This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] lando trojan

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have run just about every scan I know about and I am still getting McAfee warning of Lando Trojan. I get the redirect that seems to be happening to others from search engines and my browsers close instanly now. I am at my whits end with this.

Sometimes it will be the lando virus, other times mcafee says it is the Generic!Artemis (Trojan) Both always show that it was blocked at C:\\WINDOWS|system32\setup_u.exe .

Any help would be greatly appreciated.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:06:14 PM, on 3/30/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\DOWNLO~1\MyWebEx\319\atnthost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\DOWNLO~1\MyWebEx\319\RAAGTAPP.EXE
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1061118
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msnbc.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1061118
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [eFax 4.3] "C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\3.19.0.16\PlaxoHelper_en.exe -a
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [PlaxoSysTray] C:\Program Files\Plaxo\3.19.0.16\PlaxoSysTray.exe
O4 - HKCU\..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\ApcMain.exe -m
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan
O4 - HKCU\..\Run: [DelayShred] c:\PROGRA~1\mcafee\mshr\ShrCL.EXE /P1 /q C:\WINDOWS\system32\wdmaud.SH!
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-21-687441275-498809504-2873672193-1011\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe (User 'QBDataServiceUser19')
O4 - HKUS\S-1-5-21-687441275-498809504-2873672193-1011\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup (User 'QBDataServiceUser19')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: eFax 4.3.lnk = C:\Program Files\eFax Messenger 4.3\J2GTray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Remote Access.LNK = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} (ContactExtractor Class) - http://www.facebook.com/controls/contactx.dll
O16 - DPF: {8AA1AE9E-9FB0-41B3-8911-89A1068A7FD1} (Installer Class) - https://www.wirelesssync.vzw.com/en/SyncInstall.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://qb.webex.com/client/v_mywebex-qb20/ra/ieatgpc.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: WebEx Remote Access Agent (atnthost) - WebEx Communications, Inc. - C:\WINDOWS\DOWNLO~1\MyWebEx\319\atnthost.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: QuickBooksDB19 - Intuit, Inc. - C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE (file missing)

–
End of file - 15305 bytes
Welcome to What The Tech! My name is Adam and I will be assisting you with getting the malware off of your computer. Please observe the following points before we start:
  • If at any point you don't understand something, please let me know and I will be glad to explain or go more into depth for you. :)
  • Please remember, I am a volunteer and I have a personal life. I go to school full time, have a part time job, and I do sports. A lot of this takes a lot of time.
  • Please keep all of your replies in this topic/thread and do not make a new topic/thread, thanks!
  • Please stick with this, don't stop responding because the symptoms are gone, the infection could still be there. Keep replying to my posts until I give you the All Clean message. ;)
  • If you don't reply within five days after my last instructions this topic will be closed. If you will not be able to reply within five days please tell me so the topic will not be closed.
  • Please do not run other tools to remove the malware unless I ask you to until I give you the all clean. They will just mess up my fixes and make things more complicated, not fix the problem.

Please Download and Run Malwarebytes' Anti-Malware

Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply.
  • If you accidently close it, the log file is saved here and will be named like this: C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

RSIT
  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<

In your next reply, please include:
  • MBAM log
  • Both RSIT logs

Regards,
Adam
Here are the logs…
Malwarebytes' Anti-Malware 1.34
Database version: 1893
Windows 5.1.2600 Service Pack 3

4/1/2009 9:09:41 AM
mbam-log-2009-04-01 (09-09-41).txt

Scan type: Full Scan (C:\|)
Objects scanned: 253757
Time elapsed: 1 hour(s), 30 minute(s), 13 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


_____________________

Logfile of random's system information tool 1.06 (written by random/random)
Run by [removed] at 2009-04-01 09:11:21
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 18 GB (34%) free of 54 GB
Total RAM: 1015 MB (41% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:12:23 AM, on 4/1/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\DOWNLO~1\MyWebEx\319\atnthost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\DOWNLO~1\MyWebEx\319\RAAGTAPP.EXE
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Program Files\eFax Messenger 4.3\J2GTray.exe
C:\Documents and Settings\John Balestrieri\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\John Balestrieri.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1061118
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msnbc.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1061118
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [eFax 4.3] "C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\3.19.0.16\PlaxoHelper_en.exe -a
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [PlaxoSysTray] C:\Program Files\Plaxo\3.19.0.16\PlaxoSysTray.exe
O4 - HKCU\..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\ApcMain.exe -m
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan
O4 - HKCU\..\Run: [DelayShred] c:\PROGRA~1\mcafee\mshr\ShrCL.EXE /P1 /q C:\WINDOWS\system32\wdmaud.SH!
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-21-687441275-498809504-2873672193-1011\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe (User 'QBDataServiceUser19')
O4 - HKUS\S-1-5-21-687441275-498809504-2873672193-1011\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup (User 'QBDataServiceUser19')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: eFax 4.3.lnk = C:\Program Files\eFax Messenger 4.3\J2GTray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Remote Access.LNK = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} (ContactExtractor Class) - http://www.facebook.com/controls/contactx.dll
O16 - DPF: {8AA1AE9E-9FB0-41B3-8911-89A1068A7FD1} (Installer Class) - https://www.wirelesssync.vzw.com/en/SyncInstall.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://qb.webex.com/client/v_mywebex-qb20/ra/ieatgpc.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: WebEx Remote Access Agent (atnthost) - WebEx Communications, Inc. - C:\WINDOWS\DOWNLO~1\MyWebEx\319\atnthost.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: QuickBooksDB19 - Intuit, Inc. - C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE (file missing)

–
End of file - 15306 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\McDefragTask.job
C:\WINDOWS\tasks\McQcTask.job
C:\WINDOWS\tasks\Norton Security Scan for John Balestrieri.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2008-10-16 322864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2008-02-01 1377576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB}]
McAfee Phishing Filter - c:\PROGRA~1\mcafee\msk\mskapbho.dll [2009-01-09 246800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
scriptproxy - C:\Program Files\McAfee\VirusScan\scriptsn.dll [2009-01-16 58688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee SiteAdvisor BHO - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2009-02-13 150032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-30 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-03-30 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2008-10-16 505136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - McAfee SiteAdvisor Toolbar - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2009-02-13 150032]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"=C:\WINDOWS\system32\igfxtray.exe [2005-10-14 94208]
"igfxhkcmd"=C:\WINDOWS\system32\hkcmd.exe [2005-10-14 77824]
"igfxpers"=C:\WINDOWS\system32\igfxpers.exe [2005-10-14 114688]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2006-03-08 761947]
"Broadcom Wireless Manager UI"=C:\WINDOWS\system32\WLTRAY.exe [2005-12-19 1347584]
"Dell QuickSet"=C:\Program Files\Dell\QuickSet\quickset.exe [2006-08-03 1032192]
"DVDLauncher"=C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe [2005-02-23 53248]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2006-09-11 218032]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2006-09-11 86960]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2007-01-01 185896]
"dla"=C:\WINDOWS\system32\dla\tfswctrl.exe [2005-05-31 122941]
"eFax 4.3"=C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe [2007-03-06 116224]
"dscactivate"=C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe [2007-11-15 16384]
"RoxWatchTray"=C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe [2007-03-26 228088]
"DellSupportCenter"=C:\Program Files\Dell Support Center\bin\sprtcmd.exe [2008-08-13 206064]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2008-11-04 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-11-20 290088]
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2008-11-07 111936]
"Intuit SyncManager"=C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe [2008-09-09 623880]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"mcagent_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2009-01-08 645328]
"MSConfig"=C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe [2008-04-13 169984]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-30 148888]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"=C:\Program Files\Dell Support\DSAgnt.exe [2006-08-28 395776]
"Yahoo! Pager"=C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [2007-07-16 4670704]
"PlaxoUpdate"=C:\Program Files\Plaxo\3.19.0.16\PlaxoHelper_en.exe [2009-02-09 371271]
"MsnMsgr"=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184]
"Aim6"=C:\Program Files\AIM6\aim6.exe [2008-10-31 50480]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"DellSupportCenter"=C:\Program Files\Dell Support Center\bin\sprtcmd.exe [2008-08-13 206064]
"ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-09-11 218032]
"PlaxoSysTray"=C:\Program Files\Plaxo\3.19.0.16\PlaxoSysTray.exe [2009-02-09 20480]
"Performance Center"=C:\Program Files\Ascentive\Performance Center\ApcMain.exe [2008-08-13 3244032]
"RegistryMechanic"=C:\Program Files\Registry Mechanic\RegMech.exe [2008-07-08 2828184]
"HijackThis startup scan"=C:\Program Files\Trend Micro\HijackThis\HijackThis.exe [2009-03-26 396288]
"DelayShred"=c:\PROGRA~1\mcafee\mshr\ShrCL.EXE [2009-01-09 113168]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
C:\WINDOWS\stsystra.exe [2006-03-25 282624]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe
eFax 4.3.lnk - C:\Program Files\eFax Messenger 4.3\J2GTray.exe
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
QuickBooks Remote Access.LNK - C:\WINDOWS\DOWNLO~1\MyWebEx\319\raagtx.exe
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe

C:\Documents and Settings\John Balestrieri\Start Menu\Programs\Startup
ERUNT AutoBackup.lnk - C:\Program Files\ERUNT\AUTOBACK.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2005-10-14 135168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mfehidk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mfehidk.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mferkdk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mferkdk.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mfetdik]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mfetdik.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfehidk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfehidk.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mferkdk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mferkdk.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfetdik]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfetdik.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe"="C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\America Online 9.0\waol.exe"="C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader"
"C:\Program Files\SmartFTP Client 2.0\SmartFTP.exe"="C:\Program Files\SmartFTP Client 2.0\SmartFTP.exe:*:Enabled:SmartFTP Client 2.0"
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe"="C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:*:Enabled:RoxioUPnPRenderer9"
"C:\Documents and Settings\John Balestrieri\Application Data\Facebook\facebook.exe"="C:\Documents and Settings\John Balestrieri\Application Data\Facebook\facebook.exe:127.0.0.1/255.255.255.255:Enabled:Facebook"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\AIM6\aim6.exe"="C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Intuit\QuickBooks 2009\QBDBMgrN.exe"="C:\Program Files\Intuit\QuickBooks 2009\QBDBMgrN.exe:*:Enabled:QuickBooks 2009 Data Manager"
"D:\setup\hpznui01.exe"="D:\setup\hpznui01.exe:*:Enabled:hpznui01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe"="C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe"="C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\America Online 9.0\waol.exe"="C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0"
"C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe"="C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe:*:Enabled:RoxioUPnPRenderer9"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"D:\setup\hpznui01.exe"="D:\setup\hpznui01.exe:*:Enabled:hpznui01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"

======File associations======

.js - open - "C:\Program Files\Adobe\Adobe Dreamweaver CS3\Dreamweaver.exe","%1"

