Can I get help with a search engine redirect problem?
performed the 8 step process. Malwarebytes' Anti-Malware & GMER logs follow:
DDS Logs in 2nd post due to character limit
Malwarebytes' Anti-Malware 1.50
Database version: 5248
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180
12/5/2010 1:10:46 PM
mbam-log-2010-12-05 (13-10-46).txt
Scan type: Quick scan
Objects scanned: 139750
Time elapsed: 4 minute(s), 22 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER log
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-12-05 18:02:53
Windows 5.1.2600 Service Pack 2 Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-17 HDS722580VLSA80 rev.V32OA60A
Running: kmm9bbmx.exe; Driver: C:\DOCUME~1\Steve\LOCALS~1\Temp\uxtdypow.sys
---- System - GMER 1.0.15 ----
SSDT F7AB4436 ZwCreateKey
SSDT F7AB442C ZwCreateThread
SSDT F7AB443B ZwDeleteKey
SSDT F7AB4445 ZwDeleteValueKey
SSDT F7AB444A ZwLoadKey
SSDT F7AB4418 ZwOpenProcess
SSDT F7AB441D ZwOpenThread
SSDT F7AB4454 ZwReplaceKey
SSDT F7AB444F ZwRestoreKey
SSDT F7AB4440 ZwSetValueKey
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB9979360, 0x32E00D, 0xE8000020]
init C:\WINDOWS\system32\drivers\senfilt.sys entry point in "init" section [0xB9857F80]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\NETGEAR\NETGEAR Digital Entertainer for Windows\receiver.exe[452] WS2_32.dll!send 71AB428A 5 Bytes JMP 0206B028
.text C:\Program Files\NETGEAR\NETGEAR Digital Entertainer for Windows\receiver.exe[452] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 0206B33D
.text C:\Program Files\NETGEAR\NETGEAR Digital Entertainer for Windows\receiver.exe[452] WS2_32.dll!recv 71AB615A 5 Bytes JMP 0206B109
.text C:\Program Files\NETGEAR\NETGEAR Digital Entertainer for Windows\receiver.exe[452] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 0206B1DC
.text C:\Program Files\NETGEAR\NETGEAR Digital Entertainer for Windows\receiver.exe[452] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 0206B48B
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[472] WS2_32.dll!send 71AB428A 5 Bytes JMP 00C9B028
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[472] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 00C9B33D
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[472] WS2_32.dll!recv 71AB615A 5 Bytes JMP 00C9B109
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[472] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 00C9B1DC
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[472] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 00C9B48B
.text C:\WINDOWS\system32\winlogon.exe[708] Secur32.dll!LsaLogonUser 77FE33E8 5 Bytes JMP 01482946
.text C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe[1580] WS2_32.dll!send 71AB428A 5 Bytes JMP 00B2B028
.text C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe[1580] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 00B2B33D
.text C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe[1580] WS2_32.dll!recv 71AB615A 5 Bytes JMP 00B2B109
.text C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe[1580] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 00B2B1DC
.text C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe[1580] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 00B2B48B
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1628] WS2_32.dll!send 71AB428A 5 Bytes JMP 0164B028
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1628] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 0164B33D
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1628] WS2_32.dll!recv 71AB615A 5 Bytes JMP 0164B109
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1628] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 0164B1DC
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1628] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 0164B48B
.text C:\WINDOWS\Explorer.EXE[1808] USER32.dll!DisplayExitWindowsWarnings 77D89B89 5 Bytes JMP 00C02758
.text C:\WINDOWS\Explorer.EXE[1808] WS2_32.dll!send 71AB428A 5 Bytes JMP 011EB028
.text C:\WINDOWS\Explorer.EXE[1808] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 011EB33D
.text C:\WINDOWS\Explorer.EXE[1808] WS2_32.dll!recv 71AB615A 5 Bytes JMP 011EB109
.text C:\WINDOWS\Explorer.EXE[1808] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 011EB1DC
.text C:\WINDOWS\Explorer.EXE[1808] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 011EB48B
.text C:\WINDOWS\system32\Tablet.exe[2416] WS2_32.dll!send 71AB428A 5 Bytes JMP 0142B028
.text C:\WINDOWS\system32\Tablet.exe[2416] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 0142B33D
.text C:\WINDOWS\system32\Tablet.exe[2416] WS2_32.dll!recv 71AB615A 5 Bytes JMP 0142B109
.text C:\WINDOWS\system32\Tablet.exe[2416] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 0142B1DC
.text C:\WINDOWS\system32\Tablet.exe[2416] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 0142B48B
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[3580] WS2_32.dll!send 71AB428A 5 Bytes JMP 009AB028
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[3580] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 009AB33D
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[3580] WS2_32.dll!recv 71AB615A 5 Bytes JMP 009AB109
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[3580] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 009AB1DC
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[3580] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 009AB48B
.text C:\WINDOWS\System32\alg.exe[4060] WS2_32.dll!send 71AB428A 5 Bytes JMP 008FB028
.text C:\WINDOWS\System32\alg.exe[4060] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 008FB33D
.text C:\WINDOWS\System32\alg.exe[4060] WS2_32.dll!recv 71AB615A 5 Bytes JMP 008FB109
.text C:\WINDOWS\System32\alg.exe[4060] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 008FB1DC
.text C:\WINDOWS\System32\alg.exe[4060] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 008FB48B
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device rdpdr.sys (Microsoft RDP Device redirector/Microsoft Corporation)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xE2 0x63 0x26 0xF1 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x46 0x47 0x15 0xB0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0x7A 0x45 0x05 0xFD ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x3E 0x1E 0x9E 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xCD 0x44 0xCD 0xB9 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xB0 0x18 0xED 0xA7 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0x31 0x77 0xE1 0xBA ...
