Google search results redirect to other sites Google search results redirect to other sites
Hello,
I've noticed in the last 3 days that Google search results, when clicked on redirect to other sites with ads. I have McAfee Security Center (updated regularly). I ran the scan, found some strange files, but that didn't help. I also ran SuperAntiSpyware. It found a bunch of suspicious files, removed them, but it also didn't help. I now followed the step-by-step procedure outlined in the sticky at the top of this group. Please help me get my PC back.
Here are the log files (IN SEVERAL POSTS SINCE THE CONTENT IS TOO BIG).
************************
Malwarebytes' Anti-Malware 1.46 Malwarebytes
Database version: 4896
Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702
10/20/2010 9:22:51 PM
mbam-log-2010-10-20 (21-22-51).txt
Scan type: Quick scan
Objects scanned: 194972
Time elapsed: 20 minute(s), 20 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 4
Registry Data Items Infected: 1
Folders Infected: 4
Files Infected: 9
Memory Processes Infected:
C:\Documents and Settings\Steve\Application Data\Microsoft\svchost.exe (Trojan.Agent) -> Unloaded process successfully.
C:\Documents and Settings\Steve\Application Data\Microsoft\Windows\shell.exe (Trojan.Shell) -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\svchost (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\don't load\scui.cpl (Hijack.SecurityCenter) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Policies\Explorer\forceclassiccontrolpan el (Hijack.ControlPanelStyle) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (explorer.exe,C:\Documents and Settings\Steve\Application Data\Microsoft\Windows\shell.exe) Good: (Explorer.exe) -> Quarantined and deleted successfully.
Folders Infected:
C:\Documents and Settings\Steve\Application Data\Twain (Trojan.Matcash) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\twain_32 (Trojan.Zbot) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\twain_32 (Trojan.Zbot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\twain_32 (Backdoor.Bot) -> Quarantined and deleted successfully.
Files Infected:
C:\Documents and Settings\Steve\Application Data\Microsoft\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\twain_32\user.ds (Trojan.Zbot) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\twain_32\user.ds (Trojan.Zbot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\twain_32\local.ds (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\twain_32\local.ds.cla (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\twain_32\user.ds (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Steve\Application Data\Microsoft\Windows\shell.exe (Trojan.Shell) -> Quarantined and deleted successfully.
C:\Program Files\Shared\_lib.sig (Adware.Deepdive) -> Quarantined and deleted successfully.
C:\Program Files\Shared\lib.sig (Adware.Deepdive) -> Quarantined and deleted successfully.
I have to attach GMER log in a txt file since I keep getting errors when I try to post it directly. Attached Files ************************************************** *******
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 2 (build 2600)
Logical Drives Mask: 0x0000033d
Kernel Drivers (total 166):
0x804D7000 \WINDOWS\system32\ntoskrnl.exe
0x806FD000 \WINDOWS\system32\hal.dll
0xF7987000 \WINDOWS\system32\KDCOM.DLL
0xF7897000 \WINDOWS\system32\BOOTVID.dll
0xF75F7000 tifg.sys
0xF7508000 ACPI.sys
0xF7989000 \WINDOWS\System32\DRIVERS\WMILIB.SYS
0xF74F7000 pci.sys
0xF7607000 isapnp.sys
0xF7617000 ohci1394.sys
0xF7627000 \WINDOWS\System32\DRIVERS\1394BUS.SYS
0xF7A4F000 pciide.sys
0xF7707000 \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
0xF7637000 MountMgr.sys
0xF74D8000 ftdisk.sys
0xF798B000 dmload.sys
0xF74B2000 dmio.sys
0xF770F000 PartMgr.sys
0xF7647000 VolSnap.sys
0xF749A000 atapi.sys
0xF7465000 Si3114r5.sys
0xF744D000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
0xF7657000 disk.sys
0xF7667000 \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
0xF7857000 fltmgr.sys
0xF7845000 sr.sys
0xF789B000 SiWinAcc.sys
0xF7717000 PxHelp20.sys
0xF782E000 KSecDD.sys
0xF7974000 WudfPf.sys
0xF7B52000 Ntfs.sys
0xF7A22000 NDIS.sys
0xF771F000 uGuru.sys
0xF798D000 SiRemFil.sys
0xF7959000 Mup.sys
0xF7677000 agp440.sys
0xF798F000 AC2003.sys
0xF75B6000 \SystemRoot\System32\DRIVERS\intelppm.sys
0xB9A9D000 \SystemRoot\System32\DRIVERS\ati2mtag.sys
0xB9A89000 \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS
0xF781F000 \SystemRoot\System32\DRIVERS\usbuhci.sys
0xB9A66000 \SystemRoot\System32\DRIVERS\USBPORT.SYS
0xF7757000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xF75A6000 \SystemRoot\System32\DRIVERS\nic1394.sys
0xB9D99000 \SystemRoot\System32\DRIVERS\RTL8139.SYS
0xB9A30000 \SystemRoot\System32\DRIVERS\HSFBS2S2.sys
0xB9A0D000 \SystemRoot\System32\DRIVERS\ks.sys
0xB990E000 \SystemRoot\System32\DRIVERS\HSFDPSP2.sys
0xB9866000 \SystemRoot\System32\DRIVERS\HSFCXTS2.sys
0xB9D91000 \SystemRoot\System32\Drivers\Modem.SYS
0xB9D89000 \SystemRoot\System32\DRIVERS\fdc.sys
0xF7596000 \SystemRoot\System32\DRIVERS\serial.sys
0xBA7DC000 \SystemRoot\System32\DRIVERS\serenum.sys
0xB9852000 \SystemRoot\System32\DRIVERS\parport.sys
0xF7586000 \SystemRoot\System32\DRIVERS\i8042prt.sys
0xB9D81000 \SystemRoot\System32\DRIVERS\kbdclass.sys
0xB9F0A000 \SystemRoot\System32\Drivers\ElbyDelay.sys
0xB9D79000 \SystemRoot\System32\Drivers\AnyDVD.sys
0xF7576000 \SystemRoot\System32\Drivers\Cdr4_xp.SYS
0xF7566000 \SystemRoot\System32\DRIVERS\cdrom.sys
0xF7556000 \SystemRoot\System32\DRIVERS\redbook.sys
0xB9D71000 \SystemRoot\System32\Drivers\Cdralw2k.SYS
0xB9835000 \SystemRoot\System32\Drivers\pwd_2k.SYS
0xF7546000 \SystemRoot\system32\DRIVERS\imapi.sys
0xB979E000 \SystemRoot\system32\drivers\ALCXWDM.SYS
0xB977A000 \SystemRoot\system32\drivers\portcls.sys
0xF7536000 \SystemRoot\system32\drivers\drmk.sys
0xB9718000 \SystemRoot\system32\drivers\ALCXSENS.SYS
0xB9E8A000 \SystemRoot\System32\DRIVERS\audstub.sys
0xF743D000 \SystemRoot\System32\DRIVERS\rasl2tp.sys
0xBA7CC000 \SystemRoot\System32\DRIVERS\ndistapi.sys
0xB9701000 \SystemRoot\System32\DRIVERS\ndiswan.sys
0xF742D000 \SystemRoot\System32\DRIVERS\raspppoe.sys
0xF741D000 \SystemRoot\System32\DRIVERS\raspptp.sys
0xB9D69000 \SystemRoot\System32\DRIVERS\TDI.SYS
0xB96F0000 \SystemRoot\System32\DRIVERS\psched.sys
0xF740D000 \SystemRoot\System32\DRIVERS\msgpc.sys
0xB958C000 \SystemRoot\System32\drivers\dmboot.sys
0xF77FF000 \SystemRoot\System32\DRIVERS\ptilink.sys
0xF7807000 \SystemRoot\System32\DRIVERS\raspti.sys
0xB955B000 \SystemRoot\System32\DRIVERS\rdpdr.sys
0xF7887000 \SystemRoot\System32\DRIVERS\termdd.sys
0xF780F000 \SystemRoot\System32\DRIVERS\mouclass.sys
0xF79B7000 \SystemRoot\System32\DRIVERS\swenum.sys
0xB94DA000 \SystemRoot\System32\DRIVERS\update.sys
0xBA76D000 \SystemRoot\System32\DRIVERS\mssmbios.sys
0xF7817000 \SystemRoot\System32\Drivers\dvd_2K.SYS
0xF7877000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xBA4E0000 \SystemRoot\System32\DRIVERS\usbhub.sys
0xF79B9000 \SystemRoot\System32\DRIVERS\USBD.SYS
0xB9DA1000 \SystemRoot\System32\DRIVERS\flpydisk.sys
0xF79BB000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xF7A89000 \SystemRoot\System32\Drivers\Null.SYS
0xF79BD000 \SystemRoot\System32\Drivers\Beep.SYS
0xB9D61000 \SystemRoot\System32\drivers\vga.sys
0xF79BF000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF79C1000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xB140B000 \SystemRoot\System32\Drivers\cdudf_xp.SYS
0xB13D6000 \SystemRoot\System32\Drivers\DVDVRRdr_xp.SYS
0xB9D59000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF7767000 \SystemRoot\System32\Drivers\Npfs.SYS
0xB131B000 \SystemRoot\System32\Drivers\UDFReadr.SYS
0xB954B000 \SystemRoot\System32\DRIVERS\rasacd.sys
0xB12CE000 \SystemRoot\System32\DRIVERS\ipsec.sys
0xB1276000 \SystemRoot\System32\DRIVERS\tcpip.sys
0xB124F000 \SystemRoot\System32\Drivers\Mpfp.sys
0xB122E000 \SystemRoot\System32\DRIVERS\ipnat.sys
0xBA4B0000 \SystemRoot\System32\DRIVERS\wanarp.sys
0xB9533000 \SystemRoot\System32\DRIVERS\hidusb.sys
0xBA4A0000 \SystemRoot\System32\DRIVERS\HIDCLASS.SYS
0xF776F000 \SystemRoot\System32\DRIVERS\HIDPARSE.SYS
0xBA490000 \SystemRoot\System32\DRIVERS\ipfltdrv.sys
0xBA480000 \SystemRoot\System32\DRIVERS\arp1394.sys
0xB1166000 \SystemRoot\System32\DRIVERS\netbt.sys
0xB1144000 \SystemRoot\System32\drivers\afd.sys
0xBA470000 \SystemRoot\System32\DRIVERS\netbios.sys
0xB1122000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
0xF7777000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
0xB10CF000 \SystemRoot\System32\DRIVERS\rdbss.sys
0xB1060000 \SystemRoot\System32\DRIVERS\mrxsmb.sys
0xB102D000 \SystemRoot\system32\drivers\mfehidk.sys
0xF76B7000 \SystemRoot\System32\Drivers\Fips.SYS
0xF7787000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0xB1472000 \SystemRoot\System32\DRIVERS\mouhid.sys
0xF76E7000 \SystemRoot\System32\DRIVERS\moufiltr.sys
0xB0E4E000 \SystemRoot\system32\DRIVERS\VX3000.sys
0xF76F7000 \SystemRoot\system32\DRIVERS\STREAM.SYS
0xF75C6000 \SystemRoot\system32\drivers\usbaudio.sys
0xB96E0000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xB0E36000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xF79CB000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xB1305000 \SystemRoot\System32\drivers\Dxapi.sys
0xF778F000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xF7AB0000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\ati2dvag.dll
0xBF057000 \SystemRoot\System32\ati2cqag.dll
0xBF0D1000 \SystemRoot\System32\atikvmag.dll
0xBF13D000 \SystemRoot\System32\atiok3x2.dll
0xBF16B000 \SystemRoot\System32\ati3duag.dll
0xBF468000 \SystemRoot\System32\ativvaxx.dll
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xAE9AA000 \SystemRoot\System32\DRIVERS\mrxdav.sys
0xF79C9000 \SystemRoot\System32\Drivers\ParVdm.SYS
0xAEA06000 \SystemRoot\System32\Drivers\ElbyCDIO.sys
0xAE913000 \SystemRoot\System32\DRIVERS\HSF_FALL.sys
0xAE8F6000 \SystemRoot\System32\DRIVERS\HSF_FSKS.sys
0xAE7CE000 \SystemRoot\System32\DRIVERS\HSF_K56K.sys
0xAE777000 \SystemRoot\System32\DRIVERS\srv.sys
0xAE75F000 \SystemRoot\System32\DRIVERS\mdmxsdk.sys
0xAE51C000 \??\C:\WINDOWS\System32\drivers\mqac.sys
0xAE332000 \??\C:\WINDOWS\System32\drivers\RMCast.sys
0xAE289000 \SystemRoot\System32\DRIVERS\HSF_FAXX.sys
0xAE474000 \SystemRoot\System32\DRIVERS\HSF_TONE.sys
0xAE1E9000 \SystemRoot\System32\DRIVERS\HSF_V124.sys
0xAE0D6000 \SystemRoot\System32\Drivers\Fastfat.SYS
0xADC85000 \SystemRoot\System32\Drivers\HTTP.sys
0xB136C000 \SystemRoot\system32\drivers\mfebopk.sys
0xADB33000 \SystemRoot\system32\drivers\mfeavfk.sys
0xADF56000 \SystemRoot\system32\drivers\mfesmfk.sys
0xAD916000 \SystemRoot\system32\drivers\wdmaud.sys
0xADFC6000 \SystemRoot\system32\drivers\sysaudio.sys
0xACA36000 \??\C:\DOCUME~1\Steve\LOCALS~1\Temp\ugtdypod.sys
0xACA0B000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\system32\ntdll.dll
Processes (total 64):
0 System Idle Process
4 System
564 C:\WINDOWS\system32\smss.exe
620 csrss.exe
652 C:\WINDOWS\system32\winlogon.exe
696 C:\WINDOWS\system32\services.exe
708 C:\WINDOWS\system32\lsass.exe
856 C:\WINDOWS\system32\ati2evxx.exe
872 C:\WINDOWS\system32\svchost.exe
940 svchost.exe
1020 C:\Program Files\Windows Defender\MsMpEng.exe
1064 C:\WINDOWS\system32\svchost.exe
1108 C:\WINDOWS\system32\svchost.exe
1176 svchost.exe
1224 svchost.exe
1316 C:\WINDOWS\system32\spoolsv.exe
1400 C:\WINDOWS\system32\ati2evxx.exe
1620 svchost.exe
1676 C:\WINDOWS\system32\inetsrv\inetinfo.exe
1700 C:\Program Files\Java\jre6\bin\jqs.exe
1804 C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
1864 C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
1888 C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
1920 C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
1960 C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
2012 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
132 C:\Program Files\McAfee\MPF\MpfSrv.exe
268 C:\Program Files\Microsoft LifeCam\MSCamS32.exe
444 msdtc.exe
504 C:\Program Files\McAfee\MSK\msksrver.exe
1120 C:\WINDOWS\system32\tcpsvcs.exe
1424 C:\WINDOWS\system32\snmp.exe
1500 C:\WINDOWS\system32\svchost.exe
2116 C:\Program Files\Linksys Wireless-B Media Adapter\bin\XWPCApplicationLoaderService.exe
2288 C:\Program Files\Linksys Wireless-B Media Adapter\bin\XWPCHostService.exe
2340 C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
2496 C:\WINDOWS\system32\mqsvc.exe
3048 C:\Program Files\Canon\CAL\CALMAIN.exe
3132 C:\WINDOWS\system32\mqtgsvc.exe
3352 alg.exe
3744 C:\WINDOWS\system32\svchost.exe
3508 C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
2964 C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
2264 C:\WINDOWS\explorer.exe
2728 C:\WINDOWS\SOUNDMAN.EXE
440 C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
3036 C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
1808 C:\WINDOWS\system32\TaskSwitch.exe
2672 C:\Program Files\ABIT\ABIT uGuru\uGuru.exe
2060 C:\Program Files\Windows Defender\MSASCui.exe
1652 C:\WINDOWS\vVX3000.exe
3008 C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
2368 C:\Program Files\QuickTime\qttask.exe
3536 C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
2676 C:\WINDOWS\system32\ctfmon.exe
672 C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
4004 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
4640 C:\Program Files\Linksys Wireless-B Media Adapter\bin\XWPCLauncher.exe
4684 C:\Program Files\PIXELA\ImageMixer 3 SE Ver.3\CameraMonitor.exe
5208 C:\Program Files\Internet Explorer\iexplore.exe
5216 C:\Program Files\Internet Explorer\iexplore.exe
3288 C:\Program Files\Internet Explorer\iexplore.exe
3968 C:\Program Files\Internet Explorer\iexplore.exe
2624 \Device\HarddiskDmVolumes\PhysicalDmVolumes\BlockV olume2\Documents and Settings\Steve\My Documents\Downloads\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000018`6a631a00 (NTFS)
\\.\E: --> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (NTFS)
\\.\F: --> \\.\PhysicalDrive2 at offset 0x00000000`00007e00 (NTFS)
PhysicalDrive0 Model Number: ST3200822AS, Rev: 3.01
PhysicalDrive1 Model Number: Maxtor7Y250M0, Rev: YAR511W0
PhysicalDrive2 Model Number: Maxtor7Y250M0, Rev: YAR511W0
Size Device Name MBR Status
--------------------------------------------
186 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
931 GB \\.\PhysicalDrive1 RE: Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
233 GB \\.\PhysicalDrive2 RE: Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
Done!