======List of files/folders created in the last 2 months======

2009-04-01 09:11:21 —-D—- C:\rsit
2009-03-30 09:42:10 —-A—- C:\WINDOWS\system32\javaws.exe
2009-03-30 09:42:10 —-A—- C:\WINDOWS\system32\javaw.exe
2009-03-30 09:42:10 —-A—- C:\WINDOWS\system32\java.exe
2009-03-29 09:46:00 —-A—- C:\WINDOWS\system32\deploytk.dll
2009-03-29 09:28:49 —-A—- C:\Rooter.txt
2009-03-29 09:26:26 —-D—- C:\Rooter$
2009-03-29 09:24:12 —-D—- C:\WINDOWS\ERDNT
2009-03-29 09:23:39 —-D—- C:\Program Files\ERUNT
2009-03-28 12:59:10 —-D—- C:\Program Files\Spybot - Search & Destroy
2009-03-28 12:59:10 —-D—- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-28 12:36:23 —-D—- C:\32788R22FWJFW
2009-03-28 11:46:43 —-D—- C:\Program Files\CCleaner
2009-03-28 10:38:27 —-D—- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2009-03-28 10:38:04 —-D—- C:\Program Files\Security Task Manager
2009-03-28 07:44:44 —-A—- C:\WINDOWS\system32\MPFServiceFailureCount.txt
2009-03-26 16:46:02 —-D—- C:\Program Files\Panda Security
2009-03-26 14:49:17 —-D—- C:\Program Files\Trend Micro
2009-03-26 09:54:17 —-A—- C:\WINDOWS\system32\STKIT432.DLL
2009-03-26 09:53:56 —-D—- C:\Program Files\Registry Mechanic
2009-03-26 07:10:04 —-D—- C:\WINDOWS\pss
2009-03-25 11:03:06 —-D—- C:\Documents and Settings\John Balestrieri\Application Data\Malwarebytes
2009-03-25 11:02:47 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2009-03-25 11:02:47 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-03-24 15:58:44 —-HDC—- C:\WINDOWS\ie8
2009-03-24 14:11:33 —-D—- C:\WINDOWS\SxsCaPendDel
2009-03-24 10:31:58 —-D—- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2009-03-24 10:21:36 —-D—- C:\Program Files\Common Files\McAfee
2009-03-22 04:52:05 —-D—- C:\Documents and Settings\John Balestrieri\Application Data\HPAppData
2009-03-21 12:53:03 —-D—- C:\Documents and Settings\All Users\Application Data\WEBREG
2009-03-21 12:48:28 —-D—- C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2009-03-21 12:44:17 —-D—- C:\Documents and Settings\All Users\Application Data\HP
2009-03-21 12:44:02 —-D—- C:\WINDOWS\hpojp8500a909
2009-03-21 12:42:56 —-A—- C:\WINDOWS\system32\hpf3l082.dll
2009-03-21 12:42:55 —-RA—- C:\WINDOWS\system32\hpzids01.dll
2009-03-21 12:42:10 —-RA—- C:\WINDOWS\system32\hppldcoi.dll
2009-03-21 12:42:10 —-RA—- C:\WINDOWS\system32\hpovst11.dll
2009-03-21 12:42:10 —-RA—- C:\WINDOWS\system32\difxapi.dll
2009-03-21 12:42:09 —-RA—- C:\WINDOWS\system32\hpwwiax5.dll
2009-03-21 12:42:09 —-RA—- C:\WINDOWS\system32\hpwtiop4.dll
2009-03-21 12:37:46 —-D—- C:\Program Files\Common Files\HP
2009-03-21 12:37:43 —-D—- C:\Program Files\Common Files\Hewlett-Packard
2009-03-21 12:37:42 —-D—- C:\Program Files\Hewlett-Packard
2009-03-21 12:36:08 —-D—- C:\Program Files\HP
2009-03-21 12:34:58 —-HD—- C:\Config.Msi
2009-03-14 17:07:01 —-D—- C:\Program Files\TweetDeck
2009-03-11 09:03:15 —-HDC—- C:\WINDOWS\$NtUninstallKB960225$
2009-03-11 09:02:57 —-HDC—- C:\WINDOWS\$NtUninstallKB958690$
2009-03-11 09:00:56 —-HDC—- C:\WINDOWS\$NtUninstallKB959772_WM11$
2009-03-08 14:22:30 —-N—- C:\WINDOWS\system32\msrating.dll.mui
2009-03-08 14:22:18 —-N—- C:\WINDOWS\system32\mshta.exe.mui
2009-03-08 14:21:06 —-N—- C:\WINDOWS\system32\ie4uinit.exe.mui
2009-03-08 14:20:54 —-N—- C:\WINDOWS\system32\iedkcs32.dll.mui
2009-02-26 14:40:44 —-A—- C:\WINDOWS\atagtctl.exe
2009-02-26 14:40:16 —-A—- C:\WINDOWS\system32\atrant40.dll
2009-02-26 10:03:17 —-N—- C:\WINDOWS\system32\spmsg.dll
2009-02-26 10:03:15 —-HDC—- C:\WINDOWS\$NtUninstallKB967715$
2009-02-23 17:23:43 —-D—- C:\Documents and Settings\John Balestrieri\Application Data\CoffeeCup Software
2009-02-12 10:15:16 —-D—- C:\WINDOWS\$SQLUninstallSQL2000-KB960082-v8.00.2055-x86-ENU$
2009-02-12 10:11:24 —-HDC—- C:\WINDOWS\$NtUninstallKB960715$
2009-02-12 10:09:46 —-D—- C:\WINDOWS\SQLTools9_KB960089_ENU
2009-02-12 10:04:53 —-D—- C:\WINDOWS\SQL9_KB960089_ENU

======List of files/folders modified in the last 2 months======

2009-04-01 09:09:27 —-RSHD—- C:\WINDOWS\Temp
2009-04-01 09:00:38 —-D—- C:\WINDOWS\Prefetch
2009-04-01 08:53:14 —-D—- C:\Program Files\Mozilla Firefox
2009-04-01 07:40:21 —-SD—- C:\WINDOWS\Downloaded Program Files
2009-03-30 18:58:20 —-D—- C:\WINDOWS\system32
2009-03-30 15:31:30 —-D—- C:\WINDOWS
2009-03-30 15:31:27 —-D—- C:\WINDOWS\system32\CatRoot2
2009-03-30 09:42:20 —-SHD—- C:\WINDOWS\Installer
2009-03-30 09:41:26 —-D—- C:\Program Files\Java
2009-03-30 09:39:30 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2009-03-30 09:35:26 —-A—- C:\WINDOWS\ModemLog_Standard Modem.txt
2009-03-30 09:35:20 —-A—- C:\WINDOWS\ModemLog_Conexant HDA D110 MDC V.92 Modem.txt
2009-03-30 09:33:13 —-A—- C:\WINDOWS\SchedLgU.Txt
2009-03-30 09:32:16 —-D—- C:\Program Files\Viewpoint
2009-03-30 09:28:33 —-D—- C:\Program Files\Common Files
2009-03-30 09:27:32 —-D—- C:\dell
2009-03-29 18:01:20 —-D—- C:\Program Files\Common Files\Symantec Shared
2009-03-29 18:00:02 —-D—- C:\Program Files\Norton Security Scan
2009-03-29 09:23:39 —-D—- C:\Program Files
2009-03-28 15:20:16 —-D—- C:\WINDOWS\system32\drivers
2009-03-28 11:49:29 —-D—- C:\WINDOWS\Debug
2009-03-28 11:49:23 —-D—- C:\WINDOWS\Minidump
2009-03-28 11:35:41 —-D—- C:\WINDOWS\system32\dla
2009-03-28 11:12:01 —-AD—- C:\Documents and Settings\All Users\Application Data\TEMP
2009-03-28 09:15:53 —-SHD—- C:\System Volume Information
2009-03-28 09:15:53 —-D—- C:\WINDOWS\system32\Restore
2009-03-27 09:25:30 —-D—- C:\Documents and Settings\John Balestrieri\Application Data\Yahoo!
2009-03-27 09:25:30 —-D—- C:\Documents and Settings\All Users\Application Data\Yahoo!
2009-03-27 09:24:29 —-D—- C:\Program Files\Google
2009-03-26 16:46:29 —-HD—- C:\WINDOWS\inf
2009-03-26 16:24:47 —-D—- C:\WINDOWS\network diagnostic
2009-03-26 14:17:04 —-D—- C:\Program Files\McAfee
2009-03-26 13:31:57 —-D—- C:\Documents and Settings
2009-03-26 07:26:57 —-RASH—- C:\boot.ini
2009-03-26 07:26:57 —-A—- C:\WINDOWS\win.ini
2009-03-26 07:26:57 —-A—- C:\WINDOWS\system.ini
2009-03-25 11:39:32 —-SHD—- C:\RECYCLER
2009-03-24 16:14:00 —-D—- C:\WINDOWS\system32\en-US
2009-03-24 16:13:59 —-D—- C:\WINDOWS\Media
2009-03-24 16:13:58 —-D—- C:\WINDOWS\system32\dllcache
2009-03-24 16:13:58 —-D—- C:\WINDOWS\Help
2009-03-24 16:13:58 —-D—- C:\Program Files\Internet Explorer
2009-03-24 14:42:35 —-D—- C:\Program Files\Yogafont
2009-03-24 14:11:36 —-D—- C:\WINDOWS\WinSxS
2009-03-24 14:05:10 —-SD—- C:\Documents and Settings\John Balestrieri\Application Data\Microsoft
2009-03-24 14:04:43 —-D—- C:\Program Files\Microsoft ActiveSync
2009-03-24 14:03:43 —-D—- C:\WINDOWS\occache
2009-03-24 14:03:32 —-RSD—- C:\WINDOWS\Fonts
2009-03-24 14:03:32 —-HD—- C:\Program Files\InstallShield Installation Information
2009-03-24 14:03:31 —-D—- C:\Program Files\Macromedia
2009-03-24 14:03:09 —-D—- C:\Documents and Settings\John Balestrieri\Application Data\Macromedia
2009-03-24 14:01:27 —-D—- C:\Program Files\Common Files\Macromedia
2009-03-24 13:55:49 —-RSD—- C:\WINDOWS\assembly
2009-03-24 13:55:44 —-D—- C:\Program Files\OpenOffice.org 2.1
2009-03-24 11:56:20 —-SD—- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-03-24 10:34:59 —-D—- C:\Documents and Settings\All Users\Application Data\McAfee
2009-03-24 10:34:53 —-D—- C:\Program Files\McAfee.com
2009-03-24 10:34:53 —-D—- C:\Documents and Settings\All Users\Application Data\McAfee.com
2009-03-24 10:29:16 —-D—- C:\Program Files\Mozilla Thunderbird
2009-03-24 10:22:57 —-SD—- C:\WINDOWS\Tasks
2009-03-24 07:14:39 —-D—- C:\Program Files\Yahoo!
2009-03-22 12:18:26 —-D—- C:\WINDOWS\system32\FxsTmp
2009-03-21 12:42:43 —-D—- C:\WINDOWS\twain_32
2009-03-21 12:36:49 —-DC—- C:\WINDOWS\system32\DRVSTORE
2009-03-18 09:27:30 —-D—- C:\WINDOWS\Microsoft.NET
2009-03-18 09:23:50 —-D—- C:\Program Files\Microsoft SQL Server
2009-03-18 09:11:49 —-D—- C:\Program Files\Common Files\Microsoft Shared
2009-03-18 09:05:32 —-D—- C:\WINDOWS\Registration
2009-03-14 16:58:11 —-D—- C:\Program Files\Common Files\Adobe AIR
2009-03-11 09:47:51 —-D—- C:\Program Files\Plaxo
2009-03-10 23:54:30 —-HD—- C:\WINDOWS\$hf_mig$
2009-03-08 14:22:46 —-A—- C:\WINDOWS\system32\ieframe.dll.mui
2009-03-08 14:21:06 —-A—- C:\WINDOWS\system32\advpack.dll.mui
2009-03-08 14:09:26 —-A—- C:\WINDOWS\system32\iedkcs32.dll
2009-03-08 04:41:16 —-A—- C:\WINDOWS\system32\mshtml.dll
2009-03-08 04:39:48 —-A—- C:\WINDOWS\system32\ieframe.dll
2009-03-08 04:34:58 —-A—- C:\WINDOWS\system32\wininet.dll
2009-03-08 04:34:56 —-A—- C:\WINDOWS\system32\urlmon.dll
2009-03-08 04:34:48 —-A—- C:\WINDOWS\system32\WinFXDocObj.exe
2009-03-08 04:34:48 —-A—- C:\WINDOWS\system32\webcheck.dll
2009-03-08 04:34:30 —-A—- C:\WINDOWS\system32\licmgr10.dll
2009-03-08 04:34:28 —-A—- C:\WINDOWS\system32\url.dll
2009-03-08 04:34:18 —-A—- C:\WINDOWS\system32\occache.dll
2009-03-08 04:34:18 —-A—- C:\WINDOWS\system32\msrating.dll
2009-03-08 04:33:40 —-A—- C:\WINDOWS\system32\corpol.dll
2009-03-08 04:33:26 —-A—- C:\WINDOWS\system32\jsproxy.dll
2009-03-08 04:33:16 —-A—- C:\WINDOWS\system32\jscript.dll
2009-03-08 04:33:08 —-A—- C:\WINDOWS\system32\ieaksie.dll
2009-03-08 04:33:06 —-A—- C:\WINDOWS\system32\vbscript.dll
2009-03-08 04:33:02 —-A—- C:\WINDOWS\system32\ieakeng.dll
2009-03-08 04:32:56 —-A—- C:\WINDOWS\system32\admparse.dll
2009-03-08 04:32:54 —-A—- C:\WINDOWS\system32\ie4uinit.exe
2009-03-08 04:32:52 —-A—- C:\WINDOWS\system32\ieudinit.exe
2009-03-08 04:32:52 —-A—- C:\WINDOWS\system32\ieakui.dll
2009-03-08 04:32:50 —-A—- C:\WINDOWS\system32\iesetup.dll
2009-03-08 04:32:50 —-A—- C:\WINDOWS\system32\iernonce.dll
2009-03-08 04:32:48 —-A—- C:\WINDOWS\system32\advpack.dll
2009-03-08 04:32:46 —-A—- C:\WINDOWS\system32\inseng.dll
2009-03-08 04:32:26 —-A—- C:\WINDOWS\system32\msfeeds.dll
2009-03-08 04:32:22 —-A—- C:\WINDOWS\system32\iertutil.dll
2009-03-08 04:32:04 —-A—- C:\WINDOWS\system32\mstime.dll
2009-03-08 04:31:56 —-A—- C:\WINDOWS\system32\iepeers.dll
2009-03-08 04:31:54 —-A—- C:\WINDOWS\system32\msfeedssync.exe
2009-03-08 04:31:52 —-A—- C:\WINDOWS\system32\msfeedsbs.dll
2009-03-08 04:31:52 —-A—- C:\WINDOWS\system32\icardie.dll
2009-03-08 04:31:44 —-A—- C:\WINDOWS\system32\dxtmsft.dll
2009-03-08 04:31:38 —-A—- C:\WINDOWS\system32\imgutil.dll
2009-03-08 04:31:38 —-A—- C:\WINDOWS\system32\dxtrans.dll
2009-03-08 04:31:36 —-A—- C:\WINDOWS\system32\pngfilt.dll
2009-03-08 04:31:26 —-A—- C:\WINDOWS\system32\mshtmled.dll
2009-03-08 04:31:18 —-A—- C:\WINDOWS\system32\mshtmler.dll
2009-03-08 04:31:02 —-A—- C:\WINDOWS\system32\mshta.exe
2009-03-08 04:22:46 —-A—- C:\WINDOWS\system32\ieui.dll
2009-03-08 04:22:38 —-A—- C:\WINDOWS\system32\msls31.dll
2009-03-08 04:11:12 —-A—- C:\WINDOWS\system32\ieapfltr.dll
2009-02-26 14:34:43 —-D—- C:\Documents and Settings\All Users\Application Data\Intuit
2009-02-26 10:51:25 —-D—- C:\Program Files\Microsoft Silverlight
2009-02-25 12:55:00 —-A—- C:\WINDOWS\system32\MRT.exe
2009-02-23 17:23:30 —-D—- C:\Program Files\CoffeeCup Software
2009-02-20 11:11:56 —-A—- C:\WINDOWS\IFPClient.ini
2009-02-12 10:13:35 —-D—- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-02-12 10:13:28 —-A—- C:\WINDOWS\vbaddin.ini
2009-02-12 10:03:03 —-D—- C:\WINDOWS\ie7updates
2009-02-10 10:45:11 —-A—- C:\WINDOWS\QBChanUtil_Trigger.ini
2009-02-03 09:09:26 —-D—- C:\Program Files\Windows Media Player

