP 685A6167 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!MessageBoxExA 7627E9C9 5 Bytes JMP 685A6103 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!MessageBoxExW 7627E9ED 5 Bytes JMP 685A609F C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] ole32.dll!OleLoadFromStream 77766143 5 Bytes JMP 685A6A8C C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] WININET.dll!InternetCloseHandle 7601B7C4 5 Bytes JMP 736843D0 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] WININET.dll!InternetReadFile 7601EA3A 5 Bytes JMP 736844F0 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] WININET.dll!InternetConnectA 76045556 5 Bytes JMP 73684790 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] WININET.dll!HttpOpenRequestA 76045639 5 Bytes JMP 73684690 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\windows\system32\rundll32.exe[2888] @ C:\windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\windows\system32\rundll32.exe[2888] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\windows\system32\rundll32.exe[2888] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\windows\system32\rundll32.exe[2888] @ C:\windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe[2920] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe[2920] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe[2920] @ C:\windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe[2920] @ C:\windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe[2920] @ C:\windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe[2920] @ C:\windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe[2920] @ C:\windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\000000d0 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\000000d2 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\ACPI_HAL \Device\00000098 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\e02a823829c8
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\e02a823829c8 (not active ControlSet)
---- EOF - GMER 1.0.15 ----
WIll post the DDS log in the next post.
Hope i can get this removed
Thanks for your help
Malwarebytes Anti-Malware (Trial) 1.60.0.1800
www.malwarebytes.org
Database version: v2012.01.09.06
Windows 7 Service Pack 1 x86 NTFS (Safe Mode/Networking)
Internet Explorer 9.0.8112.16421
Protection: Disabled
1/10/2012 1:12:53 AM
mbam-log-2012-01-10 (01-12-53).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 213001
Time elapsed: 2 minute(s), 37 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 2
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|SystemBootNQtdP6TDS6cn0vSDlYFgIHWxSydqQbiS (Trojan.PMovie) -> Data: C:\Users\bbailey\UserProfile\SystemBoot.lnk -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|RegWriteNQtdP6TDS6cn0vSDlYFgIHWxSydqQbiS (Trojan.PMovie) -> Data: C:\Users\bbailey\SoftRecovery\RegWrite.lnk -> Quarantined and deleted successfully.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 2
C:\Users\bbailey\UserProfile\SystemBoot.lnk (Trojan.PMovie) -> Quarantined and deleted successfully.
C:\Users\bbailey\SoftRecovery\RegWrite.lnk (Trojan.PMovie) -> Quarantined and deleted successfully.
(end)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-01-10 01:55:31
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD25 rev.03.0
Running: gmer.exe; Driver: C:\Users\bbailey\AppData\Local\Temp\fwldrpod.sys
---- System - GMER 1.0.15 ----
SSDT 87CEB330 ZwAlertResumeThread
SSDT 87BEE7F0 ZwAlertThread
SSDT 87BF8FC0 ZwAllocateVirtualMemory
SSDT 87B66E60 ZwConnectPort
SSDT 87BE1CB0 ZwCreateMutant
SSDT 87CC93D0 ZwCreateThread
SSDT 87BEE3A0 ZwFreeVirtualMemory
SSDT 87BE1D80 ZwImpersonateAnonymousToken
SSDT 87C46728 ZwImpersonateThread
SSDT 87DB6C28 ZwMapViewOfSection
SSDT 87BE1BD0 ZwOpenEvent
SSDT 87C4DC10 ZwOpenProcessToken
SSDT 87D5C340 ZwOpenThreadToken
SSDT \??\C:\windows\system32\drivers\wpsdrvnt.sys ZwProtectVirtualMemory [0x91628880]
SSDT 87C3E6D8 ZwResumeThread
SSDT 87CE8350 ZwSetContextThread
SSDT 87CE8388 ZwSetInformationProcess
SSDT 87BE1638 ZwSetInformationThread
SSDT 87BE1AF0 ZwSuspendProcess
SSDT 87CEB8E0 ZwSuspendThread
SSDT 87CE2E80 ZwTerminateProcess
SSDT 87CEB9A0 ZwTerminateThread
SSDT 87BE8E98 ZwUnmapViewOfSection
SSDT 87BD3C88 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13D1 82E91369 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82ECAD52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10DB 82ED1D90 8 Bytes [30, B3, CE, 87, F0, E7, BE, ...]