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0xAA 0x52 0xC6 0x00 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xB2 0x46 0x9A 0xE2 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x3D 0xCE 0xEA 0x26 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0xE3 0x0E 0x66 0xD5 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{088BEC22-1854-4EEE-1509-9A64DC6C441F}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{088BEC22-1854-4EEE-1509-9A64DC6C441F}@eajdpdaekb 0x66 0x61 0x64 0x70 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{088BEC22-1854-4EEE-1509-9A64DC6C441F}@daidehao 0x64 0x62 0x66 0x6E ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{088BEC22-1854-4EEE-1509-9A64DC6C441F}@iabohmpmmgdfpgijlp 0x69 0x61 0x62 0x64 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{088BEC22-1854-4EEE-1509-9A64DC6C441F}@halnicaagkhaolhi 0x69 0x61 0x61 0x64 ...
---- EOF - GMER 1.0.15 ----
Steve Pomp
performed the 8 step process. Malwarebytes' Anti-Malware & GMER logs follow:
DDS Logs in 2nd post due to character limit
Malwarebytes' Anti-Malware 1.50
Database version: 5248
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180
12/5/2010 1:10:46 PM
mbam-log-2010-12-05 (13-10-46).txt
Scan type: Quick scan
Objects scanned: 139750
Time elapsed: 4 minute(s), 22 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER log
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-12-05 18:02:53
Windows 5.1.2600 Service Pack 2 Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-17 HDS722580VLSA80 rev.V32OA60A
Running: kmm9bbmx.exe; Driver: C:\DOCUME~1\Steve\LOCALS~1\Temp\uxtdypow.sys
---- System - GMER 1.0.15 ----
SSDT F7AB4436 ZwCreateKey
SSDT F7AB442C ZwCreateThread
SSDT F7AB443B ZwDeleteKey
SSDT F7AB4445 ZwDeleteValueKey
SSDT F7AB444A ZwLoadKey
SSDT F7AB4418 ZwOpenProcess
SSDT F7AB441D ZwOpenThread
SSDT F7AB4454 ZwReplaceKey
SSDT F7AB444F ZwRestoreKey
SSDT F7AB4440 ZwSetValueKey
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB9979360, 0x32E00D, 0xE8000020]
init C:\WINDOWS\system32\drivers\senfilt.sys entry point in "init" section [0xB9857F80]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\NETGEAR\NETGEAR Digital Entertainer for Windows\receiver.exe[452] WS2_32.dll!send 71AB428A 5 Bytes JMP 0206B028
.text C:\Program Files\NETGEAR\NETGEAR Digital Entertainer for Windows\receiver.exe[452] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 0206B33D
.text C:\Program Files\NETGEAR\NETGEAR Digital Entertainer for Windows\receiver.exe[452] WS2_32.dll!recv 71AB615A 5 Bytes JMP 0206B109
.text C:\Program Files\NETGEAR\NETGEAR Digital Entertainer for Windows\receiver.exe[452] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 0206B1DC
.text C:\Program Files\NETGEAR\NETGEAR Digital Entertainer for Windows\receiver.exe[452] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 0206B48B
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[472] WS2_32.dll!send 71AB428A 5 Bytes JMP 00C9B028
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[472] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 00C9B33D
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[472] WS2_32.dll!recv 71AB615A 5 Bytes JMP 00C9B109
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[472] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 00C9B1DC
.text C:\Program Files\Windows Media Player\WMPNSCFG.exe[472] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 00C9B48B
.text C:\WINDOWS\system32\winlogon.exe[708] Secur32.dll!LsaLogonUser 77FE33E8 5 Bytes JMP 01482946
.text C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe[1580] WS2_32.dll!send 71AB428A 5 Bytes JMP 00B2B028
.text C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe[1580] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 00B2B33D
.text C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe[1580] WS2_32.dll!recv 71AB615A 5 Bytes JMP 00B2B109
.text C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe[1580] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 00B2B1DC
.text C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe[1580] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 00B2B48B