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 APPDRV;APPDRV; C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS [2005-08-12 16128]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2009-01-16 213640]
R1 MPFP;MPFP; C:\WINDOWS\System32\Drivers\Mpfp.sys [2008-10-23 120136]
R1 sscdbhk5;sscdbhk5; C:\WINDOWS\system32\drivers\sscdbhk5.sys [2005-05-13 5627]
R1 ssrtln;ssrtln; C:\WINDOWS\system32\drivers\ssrtln.sys [2005-05-13 23545]
R2 drvnddm;drvnddm; C:\WINDOWS\system32\drivers\drvnddm.sys [2005-04-21 40544]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-03-17 13059]
R2 tfsnboio;tfsnboio; C:\WINDOWS\system32\dla\tfsnboio.sys [2005-05-31 25725]
R2 tfsncofs;tfsncofs; C:\WINDOWS\system32\dla\tfsncofs.sys [2005-05-31 34845]
R2 tfsndrct;tfsndrct; C:\WINDOWS\system32\dla\tfsndrct.sys [2005-05-31 4125]
R2 tfsndres;tfsndres; C:\WINDOWS\system32\dla\tfsndres.sys [2005-05-31 2241]
R2 tfsnifs;tfsnifs; C:\WINDOWS\system32\dla\tfsnifs.sys [2005-05-31 86876]
R2 tfsnopio;tfsnopio; C:\WINDOWS\system32\dla\tfsnopio.sys [2005-05-31 15069]
R2 tfsnpool;tfsnpool; C:\WINDOWS\system32\dla\tfsnpool.sys [2005-05-31 6365]
R2 tfsnudf;tfsnudf; C:\WINDOWS\system32\dla\tfsnudf.sys [2005-05-31 98716]
R2 tfsnudfa;tfsnudfa; C:\WINDOWS\system32\dla\tfsnudfa.sys [2005-05-31 100605]
R3 BCM43XX;Dell Wireless WLAN Card Driver; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2005-11-02 424320]
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2006-08-25 44544]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2005-07-22 1035008]
R3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2005-07-22 201600]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2005-10-14 1302812]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [2009-01-16 79304]
R3 mfebopk;McAfee Inc. mfebopk; C:\WINDOWS\system32\drivers\mfebopk.sys [2009-01-16 35272]
R3 mferkdk;McAfee Inc. mferkdk; C:\WINDOWS\system32\drivers\mferkdk.sys [2009-01-16 34216]
R3 mfesmfk;McAfee Inc. mfesmfk; C:\WINDOWS\system32\drivers\mfesmfk.sys [2009-01-16 40552]
R3 RimVSerPort;RIM Virtual Serial Port v2; C:\WINDOWS\system32\DRIVERS\RimSerial.sys [2007-01-18 26496]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-04 5888]
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2006-03-25 1156648]
R3 StillCam;Still Serial Digital Camera Driver; C:\WINDOWS\system32\DRIVERS\serscan.sys [2001-08-17 6784]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2006-03-08 191872]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys [2003-01-10 33588]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2005-07-22 717952]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 DellBIOS;DellBIOS; \??\C:\WINDOWS\DellBIOS.Sys []
S3 DSproct;DSproct; \??\C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys []
S3 E100B;Intel® PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-17 117760]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
S3 OVT511Plus;Dual Mode USB Camera Plus; C:\WINDOWS\System32\Drivers\omcamvid.sys [2001-09-18 167816]
S3 PalmUSBD;PalmUSBD; C:\WINDOWS\system32\drivers\PalmUSBD.sys []
S3 PCASp50;PCASp50 NDIS Protocol Driver; C:\WINDOWS\System32\drivers\PCASp50.sys []
S3 RimUsb;BlackBerry Device; C:\WINDOWS\System32\Drivers\RimUsb.sys [2006-11-07 22272]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 SMNDIS5;SMNDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\VERIZO~1\VZACCE~1\SMNDIS5.SYS []
S3 SQTECH905C;DB CIF Cam; C:\WINDOWS\System32\Drivers\Capt905c.sys [2007-05-18 37760]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2008-10-01 32000]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-04-10 104576]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 agp440;Intel AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
S4 agpCPQ;Compaq AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2008-04-13 44928]
S4 alim1541;ALI AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\alim1541.sys [2008-04-13 42752]
S4 amdagp;AMD AGP Bus Filter Driver; C:\WINDOWS\system32\DRIVERS\amdagp.sys [2008-04-13 43008]
S4 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
S4 sisagp;SIS AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2008-04-13 40960]
S4 sr;System Restore Filter Driver; C:\WINDOWS\system32\DRIVERS\sr.sys [2008-04-13 73472]
S4 viaagp;VIA AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2008-04-13 42240]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AOL ACS;AOL Connectivity Service; C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe [2004-04-07 1135728]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-11-07 132424]
R2 atnthost;WebEx Remote Access Agent; C:\WINDOWS\DOWNLO~1\MyWebEx\319\atnthost.exe [2009-02-26 16784]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
R2 HPSLPSVC;HP Network Devices Support; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-03-30 152984]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service; C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2009-02-11 210216]
R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2009-01-08 797864]
R2 McNASvc;McAfee Network Agent; c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe [2009-01-09 2482848]
R2 McProxy;McAfee Proxy Service; c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [2009-01-09 359952]
R2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2009-01-16 144704]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 MpfService;McAfee Personal Firewall Service; C:\Program Files\McAfee\MPF\MPFSrv.exe [2009-01-09 884360]
R2 MSK80Service;McAfee Anti-Spam Service; C:\Program Files\McAfee\MSK\MskSrver.exe [2009-01-09 26640]
R2 MSSQL$MICROSOFTSMLBIZ;MSSQL$MICROSOFTSMLBIZ; C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe [2008-12-18 9158656]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-11-24 29263712]
R2 QBCFMonitorService;QBCFMonitorService; C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [2009-01-15 24576]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-11-24 239968]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-24 87904]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
R3 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2009-01-17 365072]
R3 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2009-01-16 606736]
R3 QuickBooksDB19;QuickBooksDB19; C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe [2008-07-10 131072]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-13 267776]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S2 Roxio Upnp Server 9;Roxio Upnp Server 9; C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe [2007-03-25 359160]
S2 RoxLiveShare9;LiveShare P2P Server 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe [2007-03-26 310008]
S2 RoxWatch9;Roxio Hard Drive Watcher 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe [2007-03-26 166648]
S2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter); C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2008-08-13 201968]
S2 wltrysvc;Dell Wireless WLAN Tray Service; C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-04-13 33632]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-04-13 68952]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-08-28 654848]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-11-20 536872]
S3 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-11-24 45408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 QBFCService;Intuit QuickBooks FCS; C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [2008-08-08 61440]
S3 Roxio UPnP Renderer 9;Roxio UPnP Renderer 9; C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe [2007-03-25 88824]
S3 RoxMediaDB9;RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2007-03-26 1010424]
S3 SQLAgent$MICROSOFTSMLBIZ;SQLAgent$MICROSOFTSMLBIZ; C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE [2005-05-03 323584]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]