.text ntkrnlpa.exe!KeRemoveQueueEx + 10F3 82ED1DA8 4 Bytes [C0, 8F, BF, 87]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1193 82ED1E48 4 Bytes [60, 6E, B6, 87] {PUSHA ; OUTSB ; MOV DH, 0x87}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11CF 82ED1E84 4 Bytes [B0, 1C, BE, 87]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1203 82ED1EB8 4 Bytes [D0, 93, CC, 87]
.text ...
? System32\drivers\ghacxari.sys The system cannot find the path specified. !
? C:\windows\System32\Drivers\SafeBoot.sys The process cannot access the file because it is being used by another process.
.text peauth.sys BB636C9D 28 Bytes [55, 2F, BC, 71, E9, C7, 2B, ...]
.text peauth.sys BB636CC1 28 Bytes [55, 2F, BC, 71, E9, C7, 2B, ...]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Internet Explorer\iexplore.exe[2064] USER32.dll!EnableWindow 76228D02 5 Bytes JMP 68459A14 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2064] USER32.dll!DialogBoxParamW 76243B9B 5 Bytes JMP 683B170B C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2064] USER32.dll!DialogBoxIndirectParamW 76253B7F 5 Bytes JMP 685A62BE C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2064] USER32.dll!DialogBoxParamA 7626CF42 5 Bytes JMP 685A6259 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2064] USER32.dll!DialogBoxIndirectParamA 7626D274 5 Bytes JMP 685A6323 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2064] USER32.dll!MessageBoxIndirectA 7627E869 5 Bytes JMP 685A61E0 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2064] USER32.dll!MessageBoxIndirectW 7627E963 1 Byte [E9]
.text C:\Program Files\Internet Explorer\iexplore.exe[2064] USER32.dll!MessageBoxIndirectW 7627E963 5 Bytes JMP 685A6167 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2064] USER32.dll!MessageBoxExA 7627E9C9 5 Bytes JMP 685A6103 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2064] USER32.dll!MessageBoxExW 7627E9ED 5 Bytes JMP 685A609F C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] kernel32.dll!CreateThread 771DDCC2 5 Bytes JMP 68417303 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!EnableWindow 76228D02 5 Bytes JMP 68459A14 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!CallNextHookEx 7622ABE1 5 Bytes JMP 68477BB7 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!UnhookWindowsHookEx 7622ADF9 5 Bytes JMP 6849EB74 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!DefWindowProcA 7622BB1C 7 Bytes JMP 6841952D C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!CreateWindowExA 7622BF40 5 Bytes JMP 68423363 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!SetWindowsHookExW 7622E30C 5 Bytes JMP 68452194 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!CreateWindowExW 7622EC7C 5 Bytes JMP 6847FF8F C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!DefWindowProcW 7623507D 7 Bytes JMP 68477C1A C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!DialogBoxParamW 76243B9B 5 Bytes JMP 683B170B C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!DialogBoxIndirectParamW 76253B7F 5 Bytes JMP 685A62BE C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!DialogBoxParamA 7626CF42 5 Bytes JMP 685A6259 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!DialogBoxIndirectParamA 7626D274 5 Bytes JMP 685A6323 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!MessageBoxIndirectA 7627E869 5 Bytes JMP 685A61E0 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!MessageBoxIndirectW 7627E963 1 Byte [E9]
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!MessageBoxIndirectW 7627E963 5 Bytes JMP 685A6167 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!MessageBoxExA 7627E9C9 5 Bytes JMP 685A6103 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] USER32.dll!MessageBoxExW 7627E9ED 5 Bytes JMP 685A609F C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] ole32.dll!OleLoadFromStream 77766143 5 Bytes JMP 685A6A8C C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] WININET.dll!InternetCloseHandle 7601B7C4 5 Bytes JMP 736843D0 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] WININET.dll!InternetReadFile 7601EA3A 5 Bytes JMP 736844F0 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] WININET.dll!InternetConnectA 76045556 5 Bytes JMP 73684790 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[2304] WININET.dll!HttpOpenRequestA 76045639 5 Bytes JMP 73684690 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] kernel32.dll!CreateThread 771DDCC2 5 Bytes JMP 68417303 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!EnableWindow 76228D02 5 Bytes JMP 68459A14 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!CallNextHookEx 7622ABE1 5 Bytes JMP 68477BB7 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!UnhookWindowsHookEx 7622ADF9 5 Bytes JMP 6849EB74 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!DefWindowProcA 7622BB1C 7 Bytes JMP 6841952D C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!CreateWindowExA 7622BF40 5 Bytes JMP 68423363 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!SetWindowsHookExW 7622E30C 5 Bytes JMP 68452194 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!CreateWindowExW 7622EC7C 5 Bytes JMP 6847FF8F C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!DefWindowProcW 7623507D 7 Bytes JMP 68477C1A C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!DialogBoxParamW 76243B9B 5 Bytes JMP 683B170B C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!DialogBoxIndirectParamW 76253B7F 5 Bytes JMP 685A62BE C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!DialogBoxParamA 7626CF42 5 Bytes JMP 685A6259 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!DialogBoxIndirectParamA 7626D274 5 Bytes JMP 685A6323 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!MessageBoxIndirectA 7627E869 5 Bytes JMP 685A61E0 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!MessageBoxIndirectW 7627E963 1 Byte [E9]