**********************************************
OTL logfile created on: 10/21/2010 7:28:30 AM - Run 1
OTL by OldTimer - Version 3.2.16.0 Folder = F:\Documents and Settings\Steve\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 74.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 97.66 Gb Total Space | 25.07 Gb Free Space | 25.67% Space Free | Partition Type: NTFS
Drive D: | 88.65 Gb Total Space | 6.01 Gb Free Space | 6.78% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 824.67 Gb Free Space | 88.53% Space Free | Partition Type: NTFS
Drive F: | 233.76 Gb Total Space | 136.14 Gb Free Space | 58.24% Space Free | Partition Type: NTFS
Computer Name: STEVEN | User Name: Steve | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 90 Days ========== Processes (SafeList) ==========
PRC - [2010/10/21 07:27:33 | 000,575,488 | ---- | M] (OldTimer Tools) -- F:\Documents and Settings\Steve\My Documents\Downloads\OTL.exe
PRC - [2010/10/10 00:01:29 | 002,424,560 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
PRC - [2010/06/10 06:58:32 | 000,865,832 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe
PRC - [2010/02/17 16:52:00 | 000,144,704 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe
PRC - [2010/02/17 15:53:26 | 000,606,736 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe
PRC - [2010/02/11 12:36:12 | 001,218,008 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2009/10/27 11:19:46 | 000,895,696 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MPF\MpfSrv.exe
PRC - [2009/10/02 13:02:56 | 000,026,640 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSK\msksrver.exe
PRC - [2009/09/08 17:25:52 | 000,096,334 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe
PRC - [2009/07/08 11:54:34 | 000,359,952 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe
PRC - [2009/07/07 19:10:02 | 002,482,848 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
PRC - [2009/01/23 10:46:14 | 000,203,280 | ---- | M] () -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
PRC - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/04/28 15:49:36 | 000,253,952 | ---- | M] (PIXELA CORPORATION) -- C:\Program Files\PIXELA\ImageMixer 3 SE Ver.3\CameraMonitor.exe
PRC - [2007/06/15 21:48:52 | 000,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
PRC - [2007/06/13 06:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/11/03 19:20:12 | 000,866,584 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2006/11/03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MsMpEng.exe
PRC - [2006/10/13 18:04:06 | 000,707,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\vVX3000.exe
PRC - [2006/10/13 18:01:06 | 000,207,664 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe
PRC - [2006/10/11 12:45:12 | 000,075,304 | ---- | M] (ScanSoft, Inc.) -- C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
PRC - [2004/08/04 01 52 | 000,015,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\inetsrv\inetinfo.exe
PRC - [2004/07/01 06:23:32 | 000,067,584 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE
PRC - [2004/06/24 15:47:06 | 001,691,648 | ---- | M] (Roxio) -- C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
PRC - [2004/03/21 12:20:35 | 000,186,880 | ---- | M] (SlySoft, Inc.) -- C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
PRC - [2003/09/22 21:34:50 | 000,192,512 | ---- | M] (ABIT Computer Corporation) -- C:\Program Files\ABIT\ABIT uGuru\uGuru.exe
PRC - [2003/07/29 05:23:25 | 000,053,248 | ---- | M] () -- C:\Program Files\Linksys Wireless-B Media Adapter\bin\XWPCLauncher.exe
PRC - [2003/06/09 03:57:34 | 000,024,576 | ---- | M] (Linksys Corporation) -- C:\Program Files\Linksys Wireless-B Media Adapter\bin\XWPCHostService.exe
PRC - [2003/06/09 03:57:33 | 000,008,192 | ---- | M] (Linksys Corporation) -- C:\Program Files\Linksys Wireless-B Media Adapter\bin\XWPCApplicationLoaderService.exe
PRC - [2002/03/19 18:30:00 | 000,045,632 | ---- | M] () -- C:\WINDOWS\system32\TaskSwitch.exe ========== Modules (SafeList) ==========
MOD - [2010/10/21 07:27:33 | 000,575,488 | ---- | M] (OldTimer Tools) -- F:\Documents and Settings\Steve\My Documents\Downloads\OTL.exe
MOD - [2009/01/23 10:46:18 | 000,013,840 | ---- | M] () -- C:\Program Files\McAfee\SiteAdvisor\sahook.dll
MOD - [2006/10/04 22:07:12 | 000,144,936 | ---- | M] (ScanSoft, Inc.) -- C:\Program Files\ScanSoft\OmniPageSE4.0\OpHookSE4.dll
MOD - [2006/08/25 11:45:55 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
MOD - [2004/08/04 00:01:18 | 000,102,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx ========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc)
SRV - [2010/06/10 06:58:32 | 000,865,832 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\MSC\mcmscsvc.exe -- (mcmscsvc)
SRV - [2010/02/24 13:16:08 | 000,365,072 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV - [2010/02/17 16:52:00 | 000,144,704 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\McAfee\VirusScan\Mcshield.exe -- (McShield)
SRV - [2010/02/17 15:53:26 | 000,606,736 | ---- | M] (McAfee, Inc.) [On_Demand | Running] -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe -- (McSysmon)
SRV - [2009/10/27 11:19:46 | 000,895,696 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\MPF\MPFSrv.exe -- (MpfService)
SRV - [2009/10/02 13:02:56 | 000,026,640 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\MSK\MskSrver.exe -- (MSK80Service)
SRV - [2009/09/08 17:25:52 | 000,096,334 | ---- | M] (Canon Inc.) [Auto | Running] -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2009/07/08 11:54:34 | 000,359,952 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe -- (McProxy)
SRV - [2009/07/07 19:10:02 | 002,482,848 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe -- (McNASvc)
SRV - [2009/01/23 10:46:14 | 000,203,280 | ---- | M] () [Auto | Running] -- C:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
SRV - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2006/11/03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV - [2006/10/13 18:01:06 | 000,207,664 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe -- (MSCamSvc)
SRV - [2004/08/04 01 52 | 000,015,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\inetsrv\inetinfo.exe -- (W3SVC)
SRV - [2004/08/04 01 52 | 000,015,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\inetsrv\inetinfo.exe -- (SMTPSVC) Simple Mail Transfer Protocol (SMTP)
SRV - [2004/08/04 01 52 | 000,015,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\inetsrv\inetinfo.exe -- (MSFtpsvc)
SRV - [2004/08/04 01 52 | 000,015,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\inetsrv\inetinfo.exe -- (IISADMIN)
SRV - [2004/08/04 01 44 | 000,035,328 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\iprip.dll -- (Iprip)
SRV - [2003/06/09 03:57:34 | 000,024,576 | ---- | M] (Linksys Corporation) [Auto | Running] -- C:\Program Files\Linksys Wireless-B Media Adapter\bin\XWPCHostService.exe -- (XWPCHostService)
SRV - [2003/06/09 03:57:33 | 000,008,192 | ---- | M] (Linksys Corporation) [Auto | Running] -- C:\Program Files\Linksys Wireless-B Media Adapter\bin\XWPCApplicationLoaderService.exe -- (XWPCApplicationLoaderService) ========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\Drivers\ati7ohxx.sys -- (ati7ohxx)
DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\Drivers\ati6fkxx.sys -- (ati6fkxx)
DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\Drivers\ati2hkxx.sys -- (ati2hkxx)
DRV - File not found [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\Drivers\ati0yjxx.sys -- (ati0yjxx)
DRV - [2010/07/15 15:18:22 | 000,120,136 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\Mpfp.sys -- (MPFP)
DRV - [2010/06/04 07:26:12 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/03/11 10 01 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV)
DRV - [2010/03/11 10 01 | 000,012,872 | ---- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2010/02/17 16:52:48 | 000,214,664 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2010/02/17 16:52:48 | 000,079,816 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2010/02/17 16:52:48 | 000,040,552 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfesmfk.sys -- (mfesmfk)
DRV - [2010/02/17 16:52:48 | 000,035,272 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2010/02/17 16:52:10 | 000,034,248 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mferkdk.sys -- (mferkdk)
DRV - [2009/06/22 07:48:44 | 000,091,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mqac.sys -- (MQAC)
DRV - [2008/05/23 21:45:28 | 000,016,694 | ---- | M] (PalmSource, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PalmUSBD.sys -- (PalmUSBD)
DRV - [2008/05/08 08:28:49 | 000,202,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rmcast.sys -- (RMCAST)
DRV - [2008/02/19 21:32:28 | 000,209,200 | R--- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\Si3114r5.sys -- (Si3114r5)
DRV - [2008/02/19 21:32:28 | 000,010,368 | R--- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys -- (SiFilter)
DRV - [2008/02/19 21:32:28 | 000,005,504 | R--- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\SiRemFil.sys -- (SiRemFil)
DRV - [2007/09/29 04:06:00 | 002,456,064 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2007/07/23 09:23:46 | 000,021,632 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgusbmodem.sys -- (USBModem)
DRV - [2007/07/23 09:23:46 | 000,019,840 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgusbdiag.sys -- (UsbDiag)
DRV - [2007/07/23 09:23:44 | 000,012,416 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lgusbbus.sys -- (usbbus)
DRV - [2007/03/01 12:12:16 | 000,075,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\slabser.sys -- (slabser)
DRV - [2007/03/01 12:12:16 | 000,058,368 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\slabbus.sys -- (slabbus) CP210x USB Composite Device driver (WDM)
DRV - [2006/10/13 18:04:30 | 001,966,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VX3000.sys -- (VX3000)
DRV - [2005/02/12 07:32:48 | 000,062,592 | ---- | M] (Chic Tech.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\moufiltr.sys -- (moufiltr)
DRV - [2004/08/04 00:07:56 | 000,059,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2004/08/03 23:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rtl8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2004/07/01 02:49:00 | 000,626,977 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/06/24 15:48:38 | 000,289,408 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\Cdudf_xp.sys -- (cdudf_xp)
DRV - [2004/06/24 15:48:00 | 000,023,808 | ---- | M] (Roxio) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\dvd_2k.sys -- (dvd_2K)
DRV - [2004/06/24 15:42:00 | 000,024,832 | ---- | M] (Roxio) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\cdralw2k.sys -- (Cdralw2k)
DRV - [2004/06/24 15:39:16 | 000,044,160 | ---- | M] (Roxio) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\cdr4_xp.sys -- (Cdr4_xp)
DRV - [2004/06/24 15:39:12 | 000,141,184 | ---- | M] (Windows (R) 2000 DDK provider) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\DVDVRRdr_xp.sys -- (DVDVRRdr_xp)
DRV - [2004/06/24 15:36:00 | 000,200,704 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\Udfreadr.sys -- (UDFReadr)
DRV - [2004/06/24 15:35:48 | 000,023,808 | ---- | M] (Roxio) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\mmc_2k.sys -- (mmc_2K)
DRV - [2004/06/24 15:32:38 | 000,117,632 | ---- | M] (Roxio) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\Pwd_2k.sys -- (pwd_2k)
DRV - [2004/03/21 12:17:07 | 000,017,024 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2004/02/26 17:52:22 | 000,010,752 | ---- | M] (ABIT Computer Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\uGuru.sys -- (uGuru)
DRV - [2004/02/23 23:08:52 | 000,400,384 | ---- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXSENS.SYS -- (ALCXSENS)
DRV - [2004/01/27 15:13:45 | 000,003,840 | ---- | M] (Elaborate Bytes) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ElbyDelay.sys -- (ElbyDelay)
DRV - [2003/11/28 21 42 | 000,009,728 | ---- | M] (Elaborate Bytes AG) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV - [2003/11/26 10:40:54 | 000,004,224 | ---- | M] (ABIT Computer Corp.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\AC2003.sys -- (AC2003)
DRV - [2002/09/17 12:55:06 | 000,003,548 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\ABIT\ABIT uGuru\WinFlash.sys -- (Winflash)
DRV - [2001/11/29 19:49:56 | 000,004,047 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\ABIT\ABIT uGuru\MEMCTL.SYS -- (Memctl)
DRV - [2001/08/17 09:28:12 | 000,488,383 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\HSF_V124.sys -- (V124)
DRV - [2001/08/17 09:28:12 | 000,050,751 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\HSF_TONE.sys -- (Tones)
DRV - [2001/08/17 09:28:10 | 000,542,879 | ---- | M] (Conexant) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HSF_MSFT.sys -- (hsf_msft)
DRV - [2001/08/17 09:28:10 | 000,057,471 | ---- | M] (Conexant) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HSF_SAMP.sys -- (Rksample)
DRV - [2001/08/17 09:28:08 | 000,391,199 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\HSF_K56K.sys -- (K56)
DRV - [2001/08/17 09:28:06 | 000,289,887 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\HSF_FALL.sys -- (Fallback)
DRV - [2001/08/17 09:28:06 | 000,199,711 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\HSF_FAXX.sys -- (SoftFax)
DRV - [2001/08/17 09:28:06 | 000,115,807 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\HSF_FSKS.sys -- (Fsks)
DRV - [2001/08/17 09:28:04 | 000,067,167 | ---- | M] (Conexant) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HSF_BSC2.sys -- (basic2) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = Google Toolbar
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = Google Toolbar
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = Google Toolbar
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings: "ProxyServer" = http=127.0.0.1:50370
FF - HKLM\software\mozilla\Firefox\extensions\\{B7082FA A-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/10/21 01:31:06 | 000,000,000 | ---D | M]
[2010/10/20 20:04:43 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2001/08/23 08:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Yahooo Search Protection) - {25BC7718-0BFA-40EA-B381-4B2D9732D686} - C:\Program Files\Yahoo!\Search Protection\ysp.dll (Yahoo! Inc.)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\s wg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (ZeroBar) - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (ZeroBar) - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll ()
O4 - HKLM..\Run: [ABIT uGuru] C:\Program Files\ABIT\ABIT uGuru\uGuru.exe (ABIT Computer Corporation)
O4 - HKLM..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe (SlySoft, Inc.)