—————–EOF—————–


info.txt logfile of random's system information tool 1.06 2009-04-01 09:12:32

======Uninstall list======

–>C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
–>C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
–>C:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
–>C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
–>C:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
–>C:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
–>MsiExec.exe /I{0D397393-9B50-4C52-84D5-77E344289F87}
–>MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}
–>MsiExec.exe /I{619CDD8A-14B6-43A1-AB6C-0F4EE48CE048}
–>MsiExec.exe /I{83FFCFC7-88C6-41C6-8752-958A45325C82}
–>MsiExec.exe /I{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}
–>MsiExec.exe /X{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1)–>msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
32 Bit HP CIO Components Installer–>MsiExec.exe /I{47ECCB1F-2811-49C0-B6A7-26778639ABA0}
Ace DivX Player–>"C:\Program Files\GustoSoft\Ace DivX Player\Uninstall.exe"
Add or Remove Adobe Creative Suite 3 Master Collection–>C:\Program Files\Common Files\Adobe\Installers\4dcfd9b7e901b57f81f667144603236\Setup.exe
Adobe After Effects CS3 Presets–>MsiExec.exe /I{193EAFD0-1BAF-4FB4-B18F-79D5D6A4B285}
Adobe AIR–>c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR–>MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Anchor Service CS3–>MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3–>MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
Adobe Bridge CS3–>MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
Adobe Bridge Start Meeting–>MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
Adobe BridgeTalk Plugin CS3–>MsiExec.exe /I{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}
Adobe Camera Raw 4.0–>MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps–>MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
Adobe Color - Photoshop Specific–>MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
Adobe Color Common Settings–>C:\Program Files\Common Files\Adobe\Installers\6c8e2cb4fd241c55406016127a6ab2e\Setup.exe
Adobe Color Common Settings–>MsiExec.exe /I{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}
Adobe Color EU Extra Settings–>MsiExec.exe /I{51846830-E7B2-4218-8968-B77F0FF475B8}
Adobe Color JA Extra Settings–>MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
Adobe Color NA Recommended Settings–>MsiExec.exe /I{95655ED4-7CA5-46DF-907F-7144877A32E5}
Adobe Creative Suite 3 Master Collection–>MsiExec.exe /I{8718DC03-D066-4957-94E5-50C3C5042E8E}
Adobe Default Language CS3–>MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
Adobe Device Central CS3–>MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
Adobe Dreamweaver CS3–>MsiExec.exe /I{7C10F5C7-F00F-4BD3-A110-C7D240D2DD25}
Adobe ExtendScript Toolkit 2–>C:\Program Files\Common Files\Adobe\Installers\3e054d2218e7aa282c2369d939e58ff\Setup.exe
Adobe ExtendScript Toolkit 2–>MsiExec.exe /I{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}
Adobe Extension Manager CS3–>MsiExec.exe /I{BE5F3842-8309-4754-92D5-83E02E6077A3}
Adobe Fireworks CS3–>MsiExec.exe /I{7DFC1012-D346-46CE-B03E-FF79125AE029}
Adobe Flash CS3–>MsiExec.exe /I{6B52140A-F189-4945-BFFC-DB3F00B8C589}
Adobe Flash Player 10 ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin–>C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Video Encoder–>MsiExec.exe /I{2EFFFC71-1E66-454E-A6E6-CEEC800B96D2}
Adobe Fonts All–>MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
Adobe Help Viewer CS3–>MsiExec.exe /I{7ACFB90E-8FD0-4397-AD3A-5195412623A3}
Adobe InDesign CS3 Icon Handler–>MsiExec.exe /I{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}
Adobe Linguistics CS3–>MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe MotionPicture Color Files–>MsiExec.exe /I{6B708481-748A-4EB4-97C1-CD386244FF77}
Adobe PDF Library Files–>MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
Adobe Photoshop CS3–>MsiExec.exe /I{0046FA01-C5B9-4985-BACB-398DC480FC05}
Adobe Reader 7.1.0–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A71000000002}
Adobe Setup–>MsiExec.exe /I{4458C442-7376-4CF9-AF58-E8CEA6722363}
Adobe Setup–>MsiExec.exe /I{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}
Adobe Setup–>MsiExec.exe /I{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}
Adobe Shockwave Player 11–>C:\WINDOWS\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
Adobe SING CS3–>MsiExec.exe /I{B671CBFD-4109-4D35-9252-3062D3CCB7B2}
Adobe Stock Photos CS3–>MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
Adobe Type Support–>MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
Adobe Update Manager CS3–>MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Version Cue CS3 Client–>MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe Video Profiles–>MsiExec.exe /I{845A8DB9-8802-4FD3-9FE3-938A6C46A2EC}
Adobe WAS CS3–>MsiExec.exe /I{C5BD220A-EFE8-48A5-B70E-9503D535FACE}
Adobe WinSoft Linguistics Plugin–>MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP DVA Panels CS3–>MsiExec.exe /I{0224CACC-994D-45F8-B973-D65056EA9C2F}
Adobe XMP Panels CS3–>MsiExec.exe /I{D5A31AB1-345D-47C7-A87B-036A669F6DF1}
AgileMessenger–>C:\Program Files\Microsoft ActiveSync\AgileMessenger\Uninstall.exe AgileMessenger
AHV content for Acrobat and Flash–>MsiExec.exe /I{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}
AIM 6–>C:\Program Files\AIM6\uninst.exe
AOL Coach Version 1.0(Build:20040229.1 en)–>C:\Program Files\Common Files\aolshare\Coach\AolCInUn.exe
AOL Connectivity Services–>C:\PROGRA~1\COMMON~1\AOL\ACS\AcsUninstall.exe /c
AOL Uninstaller (Choose which Products to Remove)–>C:\Program Files\Common Files\AOL\uninstaller.exe
AOLIcon–>MsiExec.exe /I{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}
AOPA's Real-Time Flight Planner 1.2.3–>c:\Jeppesen\RTFPClient\Uninstall.exe
Apple Mobile Device Support–>MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
Apple Software Update–>MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
BlackBerry Desktop Software 4.2.2–>MsiExec.exe /I{75D6745B-2239-4182-A31F-F95CEBB35099}
BlackBerry Desktop Software 4.2.2–>MsiExec.exe /i{75D6745B-2239-4182-A31F-F95CEBB35099}
BlackBerry v4.2.2 for the 8830 Series Wireless Device–>MsiExec.exe /X{0BEA8513-9D20-4539-BC45-26203A67111D}
Bonjour–>MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
Broadcom Management Programs–>MsiExec.exe /I{26E1BFB0-E87E-4696-9F89-B467F01F81E5}
CCleaner (remove only)–>"C:\Program Files\CCleaner\uninst.exe"
CoffeeCup Web Form Builder - Registered–>C:\PROGRA~1\COFFEE~1\COFFEE~1\UNWISE.EXE C:\PROGRA~1\COFFEE~1\COFFEE~1\INSTALL.LOG
CoffeeCup Web Form Builder - Trial–>C:\PROGRA~1\COFFEE~1\COFFEE~1\UNWISE.EXE C:\PROGRA~1\COFFEE~1\COFFEE~1\INSTALL.LOG
CoffeeCup Website Access Manager–>C:\PROGRA~1\COFFEE~1\COFFEE~2\UNWISE.EXE C:\PROGRA~1\COFFEE~1\COFFEE~2\CCAccess.log
Compatibility Pack for the 2007 Office system–>MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Conexant HDA D110 MDC V.92 Modem–>C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3\HXFSETUP.EXE -U -Idel1028k.inf
Critical Update for Windows Media Player 11 (KB959772)–>"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
DB CIF Cam–>C:\Program Files\InstallShield Installation Information\{83D96ED0-98AA-4515-8DDC-816F3EFDD104}\setup.exe -runfromtemp -l0x0009 -removeonly
Dell Driver Reset Tool–>MsiExec.exe /I{5905F42D-3F5F-4916-ADA6-94A3646AEE76}
Dell Support 3.2.1–>MsiExec.exe /X{CEE2252C-4035-4B27-8EC6-0B085DD3A413}
Dell Support Center (Support Software)–>MsiExec.exe /X{E3BFEE55-39E2-4BE0-B966-89FE583822C1}
Dell Wireless WLAN Card–>"C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="C:\Program Files\Dell\Dell Wireless WLAN Card"
Digital Content Portal–>MsiExec.exe /I{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}
Digital Line Detect–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel
Disney Pix 2.2–>MsiExec.exe /X{DC8235CC-3D5A-4D32-94BE-E2F0A1749920}
Disney Pix Micro Downloader–>MsiExec.exe /X{183135A3-2CE8-43B5-BA5A-757EBAECB413}
Documentation & Support Launcher–>MsiExec.exe /X{B0DF58A2-40DF-4465-AA56-38623EC9938C}
EarthLink Setup Files–>MsiExec.exe /X{5E68BB65-4059-4FE5-AAC4-0CD1D79BBDE2}
EducateU–>MsiExec.exe /I{A683A2C0-821C-486F-858C-FA634DB5E864}
eFax Messenger 4.3–>C:\Program Files\eFax Messenger 4.3\Uninstall.exe
ERUNT 1.1j–>"C:\Program Files\ERUNT\unins000.exe"
Games, Music, & Photos Launcher–>MsiExec.exe /X{B6884A07-0305-47AE-9969-8F26FADC17DE}
High Definition Audio Driver Package - KB835221–>C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
HijackThis 2.0.2–>"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix 2050 for SQL Server 2000 ENU (KB948110)–>"C:\WINDOWS\$SQLUninstallSQL2000-KB948110-v8.00.2050-x86-ENU$\spuninst\spuninst.exe"
Hotfix 2055 for SQL Server 2000 ENU (KB960082)–>"C:\WINDOWS\$SQLUninstallSQL2000-KB960082-v8.00.2055-x86-ENU$\spuninst\spuninst.exe"
Hotfix for Windows Internet Explorer 7 (KB947864)–>"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Hotfix for Windows Media Format 11 SDK (KB929399)–>"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)–>"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
HP Document Manager 2.0–>C:\Program Files\HP\Digital Imaging\DocumentManager\hpzscr01.exe -datfile hpqbud18.dat
HP Imaging Device Functions 12.0–>C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP Smart Web Printing–>C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpzscr01.exe -datfile hpqbud15.dat
HP Solution Center 12.0–>C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat -forcereboot
HP Update–>MsiExec.exe /X{7059BDA7-E1DB-442C-B7A1-6144596720A4}
Intel® Graphics Media Accelerator Driver for Mobile–>RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx2ID PCI\VEN_8086&DEV_2792 PCI\VEN_8086&DEV_2592
Ipswitch WS_FTP LE–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B3A31EEE-7C65-4EE6-BB0D-5549FD2D67B9}\setup.exe" -l0x9
iSkysoft DVD to iPod Converter(Build 1.5.23)–>"C:\Program Files\iSkysoft\DVD to iPod Converter\unins000.exe"
iTunes–>MsiExec.exe /I{318AB667-3230-41B5-A617-CB3BF748D371}
Japanese Language Support–>RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\ja.inf, Uninstall
Java™ 6 Update 13–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
McAfee SecurityCenter–>C:\Program Files\McAfee\MSC\mcuninst.exe
MCU–>MsiExec.exe /I{D2988E9B-C73F-422C-AD4B-A66EBE257120}
Microsoft .NET Framework 1.1 Hotfix (KB928366)–>"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0–>C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Compression Client Pack 1.0 for Windows XP–>"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs–>"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs–>"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office 2003 Primary Interop Assemblies–>MsiExec.exe /X{91490409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Accounting 2008 Equifax Addin–>MsiExec.exe /X{0C2AF762-0565-4C91-9F55-B8B53BB82A38}
Microsoft Office Accounting 2008 Fixed Asset Manager–>MsiExec.exe /X{E3DF6916-2472-43D9-8B3C-9F2F0AAB01B5}
Microsoft Office Accounting 2008 PayPal Addin–>MsiExec.exe /X{B391EECE-DFEA-4FC5-9D40-47FA43E2DBE6}
Microsoft Office Accounting 2008–>"C:\Program Files\Microsoft Small Business\Office Accounting 2008\SetupBootstrap\Setup.exe" /remove {270940EA-C235-40D9-B2AE-2D450356DF8E}
Microsoft Office Accounting 2008–>MsiExec.exe /X{270940EA-C235-40D9-B2AE-2D450356DF8E}
Microsoft Office Accounting ADP Payroll Addin–>MsiExec.exe /I{5FA793A6-0071-42C1-9355-8F69A428C44F}
Microsoft Office Outlook 2003 with Business Contact Manager Update–>MsiExec.exe /I{BA68600E-96D9-4E92-80F2-26B9681B5A63}
Microsoft Office Proof (English) 2007–>MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007–>MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007–>MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007–>MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007–>MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007–>MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Small Business Connectivity Components–>MsiExec.exe /X{A939D341-5A04-4E0A-BB55-3E65B386432D}
Microsoft Office Small Business Edition 2003–>MsiExec.exe /I{91CA0409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Visio 2007 Service Pack 1 (SP1)–>msiexec /package {90120000-0051-0000-0000-0000000FF1CE} /uninstall {AA4F2610-5FF1-4DCD-A6FB-BCA2D09A6443}
Microsoft Office Visio 2007 Service Pack 1 (SP1)–>msiexec /package {90120000-0054-0409-0000-0000000FF1CE} /uninstall {EA35370F-586C-45E1-AC6C-A4E275C6B762}
Microsoft Office Visio MUI (English) 2007–>MsiExec.exe /X{90120000-0054-0409-0000-0000000FF1CE}
Microsoft Office Visio Professional 2007–>"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall VISPRO /dll OSETUP.DLL
Microsoft Office Visio Professional 2007–>MsiExec.exe /X{90120000-0051-0000-0000-0000000FF1CE}
Microsoft Plus! Digital Media Edition Installer–>MsiExec.exe /X{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}
Microsoft Plus! Photo Story 2 LE–>MsiExec.exe /X{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}
Microsoft Silverlight–>MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)–>MsiExec.exe /I{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}
Microsoft SQL Server 2005 Tools Express Edition–>MsiExec.exe /I{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}
Microsoft SQL Server 2005–>"c:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\ARPWrapper.exe" /Remove
Microsoft SQL Server Desktop Engine (MICROSOFTSMLBIZ)–>MsiExec.exe /X{E09B48B5-E141-427A-AB0C-D3605127224A}
Microsoft SQL Server Native Client–>MsiExec.exe /I{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}
Microsoft SQL Server Setup Support Files (English)–>MsiExec.exe /X{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}
Microsoft SQL Server VSS Writer–>MsiExec.exe /I{56B4002F-671C-49F4-984C-C760FE3806B5}
Microsoft User-Mode Driver Framework Feature Pack 1.0–>"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual Studio 2005 Tools for Office Runtime–>MsiExec.exe /X{388E4B09-3E71-4649-8921-F44A3A2954A7}
Microsoft Works–>MsiExec.exe /I{6D52C408-B09A-4520-9B18-475B81D393F1}
MobileMe Control Panel–>MsiExec.exe /I{924EB80F-C2BB-4B9F-8412-88BBA937393F}
Modem Helper–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F142D56-3326-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel
Mozilla Firefox (3.0.8)–>C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Mozilla Thunderbird (1.5)–>C:\Program Files\Mozilla Thunderbird\uninstall\uninstall.exe /ua "1.5 (en-US)"
MPM–>MsiExec.exe /X{CD8C5C7F-7C58-4F85-8977-A6C08C087912}
MSN–>C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSXML 4.0 SP2 (KB927978)–>MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)–>MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 Parser and SDK–>MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
MSXML 6.0 Parser (KB933579)–>MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
NetWaiting–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel
Norton Security Scan (Symantec Corporation)–>"C:\Program Files\Common Files\Symantec Shared\NSSSetup\{3FADAA19-E595-44CA-A072-58B6B0851768}_2_0_0\NSSSetup.exe" /X
Norton Security Scan–>MsiExec.exe /X{3FADAA19-E595-44CA-A072-58B6B0851768}
OCR Software by I.R.I.S. 12.0–>C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
Officejet Pro 8500 A909 Series–>C:\Program Files\HP\Digital Imaging\{624E7452-BA43-4f55-B9D5-FC75EEA0808B}\setup\hpzscr01.exe -datfile hpwscr22.dat -forcereboot
Panda ActiveScan 2.0–>C:\Program Files\Panda Security\ActiveScan 2.0\as2uninst.exe
PC SpeedScan Pro–>C:\Program Files\InstallShield Installation Information\{80F24F31-F641-4349-83F3-59E335976D16}\setup.exe -runfromtemp -l0x0009 -removeonly
PDF Settings–>MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
Performance Center–>C:\Program Files\InstallShield Installation Information\{BB05BD70-4605-4829-93FC-AD80D8CC5B66}\setup.exe -runfromtemp -l0x0009 -removeonly
Photodex Presenter–>C:\Program Files\Photodex Presenter\uninst.exe
PHP to ASP.NET Migration Assistant–>MsiExec.exe /I{C55243C9-F058-4FD8-9693-E9C75BD7A84F}
Plaxo Toolbar for Windows–>C:\Program Files\Plaxo\3.19.0.16\uninstall.exe
PowerDVD 5.5–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
PremiumSoft Navicat MySQL 7.2–>"C:\Program Files\PremiumSoft\Navicat MySQL\unins000.exe"
PrimoPDF Redistribution Package–>MsiExec.exe /I{885744A4-1A01-44B0-858A-0AE6738CBCF7}
PrimoPDF–>"C:\WINDOWS\PrimoPDF\uninstall.exe" "/U:C:\Program Files\activePDF\PrimoPDF\Uninstall\uninstall.xml"
QuickBooks Pro 2009–>msiexec.exe /I {9A2F0810-369F-4E86-9072-973FBE1679C5} UNIQUE_NAME="pro" QBFULLNAME="QuickBooks Pro 2009" ADDREMOVE=1
QuickBooks Remote Access–>C:\WINDOWS\DOWNLO~1\mwcliun.exe
QuickBooks–>MsiExec.exe /I{9A2F0810-369F-4E86-9072-973FBE1679C5}
QuickSet–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C5074CC4-0E26-4716-A307-960272A90040}\setup.exe" -l0x9 APPDRVNT4
QuickTime–>MsiExec.exe /I{F958CA02-BB40-4007-894B-258729456EE4}
RealPlayer–>C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Registry Mechanic 8.0–>"C:\Program Files\Registry Mechanic\unins000.exe" /Log
Risk–>"C:\Program Files\Risk\ReflexiveArcade\unins000.exe"
Roxio Media Manager–>MsiExec.exe /X{66D171AA-670F-4309-9C74-5BA7F7DBA0B3}
Safari–>MsiExec.exe /I{582D2A53-F426-4C5E-A2E6-43C1AB36B907}
SearchAssist–>C:\DELL\SearchAssist\UninstSA.bat
Security Task Manager 1.7h–>C:\Program Files\Security Task Manager\Uninstal.exe "C:\Documents and Settings\All Users\Start Menu\Programs\Security Task Manager"
Security Update for 2007 Microsoft Office System (KB951550)–>msiexec /package {90120000-0051-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
Security Update for 2007 Microsoft Office System (KB951944)–>msiexec /package {90120000-0051-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
Security Update for Microsoft .NET Framework 2.0 (KB928365)–>C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {8056AC9E-49C5-4375-9ADE-B2F862C9DF51} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
Security Update for Microsoft Office system 2007 (KB954326)–>msiexec /package {90120000-0051-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
Security Update for Microsoft Office Visio 2007 (KB957831)–>msiexec /package {90120000-0051-0000-0000-0000000FF1CE} /uninstall {DA824D83-D80E-47AE-9726-7F5E810330C8}
Security Update for Step By Step Interactive Training (KB898458)–>"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
Security Update for Step By Step Interactive Training (KB923723)–>"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB928090)–>"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB929969)–>"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB931768)–>"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB933566)–>"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB937143)–>"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127)–>"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB939653)–>"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)–>"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)–>"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)–>"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)–>"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)–>"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)–>"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)–>"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB961260)–>"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)–>"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB917734)–>"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)–>"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)–>"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)–>"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)–>"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)–>"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)–>"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)–>"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)–>"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)–>"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)–>"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)–>"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)–>"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958690)–>"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)–>"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960715)–>"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Skype™ 3.6–>MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
Sonic DLA–>MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
Sonic MyDVD LE–>MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
Sonic RecordNow Audio–>MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
Sonic RecordNow Copy–>MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}
Sonic RecordNow Data–>MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
Sonic Update Manager–>MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
Spybot - Search & Destroy–>"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
SSH Secure Shell–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{74E2CD0C-D4A2-11D3-95A6-0000E86CFDE5}\Setup.exe"
SupportSoft Assisted Service–>MsiExec.exe /I{5A3F6A80-7913-475E-8B96-477A952CFA43}
SWF-AVI-GIF Converter 1.0–>"C:\Program Files\SWF-AVI-GIF Converter\unins000.exe"
Synaptics Pointing Device Driver–>rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Treo 700wx User Guide–>MsiExec.exe /X{6F1C9D19-5CA8-4D21-8087-AB2089ACDE3C}
TweetDeck–>MsiExec.exe /X{6E19B918-2820-74A9-3CE0-9BAD5E1D360C}
Update for Office 2007 (KB946691)–>msiexec /package {90120000-0051-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
Update for Windows XP (KB951072-v2)–>"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)–>"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)–>"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)–>"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Visual Studio 2005 Tools for Office Second Edition Runtime–>c:\Program Files\Common Files\Microsoft Shared\VSTO\8.0\Microsoft Visual Studio 2005 Tools for Office Runtime\install.exe
VZAccess Manager for RIM–>MsiExec.exe /X{5C1A8800-9D79-43FF-9432-921ACB7AA69D}
Windows Internet Explorer 8–>"C:\WINDOWS\ie8\spuninst\spuninst.exe"
Windows Live installer–>MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Messenger–>MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Sign-in Assistant–>MsiExec.exe /I{9422C8EA-B0C6-4197-B8FC-DC797658CA00}
Windows Media Format 11 runtime–>"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime–>"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 10–>MsiExec.exe /I{33BB4982-DC52-4886-A03B-F4C5C80BEE89}
Windows Media Player 11–>"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11–>"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 3–>"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archiver–>C:\Program Files\WinRAR\uninstall.exe
WinSCP 3.8.2–>"C:\Program Files\WinSCP3\unins000.exe"
Xilisoft Video Converter Standard–>C:\Program Files\Xilisoft\Video Converter Standard\Uninstall.exe
Xilisoft Video Converter Ultimate–>C:\Program Files\Xilisoft\Video Converter Ultimate\Uninstall.exe
Yahoo! Messenger–>C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG