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1628] WS2_32.dll!send 71AB428A 5 Bytes JMP 0164B028
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1628] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 0164B33D
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1628] WS2_32.dll!recv 71AB615A 5 Bytes JMP 0164B109
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1628] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 0164B1DC
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1628] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 0164B48B
.text C:\WINDOWS\Explorer.EXE[1808] USER32.dll!DisplayExitWindowsWarnings 77D89B89 5 Bytes JMP 00C02758
.text C:\WINDOWS\Explorer.EXE[1808] WS2_32.dll!send 71AB428A 5 Bytes JMP 011EB028
.text C:\WINDOWS\Explorer.EXE[1808] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 011EB33D
.text C:\WINDOWS\Explorer.EXE[1808] WS2_32.dll!recv 71AB615A 5 Bytes JMP 011EB109
.text C:\WINDOWS\Explorer.EXE[1808] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 011EB1DC
.text C:\WINDOWS\Explorer.EXE[1808] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 011EB48B
.text C:\WINDOWS\system32\Tablet.exe[2416] WS2_32.dll!send 71AB428A 5 Bytes JMP 0142B028
.text C:\WINDOWS\system32\Tablet.exe[2416] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 0142B33D
.text C:\WINDOWS\system32\Tablet.exe[2416] WS2_32.dll!recv 71AB615A 5 Bytes JMP 0142B109
.text C:\WINDOWS\system32\Tablet.exe[2416] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 0142B1DC
.text C:\WINDOWS\system32\Tablet.exe[2416] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 0142B48B
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[3580] WS2_32.dll!send 71AB428A 5 Bytes JMP 009AB028
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[3580] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 009AB33D
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[3580] WS2_32.dll!recv 71AB615A 5 Bytes JMP 009AB109
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[3580] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 009AB1DC
.text C:\Program Files\Windows Media Player\WMPNetwk.exe[3580] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 009AB48B
.text C:\WINDOWS\System32\alg.exe[4060] WS2_32.dll!send 71AB428A 5 Bytes JMP 008FB028
.text C:\WINDOWS\System32\alg.exe[4060] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 008FB33D
.text C:\WINDOWS\System32\alg.exe[4060] WS2_32.dll!recv 71AB615A 5 Bytes JMP 008FB109
.text C:\WINDOWS\System32\alg.exe[4060] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 008FB1DC
.text C:\WINDOWS\System32\alg.exe[4060] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 008FB48B
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device rdpdr.sys (Microsoft RDP Device redirector/Microsoft Corporation)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xE2 0x63 0x26 0xF1 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x46 0x47 0x15 0xB0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0x7A 0x45 0x05 0xFD ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x3E 0x1E 0x9E 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xCD 0x44 0xCD 0xB9 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xB0 0x18 0xED 0xA7 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0x31 0x77 0xE1 0xBA ...
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0xAA 0x52 0xC6 0x00 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xB2 0x46 0x9A 0xE2 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x3D 0xCE 0xEA 0x26 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0xE3 0x0E 0x66 0xD5 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{088BEC22-1854-4EEE-1509-9A64DC6C441F}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{088BEC22-1854-4EEE-1509-9A64DC6C441F}@eajdpdaekb 0x66 0x61 0x64 0x70 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{088BEC22-1854-4EEE-1509-9A64DC6C441F}@daidehao 0x64 0x62 0x66 0x6E ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{088BEC22-1854-4EEE-1509-9A64DC6C441F}@iabohmpmmgdfpgijlp 0x69 0x61 0x62 0x64 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{088BEC22-1854-4EEE-1509-9A64DC6C441F}@halnicaagkhaolhi 0x69 0x61 0x61 0x64 ...
---- EOF - GMER 1.0.15 ----
Steve Pomp