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!MessageBoxIndirectW 7627E963 5 Bytes JMP 685A6167 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!MessageBoxExA 7627E9C9 5 Bytes JMP 685A6103 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] USER32.dll!MessageBoxExW 7627E9ED 5 Bytes JMP 685A609F C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] ole32.dll!OleLoadFromStream 77766143 5 Bytes JMP 685A6A8C C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] WININET.dll!InternetCloseHandle 7601B7C4 5 Bytes JMP 736843D0 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] WININET.dll!InternetReadFile 7601EA3A 5 Bytes JMP 736844F0 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] WININET.dll!InternetConnectA 76045556 5 Bytes JMP 73684790 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[3812] WININET.dll!HttpOpenRequestA 76045639 5 Bytes JMP 73684690 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] kernel32.dll!CreateThread 771DDCC2 5 Bytes JMP 68417303 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!EnableWindow 76228D02 5 Bytes JMP 68459A14 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!CallNextHookEx 7622ABE1 5 Bytes JMP 68477BB7 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!UnhookWindowsHookEx 7622ADF9 5 Bytes JMP 6849EB74 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!DefWindowProcA 7622BB1C 7 Bytes JMP 6841952D C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!CreateWindowExA 7622BF40 5 Bytes JMP 68423363 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!SetWindowsHookExW 7622E30C 5 Bytes JMP 68452194 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!CreateWindowExW 7622EC7C 5 Bytes JMP 6847FF8F C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!DefWindowProcW 7623507D 7 Bytes JMP 68477C1A C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!DialogBoxParamW 76243B9B 5 Bytes JMP 683B170B C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!DialogBoxIndirectParamW 76253B7F 5 Bytes JMP 685A62BE C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!DialogBoxParamA 7626CF42 5 Bytes JMP 685A6259 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!DialogBoxIndirectParamA 7626D274 5 Bytes JMP 685A6323 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!MessageBoxIndirectA 7627E869 5 Bytes JMP 685A61E0 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!MessageBoxIndirectW 7627E963 1 Byte [E9]
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!MessageBoxIndirectW 7627E963 5 Bytes JMP 685A6167 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!MessageBoxExA 7627E9C9 5 Bytes JMP 685A6103 C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] USER32.dll!MessageBoxExW 7627E9ED 5 Bytes JMP 685A609F C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] ole32.dll!OleLoadFromStream 77766143 5 Bytes JMP 685A6A8C C:\windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] WININET.dll!InternetCloseHandle 7601B7C4 5 Bytes JMP 736843D0 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] WININET.dll!InternetReadFile 7601EA3A 5 Bytes JMP 736844F0 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] WININET.dll!InternetConnectA 76045556 5 Bytes JMP 73684790 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[6000] WININET.dll!HttpOpenRequestA 76045639 5 Bytes JMP 73684690 c:\progra~1\mcafee\sitead~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\windows\system32\rundll32.exe[2888] @ C:\windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\windows\system32\rundll32.exe[2888] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\windows\system32\rundll32.exe[2888] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\windows\system32\rundll32.exe[2888] @ C:\windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe[2920] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe[2920] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe[2920] @ C:\windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe[2920] @ C:\windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe[2920] @ C:\windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe[2920] @ C:\windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Synaptics\Scrybe\Service\ScrybeUpdater.exe[2920] @ C:\windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [75B2FFF6] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\000000d0 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\000000d2 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\ACPI_HAL \Device\00000098 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\e02a823829c8
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\e02a823829c8 (not active ControlSet)
---- EOF - GMER 1.0.15 ----
WIll post the DDS log in the next post.
Hope i can get this removed
Thanks for your help