=====HijackThis Backups=====

O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe [2009-03-26]
O1 - Hosts: 216.213.84.130 www.timesheeter.com [2009-03-26]
O1 - Hosts: 216.213.84.130 www.coachingconsortium.org [2009-03-26]
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing) [2009-03-26]
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file) [2009-03-26]
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) [2009-03-26]

======Hosts File======

127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com

======Security center information======

AV: McAfee VirusScan
FW: McAfee Personal Firewall

======System event log======

Computer Name: JOHNLAPTOP
Event Code: 10010
Message: The server {6A972E27-93E2-4F98-8367-4101B2073814} did not register with DCOM within the required timeout.

Record Number: 70857
Source Name: DCOM
Time Written: 20090330082119.000000-240
Event Type: error
User: NT AUTHORITY\SYSTEM

Computer Name: JOHNLAPTOP
Event Code: 10010
Message: The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register with DCOM within the required timeout.

Record Number: 70856
Source Name: DCOM
Time Written: 20090330082038.000000-240
Event Type: error
User: NT AUTHORITY\SYSTEM

Computer Name: JOHNLAPTOP
Event Code: 10010
Message: The server {6A972E27-93E2-4F98-8367-4101B2073814} did not register with DCOM within the required timeout.

Record Number: 70855
Source Name: DCOM
Time Written: 20090330082008.000000-240
Event Type: error
User: NT AUTHORITY\SYSTEM

Computer Name: JOHNLAPTOP
Event Code: 10010
Message: The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register with DCOM within the required timeout.

Record Number: 70854
Source Name: DCOM
Time Written: 20090330081927.000000-240
Event Type: error
User: NT AUTHORITY\SYSTEM

Computer Name: JOHNLAPTOP
Event Code: 10010
Message: The server {6A972E27-93E2-4F98-8367-4101B2073814} did not register with DCOM within the required timeout.

Record Number: 70853
Source Name: DCOM
Time Written: 20090330081857.000000-240
Event Type: error
User: NT AUTHORITY\SYSTEM

=====Application event log=====

Computer Name: JOHNLAPTOP
Event Code: 4
Message: An unexpected error has occured in "QuickBooks Pro 2009":
Connection String:CON=QBConnectionPool-Probe-QB_JOHNLAPTOP_19;;DBF=C:\Documents and Settings\John Balestrieri\My Documents\exit5\bank_statements\quickbooks_file\Exit5, LLC (Acct Transfer Feb 26,2009 11 01 AM).QBW;CommLinks="tcpip(IP=192.168.1.102;TO=5;DOBROADCAST=NONE;port=55333)";ServerName=QB_JOHNLAPTOP_19;DBN=bb416e92094d4e36b9091f5d1d932400
Record Number: 22118
Source Name: QuickBooks
Time Written: 20090310123838.000000-300
Event Type: error
User:

Computer Name: JOHNLAPTOP
Event Code: 4
Message: An unexpected error has occured in "QuickBooks Pro 2009":
Connection Error:Invalid user ID or password
Record Number: 22117
Source Name: QuickBooks
Time Written: 20090310123838.000000-300
Event Type: error
User:

Computer Name: JOHNLAPTOP
Event Code: 4
Message: An unexpected error has occured in "QuickBooks":
Returning NULL QBWinInstance Handle
Record Number: 22116
Source Name: QuickBooks
Time Written: 20090310123814.000000-300
Event Type: error
User:

Computer Name: JOHNLAPTOP
Event Code: 4
Message: An unexpected error has occured in "QuickBooks":
Returning NULL QBWinInstance Handle
Record Number: 22115
Source Name: QuickBooks
Time Written: 20090310123814.000000-300
Event Type: error
User:

Computer Name: JOHNLAPTOP
Event Code: 4
Message: An unexpected error has occured in "QuickBooks":
Returning NULL QBWinInstance Handle
Record Number: 22114
Source Name: QuickBooks
Time Written: 20090310123814.000000-300
Event Type: error
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;c:\Program Files\Microsoft SQL Server\90\Tools\binn\;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Common Files\Intuit\QBPOSSDKRuntime;C:\Program Files\Common Files\HP\Digital Imaging\bin;C:\Program Files\HP\Digital Imaging\bin\;C:\Program Files\HP\Digital Imaging\bin\Qt\Qt 4.3.3
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 13 Stepping 8, GenuineIntel
"PROCESSOR_REVISION"=0d08
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"SonicCentral"=C:\Program Files\Common Files\Sonic Shared\Sonic Central\
"RoxioCentral"=C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\
"CLASSPATH"=.;C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip

—————–EOF—————–
Hi there,

Fix HijackThis lines

  • Run HijackThis!
  • Click on Do a System Scan only
  • Place a tick next to the following lines:

    O4 - HKCU\..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\ApcMain.exe -m
Close all open windows and click on Fix checked and when you get a popup window click on Yes.