O4 - HKLM..\Run: [CoolSwitch] C:\WINDOWS\system32\TaskSwitch.exe ()
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McENUI] C:\Program Files\McAfee\MHN\McENUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MP10_EnsureFileVer] C:\WINDOWS\inf\unregmp2.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MsmqIntCert] C:\WINDOWS\System32\mqrt.dll (Microsoft Corporation)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [RoxioDragToDisc] C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe (Roxio)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [VX3000] C:\WINDOWS\vVX3000.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe File not found
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe (Google Inc.)
O4 - HKCU..\Run: [Twain] C:\Documents and Settings\Steve\Application Data\Twain\Twain.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adapter Utility.lnk = C:\WINDOWS\Installer\{13515E3B-B512-45FF-BA78-0F677794AC99}\Launcher.exe (InstallShield Software Corp.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ImageMixer 3 SE Camera Monitor Ver.3.lnk = C:\Program Files\PIXELA\ImageMixer 3 SE Ver.3\CameraMonitor.exe (PIXELA CORPORATION)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Yahoo! Search - C:\Program Files\Yahoo!\Common [2007/11/06 08:34:31 | 000,000,000 | ---D | M]
O8 - Extra context menu item: Yahoo! &Dictionary - C:\Program Files\Yahoo!\Common [2007/11/06 08:34:31 | 000,000,000 | ---D | M]
O8 - Extra context menu item: Yahoo! &Maps - C:\Program Files\Yahoo!\Common [2007/11/06 08:34:31 | 000,000,000 | ---D | M]
O9 - Extra Button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll (Yahoo! Inc.)
O9 - Extra 'Tools' menuitem : Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll (Yahoo! Inc.)
O9 - Extra Button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - File not found
O9 - Extra Button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - File not found
O9 - Extra Button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - File not found
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} https://activatemyfios.verizon.net/s...0Installer.cab (Support.com Configuration Class)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/s...irector/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {20CE7BA6-1131-433A-8751-4BC7A1A41845} http://ari08.myphotoalbum.com/MyPhot...syUploader.cab (MyPhotoAlbum Upload Tool Combo Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www1.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/sh...0/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get.../ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} http://web1.shutterfly.com/downloads/Uploader.cab (Shutterfly Picture Upload Plugin)
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} http://www.photofinale.com/ImageUplo...eUploader4.cab (Reg Error: Key error.)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/sh...23/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jin...ndows-i586.cab (Java Plug-in 1.5.0_01)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jin...ndows-i586.cab (Java Plug-in 1.5.0_02)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jin...ndows-i586.cab (Java Plug-in 1.5.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub...sh/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DC11F230-5717-4C25-BAD7-37B879C19655} http://ari08.myphotoalbum.com/ImageUploader4.cab (MyPhotoAlbum Easy Upload Tool Combo Control)
O16 - DPF: {DF304508-B304-11D3-B860-00201857EBF5} http://www.imagestation.com/common/c...b?ver=2,0,0,54 (Pixami Print Layout Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E9A7F56F-C40F-4928-8C6F-7A72F2A25222} http://www.imagestation.com/common/c...cab?v=1,0,0,37 (AxRUploadControl Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 71.242.0.12
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O29 - HKLM SecurityProviders - (msansspc.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/02/12 06:54:25 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{89cc4e02-39fd-11df-ad5d-00508ded6cff}\Shell - "" = AutoRun
O33 - MountPoints2\{89cc4e02-39fd-11df-ad5d-00508ded6cff}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{89cc4e02-39fd-11df-ad5d-00508ded6cff}\Shell\AutoRun\command - "" = G:\DTVP_Launcher.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - C:\WINDOWS\system32\iprip.dll (Microsoft Corporation)
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: midi9 - C:\DOCUME~1\Steve\LOCALS~1\Temp\mjx.bak 2yGBEBNEED File not found
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imc - C:\WINDOWS\System32\IMC32.acm (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\WINDOWS\System32\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (www )
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: VIDC.3iv2 - C:\WINDOWS\System32\3ivxVfWCodec.dll (3ivx.com)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.DIVX - C:\WINDOWS\System32\divx.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: VIDC.HFYU - C:\WINDOWS\System32\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\WINDOWS\System32\I263_32.drv (Intel Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll ()
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: VIDC.VP31 - C:\WINDOWS\System32\vp31vfw.dll (On2.com)
Drivers32: VIDC.VP60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP70 - C:\WINDOWS\System32\vp7vfw.dll (On2.com)
Drivers32: VIDC.wmv3 - C:\WINDOWS\System32\WMV9VCM.dll (Microsoft Corporation)
Drivers32: VIDC.X264 - C:\WINDOWS\System32\x264vfw.dll ()
Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (58560350072602624) ========== Files/Folders - Created Within 90 Days ==========
[2010/10/21 01:31:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2010/10/20 21:01:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Steve\Application Data\Malwarebytes
[2010/10/20 21:01:12 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/10/20 21:01:11 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/10/20 21:01:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/10/20 21:01:10 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/10/20 00:19:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Steve\Local Settings\Application Data\Temp
[2010/10/20 00:19:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Steve\Local Settings\Application Data\Deployment
[2010/10/18 07:15:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\Canon MyCameraFiles
[2010/10/18 07:14:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
[2010/10/09 11:47:13 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Adobe
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files - Modified Within 90 Days ==========
[2010/10/21 07:24:00 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-583907252-879983540-839522115-1003UA.job
[2010/10/21 01:32:19 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/10/21 01:00:00 | 000,000,412 | ---- | M] () -- C:\WINDOWS\tasks\McAfee.com Scan for Viruses - My Computer (STEVEN-Temp).job
[2010/10/21 00:24:00 | 000,000,926 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-583907252-879983540-839522115-1003Core.job
[2010/10/20 21:29:57 | 000,002,445 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adapter Utility.lnk
[2010/10/20 21:29:13 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/10/20 21:25:55 | 000,016,493 | ---- | M] () -- C:\WINDOWS\System32\Config.MPF
[2010/10/20 21:25:14 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/10/20 21:01:15 | 000,000,702 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/20 18:45:49 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/10/20 00:20:43 | 000,002,290 | ---- | M] () -- C:\Documents and Settings\Steve\Desktop\Google Chrome.lnk
[2010/10/20 00:20:43 | 000,002,268 | ---- | M] () -- C:\Documents and Settings\Steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/10/19 23:18:28 | 000,115,224 | ---- | M] () -- C:\img2-001.raw
[2010/10/18 07:16:30 | 000,000,793 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\DCSD Software Guide.lnk
[2010/10/18 07:16:24 | 000,000,873 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Personal Printing Guide.lnk
[2010/10/18 07:16:23 | 000,000,798 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\PowerShot S95 Camera User Guide.lnk
[2010/10/18 07:16:03 | 000,000,803 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Digital Photo Professional.lnk
[2010/10/18 07:14:18 | 000,000,929 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ZoomBrowser EX.lnk
[2010/10/18 01:00:00 | 000,000,880 | ---- | M] () -- C:\WINDOWS\tasks\BackupSteveDocuments.job
[2010/10/15 01:10:26 | 000,000,340 | ---- | M] () -- C:\WINDOWS\tasks\McDefragTask.job
[2010/10/01 01:00:05 | 000,000,318 | ---- | M] () -- C:\WINDOWS\tasks\McQcTask.job
[2010/09/12 14:17:14 | 000,787,817 | ---- | M] () -- C:\Documents and Settings\Steve\Desktop\Lead Indian Spices.mht
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files Created - No Company Name ==========
[2010/10/20 21:01:15 | 000,000,702 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/20 00:20:43 | 000,002,290 | ---- | C] () -- C:\Documents and Settings\Steve\Desktop\Google Chrome.lnk
[2010/10/20 00:20:43 | 000,002,268 | ---- | C] () -- C:\Documents and Settings\Steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/10/20 00:19:41 | 000,000,978 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-583907252-879983540-839522115-1003UA.job
[2010/10/20 00:19:41 | 000,000,926 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-583907252-879983540-839522115-1003Core.job
[2010/10/18 07:16:30 | 000,000,793 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\DCSD Software Guide.lnk
[2010/10/18 07:16:24 | 000,000,873 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Personal Printing Guide.lnk
[2010/10/18 07:16:23 | 000,000,798 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\PowerShot S95 Camera User Guide.lnk
[2010/10/18 07:14:18 | 000,000,929 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ZoomBrowser EX.lnk
[2010/09/12 14:17:11 | 000,787,817 | ---- | C] () -- C:\Documents and Settings\Steve\Desktop\Lead Indian Spices.mht
[2009/05/17 17:32:55 | 000,000,947 | ---- | C] () -- C:\WINDOWS\MyHeritage.INI
[2009/05/17 17:30:18 | 000,454,656 | ---- | C] () -- C:\WINDOWS\System32\PaintX.dll
[2008/08/22 23 56 | 000,870,128 | ---- | C] () -- C:\Documents and Settings\Steve\Application Data\mcs.rma
[2008/08/22 23 56 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\Steve\Application Data\409924
[2008/08/06 21:23:21 | 000,000,416 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2007/06/02 17:45:33 | 000,782,336 | ---- | C] () -- C:\WINDOWS\System32\IlmImf.dll
[2007/06/02 17:45:33 | 000,204,288 | ---- | C] () -- C:\WINDOWS\System32\pmtf3.dll
[2007/06/02 17:45:33 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\pmexr.dll
[2007/06/02 17:45:33 | 000,011,776 | ---- | C] () -- C:\WINDOWS\System32\pmbm.dll
[2007/06/02 17:45:32 | 000,353,280 | ---- | C] () -- C:\WINDOWS\System32\pmtf2.dll
[2007/06/02 17:45:32 | 000,271,872 | ---- | C] () -- C:\WINDOWS\System32\PhotomatixLib.dll
[2007/06/02 17:45:32 | 000,229,376 | ---- | C] () -- C:\WINDOWS\System32\PhotomatixLib2.dll
[2007/06/02 17:45:32 | 000,216,064 | ---- | C] () -- C:\WINDOWS\System32\pmjp.dll
[2007/06/02 17:45:32 | 000,205,824 | ---- | C] () -- C:\WINDOWS\System32\pmtf1.dll
[2007/06/02 17:45:32 | 000,112,128 | ---- | C] () -- C:\WINDOWS\System32\PhotomatixLib3.dll
[2007/06/02 16:32:49 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2006/05/25 20:13:11 | 000,000,005 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\DragToDiscUserNameG.txt
[2006/04/15 21:23:59 | 000,000,005 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\DragToDiscUserNameF.txt
[2006/04/14 22:30:47 | 000,015,498 | ---- | C] () -- C:\WINDOWS\VX3000.ini
[2006/04/08 23:40:03 | 000,010,414 | ---- | C] () -- C:\WINDOWS\System32\FlashMenu.sys
[2006/04/08 23:40:03 | 000,003,548 | ---- | C] () -- C:\WINDOWS\System32\WINFLASH.SYS
[2006/04/08 23:39:39 | 000,005,960 | ---- | C] () -- C:\WINDOWS\System32\drivers\HWDRV.SYS
[2006/04/08 23:39:39 | 000,005,018 | ---- | C] () -- C:\WINDOWS\System32\drivers\HWIOCTL.SYS
[2006/04/08 23:39:39 | 000,004,047 | ---- | C] () -- C:\WINDOWS\System32\drivers\MEMCTL.SYS
[2006/04/08 23:39:39 | 000,003,548 | ---- | C] () -- C:\WINDOWS\System32\drivers\WINFLASH.SYS
[2006/04/08 23:39:39 | 000,002,721 | ---- | C] () -- C:\WINDOWS\System32\drivers\AMINTSYS.SYS
[2006/03/01 20:04:05 | 000,157,696 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2006/03/01 20:04:02 | 000,454,162 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll
[2006/03/01 20:04:02 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
[2006/03/01 20:04:01 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2006/03/01 20:04:01 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2006/03/01 20:03:59 | 000,006,144 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2006/03/01 20:03:57 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll
[2005/08/12 17:57:09 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005/08/07 09:15:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\QuickInstall.INI
[2005/08/06 09 07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ATIMMC.INI
[2005/05/01 16:11:11 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\Inst2891.dll
[2005/03/15 21:46:20 | 000,000,048 | ---- | C] () -- C:\WINDOWS\PerWin.ini
[2005/02/13 02:46:36 | 000,000,005 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\DragToDiscUserNameE.txt
[2005/02/13 02 44 | 000,092,160 | ---- | C] () -- C:\Documents and Settings\Steve\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/02/12 11:35:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\RussSqr.INI
[2005/02/12 08:36:36 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/02/12 08:10:24 | 000,000,204 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
[2005/02/12 07:36:17 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2005/02/12 07:36:15 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2005/02/12 07:15:24 | 000,000,102 | ---- | C] () -- C:\WINDOWS\VSWizard.ini