Backup Registry
  • Start Erunt.exe to backup your registry to the folder of your choice.

    Note: If you ever need to restore your registry in case something breaks, go to the folder and start ERDNT.exe

    • Please download OTMoveIt3.exe from Geeks to Go and save it to your desktop.
    • Double click on OTMoveIt3.exe to run it.
    • Please copy and paste the following in the Code box into OTMoveIt3 (1).

      Warning: Do not type it out to prevent any typo errors and damaging your machine.

      :Files
      C:\Program Files\Ascentive\Performance Center
      
      :Reg
      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
      "C:\Program Files\BitTorrent\bittorrent.exe"=-
      :Commands
      [EmptyTemp]
      [Reboot]

      Please refer to this image to use OTMoveIt3.

      [external image: Posted Image]
    • Click on MoveIt! (2)
    • Click Exit (3) when done.

    Kaspersky Online Scanner
    Please go to Kaspersky website and perform an online antivirus scan.

    • Read through the requirements and privacy statement and click on Accept button.
    • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    • When the downloads have finished, click on Settings.
    • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
        Spyware, Adware, Dialers, and other potentially dangerous programs
        Archives
        Mail databases
    • Click on My Computer under Scan.
    • Once the scan is complete, it will display the results. Click on View Scan Report.
    • You will see a list of infected items there. Click on Save Report As….
    • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
    • Please post this log in your next reply.

    In your next reply, please include:
    • OTMoveIt Results
    • Kaspersky results
    • A new HijackThis log

    Regards,
    Adam
Thanks for your help… Here are the newest log files.

========== FILES ==========
C:\Program Files\Ascentive\Performance Center moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\Program Files\BitTorrent\bittorrent.exe deleted successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\JOHNBA~1\LOCALS~1\Temp\etilqs_7dq8LGJW5HJo3zjamt4j scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\John Balestrieri\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_5b0.dat scheduled to be deleted on reboot.
Network Service Temp folder emptied.
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\WebEx\Log\330\atnthost.log scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcafee_xK8L8YZccxPCb4m scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcmsc_1voUL173yzg5MB8 scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcmsc_EFn41tpMdBKVnxP scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcmsc_F8fPlKHXQhFuwSf scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcmsc_FOgFqmJyRJyKb1k scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcmsc_FyrnRYTmavvGIRB scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcmsc_zYycoxUFZWbkwgb scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_148.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_b1c.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_d48.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_06wiNk92HHfUxEx scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_9f3ffvn2DqwM8uM scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_gM2DJwu8KB91aff scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_HjxWuLoft0nTfgH scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_RUSmTRTxUMlk457 scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_UWmY19lnLlmQrzp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_V3LpFWllBcVZqRk scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\John Balestrieri\Local Settings\Application Data\Mozilla\Firefox\Profiles\6e0cxt63.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\John Balestrieri\Local Settings\Application Data\Mozilla\Firefox\Profiles\6e0cxt63.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\John Balestrieri\Local Settings\Application Data\Mozilla\Firefox\Profiles\6e0cxt63.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\John Balestrieri\Local Settings\Application Data\Mozilla\Firefox\Profiles\6e0cxt63.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\John Balestrieri\Local Settings\Application Data\Mozilla\Firefox\Profiles\6e0cxt63.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\John Balestrieri\Local Settings\Application Data\Mozilla\Firefox\Profiles\6e0cxt63.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.

OTMoveIt3 by OldTimer - Version 1.0.10.0 log created on 04022009_055950

Files moved on Reboot…
File C:\DOCUME~1\JOHNBA~1\LOCALS~1\Temp\etilqs_7dq8LGJW5HJo3zjamt4j not found!
File C:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_5b0.dat not found!
C:\WINDOWS\temp\WebEx\Log\330\atnthost.log moved successfully.
C:\WINDOWS\temp\mcafee_xK8L8YZccxPCb4m moved successfully.
File C:\WINDOWS\temp\mcmsc_1voUL173yzg5MB8 not found!
C:\WINDOWS\temp\mcmsc_EFn41tpMdBKVnxP moved successfully.
File C:\WINDOWS\temp\mcmsc_F8fPlKHXQhFuwSf not found!
File C:\WINDOWS\temp\mcmsc_FOgFqmJyRJyKb1k not found!
C:\WINDOWS\temp\mcmsc_FyrnRYTmavvGIRB moved successfully.
File C:\WINDOWS\temp\mcmsc_zYycoxUFZWbkwgb not found!
File C:\WINDOWS\temp\Perflib_Perfdata_148.dat not found!
File C:\WINDOWS\temp\Perflib_Perfdata_b1c.dat not found!
File C:\WINDOWS\temp\Perflib_Perfdata_d48.dat not found!
File C:\WINDOWS\temp\sqlite_06wiNk92HHfUxEx not found!
File C:\WINDOWS\temp\sqlite_9f3ffvn2DqwM8uM not found!
C:\WINDOWS\temp\sqlite_gM2DJwu8KB91aff moved successfully.
File C:\WINDOWS\temp\sqlite_HjxWuLoft0nTfgH not found!
C:\WINDOWS\temp\sqlite_RUSmTRTxUMlk457 moved successfully.
File C:\WINDOWS\temp\sqlite_UWmY19lnLlmQrzp not found!
C:\WINDOWS\temp\sqlite_V3LpFWllBcVZqRk moved successfully.
C:\Documents and Settings\John Balestrieri\Local Settings\Application Data\Mozilla\Firefox\Profiles\6e0cxt63.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\John Balestrieri\Local Settings\Application Data\Mozilla\Firefox\Profiles\6e0cxt63.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\John Balestrieri\Local Settings\Application Data\Mozilla\Firefox\Profiles\6e0cxt63.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\John Balestrieri\Local Settings\Application Data\Mozilla\Firefox\Profiles\6e0cxt63.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\John Balestrieri\Local Settings\Application Data\Mozilla\Firefox\Profiles\6e0cxt63.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\John Balestrieri\Local Settings\Application Data\Mozilla\Firefox\Profiles\6e0cxt63.default\XUL.mfl moved successfully.



_________________

——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Thursday, April 2, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Thursday, April 02, 2009 13:40:24
Records in database: 1999196
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
F:\

Scan statistics:
Files scanned: 163813
Threat name: 1
Infected objects: 0
Suspicious objects: 4
Duration of the scan: 03:40:12


File name / Threat name / Threats count
C:\Documents and Settings\All Users\Application Data\McAfee\MSK\Users\2\Front\1\M0000002483.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Documents and Settings\All Users\Application Data\McAfee\MSK\Users\2\Front\1\M0000004309.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Documents and Settings\All Users\Application Data\McAfee\MSK\Users\2\Front\1\M0000007052.eml Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Documents and Settings\All Users\Application Data\McAfee\MSK\Users\2\Front\1\M0000007052.msg Suspicious: Trojan-Spy.HTML.Fraud.gen 1

The selected area was scanned.


_______________________

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:06:15 PM, on 4/2/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\DOWNLO~1\MyWebEx\319\atnthost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\DOWNLO~1\MyWebEx\319\RAAGTAPP.EXE
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\McAfee\MSC\mcshell.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1061118
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msnbc.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1061118
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [eFax 4.3] "C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\3.19.0.16\PlaxoHelper_en.exe -a
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [PlaxoSysTray] C:\Program Files\Plaxo\3.19.0.16\PlaxoSysTray.exe
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan
O4 - HKCU\..\Run: [DelayShred] c:\PROGRA~1\mcafee\mshr\ShrCL.EXE /P1 /q C:\WINDOWS\system32\wdmaud.SH!
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-21-687441275-498809504-2873672193-1011\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe (User 'QBDataServiceUser19')
O4 - HKUS\S-1-5-21-687441275-498809504-2873672193-1011\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup (User 'QBDataServiceUser19')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: eFax 4.3.lnk = C:\Program Files\eFax Messenger 4.3\J2GTray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Remote Access.LNK = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} (ContactExtractor Class) - http://www.facebook.com/controls/contactx.dll
O16 - DPF: {8AA1AE9E-9FB0-41B3-8911-89A1068A7FD1} (Installer Class) - https://www.wirelesssync.vzw.com/en/SyncInstall.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://qb.webex.com/client/v_mywebex-qb20/ra/ieatgpc.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: WebEx Remote Access Agent (atnthost) - WebEx Communications, Inc. - C:\WINDOWS\DOWNLO~1\MyWebEx\319\atnthost.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: QuickBooksDB19 - Intuit, Inc. - C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE (file missing)

–
End of file - 15177 bytes
Hello,

  • Double click on OTMoveIt3.exe to run it.
  • Please copy and paste the following in the Code box into OTMoveIt3 (1).

    Warning: Do not type it out to prevent any typo errors and damaging your machine.

    :Files
    C:\Documents and Settings\All Users\Application Data\McAfee\MSK\Users\2\Front\1\M0000002483.eml
    C:\Documents and Settings\All Users\Application Data\McAfee\MSK\Users\2\Front\1\M0000004309.eml
    C:\Documents and Settings\All Users\Application Data\McAfee\MSK\Users\2\Front\1\M0000007052.eml
    C:\Documents and Settings\All Users\Application Data\McAfee\MSK\Users\2\Front\1\M0000007052.msg

    Please refer to this image to use OTMoveIt3.

    [external image: Posted Image]

  • Click on MoveIt! (2)
  • Click Exit (3) when done.

In your next reply, please include:
  • How is your computer running now?
  • OTMoveIt results
  • A new HijackThis log

Regards,
Adam
The browser is still hijacked. McAfee no longer says there is anything wrong. But you can not do a search without the browser being redirected.

Moveit log did not appear, so I am not posting it here. Where would it be?

Here is the Hijackit Log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:21:42 PM, on 4/2/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\DOWNLO~1\MyWebEx\319\atnthost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\DOWNLO~1\MyWebEx\319\RAAGTAPP.EXE
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\MI1933~1\OFFICE11\OUTLOOK.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1061118
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msnbc.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1061118
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [eFax 4.3] "C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\3.19.0.16\PlaxoHelper_en.exe -a
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [PlaxoSysTray] C:\Program Files\Plaxo\3.19.0.16\PlaxoSysTray.exe
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan
O4 - HKCU\..\Run: [DelayShred] c:\PROGRA~1\mcafee\mshr\ShrCL.EXE /P1 /q C:\WINDOWS\system32\wdmaud.SH!
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-21-687441275-498809504-2873672193-1011\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe (User 'QBDataServiceUser19')
O4 - HKUS\S-1-5-21-687441275-498809504-2873672193-1011\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup (User 'QBDataServiceUser19')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: eFax 4.3.lnk = C:\Program Files\eFax Messenger 4.3\J2GTray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Remote Access.LNK = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} (ContactExtractor Class) - http://www.facebook.com/controls/contactx.dll
O16 - DPF: {8AA1AE9E-9FB0-41B3-8911-89A1068A7FD1} (Installer Class) - https://www.wirelesssync.vzw.com/en/SyncInstall.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://qb.webex.com/client/v_mywebex-qb20/ra/ieatgpc.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: WebEx Remote Access Agent (atnthost) - WebEx Communications, Inc. - C:\WINDOWS\DOWNLO~1\MyWebEx\319\atnthost.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: QuickBooksDB19 - Intuit, Inc. - C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE (file missing)

–
End of file - 15207 bytes
Hmmm, ok. Let's investigate this further.

Run GMER
Please download gmer.zip from Gmer and save it to your desktop.

  • Right click on gmer.zip and select Extract All….
  • Click Next on seeing the Welcome to the Compressed (zipped) Folders Extraction Wizard.
  • Click on the Browse button. Click on Desktop. Then click OK.
  • Click Next. It will start extracting.
  • Once done, check (tick) the Show extracted files box and click Finish.
  • Double click on gmer.exe to run it.
  • Select the Rootkit tab.
  • On the right hand side, check all the items to be scanned, but leave Show All box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click on the Scan button.
  • When the scan is finished, click Copy to save the scan log to the Windows clipboard.
  • Open Notepad or a similar text editor.
  • Paste the clipboard contents into the text editor.
  • Save the Gmer scan log and post it in your next reply.
  • Close Gmer.
  • Open Command Prompt by going to Start > Run and type in cmd. Press Enter.
  • In Command Prompt, type in net stop gmer. Press Enter.
  • Type in exit to close Command Prompt.

Note: Do not run any programs while Gmer is running.

Export a registry key

Copy/paste the following code into a new notepad (not wordpad) document.
regedit /e look.txt "HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32"
notepad look.txt
del /q look.txt

Save it to your Desktop as look.bat. Save it as File Type: All Files (not as a text document or it wont work).

Locate look.bat on your Desktop and double-click it.
When Notepad opens, copy/paste the content in your reply.
When you close Notepad, the command window will close automatically and the text file will be deleted.

In your next reply, please include:
  • GMER log
  • Look.txt contents
  • A new HijackThis log

Regards,
Adam
I have attached the gmer.zip file that I just downloaded, odds are the infection is blocking you from visiting the site. Please use the file I attached and post that you have downloaded it when you have so that I can remove it so noone else downloads it. Regards Adam
Gmer is running. I can't remember if I meantioned that I can't open a command promte or regedit. It's a smart little bugger. I also for the hell of it tried a couple sites. It blocked. Bleepingcomputers. Now worries I am doing this from my iPhone.
GMER 1.0.15.14966 - http://www.gmer.net
Rootkit scan 2009-04-03 08:59:33
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xAA23344A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xAA2334E1]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xAA2333F8]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xAA23340C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xAA2334F5]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xAA233521]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xAA23358F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xAA233579]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xAA23348A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xAA2335BB]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xAA2334CD]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xAA2333D0]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xAA2333E4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xAA23345E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xAA2335F7]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xAA233563]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xAA23354D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xAA23350B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xAA2335E3]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xAA2335CF]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xAA233436]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xAA233422]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xAA233537]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xAA2334B9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xAA2335A5]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xAA2334A0]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xAA233474]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwYieldExecution 8050223C 7 Bytes JMP AA233478 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtCreateFile 8056E2FC 5 Bytes JMP AA23344E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 805A7500 7 Bytes JMP AA23348E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805A8316 5 Bytes JMP AA2334A4 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 805ADA94 7 Bytes JMP AA233462 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess 805C1322 5 Bytes JMP AA2333D4 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 805C15AE 5 Bytes JMP AA2333E8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetInformationProcess 805C3DE0 5 Bytes JMP AA233426 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805C73F6 7 Bytes JMP AA233410 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcess 805C74AC 5 Bytes JMP AA2333FC \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetContextThread 805C79B6 5 Bytes JMP AA23343A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805C8CB6 5 Bytes JMP AA2334BD \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryValueKey 8061854A 7 Bytes JMP AA233551 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetValueKey 80618898 7 Bytes JMP AA23353B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnloadKey 80618BC2 7 Bytes JMP AA2335A9 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryMultipleValueKey 80619460 7 Bytes JMP AA233567 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRenameKey 80619D34 7 Bytes JMP AA23350F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateKey 8061A312 5 Bytes JMP AA2334E5 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteKey 8061A7A2 7 Bytes JMP AA2334F9 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteValueKey 8061A972 7 Bytes JMP AA233525 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateKey 8061AB52 7 Bytes JMP AA233593 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateValueKey 8061ADBC 7 Bytes JMP AA23357D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwOpenKey 8061B6E4 5 Bytes JMP AA2334D1 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryKey 8061BA0A 7 Bytes JMP AA2335FB \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRestoreKey 8061BCCA 5 Bytes JMP AA2335D3 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwReplaceKey 8061C3BE 5 Bytes JMP AA2335E7 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwNotifyChangeKey 8061C4D8 5 Bytes JMP AA2335BF \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
? System32\Drivers\hiber_WMILIB.SYS The system cannot find the path specified. !