[2005/02/12 07:05:11 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2005/02/12 07:03:20 | 000,000,000 | ---- | C] () -- C:\WINDOWS\frontpg.ini
[2005/02/12 07:02:29 | 000,021,791 | ---- | C] () -- C:\WINDOWS\System32\smtpctrs.ini
[2005/02/12 07:02:29 | 000,001,037 | ---- | C] () -- C:\WINDOWS\System32\ntfsdrct.ini
[2005/02/12 07:02:18 | 000,007,909 | ---- | C] () -- C:\WINDOWS\System32\ftpctrs.ini
[2005/02/12 07:02:15 | 000,038,576 | ---- | C] () -- C:\WINDOWS\System32\w3ctrs.ini
[2005/02/12 07:02:15 | 000,010,225 | ---- | C] () -- C:\WINDOWS\System32\axperf.ini
[2005/02/12 07:02:11 | 000,011,435 | ---- | C] () -- C:\WINDOWS\System32\infoctrs.ini
[2005/02/12 07:02:08 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2005/02/12 01:46:31 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2003/03/28 16:31:52 | 000,013,601 | ---- | C] () -- C:\WINDOWS\System32\vctest.ini
[2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/08/23 08:00:00 | 000,755,200 | ---- | C] () -- C:\WINDOWS\System32\ir50_32.dll
[2001/08/23 08:00:00 | 000,338,432 | ---- | C] () -- C:\WINDOWS\System32\ir41_qcx.dll
[2001/08/23 08:00:00 | 000,200,192 | ---- | C] () -- C:\WINDOWS\System32\ir50_qc.dll
[2001/08/23 08:00:00 | 000,183,808 | ---- | C] () -- C:\WINDOWS\System32\ir50_qcx.dll
[2001/08/23 08:00:00 | 000,120,320 | ---- | C] () -- C:\WINDOWS\System32\ir41_qc.dll ========== LOP Check ==========
[2008/05/10 15:27:50 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2006/03/14 23:31:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\element5
[2008/05/23 21:10:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HotSync
[2009/05/17 17:35:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MyHeritage
[2010/05/10 23:49:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PIXELA
[2008/08/06 21:23:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2009/07/19 09:45:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\Broderbund Software
[2010/06/02 23:57:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\Canon
[2008/05/02 06:47:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\HotSync
[2006/12/14 10:23:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\Juniper Networks
[2005/02/12 07:15:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\Leadertech
[2009/05/17 17:31:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\MyHeritage
[2008/08/06 21:23:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\ScanSoft
[2009/09/12 23:34:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\SmartDraw
[2007/07/13 00:06:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\Snapfish
[2009/05/17 17:30:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\The Complete Genealogy Reporter - FTB
[2007/10/11 20:13:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\Yapta
[2010/10/18 01:00:00 | 000,000,880 | ---- | M] () -- C:\WINDOWS\Tasks\BackupSteveDocuments.job
[2010/10/15 01:10:26 | 000,000,340 | ---- | M] () -- C:\WINDOWS\Tasks\McDefragTask.job
[2010/10/01 01:00:05 | 000,000,318 | ---- | M] () -- C:\WINDOWS\Tasks\McQcTask.job
[2010/10/21 01:32:19 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.* >
[2008/05/23 22:32:16 | 000,001,788 | ---- | M] () -- C:\additdiag.txt
[2005/02/12 06:54:25 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009/08/22 00:11:49 | 4140,468,218 | ---- | M] () -- C:\BackupDocsSettings.bkf
[2010/01/24 17:00:12 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2005/02/12 06:54:25 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2005/08/07 08:39:29 | 000,000,636 | ---- | M] () -- C:\Ctp.log
[2005/02/19 18:05:00 | 000,000,081 | ---- | M] () -- C:\DVDPATH.TXT
[2001/09/05 22:00:58 | 001,700,352 | ---- | M] (Microsoft Corporation) -- C:\gdiplus.dll
[2008/05/23 21:41:31 | 006,813,820 | ---- | M] () -- C:\HuskyInstallerLog.txt
[2010/10/19 23:18:28 | 000,115,224 | ---- | M] () -- C:\img2-001.raw
[2005/02/12 06:54:25 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2005/02/12 06:54:25 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2005/03/01 20:26:23 | 000,001,089 | ---- | M] () -- C:\net_save.dna
[2005/02/12 07:44:52 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2005/02/12 07:44:52 | 000,250,032 | RHS- | M] () -- C:\ntldr
[2008/10/14 18:53:53 | 000,262,144 | ---- | M] () -- C:\ntuser.dat
[2008/10/14 18:53:54 | 000,001,024 | -H-- | M] () -- C:\ntuser.dat.LOG
[2010/10/20 21:25:08 | 1610,612,736 | -HS- | M] () -- C:\pagefile.sys
[2010/05/11 00:26:06 | 000,008,704 | ---- | M] () -- C:\palm.grf
[2006/08/06 23:25:45 | 000,000,015 | --S- | M] () -- C:\testlog.log < %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont < %systemroot%\Fonts\*.dll > < %systemroot%\Fonts\*.ini >
[2005/02/12 06:54:06 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini < %systemroot%\Fonts\*.ini2 > < %systemroot%\Fonts\*.exe > < %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/09/13 01:00:00 | 000,027,136 | ---- | M] (CANON INC.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD85. DLL
[2006/09/13 01:00:00 | 000,069,632 | ---- | M] (CANON INC.) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP85. DLL
[2008/07/06 08:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpi pelineprintproc.dll
[2003/06/18 18:31:48 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.d ll
[2008/07/06 06:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfil terpipelinesvc.exe < %systemroot%\REPAIR\*.bak1 > < %systemroot%\REPAIR\*.ini > < %systemroot%\system32\*.jpg > < %systemroot%\*.jpg > < %systemroot%\*.png > < %systemroot%\*.scr > < %systemroot%\*._sy > < %APPDATA%\Adobe\Update\*.* > < %ALLUSERSPROFILE%\Favorites\*.* >
[2004/05/18 12:50:58 | 000,000,204 | ---- | M] () -- C:\Documents and Settings\All Users\Favorites\My Yahoo!.url
[2004/05/18 12:49:54 | 000,000,213 | ---- | M] () -- C:\Documents and Settings\All Users\Favorites\Yahoo! Bookmarks.url
[2004/05/18 17:26:04 | 000,000,208 | ---- | M] () -- C:\Documents and Settings\All Users\Favorites\Yahoo! Mail.url
[2004/05/18 17:13:06 | 000,000,207 | ---- | M] () -- C:\Documents and Settings\All Users\Favorites\Yahoo! < %APPDATA%\Microsoft\*.* >
[2010/10/20 20:01:00 | 000,015,397 | ---- | M] () -- C:\Documents and Settings\Steve\Application Data\Microsoft\stor.cfg < %PROGRAMFILES%\*.* > < %APPDATA%\Update\*.* > < %systemroot%\*. /mp /s > < %systemroot%\System32\config\*.sav >
[2005/02/12 01:44:52 | 000,090,112 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2005/02/12 01:44:52 | 000,630,784 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2005/02/12 01:44:52 | 000,405,504 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav < %PROGRAMFILES%\bak. /s > < %systemroot%\system32\bak. /s > < %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2005/02/12 07:48:12 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini < %systemroot%\system32\config\systemprofile\*.dat /x > < %systemroot%\*.config > < %systemroot%\system32\*.db > < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/02/12 07:54:36 | 000,000,177 | -HS- | M] () -- C:\Documents and Settings\Steve\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/01/17 16:37:18 | 003,222,166 | ---- | M] () -- C:\Documents and Settings\Steve\Application Data\Microsoft\Internet Explorer\Quick Launch\IMG_3866.JPG
[2005/02/12 07:00:09 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf < %USERPROFILE%\Desktop\*.exe > < %PROGRAMFILES%\Common Files\*.* > < %systemroot%\*.src >
[2006/09/11 19:59:36 | 000,013,023 | ---- | M] () -- C:\WINDOWS\VX3000.src
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] < %systemroot%\install\*.* > < %systemroot%\system32\DLL\*.* > < %systemroot%\system32\HelpFiles\*.* > < %systemroot%\system32\rundll\*.* > < %systemroot%\winn32\*.* > < %systemroot%\Java\*.* > < %systemroot%\system32\test\*.* > < %systemroot%\system32\Rundll32\*.* > < %systemroot%\AppPatch\Custom\*.* > < %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x > < %PROGRAMFILES%\PC-Doctor\Downloads\*.* > < %PROGRAMFILES%\Internet Explorer\*.tmp > < %PROGRAMFILES%\Internet Explorer\*.dat > < %USERPROFILE%\My Documents\*.exe > < %USERPROFILE%\*.exe > < %systemroot%\ADDINS\*.* >
[2001/08/23 08:00:00 | 000,000,791 | ---- | M] () -- C:\WINDOWS\addins\fxsext.ecf < %systemroot%\assembly\*.bak2 > < %systemroot%\Config\*.* > < %systemroot%\REPAIR\*.bak2 > < %systemroot%\SECURITY\Database\*.sdb /x > < %systemroot%\SYSTEM\*.bak2 > < %systemroot%\Web\*.bak2 > < %systemroot%\Driver Cache\*.* > < %PROGRAMFILES%\Mozilla Firefox\0*.exe > < %ProgramFiles%\Microsoft Common\*.* > < %ProgramFiles%\TinyProxy. > < %USERPROFILE%\Favorites\*.url /x >
[2005/02/12 07:54:36 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\Steve\Favorites\Desktop.ini < %systemroot%\system32\*.bk > < %systemroot%\*.te > < %systemroot%\system32\system32\*.* > < %ALLUSERSPROFILE%\*.dat /x > < %systemroot%\system32\drivers\*.rmv > < dir /b "%systemroot%\system32\*.exe" | find /i " " /c > < dir /b "%systemroot%\*.exe" | find /i " " /c > < %PROGRAMFILES%\Microsoft\*.* > < %systemroot%\System32\Wbem\proquota.exe > < %PROGRAMFILES%\Mozilla Firefox\*.dat > < %USERPROFILE%\Cookies\*.txt /x >
[2010/10/21 07:24:44 | 000,573,440 | ---- | M] () -- C:\Documents and Settings\Steve\Cookies\index.dat < %SystemRoot%\system32\fonts\*.* > < %systemroot%\system32\winlog\*.* > < %systemroot%\system32\Language\*.* > < %systemroot%\system32\Settings\*.* > < %systemroot%\system32\*.quo > < %SYSTEMROOT%\AppPatch\*.exe > < %SYSTEMROOT%\inf\*.exe >
[2004/08/04 01 58 | 000,208,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\inf\unregmp2.exe < %SYSTEMROOT%\Installer\*.exe > < %systemroot%\system32\config\*.bak2 > < %systemroot%\system32\Computers\*.* > < %SystemRoot%\system32\Sound\*.* > < %SystemRoot%\system32\SpecialImg\*.* > < %SystemRoot%\system32\code\*.* > < %SystemRoot%\system32\draft\*.* > < %SystemRoot%\system32\MSSSys\*.* > < %ProgramFiles%\Javascript\*.* > < %systemroot%\pchealth\helpctr\System\*.exe /s > < %systemroot%\Web\*.exe > < %systemroot%\system32\msn\*.* > < %systemroot%\system32\*.tro > < %AppData%\Microsoft\Installer\msupdates\*.* > < %ProgramFiles%\Messenger\*.* >
[2001/05/02 16:24:18 | 000,004,821 | ---- | M] () -- C:\Program Files\Messenger\blogo.gif
[2004/08/04 01 42 | 000,028,672 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\custsat.dll
[2004/07/17 12:41:10 | 000,004,821 | ---- | M] () -- C:\Program Files\Messenger\logowin.gif
[2001/03/07 07:00:26 | 000,007,047 | ---- | M] () -- C:\Program Files\Messenger\lvback.gif
[2001/05/22 14:06:52 | 000,000,866 | ---- | M] () -- C:\Program Files\Messenger\mailtmpl.txt
[2008/05/02 10:22:02 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgsc.dll
[2004/08/04 01 14 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgslang.dll
[2004/10/13 12:24:37 | 001,694,208 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
[2001/02/01 07:00:26 | 000,000,685 | ---- | M] () -- C:\Program Files\Messenger\msmsgs.exe.manifest
[2001/08/01 22:58:12 | 000,016,415 | ---- | M] () -- C:\Program Files\Messenger\msmsgsin.exe
[2004/07/17 12:41:10 | 000,002,882 | ---- | M] () -- C:\Program Files\Messenger\newalert.wav
[2004/07/17 12:41:10 | 000,006,156 | ---- | M] () -- C:\Program Files\Messenger\newemail.wav
[2004/07/17 12:41:10 | 000,006,160 | ---- | M] () -- C:\Program Files\Messenger\online.wav
[2000/12/05 14:10:32 | 000,004,454 | ---- | M] () -- C:\Program Files\Messenger\type.wav
[2004/07/17 12:41:06 | 000,115,981 | ---- | M] () -- C:\Program Files\Messenger\xpmsgr.chm < %systemroot%\system32\systhem32\*.* > < %systemroot%\system\*.exe > < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dows\WindowsUpdate\AU > < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs > ========== Files - Unicode (All) ==========
[2010/06/18 22:25:34 | 000,000,000 | ---D | M](C:\Documents and Settings\Steve\Favorites\?£sorted Bookmarks) -- C:\Documents and Settings\Steve\Favorites\ꤠ£sorted Bookmarks
< End of report >
********************************
OTL Extras logfile created on: 10/21/2010 7:28:30 AM - Run 1
OTL by OldTimer - Version 3.2.16.0 Folder = F:\Documents and Settings\Steve\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 74.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 97.66 Gb Total Space | 25.07 Gb Free Space | 25.67% Space Free | Partition Type: NTFS
Drive D: | 88.65 Gb Total Space | 6.01 Gb Free Space | 6.78% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 824.67 Gb Free Space | 88.53% Space Free | Partition Type: NTFS
Drive F: | 233.76 Gb Total Space | 136.14 Gb Free Space | 58.24% Space Free | Partition Type: NTFS
Computer Name: STEVEN | User Name: Steve | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 90 Days ========== Extra Registry (SafeList) ========== ========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- Reg Error: Key error. File not found ========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /k "cd %L" (Microsoft Corporation)
Directory [Digital Photo Professional] -- C:\Program Files\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride" = 1
"FirewallOverride" = 0
"UpdatesDisableNotify" = 0
"ANTIVIRUSDISABLENOTIFY" = 0
"FIREWALLDISABLENOTIFY" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] ========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SrService]
"Start" = 2 ========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\DomainPr ofile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\DomainPr ofile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\Standard Profile]
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\Standard Profile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"9051:UDP" = 9051:UDP:LocalSubNet:Enabled:Verizon Tech Wizard ========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\DomainPr ofile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\Standard Profile\AuthorizedApplications\List]
"C:\Program Files\support.com\bin\tgcmd.exe" = C:\Program Files\support.com\bin\tgcmd.exe:*:Enabled:Support. com Scheduler and Command Dispatcher -- File not found
"C:\Program Files\Yahoo!\Messenger\YPager.exe" = C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo ! FT Server -- (Yahoo! Inc.)
"C:\Program Files\eMule\emule.exe" = C:\Program Files\eMule\emule.exe:*:Enabled:eMule -- (eMule-Project.net - Official eMule Homepage. Downloads, Help, Docu, News... )
"C:\Program Files\Linksys Wireless-B Media Adapter\bin\AdapterManager.exe" = C:\Program Files\Linksys Wireless-B Media Adapter\bin\AdapterManager.exe:*:Enabled:AdapterMa nager.exe -- (Linksys Corporation)
"C:\Program Files\Linksys Wireless-B Media Adapter\bin\NetworkSettings.exe" = C:\Program Files\Linksys Wireless-B Media Adapter\bin\NetworkSettings.exe:*:Enabled:NetworkS ettings.exe -- (Linksys Corporation)
"C:\Program Files\Linksys Wireless-B Media Adapter\bin\WMA_SET.exe" = C:\Program Files\Linksys Wireless-B Media Adapter\bin\WMA_SET.exe:*:Enabled:WMA_SET.exe -- ()
"C:\Program Files\Linksys Wireless-B Media Adapter\bin\XWPCApplicationLoaderService.exe" = C:\Program Files\Linksys Wireless-B Media Adapter\bin\XWPCApplicationLoaderService.exe:*:Ena bled:XWPCApplicationLoaderService.exe -- (Linksys Corporation)
"C:\Program Files\Linksys Wireless-B Media Adapter\bin\XWPCHostService.exe" = C:\Program Files\Linksys Wireless-B Media Adapter\bin\XWPCHostService.exe:*:Enabled:XWPCHost Service.exe -- (Linksys Corporation)
"C:\Program Files\Linksys Wireless-B Media Adapter\bin\XWPCLauncher.exe" = C:\Program Files\Linksys Wireless-B Media Adapter\bin\XWPCLauncher.exe:*:Enabled:XWPCLaunche r.exe -- ()
"C:\Program Files\Linksys Wireless-B Media Adapter\bin\XWPCTool7.exe" = C:\Program Files\Linksys Wireless-B Media Adapter\bin\XWPCTool7.exe:*:Enabled:XWPCTool7.exe -- ( )
"C:\Program Files\Linksys Wireless-B Media Adapter\bin\XWPCTool8.exe" = C:\Program Files\Linksys Wireless-B Media Adapter\bin\XWPCTool8.exe:*:Enabled:XWPCTool8.exe -- ()
"C:\Program Files\Linksys Wireless-B Media Adapter\bin\SharedMediaManager.exe" = C:\Program Files\Linksys Wireless-B Media Adapter\bin\SharedMediaManager.exe:*:Enabled:Share dMediaManager.exe -- (Linksys Corporation)
"C:\Documents and Settings\Emule Xtreme\emule.exe" = C:\Documents and Settings\Emule Xtreme\emule.exe:*:Enabled:eMule -- File not found
"C:\Program Files\Microsoft LifeCam\LifeExp.exe" = C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe -- (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeCam.exe" = C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe -- (Microsoft Corporation)
"C:\Program Files\Google\Google Talk\googletalk.exe" = C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk -- (Google)
"C:\Program Files\Verizon\Verizon Media Manager\Release\Verizon Media Manager.exe" = C:\Program Files\Verizon\Verizon Media Manager\Release\Verizon Media Manager.exe:*:Enabled:Verizon Media Manager -- File not found
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent -- (McAfee, Inc.) ========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall]
"{083F79E4-6FE9-46FB-A6C6-4F8862742947}" = ATI HYDRAVISION
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP510" = Canon MP510
"{13515E3B-B512-45FF-BA78-0F677794AC99}" = Linksys Wireless-B Media Adapter
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java(TM) 6 Update 14
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{3248F0A8-6813-11D6-A77B-00B0D0150010}" = J2SE Runtime Environment 5.0 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0150050}" = J2SE Runtime Environment 5.0 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java(TM) 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A95D49D-0076-4DB7-A91E-0E685DC6D6AD}" = ImageMixer 3 SE Ver.3
"{3AC275FB-658D-43DA-A04D-9B2E30E517B2}" = Palm
"{45D228AA-4284-467A-9DB6-942B92BFF656}" = DVDDec
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{55937F00-A69B-4049-8D3A-1C7729742B6F}" = BUM
"{5C74694C-A687-E3EB-FF18-B018D4A76ECD}" = Adobe Media Player
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6421F085-1FAA-DE13-D02A-CFB412C522A4}" = Acrobat.com
"{6855CCDD-BDF9-48E4-B80A-80DFB96FE36C}" = CmdHere Powertoy For Windows XP
"{6c651250-2eb2-11d5-8e33-0050dad72ac2}" = NetZero
"{6F00F343-7562-4F03-B3C3-F9360E2DA333}" = DiMAGE Scan Dual4 ver.1.0
"{747D1B34-A1FC-4EF3-A6AE-E86F39CEFDE5}" = Roxio Easy Media Creator 7 Basic DVD Edition
"{85309D89-7BE9-4094-BB17-24999C6118FC}" = ArcSoft PhotoStudio 5.5
"{893306B3-C1B7-4CF0-A3F5-20C7047D6A08}" = MMC87
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8CFC7570-DD90-486E-A239-E31D455BDE93}" = Microsoft LifeCam
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{95C2FBF3-4462-41E3-89DC-0F784387BD53}" = Family Lawyer 2004
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{A7050037-F0EA-4BAB-BCD5-FC05507D6147}" = Alt-Tab Task Switcher Powertoy for Windows XP
"{AC76BA86-1033-0000-7760-000000000001}" = Adobe Acrobat 6.0 Professional
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{B37C842A-B624-46B8-A727-654E72F1C91A}" = Calculator Powertoy for Windows XP
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English)
"{B4FEA924-630D-11D4-B78E-005004566E4D}" = ViewSonic Monitor Drivers
"{BA0CA1B4-5491-11D7-97BC-00055D0CA761}" = Roxio DVDMax Player
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1E693A4-B1D5-4DCD-B68D-2087835B7184}" = ScanSoft OmniPage SE 4.0
"{C7E6091E-44D3-4E50-B9BA-B020A186520E}" = aXbo up2date
"{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO
"{CC4C261A-B915-4F23-BD23-7E1AE5713B4E}" = Vz In Home Agent
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF3BC7E2-A4DF-4B84-9367-A63DF7690659}" = Silicon Laboratories CP210x VCP Drivers for Windows 2000/XP/2003 Server/Vista
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{EEC2DAFD-5558-40AC-8E9C-5005C8F810E8}" = Microsoft Plus! for Windows XP
"{FA02ACAC-9E14-4878-A257-92A22A647C2C}" = LG USB Modem Drivers
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FF8500E6-EA0D-11D7-8755-0080C8F92A32}" = ABIT uGuru
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"All ATI Software" = ATI - Software Uninstall Utility
"AnyDVD" = AnyDVD
"ATI Display Driver" = ATI Display Driver
"CAL" = Canon Camera Access Library
"CalorieKing.com Diet Diary for PalmOS" = CalorieKing.com Diet Diary for PalmOS
"CameraUserGuide-PS95" = Canon PowerShot S95 Camera User Guide
"CameraWindowDC8" = Canon Utilities CameraWindow DC 8
"CameraWindowDVC5" = Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
"CameraWindowLauncher" = Canon Utilities CameraWindow Launcher
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
"Canon MOV Decoder" = Canon MOV Decoder
"Canon MOV Encoder" = Canon MOV Encoder
"Canon MP510 User Registration" = Canon MP510 User Registration
"CloneDVD2" = CloneDVD2
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485 DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B3204 85DF8CE.1" = Acrobat.com
"CSCLIB" = Canon Camera Support Core Library
"DPP" = Canon Utilities Digital Photo Professional 3.9
"Easy-WebPrint" = Easy-WebPrint
"eMule" = eMule
"EOS Utility" = Canon Utilities EOS Utility
"Family Tree Builder" = MyHeritage Family Tree Builder
"FreeStyle CoPilot Health Management System" = FreeStyle CoPilot Health Management System
"ie8" = Windows Internet Explorer 8
"InstallShield_{13515E3B-B512-45FF-BA78-0F677794AC99}" = Linksys Wireless-B Media Adapter
"InstallShield_{45D228AA-4284-467A-9DB6-942B92BFF656}" = ATI DVD Decoder 2.2.0.0
"InstallShield_{893306B3-C1B7-4CF0-A3F5-20C7047D6A08}" = ATI Multimedia Center 8.7.0.0
"InstallShield_{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO
"KLiteCodecPack_is1" = K-Lite Codec Pack 2.70 Full
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework Full v1.0.3705 (1033)" = Microsoft .NET Framework (English) v1.0.3705
"MOCmd Volume 1" = MOCmd Volume 1
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"MovieUploaderForYouTube" = Canon Utilities Movie Uploader for YouTube
"MSC" = McAfee SecurityCenter
"MSTTS" = Microsoft Text-to-Speech Engine 4.0 (English)
"MyCamera" = Canon Utilities MyCamera
"MyCamera Download Plugin" = CANON iMAGE GATEWAY MyCamera Download Plugin
"Office Mouse" = Office Mouse
"Original Data Security Tools" = Canon Utilities Original Data Security Tools
"Personal Printing Guide" = Canon Personal Printing Guide
"Photomatix Pro_is1" = Photomatix Pro version 2.4.1
"PhotoStitch" = Canon Utilities PhotoStitch
"Picture Style Editor" = Canon Utilities Picture Style Editor
"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
"Shockwave" = Shockwave
"SLABCOMM&10C4&EA60" = Silicon Laboratories CP210x USB to UART Bridge (Driver Removal)
"Software Guide" = Canon DIGITAL CAMERA Solution Disk Software Guide
"Tweak UI 2.10" = Tweak UI
"USDA-ARS SR17 for PalmOS" = USDA-ARS SR17 for PalmOS
"V CAST Music with Rhapsody" = V CAST Music with Rhapsody
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"WinAce Archiver" = WinAce Archiver
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 2
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Customizations" = Yahoo! extras
"Yahoo! Internet Mail" = Yahoo! Internet Mail
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Messenger Explorer Bar" = Yahoo! Messenger Explorer Bar
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Software Update" = Yahoo! Software Update
"Yahoo! Toolbar" = Yahoo! Toolbar
"YInstHelper" = Yahoo! Install Manager
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility ========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Uninstall]
"{9863F141-7A33-4c9a-A5F2-96996461B216}" = KODAK EASYSHARE Gallery Easy Upload, v2.1
"aXbo research" = aXbo research
"Google Chrome" = Google Chrome ========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 10/3/2010 3:10:17 PM | Computer Name = STEVEN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 10/10/2010 3:50:38 AM | Computer Name = STEVEN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 10/10/2010 3:50:38 AM | Computer Name = STEVEN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 10/10/2010 4:00:13 PM | Computer Name = STEVEN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 10/10/2010 4:00:13 PM | Computer Name = STEVEN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 10/10/2010 4:00:14 PM | Computer Name = STEVEN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 10/10/2010 4:00:14 PM | Computer Name = STEVEN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 10/10/2010 10:32:19 PM | Computer Name = STEVEN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 10/20/2010 8:45:47 PM | Computer Name = STEVEN | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 800706BA from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsyste mobj.cpp.
Please contact Microsoft Product Support Services to report this erro
Error - 10/20/2010 8:45:47 PM | Computer Name = STEVEN | Source = VSS | ID = 8193
Description = Volume Shadow Copy Service error: Unexpected error calling routine
CoCreateInstance. hr = 0x80040206.
[ Intel Extended PC Events ]
Error - 10/29/2006 2:00:58 AM | Computer Name = STEVEN | Source = Media Service Layer | ID = 0
Description = RemoteIoDevice: Remote IO Client is in a bad state. Please restart
the Digital Media Adapter. (ErrorCode: C2T)
Error - 11/6/2006 8:57:58 PM | Computer Name = STEVEN | Source = Media Service Layer | ID = 0
Description = RemoteIoDevice: Remote IO Client is in a bad state. Please restart
the Digital Media Adapter. (ErrorCode: C2T)
Error - 12/14/2006 10:00:12 AM | Computer Name = STEVEN | Source = Media Service Layer | ID = 0
Description = RemoteIoDevice: Remote IO Client is in a bad state. Please restart
the Digital Media Adapter. (ErrorCode: C2T)
Error - 12/16/2006 5:38:45 PM | Computer Name = STEVEN | Source = Media Service Layer | ID = 0
Description = RemoteIoDevice: Remote IO Client is in a bad state. Please restart
the Digital Media Adapter. (ErrorCode: C2T)
Error - 1/13/2007 11 53 AM | Computer Name = STEVEN | Source = Media Service Layer | ID = 0
Description = RemoteIoDevice: Remote IO Client is in a bad state. Please restart
the Digital Media Adapter. (ErrorCode: C2T)
Error - 5/13/2008 8:42:56 AM | Computer Name = STEVEN | Source = Media Service Layer | ID = 0
Description = RemoteIoDevice: Remote IO Client is in a bad state. Please restart
the Digital Media Adapter. (ErrorCode: C2T)
[ System Events ]
Error - 10/20/2010 8:44:46 PM | Computer Name = STEVEN | Source = Service Control Manager | ID = 7034
Description = The Simple TCP/IP Services service terminated unexpectedly. It has
done this 1 time(s).
Error - 10/20/2010 8:44:46 PM | Computer Name = STEVEN | Source = Service Control Manager | ID = 7034
Description = The SNMP Service service terminated unexpectedly. It has done this
1 time(s).
Error - 10/20/2010 8:44:46 PM | Computer Name = STEVEN | Source = Service Control Manager | ID = 7034
Description = The Digital Media Adapter Application Loader Service service terminated
unexpectedly. It has done this 1 time(s).
Error - 10/20/2010 8:44:46 PM | Computer Name = STEVEN | Source = Service Control Manager | ID = 7034
Description = The Canon Camera Access Library 8 service terminated unexpectedly.
It has done this 1 time(s).
Error - 10/20/2010 8:44:46 PM | Computer Name = STEVEN | Source = Service Control Manager | ID = 7034
Description = The Digital Media Adapter Host Service service terminated unexpectedly.
It has done this 1 time(s).
Error - 10/20/2010 8:44:46 PM | Computer Name = STEVEN | Source = Service Control Manager | ID = 7034
Description = The Yahoo! Updater service terminated unexpectedly. It has done this
1 time(s).
Error - 10/20/2010 8:54:27 PM | Computer Name = STEVEN | Source = ati2mtag | ID = 45062
Description = CRT invalid display type
Error - 10/20/2010 8:54:30 PM | Computer Name = STEVEN | Source = Service Control Manager | ID = 7000
Description = The MCSTRM service failed to start due to the following error: %%2
Error - 10/20/2010 9:25:43 PM | Computer Name = STEVEN | Source = ati2mtag | ID = 45062
Description = CRT invalid display type
Error - 10/20/2010 9:25:46 PM | Computer Name = STEVEN | Source = Service Control Manager | ID = 7000
Description = The MCSTRM service failed to start due to the following error: %%2
< End of report >
******************************************
Welcome aboard
***********************
GMER 1.0.15.15477 - GMER - Rootkit Detector and Remover
Rootkit scan 2010-10-21 07:25:00
Windows 5.1.2600 Service Pack 2
Running: h675b79p.exe; Driver: C:\DOCUME~1\Steve\LOCALS~1\Temp\ugtdypod.sys
---- System - GMER 1.0.15 ----
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xB112C620]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xB104678A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xB1046821]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xB1046738]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xB104674C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xB1046835]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xB1046861]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xB10468CF]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xB10468B9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xB10467CA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xB10468FB]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xB104680D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xB1046710]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xB1046724]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xB104679E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xB1046937]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xB10468A3]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xB104688D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xB104684B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xB1046923]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xB104690F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xB1046776]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xB1046762]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xB1046877]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xB10467F9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xB10468E5]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xB10467E0]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xB10467B4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!ZwYieldExecution 80509034 7 Bytes JMP B10467B8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwOpenKey 80571B19 5 Bytes JMP B1046811 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryValueKey 80571E8B 7 Bytes JMP B1046891 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtCreateFile 80572DCF 5 Bytes JMP B104678E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtSetInformationProcess 80573B37 5 Bytes JMP B1046766 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateKey 80577A7A 5 Bytes JMP B1046825 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryKey 805787F6 7 Bytes JMP B104693B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwEnumerateKey 80578BF6 7 Bytes JMP B10468D3 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwSetValueKey 805792AB 7 Bytes JMP B104687B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenProcess 8057964C 5 Bytes JMP B1046714 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnmapViewOfSection 8057BCA8 5 Bytes JMP B10467E4 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtMapViewOfSection 8057C120 7 Bytes JMP B10467CE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwProtectVirtualMemory 80583D91 7 Bytes JMP B10467A2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcessEx 8058AB6C 7 Bytes JMP B1046750 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwTerminateProcess 8058C3F5 5 Bytes JMP B10467FD \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwEnumerateValueKey 8058F4B7 7 Bytes JMP B10468BD \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwDeleteValueKey 80596A23 7 Bytes JMP B1046865 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwDeleteKey 805981DF 7 Bytes JMP B1046839 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenThread 805B13C6 5 Bytes JMP B1046728 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwNotifyChangeKey 805B1C35 5 Bytes JMP B10468FF \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcess 805C0C98 5 Bytes JMP B104673C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwSetContextThread 806340DB 5 Bytes JMP B104677A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwRestoreKey 8065349E 5 Bytes JMP B1046913 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnloadKey 80653773 7 Bytes JMP B10468E9 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryMultipleValueKey 80654055 7 Bytes JMP B10468A7 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwRenameKey 8065449B 7 Bytes JMP B104684F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwReplaceKey 8065498E 5 Bytes JMP B1046927 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
? tifg.sys The system cannot find the file specified. !
init C:\WINDOWS\system32\drivers\ALCXSENS.SYS entry point in "init" section [0xB9772900]
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\services.exe[696] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00070000
.text C:\WINDOWS\system32\services.exe[696] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00070F8A
.text C:\WINDOWS\system32\services.exe[696] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00070089
.text C:\WINDOWS\system32\services.exe[696] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00070078
.text C:\WINDOWS\system32\services.exe[696] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00070FAF
.text C:\WINDOWS\system32\services.exe[696] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00070047
.text C:\WINDOWS\system32\services.exe[696] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 000700BA
.text C:\WINDOWS\system32\services.exe[696] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00070F68
.text C:\WINDOWS\system32\services.exe[696] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 000700E6
.text C:\WINDOWS\system32\services.exe[696] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00070F4D
.text C:\WINDOWS\system32\services.exe[696] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00070F28
.text C:\WINDOWS\system32\services.exe[696] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00070FC0
.text C:\WINDOWS\system32\services.exe[696] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00070011
.text C:\WINDOWS\system32\services.exe[696] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00070F79
.text C:\WINDOWS\system32\services.exe[696] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 0007002C
.text C:\WINDOWS\system32\services.exe[696] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00070FDB
.text C:\WINDOWS\system32\services.exe[696] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 000700CB
.text C:\WINDOWS\system32\services.exe[696] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00060FAF
.text C:\WINDOWS\system32\services.exe[696] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00060F72
.text C:\WINDOWS\system32\services.exe[696] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00060FCA
.text C:\WINDOWS\system32\services.exe[696] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00060000
.text C:\WINDOWS\system32\services.exe[696] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 0006002F
.text C:\WINDOWS\system32\services.exe[696] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00060FEF
.text C:\WINDOWS\system32\services.exe[696] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00060F8D
.text C:\WINDOWS\system32\services.exe[696] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00060F9E
.text C:\WINDOWS\system32\services.exe[696] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0005003D
.text C:\WINDOWS\system32\services.exe[696] msvcrt.dll!system 77C293C7 5 Bytes JMP 00050FB2
.text C:\WINDOWS\system32\services.exe[696] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00050FDE
.text C:\WINDOWS\system32\services.exe[696] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00050FEF
.text C:\WINDOWS\system32\services.exe[696] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00050FCD
.text C:\WINDOWS\system32\services.exe[696] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00050018
.text C:\WINDOWS\system32\services.exe[696] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00040FE5
.text C:\WINDOWS\system32\lsass.exe[708] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00DA0FE5
.text C:\WINDOWS\system32\lsass.exe[708] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00DA0F38
.text C:\WINDOWS\system32\lsass.exe[708] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00DA0F49
.text C:\WINDOWS\system32\lsass.exe[708] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00DA0F5A
.text C:\WINDOWS\system32\lsass.exe[708] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00DA0F75
.text C:\WINDOWS\system32\lsass.exe[708] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00DA0F97
.text C:\WINDOWS\system32\lsass.exe[708] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00DA0EFB
.text C:\WINDOWS\system32\lsass.exe[708] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00DA0F0C
.text C:\WINDOWS\system32\lsass.exe[708] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00DA008A
.text C:\WINDOWS\system32\lsass.exe[708] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00DA006F
.text C:\WINDOWS\system32\lsass.exe[708] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00DA00AF
.text C:\WINDOWS\system32\lsass.exe[708] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00DA0F86
.text C:\WINDOWS\system32\lsass.exe[708] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00DA0FCA
.text C:\WINDOWS\system32\lsass.exe[708] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00DA0F1D
.text C:\WINDOWS\system32\lsass.exe[708] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00DA0FA8
.text C:\WINDOWS\system32\lsass.exe[708] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00DA0FB9
.text C:\WINDOWS\system32\lsass.exe[708] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00DA0054
.text C:\WINDOWS\system32\lsass.exe[708] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00D90FC3
.text C:\WINDOWS\system32\lsass.exe[708] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00D90F97
.text C:\WINDOWS\system32\lsass.exe[708] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00D90FDE
.text C:\WINDOWS\system32\lsass.exe[708] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00D9000A
.text C:\WINDOWS\system32\lsass.exe[708] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00D9004A
.text C:\WINDOWS\system32\lsass.exe[708] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00D90FEF
.text C:\WINDOWS\system32\lsass.exe[708] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00D90039
.text C:\WINDOWS\system32\lsass.exe[708] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00D90FB2
.text C:\WINDOWS\system32\lsass.exe[708] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00D8002C
.text C:\WINDOWS\system32\lsass.exe[708] msvcrt.dll!system 77C293C7 5 Bytes JMP 00D80FA1
.text C:\WINDOWS\system32\lsass.exe[708] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00D80011
.text C:\WINDOWS\system32\lsass.exe[708] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00D80FEF
.text C:\WINDOWS\system32\lsass.exe[708] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00D80FBC
.text C:\WINDOWS\system32\lsass.exe[708] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00D80000
.text C:\WINDOWS\system32\lsass.exe[708] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00B80FEF
.text C:\WINDOWS\system32\svchost.exe[872] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00870000
.text C:\WINDOWS\system32\svchost.exe[872] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 0087009D
.text C:\WINDOWS\system32\svchost.exe[872] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00870F9E
.text C:\WINDOWS\system32\svchost.exe[872] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 0087006C
.text C:\WINDOWS\system32\svchost.exe[872] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00870FAF
.text C:\WINDOWS\system32\svchost.exe[872] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00870047
.text C:\WINDOWS\system32\svchost.exe[872] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 008700C9
.text C:\WINDOWS\system32\svchost.exe[872] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00870F81
.text C:\WINDOWS\system32\svchost.exe[872] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00870113
.text C:\WINDOWS\system32\svchost.exe[872] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 008700F8
.text C:\WINDOWS\system32\svchost.exe[872] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00870F5F
.text C:\WINDOWS\system32\svchost.exe[872] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00870FC0
.text C:\WINDOWS\system32\svchost.exe[872] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00870011
.text C:\WINDOWS\system32\svchost.exe[872] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 008700B8
.text C:\WINDOWS\system32\svchost.exe[872] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00870FDB
.text C:\WINDOWS\system32\svchost.exe[872] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 0087002C
.text C:\WINDOWS\system32\svchost.exe[872] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00870F70
.text C:\WINDOWS\system32\svchost.exe[872] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00860FE5
.text C:\WINDOWS\system32\svchost.exe[872] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00860F9E
.text C:\WINDOWS\system32\svchost.exe[872] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 0086002C
.text C:\WINDOWS\system32\svchost.exe[872] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 0086001B
.text C:\WINDOWS\system32\svchost.exe[872] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00860051
.text C:\WINDOWS\system32\svchost.exe[872] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 0086000A
.text C:\WINDOWS\system32\svchost.exe[872] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00860FB9
.text C:\WINDOWS\system32\svchost.exe[872] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00860FCA
.text C:\WINDOWS\system32\svchost.exe[872] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0085005A
.text C:\WINDOWS\system32\svchost.exe[872] msvcrt.dll!system 77C293C7 5 Bytes JMP 00850049
.text C:\WINDOWS\system32\svchost.exe[872] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0085002E
.text C:\WINDOWS\system32\svchost.exe[872] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00850000
.text C:\WINDOWS\system32\svchost.exe[872] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00850FD9
.text C:\WINDOWS\system32\svchost.exe[872] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00850011
.text C:\WINDOWS\system32\svchost.exe[872] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00840FEF
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00980FEF
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00980F72
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00980F83
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00980051
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00980040
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00980FA8
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 0098008E
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00980F46
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00980F06
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00980F17
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00980EEB
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 0098002F
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00980FD4
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00980F57
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00980FC3
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 0098000A
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 0098009F
.text C:\WINDOWS\system32\svchost.exe[940] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 0097002F
.text C:\WINDOWS\system32\svchost.exe[940] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00970F8D
.text C:\WINDOWS\system32\svchost.exe[940] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 0097001E
.text C:\WINDOWS\system32\svchost.exe[940] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00970FDE
.text C:\WINDOWS\system32\svchost.exe[940] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00970F9E
.text C:\WINDOWS\system32\svchost.exe[940] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00970FEF
.text C:\WINDOWS\system32\svchost.exe[940] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00970FB9
.text C:\WINDOWS\system32\svchost.exe[940] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00970040
.text C:\WINDOWS\system32\svchost.exe[940] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00960FB2
.text C:\WINDOWS\system32\svchost.exe[940] msvcrt.dll!system 77C293C7 5 Bytes JMP 00960FC3
.text C:\WINDOWS\system32\svchost.exe[940] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00960FEF
.text C:\WINDOWS\system32\svchost.exe[940] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0096000C
.text C:\WINDOWS\system32\svchost.exe[940] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00960FD4
.text C:\WINDOWS\system32\svchost.exe[940] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0096001D
.text C:\WINDOWS\system32\svchost.exe[940] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00950FEF
.text C:\WINDOWS\System32\svchost.exe[1064] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 03B00000
.text C:\WINDOWS\System32\svchost.exe[1064] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 03B000A7
.text C:\WINDOWS\System32\svchost.exe[1064] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 03B00FA8
.text C:\WINDOWS\System32\svchost.exe[1064] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 03B00080
.text C:\WINDOWS\System32\svchost.exe[1064] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 03B00FC3
.text C:\WINDOWS\System32\svchost.exe[1064] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 03B0004A
.text C:\WINDOWS\System32\svchost.exe[1064] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 03B00F97
.text C:\WINDOWS\System32\svchost.exe[1064] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 03B000D3
.text C:\WINDOWS\System32\svchost.exe[1064] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 03B00F46
.text C:\WINDOWS\System32\svchost.exe[1064] kernel32.dll!CreateProcessA 7C802367 1 Byte [E9]
.text C:\WINDOWS\System32\svchost.exe[1064] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 03B00F6B
.text C:\WINDOWS\System32\svchost.exe[1064] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 03B000FA
.text C:\WINDOWS\System32\svchost.exe[1064] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 03B0005B
.text C:\WINDOWS\System32\svchost.exe[1064] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 03B00FEF
.text C:\WINDOWS\System32\svchost.exe[1064] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 03B000B8
.text C:\WINDOWS\System32\svchost.exe[1064] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 03B00FDE
.text C:\WINDOWS\System32\svchost.exe[1064] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 03B00025
.text C:\WINDOWS\System32\svchost.exe[1064] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 03B00F86
.text C:\WINDOWS\System32\svchost.exe[1064] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 03AF0FA8
.text C:\WINDOWS\System32\svchost.exe[1064] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 03AF0040
.text C:\WINDOWS\System32\svchost.exe[1064] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 03AF0FB9
.text C:\WINDOWS\System32\svchost.exe[1064] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 03AF0FD4
.text C:\WINDOWS\System32\svchost.exe[1064] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 03AF0F83
.text C:\WINDOWS\System32\svchost.exe[1064] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 03AF0FEF
.text C:\WINDOWS\System32\svchost.exe[1064] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 03AF0025
.text C:\WINDOWS\System32\svchost.exe[1064] ADVAPI32.dll!RegCreateKeyA 77DE4706 1 Byte [E9]
.text C:\WINDOWS\System32\svchost.exe[1064] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 03AF000A
.text C:\WINDOWS\System32\svchost.exe[1064] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 03AE002F
.text C:\WINDOWS\System32\svchost.exe[1064] msvcrt.dll!system 77C293C7 5 Bytes JMP 03AE0014
.text C:\WINDOWS\System32\svchost.exe[1064] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 03AE0FB5
.text C:\WINDOWS\System32\svchost.exe[1064] msvcrt.dll!_open 77C2F566 5 Bytes JMP 03AE0FE3
.text C:\WINDOWS\System32\svchost.exe[1064] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 03AE0FA4
.text C:\WINDOWS\System32\svchost.exe[1064] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 03AE0FD2
.text C:\WINDOWS\System32\svchost.exe[1064] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 03AD0000
.text C:\WINDOWS\System32\svchost.exe[1064] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 03AC0FEF
.text C:\WINDOWS\System32\svchost.exe[1064] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 03AC0FD4
.text C:\WINDOWS\System32\svchost.exe[1064] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 03AC000A
.text C:\WINDOWS\System32\svchost.exe[1064] WININET.dll!InternetOpenUrlW 3D9A6DDF 5 Bytes JMP 03AC0FB9
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00640FE5
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00640087
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00640F92
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00640FA3
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 0064006C
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00640FCA
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 006400C9
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00640F77
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00640F5C
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 006400F5
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00640110
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00640051
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00640000
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 006400A2
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 0064002C
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00640011
.text C:\WINDOWS\system32\svchost.exe[1108] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 006400DA
.text C:\WINDOWS\system32\svchost.exe[1108] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00630FC0
.text C:\WINDOWS\system32\svchost.exe[1108] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 0063006C
.text C:\WINDOWS\system32\svchost.exe[1108] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00630FD1
.text C:\WINDOWS\system32\svchost.exe[1108] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00630011
.text C:\WINDOWS\system32\svchost.exe[1108] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00630051
.text C:\WINDOWS\system32\svchost.exe[1108] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00630000
.text C:\WINDOWS\system32\svchost.exe[1108] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00630FAF
.text C:\WINDOWS\system32\svchost.exe[1108] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 0063002C
.text C:\WINDOWS\system32\svchost.exe[1108] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00620F86
.text C:\WINDOWS\system32\svchost.exe[1108] msvcrt.dll!system 77C293C7 5 Bytes JMP 0062001B
.text C:\WINDOWS\system32\svchost.exe[1108] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00620FBC
.text C:\WINDOWS\system32\svchost.exe[1108] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00620FEF
.text C:\WINDOWS\system32\svchost.exe[1108] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00620FAB
.text C:\WINDOWS\system32\svchost.exe[1108] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00620000
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00970000
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00970062
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00970051
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00970F79
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00970F8A
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00970011
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00970F4B
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00970093
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00970F29
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 009700B8
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00970F0E
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00970022
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00970FE5
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00970F5C
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00970FA5
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00970FCA
.text C:\WINDOWS\System32\svchost.exe[1176] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00970F3A
.text C:\WINDOWS\System32\svchost.exe[1176] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00960036
.text C:\WINDOWS\System32\svchost.exe[1176] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00960FA5
.text C:\WINDOWS\System32\svchost.exe[1176] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00960025
.text C:\WINDOWS\System32\svchost.exe[1176] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00960000
.text C:\WINDOWS\System32\svchost.exe[1176] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00960FB6
.text C:\WINDOWS\System32\svchost.exe[1176] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00960FEF
.text C:\WINDOWS\System32\svchost.exe[1176] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00960062
.text C:\WINDOWS\System32\svchost.exe[1176] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00960047
.text C:\WINDOWS\System32\svchost.exe[1176] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00950FDE
.text C:\WINDOWS\System32\svchost.exe[1176] msvcrt.dll!system 77C293C7 5 Bytes JMP 00950069
.text C:\WINDOWS\System32\svchost.exe[1176] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0095003A
.text C:\WINDOWS\System32\svchost.exe[1176] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00950000
.text C:\WINDOWS\System32\svchost.exe[1176] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00950FEF
.text C:\WINDOWS\System32\svchost.exe[1176] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00950029
.text C:\WINDOWS\System32\svchost.exe[1176] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00940FE5
.text C:\WINDOWS\System32\svchost.exe[1224] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00CD0000
.text C:\WINDOWS\System32\svchost.exe[1224] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00CD009D
.text C:\WINDOWS\System32\svchost.exe[1224] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00CD0FA8
.text C:\WINDOWS\System32\svchost.exe[1224] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00CD0082
.text C:\WINDOWS\System32\svchost.exe[1224] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00CD0FC3
.text C:\WINDOWS\System32\svchost.exe[1224] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00CD0FE5
.text C:\WINDOWS\System32\svchost.exe[1224] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00CD0F7C
.text C:\WINDOWS\System32\svchost.exe[1224] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00CD0F8D
.text C:\WINDOWS\System32\svchost.exe[1224] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00CD0F6B
.text C:\WINDOWS\System32\svchost.exe[1224] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00CD00FA
.text C:\WINDOWS\System32\svchost.exe[1224] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00CD0F46
.text C:\WINDOWS\System32\svchost.exe[1224] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00CD0FD4
.text C:\WINDOWS\System32\svchost.exe[1224] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00CD001B
.text C:\WINDOWS\System32\svchost.exe[1224] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00CD00AE
.text C:\WINDOWS\System32\svchost.exe[1224] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00CD0047
.text C:\WINDOWS\System32\svchost.exe[1224] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00CD002C
.text C:\WINDOWS\System32\svchost.exe[1224] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00CD00E9
.text C:\WINDOWS\System32\svchost.exe[1224] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00CC001B
.text C:\WINDOWS\System32\svchost.exe[1224] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00CC0073
.text C:\WINDOWS\System32\svchost.exe[1224] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00CC0FD4
.text C:\WINDOWS\System32\svchost.exe[1224] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00CC0FE5
.text C:\WINDOWS\System32\svchost.exe[1224] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00CC0062
.text C:\WINDOWS\System32\svchost.exe[1224] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00CC000A
.text C:\WINDOWS\System32\svchost.exe[1224] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00CC0047
.text C:\WINDOWS\System32\svchost.exe[1224] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00CC0036
.text C:\WINDOWS\System32\svchost.exe[1224] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00CB0F8D
.text C:\WINDOWS\System32\svchost.exe[1224] msvcrt.dll!system 77C293C7 5 Bytes JMP 00CB0FB2
.text C:\WINDOWS\System32\svchost.exe[1224] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00CB0011
.text C:\WINDOWS\System32\svchost.exe[1224] msvcrt.dll!_open 77C2F566 3 Bytes JMP 00CB0FE3
.text C:\WINDOWS\System32\svchost.exe[1224] msvcrt.dll!_open + 4 77C2F56A 1 Byte [89]
.text C:\WINDOWS\System32\svchost.exe[1224] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00CB0022
.text C:\WINDOWS\System32\svchost.exe[1224] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00CB0000
.text C:\WINDOWS\System32\svchost.exe[1224] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00CA0000
.text C:\WINDOWS\System32\svchost.exe[1500] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00930FEF
.text C:\WINDOWS\System32\svchost.exe[1500] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00930047
.text C:\WINDOWS\System32\svchost.exe[1500] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00930F52
.text C:\WINDOWS\System32\svchost.exe[1500] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00930F6F
.text C:\WINDOWS\System32\svchost.exe[1500] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 0093002C
.text C:\WINDOWS\System32\svchost.exe[1500] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00930F8A
.text C:\WINDOWS\System32\svchost.exe[1500] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00930084
.text C:\WINDOWS\System32\svchost.exe[1500] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00930073
.text C:\WINDOWS\System32\svchost.exe[1500] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00930EF2
.text C:\WINDOWS\System32\svchost.exe[1500] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00930095
.text C:\WINDOWS\System32\svchost.exe[1500] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00930EE1
.text C:\WINDOWS\System32\svchost.exe[1500] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00930011
.text C:\WINDOWS\System32\svchost.exe[1500] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00930FD4
.text C:\WINDOWS\System32\svchost.exe[1500] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00930062
.text C:\WINDOWS\System32\svchost.exe[1500] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00930FA5
.text C:\WINDOWS\System32\svchost.exe[1500] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00930000
.text C:\WINDOWS\System32\svchost.exe[1500] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00930F21
.text C:\WINDOWS\System32\svchost.exe[1500] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00920FD4
.text C:\WINDOWS\System32\svchost.exe[1500] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00920F79
.text C:\WINDOWS\System32\svchost.exe[1500] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00920FEF
.text C:\WINDOWS\System32\svchost.exe[1500] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00920025
.text C:\WINDOWS\System32\svchost.exe[1500] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00920F94
.text C:\WINDOWS\System32\svchost.exe[1500] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 0092000A
.text C:\WINDOWS\System32\svchost.exe[1500] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00920036
.text C:\WINDOWS\System32\svchost.exe[1500] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00920FAF
.text C:\WINDOWS\System32\svchost.exe[1500] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00910FA4
.text C:\WINDOWS\System32\svchost.exe[1500] msvcrt.dll!system 77C293C7 5 Bytes JMP 0091002F
.text C:\WINDOWS\System32\svchost.exe[1500] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00910FB5
.text C:\WINDOWS\System32\svchost.exe[1500] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00910FE3
.text C:\WINDOWS\System32\svchost.exe[1500] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0091000A
.text C:\WINDOWS\System32\svchost.exe[1500] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00910FC6
.text C:\WINDOWS\System32\svchost.exe[1620] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00900FEF
.text C:\WINDOWS\System32\svchost.exe[1620] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 009000BF
.text C:\WINDOWS\System32\svchost.exe[1620] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 009000A4
.text C:\WINDOWS\System32\svchost.exe[1620] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00900FCA
.text C:\WINDOWS\System32\svchost.exe[1620] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00900087
.text C:\WINDOWS\System32\svchost.exe[1620] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 0090005B
.text C:\WINDOWS\System32\svchost.exe[1620] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00900F81
.text C:\WINDOWS\System32\svchost.exe[1620] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00900F92
.text C:\WINDOWS\System32\svchost.exe[1620] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 009000EE
.text C:\WINDOWS\System32\svchost.exe[1620] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00900F55
.text C:\WINDOWS\System32\svchost.exe[1620] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 009000FF
.text C:\WINDOWS\System32\svchost.exe[1620] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 0090006C
.text C:\WINDOWS\System32\svchost.exe[1620] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00900014
.text C:\WINDOWS\System32\svchost.exe[1620] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00900FAF
.text C:\WINDOWS\System32\svchost.exe[1620] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00900040
.text C:\WINDOWS\System32\svchost.exe[1620] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00900025
.text C:\WINDOWS\System32\svchost.exe[1620] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00900F70
.text C:\WINDOWS\System32\svchost.exe[1620] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00650FDE
.text C:\WINDOWS\System32\svchost.exe[1620] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 0065004A
.text C:\WINDOWS\System32\svchost.exe[1620] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00650FEF
.text C:\WINDOWS\System32\svchost.exe[1620] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00650025
.text C:\WINDOWS\System32\svchost.exe[1620] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00650F8D
.text C:\WINDOWS\System32\svchost.exe[1620] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00650000
.text C:\WINDOWS\System32\svchost.exe[1620] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00650FA8
.text C:\WINDOWS\System32\svchost.exe[1620] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00650FC3
.text C:\WINDOWS\System32\svchost.exe[1620] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00640FB2
.text C:\WINDOWS\System32\svchost.exe[1620] msvcrt.dll!system 77C293C7 5 Bytes JMP 0064003D
.text C:\WINDOWS\System32\svchost.exe[1620] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00640FD7
.text C:\WINDOWS\System32\svchost.exe[1620] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00640000
.text C:\WINDOWS\System32\svchost.exe[1620] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00640022
.text C:\WINDOWS\System32\svchost.exe[1620] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00640011
.text C:\WINDOWS\System32\svchost.exe[1620] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 0062000A
.text C:\WINDOWS\System32\svchost.exe[1620] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 00620025
.text C:\WINDOWS\System32\svchost.exe[1620] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 00620036
.text C:\WINDOWS\System32\svchost.exe[1620] WININET.dll!InternetOpenUrlW 3D9A6DDF 5 Bytes JMP 00620FEF
.text C:\WINDOWS\System32\svchost.exe[1620] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00630FEF
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00DC0FE5
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00DC0F57
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00DC0F68
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00DC0036
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00DC0025
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00DC0F9E
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00DC0087
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00DC0F35
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00DC0F09
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00DC0F1A
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00DC00B3
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00DC0F8D
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00DC0000
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00DC0F46
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00DC0FAF
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00DC0FCA
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00DC0098
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00DA0FA6
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] msvcrt.dll!system 77C293C7 5 Bytes JMP 00DA0FB7
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00DA0FE3
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00DA000C
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00DA0FD2
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00DA001D
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00DB0FE5
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00DB006C
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] ADVAPI32.dll!RegOpenKeyExA 77DD7832 1 Byte [E9]
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00DB0036
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00DB0025
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00DB0FAF
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00DB000A
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00DB0051
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00DB0FD4
.text C:\WINDOWS\System32\inetsrv\inetinfo.exe[1676] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00D90000
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[1920] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 0041C130 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[1920] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 0041C1B0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\Explorer.EXE[2264] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 001A0FEF
.text C:\WINDOWS\Explorer.EXE[2264] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001A0F55
.text C:\WINDOWS\Explorer.EXE[2264] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 001A0F66
.text C:\WINDOWS\Explorer.EXE[2264] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 001A0040
.text C:\WINDOWS\Explorer.EXE[2264] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 001A002F
.text C:\WINDOWS\Explorer.EXE[2264] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 001A0FA8
.text C:\WINDOWS\Explorer.EXE[2264] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 001A0F13
.text C:\WINDOWS\Explorer.EXE[2264] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 001A005B
.text C:\WINDOWS\Explorer.EXE[2264] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001A009B
.text C:\WINDOWS\Explorer.EXE[2264] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 001A008A
.text C:\WINDOWS\Explorer.EXE[2264] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 001A00B6
.text C:\WINDOWS\Explorer.EXE[2264] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 001A0F97
.text C:\WINDOWS\Explorer.EXE[2264] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 001A0FDE
.text C:\WINDOWS\Explorer.EXE[2264] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 001A0F30
.text C:\WINDOWS\Explorer.EXE[2264] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 001A0014
.text C:\WINDOWS\Explorer.EXE[2264] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 001A0FC3
.text C:\WINDOWS\Explorer.EXE[2264] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 001A0F02
.text C:\WINDOWS\Explorer.EXE[2264] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00280FB9
.text C:\WINDOWS\Explorer.EXE[2264] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00280051
.text C:\WINDOWS\Explorer.EXE[2264] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 0028000A
.text C:\WINDOWS\Explorer.EXE[2264] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00280FD4
.text C:\WINDOWS\Explorer.EXE[2264] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00280036
.text C:\WINDOWS\Explorer.EXE[2264] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00280FEF
.text C:\WINDOWS\Explorer.EXE[2264] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 0028001B
.text C:\WINDOWS\Explorer.EXE[2264] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00280F94
.text C:\WINDOWS\Explorer.EXE[2264] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0029003D
.text C:\WINDOWS\Explorer.EXE[2264] msvcrt.dll!system 77C293C7 5 Bytes JMP 00290FB2
.text C:\WINDOWS\Explorer.EXE[2264] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00290011
.text C:\WINDOWS\Explorer.EXE[2264] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00290000
.text C:\WINDOWS\Explorer.EXE[2264] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00290022
.text C:\WINDOWS\Explorer.EXE[2264] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00290FD7
.text C:\WINDOWS\Explorer.EXE[2264] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 002B0FEF
.text C:\WINDOWS\Explorer.EXE[2264] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 002B0FDE
.text C:\WINDOWS\Explorer.EXE[2264] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 002B0FC3
.text C:\WINDOWS\Explorer.EXE[2264] WININET.dll!InternetOpenUrlW 3D9A6DDF 5 Bytes JMP 002B0014
.text C:\WINDOWS\Explorer.EXE[2264] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 02410FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00260FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00260F77
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 0026006C
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 0026005B
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00260F9E
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 0026002F
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 0026009B
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00260F49
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00260F1D
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 002600B6
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00260F0C
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00260040
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00260FD4
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00260F66
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00260014
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00260FC3
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00260F38
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00340FBC
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 0034004D
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00340FCD
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00340FDE
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00340F86
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00340FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00340028
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00340FA1
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] USER32.dll!UnhookWindowsHookEx 7E41F21E 5 Bytes JMP 3E25467C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] USER32.dll!CallNextHookEx 7E41F85B 5 Bytes JMP 3E2DD0ED C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] USER32.dll!CreateWindowExW 7E41FC25 5 Bytes JMP 3E2EDB1C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] USER32.dll!DialogBoxParamW 7E42555F 5 Bytes JMP 3E2154C5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] USER32.dll!SetWindowsHookExW 7E42DDB5 5 Bytes JMP 3E2E9AC9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] USER32.dll!DialogBoxIndirectParamW 7E432032 5 Bytes JMP 3E3E480F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] USER32.dll!MessageBoxIndirectA 7E43A04A 5 Bytes JMP 3E3E4741 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] USER32.dll!DialogBoxParamA 7E43B10C 5 Bytes JMP 3E3E47AC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] USER32.dll!MessageBoxExW 7E4505D8 5 Bytes JMP 3E3E4612 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] USER32.dll!MessageBoxExA 7E4505FC 5 Bytes JMP 3E3E4674 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] USER32.dll!DialogBoxIndirectParamA 7E456B50 5 Bytes JMP 3E3E4872 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 3E3E46D6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0035004C
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] msvcrt.dll!system 77C293C7 5 Bytes JMP 00350027
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00350FC1
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00350FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00350016
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00350FD2
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] ole32.dll!CoCreateInstance 774FFAC3 5 Bytes JMP 3E2EDB78 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] ole32.dll!OleLoadFromStream 7752A257 5 Bytes JMP 3E3E4B77 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 01A2000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 01A20FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 01A20FDE
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] WININET.dll!InternetOpenUrlW 3D9A6DDF 5 Bytes JMP 01A2002F
.text C:\Program Files\Internet Explorer\iexplore.exe[3288] ws2_32.dll!socket 71AB3B91 5 Bytes JMP 02630FEF
.text C:\WINDOWS\System32\svchost.exe[3744] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00C90FE5
.text C:\WINDOWS\System32\svchost.exe[3744] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00C90F55
.text C:\WINDOWS\System32\svchost.exe[3744] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00C90F66
.text C:\WINDOWS\System32\svchost.exe[3744] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00C90F77
.text C:\WINDOWS\System32\svchost.exe[3744] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00C90F9E
.text C:\WINDOWS\System32\svchost.exe[3744] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00C90FCA
.text C:\WINDOWS\System32\svchost.exe[3744] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00C90F1F
.text C:\WINDOWS\System32\svchost.exe[3744] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00C90067
.text C:\WINDOWS\System32\svchost.exe[3744] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00C9009D
.text C:\WINDOWS\System32\svchost.exe[3744] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00C90F04
.text C:\WINDOWS\System32\svchost.exe[3744] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00C90EE9
.text C:\WINDOWS\System32\svchost.exe[3744] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00C90FAF
.text C:\WINDOWS\System32\svchost.exe[3744] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00C9000A
.text C:\WINDOWS\System32\svchost.exe[3744] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00C90F3A
.text C:\WINDOWS\System32\svchost.exe[3744] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00C90036
.text C:\WINDOWS\System32\svchost.exe[3744] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00C90025
.text C:\WINDOWS\System32\svchost.exe[3744] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00C90082
.text C:\WINDOWS\System32\svchost.exe[3744] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00C80025
.text C:\WINDOWS\System32\svchost.exe[3744] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00C80FA8
.text C:\WINDOWS\System32\svchost.exe[3744] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00C80014
.text C:\WINDOWS\System32\svchost.exe[3744] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00C80FD4
.text C:\WINDOWS\System32\svchost.exe[3744] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00C8005B
.text C:\WINDOWS\System32\svchost.exe[3744] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00C80FE5
.text C:\WINDOWS\System32\svchost.exe[3744] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00C80FB9
.text C:\WINDOWS\System32\svchost.exe[3744] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00C80036
.text C:\WINDOWS\System32\svchost.exe[3744] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00C70044
.text C:\WINDOWS\System32\svchost.exe[3744] msvcrt.dll!system 77C293C7 5 Bytes JMP 00C70FB9
.text C:\WINDOWS\System32\svchost.exe[3744] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00C70033
.text C:\WINDOWS\System32\svchost.exe[3744] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00C7000C
.text C:\WINDOWS\System32\svchost.exe[3744] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00C70FD4
.text C:\WINDOWS\System32\svchost.exe[3744] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00C70FEF
.text C:\WINDOWS\System32\svchost.exe[3744] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00C60FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00260FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 002600AB
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 0026009A
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 0026007D
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 0026006C
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00260040
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 002600E3
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00260F91
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00260F65
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00260F76
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00260F4A
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00260051
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00260014
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 002600BC
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00260FDE
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 0026002F
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 002600F4
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00340FCA
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00340076
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 0034001B
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00340FE5
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00340065
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00340000
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 0034004A
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00340FB9
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!UnhookWindowsHookEx 7E41F21E 5 Bytes JMP 3E25467C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!CallNextHookEx 7E41F85B 5 Bytes JMP 3E2DD0ED C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!CreateWindowExW 7E41FC25 5 Bytes JMP 3E2EDB1C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!DialogBoxParamW 7E42555F 5 Bytes JMP 3E2154C5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!SetWindowsHookExW 7E42DDB5 5 Bytes JMP 3E2E9AC9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!DialogBoxIndirectParamW 7E432032 5 Bytes JMP 3E3E480F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!MessageBoxIndirectA 7E43A04A 5 Bytes JMP 3E3E4741 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!DialogBoxParamA 7E43B10C 5 Bytes JMP 3E3E47AC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!MessageBoxExW 7E4505D8 5 Bytes JMP 3E3E4612 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!MessageBoxExA 7E4505FC 5 Bytes JMP 3E3E4674 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!DialogBoxIndirectParamA 7E456B50 5 Bytes JMP 3E3E4872 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 3E3E46D6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00350FB2
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] msvcrt.dll!system 77C293C7 5 Bytes JMP 00350FC3
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00350FDE
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00350FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00350033
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0035000C
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] ole32.dll!CoCreateInstance 774FFAC3 5 Bytes JMP 3E2EDB78 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] ole32.dll!OleLoadFromStream 7752A257 5 Bytes JMP 3E3E4B77 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 01700000
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 01700FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 01700FDE
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] WININET.dll!InternetOpenUrlW 3D9A6DDF 5 Bytes JMP 0170002F
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] ws2_32.dll!socket 71AB3B91 5 Bytes JMP 02620FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 0026000A
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00260F6D
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00260062
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00260051
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00260040
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00260FB9
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 002600A4
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00260093
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 002600EE
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 002600D3
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 002600FF
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00260F9E
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00260025
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00260F5C
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00260FD4
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00260FE5
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00260F4B
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 00340FD4
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00340076
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00340025
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 0034000A
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 00340065
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00340FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00340FB9
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00340040
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] USER32.dll!CreateWindowExW 7E41FC25 5 Bytes JMP 3E2EDB1C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] USER32.dll!DialogBoxParamW 7E42555F 5 Bytes JMP 3E2154C5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] USER32.dll!DialogBoxIndirectParamW 7E432032 5 Bytes JMP 3E3E480F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] USER32.dll!MessageBoxIndirectA 7E43A04A 5 Bytes JMP 3E3E4741 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] USER32.dll!DialogBoxParamA 7E43B10C 5 Bytes JMP 3E3E47AC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] USER32.dll!MessageBoxExW 7E4505D8 5 Bytes JMP 3E3E4612 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] USER32.dll!MessageBoxExA 7E4505FC 5 Bytes JMP 3E3E4674 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] USER32.dll!DialogBoxIndirectParamA 7E456B50 5 Bytes JMP 3E3E4872 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 3E3E46D6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00350053
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] msvcrt.dll!system 77C293C7 5 Bytes JMP 00350FBE
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00350027
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00350FE3
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00350038
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00350000
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 00A50FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 00A50014
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 00A5002F
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] WININET.dll!InternetOpenUrlW 3D9A6DDF 5 Bytes JMP 00A50FD4
.text C:\Program Files\Internet Explorer\iexplore.exe[5208] ws2_32.dll!socket 71AB3B91 5 Bytes JMP 00A80FE5
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00260FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00260F35
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00260F50
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00260F61
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00260014
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00260F97
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00260F09
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00260051
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00260EDD
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 0026006C
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] kernel32.dll!GetProcAddress 7C80ADB0 5 Bytes JMP 00260EC2
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] kernel32.dll!LoadLibraryW 7C80AE5B 5 Bytes JMP 00260F7C
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] kernel32.dll!CreateFileW 7C810770 5 Bytes JMP 00260FD4
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] kernel32.dll!CreatePipe 7C81E0D7 5 Bytes JMP 00260F24
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] kernel32.dll!CreateNamedPipeW 7C82F0EF 5 Bytes JMP 00260FA8
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] kernel32.dll!CreateNamedPipeA 7C85FE94 5 Bytes JMP 00260FB9
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] kernel32.dll!WinExec 7C86158D 5 Bytes JMP 00260EEE
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] ADVAPI32.dll!RegOpenKeyExW 77DD6A8F 5 Bytes JMP 0034001B
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] ADVAPI32.dll!RegCreateKeyExW 77DD774C 5 Bytes JMP 00340FAF
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] ADVAPI32.dll!RegOpenKeyExA 77DD7832 5 Bytes JMP 00340FCA
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] ADVAPI32.dll!RegOpenKeyW 77DD7926 5 Bytes JMP 00340000
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] ADVAPI32.dll!RegCreateKeyExA 77DDE834 5 Bytes JMP 0034006C
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] ADVAPI32.dll!RegOpenKeyA 77DDEE08 5 Bytes JMP 00340FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] ADVAPI32.dll!RegCreateKeyW 77DE45EE 5 Bytes JMP 00340051
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] ADVAPI32.dll!RegCreateKeyA 77DE4706 5 Bytes JMP 00340036
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] USER32.dll!UnhookWindowsHookEx 7E41F21E 5 Bytes JMP 3E25467C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] USER32.dll!CallNextHookEx 7E41F85B 5 Bytes JMP 3E2DD0ED C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] USER32.dll!CreateWindowExW 7E41FC25 5 Bytes JMP 3E2EDB1C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] USER32.dll!DialogBoxParamW 7E42555F 5 Bytes JMP 3E2154C5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] USER32.dll!SetWindowsHookExW 7E42DDB5 5 Bytes JMP 3E2E9AC9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] USER32.dll!DialogBoxIndirectParamW 7E432032 5 Bytes JMP 3E3E480F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] USER32.dll!MessageBoxIndirectA 7E43A04A 5 Bytes JMP 3E3E4741 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] USER32.dll!DialogBoxParamA 7E43B10C 5 Bytes JMP 3E3E47AC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] USER32.dll!MessageBoxExW 7E4505D8 5 Bytes JMP 3E3E4612 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] USER32.dll!MessageBoxExA 7E4505FC 5 Bytes JMP 3E3E4674 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] USER32.dll!DialogBoxIndirectParamA 7E456B50 5 Bytes JMP 3E3E4872 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 3E3E46D6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0035004E
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] msvcrt.dll!system 77C293C7 5 Bytes JMP 00350FC3
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00350022
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00350000
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0035003D
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00350011
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] ole32.dll!CoCreateInstance 774FFAC3 5 Bytes JMP 3E2EDB78 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] ole32.dll!OleLoadFromStream 7752A257 5 Bytes JMP 3E3E4B77 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 01710FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 0171000A
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 01710FD4
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] WININET.dll!InternetOpenUrlW 3D9A6DDF 5 Bytes JMP 0171001B
.text C:\Program Files\Internet Explorer\iexplore.exe[5216] ws2_32.dll!socket 71AB3B91 5 Bytes JMP 02630FEF
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Internet Explorer\iexplore.exe[3288] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [451F1ACB] C:\Program Files\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3968] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [451F1ACB] C:\Program Files\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[5216] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [451F1ACB] C:\Program Files\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.)
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
Device pci.sys (NT Plug and Play PCI Enumerator/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
Device ACPI.sys (ACPI Driver for NT/Microsoft Corporation)
Device AnyDVD.sys (Watch & copy any DVD!/SlySoft, Inc.)
Device \Driver\atapi \Device\Ide\IdePort0 AnyDVD.sys (Watch & copy any DVD!/SlySoft, Inc.)
Device \Driver\atapi \Device\Ide\IdePort1 AnyDVD.sys (Watch & copy any DVD!/SlySoft, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \OptionalComponents\IMAIL@Installed 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \OptionalComponents\IMAIL@
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \OptionalComponents\MAPI@Installed 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \OptionalComponents\MAPI@NoChange 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \OptionalComponents\MAPI@
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \OptionalComponents\MSFS@Installed 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \OptionalComponents\MSFS@
---- EOF - GMER 1.0.15 ----
Please download ComboFix from Here or Here to your Desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop** Please, never rename Combofix unless instructed. Close any open browsers. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Very Important! Temporarily disable your anti-virus , script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results" . Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask. NOTE1. If Combofix asks you to install Recovery Console , please allow it. NOTE 2. If Combofix asks you to update the program, always do so . Close any open browsers. WARNING: Combofix will disconnect your machine from the Internet as soon as it starts Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished. If there is no internet connection after running Combofix, then restart your computer to restore back your connection. Double click on combofix.exe & follow the prompts. When finished, it will produce a report for you. Please post the "C:\ComboFix.txt" **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall** Make sure, you re-enable your security programs, when you're done with Combofix. DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
Before I run Combofix I wanted to ask something. It appears that the problem is already resolved. The Google search results do not redirect to other sites any more. Should I still Combofix? The PC appears to run okay as it is.
Also, how do I protect my PC from this again.
Thanks for your help!!! It's much appreciated.
OK, cleaning process, once started, has to be finished.
Please, run Combofix.
I'll post some advice about keeping your computer safer, at the end of this thread.
Here's the Combofix log in an attached .txt file.
Thanks! Attached Files