—- User code sections - GMER 1.0.15 —-

.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 10900000
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 10900F8A
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 10900F9B
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 10900FB6
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 10900FC7
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 10900058
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 1090009A
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 10900F52
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 109000E4
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10900F41
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 10900F30
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 10900069
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 1090001B
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 10900F6F
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 10900047
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 1090002C
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 109000B5
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 108E004B
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] msvcrt.dll!system 77C293C7 5 Bytes JMP 108E003A
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 108E0018
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] msvcrt.dll!_open 77C2F566 5 Bytes JMP 108E0FEF
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 108E0029
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 108E0FDE
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 108F0FC3
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 108F0F83
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 108F0FD4
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 108F0FE5
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 108F0040
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 108F0000
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 108F0025
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 108F0FA8
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] ws2_32.dll!socket 71AB4211 5 Bytes JMP 108D0FEF
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] wininet.dll!InternetOpenA 6302B2D5 5 Bytes JMP 108C0FEF
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] wininet.dll!InternetOpenW 6302B92E 5 Bytes JMP 108C0FDE
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] wininet.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 108C0FC3
.text c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[144] wininet.dll!InternetOpenUrlW 63077347 5 Bytes JMP 108C001E
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[192] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10183428
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[192] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10183370
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[192] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10182BF8
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[192] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10182440
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[192] WS2_32.dll!recv 71AB676F 5 Bytes JMP 101823C4
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[192] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10183324
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[264] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0041C130 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[264] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 0041C1B0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[332] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003428
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[332] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[332] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[332] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[332] WS2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[332] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text C:\WINDOWS\system32\winlogon.exe[784] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003428
.text C:\WINDOWS\system32\winlogon.exe[784] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text C:\WINDOWS\system32\winlogon.exe[784] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINDOWS\system32\winlogon.exe[784] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINDOWS\system32\winlogon.exe[784] WS2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINDOWS\system32\winlogon.exe[784] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text C:\WINDOWS\system32\services.exe[828] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 0110000A
.text C:\WINDOWS\system32\services.exe[828] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01100058
.text C:\WINDOWS\system32\services.exe[828] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01100F63
.text C:\WINDOWS\system32\services.exe[828] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0110003D
.text C:\WINDOWS\system32\services.exe[828] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01100F80
.text C:\WINDOWS\system32\services.exe[828] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0110002C
.text C:\WINDOWS\system32\services.exe[828] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01100F32
.text C:\WINDOWS\system32\services.exe[828] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01100084
.text C:\WINDOWS\system32\services.exe[828] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01100F21
.text C:\WINDOWS\system32\services.exe[828] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 011000B0
.text C:\WINDOWS\system32\services.exe[828] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 01100EFC
.text C:\WINDOWS\system32\services.exe[828] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 01100F9B
.text C:\WINDOWS\system32\services.exe[828] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 0110001B
.text C:\WINDOWS\system32\services.exe[828] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 01100069
.text C:\WINDOWS\system32\services.exe[828] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 01100FCA
.text C:\WINDOWS\system32\services.exe[828] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 01100FE5
.text C:\WINDOWS\system32\services.exe[828] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 0110009F
.text C:\WINDOWS\system32\services.exe[828] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 010F0025
.text C:\WINDOWS\system32\services.exe[828] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 010F0F83
.text C:\WINDOWS\system32\services.exe[828] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 010F0FDE
.text C:\WINDOWS\system32\services.exe[828] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 010F000A
.text C:\WINDOWS\system32\services.exe[828] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 010F0F9E
.text C:\WINDOWS\system32\services.exe[828] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 010F0FEF
.text C:\WINDOWS\system32\services.exe[828] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 010F004A
.text C:\WINDOWS\system32\services.exe[828] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 010F0FB9
.text C:\WINDOWS\system32\services.exe[828] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 010E0053
.text C:\WINDOWS\system32\services.exe[828] msvcrt.dll!system 77C293C7 5 Bytes JMP 010E0038
.text C:\WINDOWS\system32\services.exe[828] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 010E000C
.text C:\WINDOWS\system32\services.exe[828] msvcrt.dll!_open 77C2F566 5 Bytes JMP 010E0FE3
.text C:\WINDOWS\system32\services.exe[828] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 010E001D
.text C:\WINDOWS\system32\services.exe[828] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 010E0FD2
.text C:\WINDOWS\system32\services.exe[828] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FF0FEF
.text C:\WINDOWS\system32\lsass.exe[840] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F60FEF
.text C:\WINDOWS\system32\lsass.exe[840] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F60F61
.text C:\WINDOWS\system32\lsass.exe[840] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F60060
.text C:\WINDOWS\system32\lsass.exe[840] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F60F7C
.text C:\WINDOWS\system32\lsass.exe[840] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F60F8D
.text C:\WINDOWS\system32\lsass.exe[840] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F60FA8
.text C:\WINDOWS\system32\lsass.exe[840] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F60085
.text C:\WINDOWS\system32\lsass.exe[840] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F60F3F
.text C:\WINDOWS\system32\lsass.exe[840] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F60F11
.text C:\WINDOWS\system32\lsass.exe[840] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F60F22
.text C:\WINDOWS\system32\lsass.exe[840] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00F60F00
.text C:\WINDOWS\system32\lsass.exe[840] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00F6002F
.text C:\WINDOWS\system32\lsass.exe[840] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00F6000A
.text C:\WINDOWS\system32\lsass.exe[840] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00F60F50
.text C:\WINDOWS\system32\lsass.exe[840] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00F60FB9
.text C:\WINDOWS\system32\lsass.exe[840] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00F60FD4
.text C:\WINDOWS\system32\lsass.exe[840] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00F600A0
.text C:\WINDOWS\system32\lsass.exe[840] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00F50011
.text C:\WINDOWS\system32\lsass.exe[840] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00F50F91
.text C:\WINDOWS\system32\lsass.exe[840] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00F50FC0
.text C:\WINDOWS\system32\lsass.exe[840] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00F50000
.text C:\WINDOWS\system32\lsass.exe[840] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00F5004E
.text C:\WINDOWS\system32\lsass.exe[840] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00F50FEF
.text C:\WINDOWS\system32\lsass.exe[840] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00F5003D
.text C:\WINDOWS\system32\lsass.exe[840] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00F5002C
.text C:\WINDOWS\system32\lsass.exe[840] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00F40FAD
.text C:\WINDOWS\system32\lsass.exe[840] msvcrt.dll!system 77C293C7 5 Bytes JMP 00F40038
.text C:\WINDOWS\system32\lsass.exe[840] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00F40FD2
.text C:\WINDOWS\system32\lsass.exe[840] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00F40FEF
.text C:\WINDOWS\system32\lsass.exe[840] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00F4001D
.text C:\WINDOWS\system32\lsass.exe[840] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00F4000C
.text C:\WINDOWS\system32\lsass.exe[840] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00F30FEF
.text C:\WINDOWS\system32\lsass.exe[840] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text C:\WINDOWS\system32\lsass.exe[840] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINDOWS\system32\lsass.exe[840] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINDOWS\system32\lsass.exe[840] WS2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINDOWS\system32\lsass.exe[840] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text C:\WINDOWS\system32\lsass.exe[840] wininet.dll!InternetOpenA 6302B2D5 5 Bytes JMP 00F20FEF
.text C:\WINDOWS\system32\lsass.exe[840] wininet.dll!InternetOpenW 6302B92E 5 Bytes JMP 00F2000A
.text C:\WINDOWS\system32\lsass.exe[840] wininet.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 00F20025
.text C:\WINDOWS\system32\lsass.exe[840] wininet.dll!InternetOpenUrlW 63077347 5 Bytes JMP 00F20FD4
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00D20000
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00D200A1
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00D20090
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00D20FB6
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00D20FC7
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00D20062
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00D20F74
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00D20F85
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D20103
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D200F2
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00D2011E
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00D20073
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00D20025
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00D200B2
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00D20051
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00D20040
.text C:\WINDOWS\system32\svchost.exe[1004] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00D200D7
.text C:\WINDOWS\system32\svchost.exe[1004] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00D10F9E
.text C:\WINDOWS\system32\svchost.exe[1004] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00D10F79
.text C:\WINDOWS\system32\svchost.exe[1004] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00D10FB9
.text C:\WINDOWS\system32\svchost.exe[1004] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00D10FD4
.text C:\WINDOWS\system32\svchost.exe[1004] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00D10036
.text C:\WINDOWS\system32\svchost.exe[1004] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00D10FE5
.text C:\WINDOWS\system32\svchost.exe[1004] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00D10025
.text C:\WINDOWS\system32\svchost.exe[1004] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00D10014
.text C:\WINDOWS\system32\svchost.exe[1004] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00D00F90
.text C:\WINDOWS\system32\svchost.exe[1004] msvcrt.dll!system 77C293C7 5 Bytes JMP 00D0001B
.text C:\WINDOWS\system32\svchost.exe[1004] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00D00FAB
.text C:\WINDOWS\system32\svchost.exe[1004] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00D00FE3
.text C:\WINDOWS\system32\svchost.exe[1004] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00D00000
.text C:\WINDOWS\system32\svchost.exe[1004] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00D00FD2
.text C:\WINDOWS\system32\svchost.exe[1004] ws2_32.dll!socket 71AB4211 5 Bytes JMP 00CF0000
.text C:\WINDOWS\system32\svchost.exe[1004] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text C:\WINDOWS\system32\svchost.exe[1004] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINDOWS\system32\svchost.exe[1004] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINDOWS\system32\svchost.exe[1004] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINDOWS\system32\svchost.exe[1004] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text C:\WINDOWS\system32\svchost.exe[1004] wininet.dll!InternetOpenA 6302B2D5 5 Bytes JMP 00CE0FEF
.text C:\WINDOWS\system32\svchost.exe[1004] wininet.dll!InternetOpenW 6302B92E 5 Bytes JMP 00CE0000
.text C:\WINDOWS\system32\svchost.exe[1004] wininet.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 00CE0FD4
.text C:\WINDOWS\system32\svchost.exe[1004] wininet.dll!InternetOpenUrlW 63077347 5 Bytes JMP 00CE0025
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[1044] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003428
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[1044] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[1044] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[1044] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[1044] WS2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[1044] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F60FE5
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F60F9B
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F60090
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F6007F
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F60062
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F60FC0
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F600B7
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F60F6F
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F600ED
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F60F54
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00F60108
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00F60047
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00F60000
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00F60F80
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00F6002C
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00F6001B
.text C:\WINDOWS\system32\svchost.exe[1072] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00F600D2
.text C:\WINDOWS\system32\svchost.exe[1072] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00F50FB2
.text C:\WINDOWS\system32\svchost.exe[1072] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00F50F97
.text C:\WINDOWS\system32\svchost.exe[1072] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00F50FC3
.text C:\WINDOWS\system32\svchost.exe[1072] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00F50FDE
.text C:\WINDOWS\system32\svchost.exe[1072] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00F50054
.text C:\WINDOWS\system32\svchost.exe[1072] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00F50FEF
.text C:\WINDOWS\system32\svchost.exe[1072] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00F50043
.text C:\WINDOWS\system32\svchost.exe[1072] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00F5001E
.text C:\WINDOWS\system32\svchost.exe[1072] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00F40F9C
.text C:\WINDOWS\system32\svchost.exe[1072] msvcrt.dll!system 77C293C7 5 Bytes JMP 00F40FB7
.text C:\WINDOWS\system32\svchost.exe[1072] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00F4001D
.text C:\WINDOWS\system32\svchost.exe[1072] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00F40FE3
.text C:\WINDOWS\system32\svchost.exe[1072] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00F40FC8
.text C:\WINDOWS\system32\svchost.exe[1072] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00F4000C
.text C:\WINDOWS\system32\svchost.exe[1072] ws2_32.dll!socket 71AB4211 5 Bytes JMP 00F30FEF
.text C:\WINDOWS\system32\svchost.exe[1072] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text C:\WINDOWS\system32\svchost.exe[1072] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINDOWS\system32\svchost.exe[1072] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINDOWS\system32\svchost.exe[1072] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINDOWS\system32\svchost.exe[1072] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text C:\WINDOWS\system32\svchost.exe[1072] wininet.dll!InternetOpenA 6302B2D5 5 Bytes JMP 00F20FEF
.text C:\WINDOWS\system32\svchost.exe[1072] wininet.dll!InternetOpenW 6302B92E 5 Bytes JMP 00F20FDE
.text C:\WINDOWS\system32\svchost.exe[1072] wininet.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 00F20FCD
.text C:\WINDOWS\system32\svchost.exe[1072] wininet.dll!InternetOpenUrlW 63077347 5 Bytes JMP 00F20014
.text C:\WINDOWS\System32\svchost.exe[1116] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 028B0000
.text C:\WINDOWS\System32\svchost.exe[1116] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 028B0F63
.text C:\WINDOWS\System32\svchost.exe[1116] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 028B0F7E
.text C:\WINDOWS\System32\svchost.exe[1116] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 028B0062
.text C:\WINDOWS\System32\svchost.exe[1116] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 028B0FAF
.text C:\WINDOWS\System32\svchost.exe[1116] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 028B0FCA
.text C:\WINDOWS\System32\svchost.exe[1116] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 028B009A
.text C:\WINDOWS\System32\svchost.exe[1116] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 028B007F
.text C:\WINDOWS\System32\svchost.exe[1116] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 028B0F23
.text C:\WINDOWS\System32\svchost.exe[1116] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 028B00C6
.text C:\WINDOWS\System32\svchost.exe[1116] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 028B00D7
.text C:\WINDOWS\System32\svchost.exe[1116] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 028B0051
.text C:\WINDOWS\System32\svchost.exe[1116] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 028B0FE5
.text C:\WINDOWS\System32\svchost.exe[1116] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 028B0F52
.text C:\WINDOWS\System32\svchost.exe[1116] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 028B002C
.text C:\WINDOWS\System32\svchost.exe[1116] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 028B001B
.text C:\WINDOWS\System32\svchost.exe[1116] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 028B00B5
.text C:\WINDOWS\System32\svchost.exe[1116] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 028A0FA5
.text C:\WINDOWS\System32\svchost.exe[1116] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 028A0025
.text C:\WINDOWS\System32\svchost.exe[1116] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 028A0FCA
.text C:\WINDOWS\System32\svchost.exe[1116] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 028A0000
.text C:\WINDOWS\System32\svchost.exe[1116] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 028A0F68
.text C:\WINDOWS\System32\svchost.exe[1116] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 028A0FE5
.text C:\WINDOWS\System32\svchost.exe[1116] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 028A0F79
.text C:\WINDOWS\System32\svchost.exe[1116] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [AA, 8A]
.text C:\WINDOWS\System32\svchost.exe[1116] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 028A0F8A
.text C:\WINDOWS\System32\svchost.exe[1116] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 02890F86
.text C:\WINDOWS\System32\svchost.exe[1116] msvcrt.dll!system 77C293C7 5 Bytes JMP 0289001B
.text C:\WINDOWS\System32\svchost.exe[1116] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 02890FC6
.text C:\WINDOWS\System32\svchost.exe[1116] msvcrt.dll!_open 77C2F566 5 Bytes JMP 02890FEF
.text C:\WINDOWS\System32\svchost.exe[1116] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 02890FAB
.text C:\WINDOWS\System32\svchost.exe[1116] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 02890000
.text C:\WINDOWS\System32\svchost.exe[1116] ws2_32.dll!socket 71AB4211 5 Bytes JMP 02880000
.text C:\WINDOWS\System32\svchost.exe[1116] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text C:\WINDOWS\System32\svchost.exe[1116] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINDOWS\System32\svchost.exe[1116] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINDOWS\System32\svchost.exe[1116] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINDOWS\System32\svchost.exe[1116] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text C:\WINDOWS\System32\svchost.exe[1116] wininet.dll!InternetOpenA 6302B2D5 5 Bytes JMP 02870FE5
.text C:\WINDOWS\System32\svchost.exe[1116] wininet.dll!InternetOpenW 6302B92E 5 Bytes JMP 02870000
.text C:\WINDOWS\System32\svchost.exe[1116] wininet.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 02870FC0
.text C:\WINDOWS\System32\svchost.exe[1116] wininet.dll!InternetOpenUrlW 63077347 5 Bytes JMP 02870FAF
.text C:\WINDOWS\system32\svchost.exe[1192] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BB0000
.text C:\WINDOWS\system32\svchost.exe[1192] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BB00A9
.text C:\WINDOWS\system32\svchost.exe[1192] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BB0FB4
.text C:\WINDOWS\system32\svchost.exe[1192] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BB008E
.text C:\WINDOWS\system32\svchost.exe[1192] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BB0FD1
.text C:\WINDOWS\system32\svchost.exe[1192] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BB0058
.text C:\WINDOWS\system32\svchost.exe[1192] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BB00DA
.text C:\WINDOWS\system32\svchost.exe[1192] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BB0F92
.text C:\WINDOWS\system32\svchost.exe[1192] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BB0117
.text C:\WINDOWS\system32\svchost.exe[1192] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BB0106
.text C:\WINDOWS\system32\svchost.exe[1192] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00BB0132
.text C:\WINDOWS\system32\svchost.exe[1192] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00BB0073
.text C:\WINDOWS\system32\svchost.exe[1192] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00BB0025
.text C:\WINDOWS\system32\svchost.exe[1192] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00BB0FA3
.text C:\WINDOWS\system32\svchost.exe[1192] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00BB0047
.text C:\WINDOWS\system32\svchost.exe[1192] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00BB0036
.text C:\WINDOWS\system32\svchost.exe[1192] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00BB00F5
.text C:\WINDOWS\system32\svchost.exe[1192] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00BA0033
.text C:\WINDOWS\system32\svchost.exe[1192] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00BA0FA5
.text C:\WINDOWS\system32\svchost.exe[1192] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00BA0022
.text C:\WINDOWS\system32\svchost.exe[1192] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00BA0011
.text C:\WINDOWS\system32\svchost.exe[1192] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00BA0FB6
.text C:\WINDOWS\system32\svchost.exe[1192] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00BA0000
.text C:\WINDOWS\system32\svchost.exe[1192] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00BA0058
.text C:\WINDOWS\system32\svchost.exe[1192] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00BA0FD1
.text C:\WINDOWS\system32\svchost.exe[1192] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00B90F99
.text C:\WINDOWS\system32\svchost.exe[1192] msvcrt.dll!system 77C293C7 5 Bytes JMP 00B9002E
.text C:\WINDOWS\system32\svchost.exe[1192] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00B90FE3
.text C:\WINDOWS\system32\svchost.exe[1192] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00B90000
.text C:\WINDOWS\system32\svchost.exe[1192] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00B90FBE
.text C:\WINDOWS\system32\svchost.exe[1192] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00B9001D
.text C:\WINDOWS\system32\svchost.exe[1192] ws2_32.dll!socket 71AB4211 5 Bytes JMP 00B80FEF
.text C:\WINDOWS\system32\svchost.exe[1192] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text C:\WINDOWS\system32\svchost.exe[1192] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINDOWS\system32\svchost.exe[1192] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINDOWS\system32\svchost.exe[1192] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINDOWS\system32\svchost.exe[1192] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text C:\WINDOWS\system32\svchost.exe[1192] wininet.dll!InternetOpenA 6302B2D5 5 Bytes JMP 00B60FEF
.text C:\WINDOWS\system32\svchost.exe[1192] wininet.dll!InternetOpenW 6302B92E 5 Bytes JMP 00B60FD4
.text C:\WINDOWS\system32\svchost.exe[1192] wininet.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 00B60FB9
.text C:\WINDOWS\system32\svchost.exe[1192] wininet.dll!InternetOpenUrlW 63077347 5 Bytes JMP 00B6000A
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C80FE5
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C80098
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C8007D
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C8006C
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C80051
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C80040
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C80F50
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C80F6D
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C800E9
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C800D8
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00C80F3F
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00C80FB9
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00C80000
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00C80F7E
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00C8001B
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00C80FCA
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00C800B3
.text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00B80047
.text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00B80FAC
.text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00B80036
.text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00B80011
.text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00B80FBD
.text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00B80000
.text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00B80069
.text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00B80058
.text C:\WINDOWS\system32\svchost.exe[1312] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00B7005F
.text C:\WINDOWS\system32\svchost.exe[1312] msvcrt.dll!system 77C293C7 5 Bytes JMP 00B7004E
.text C:\WINDOWS\system32\svchost.exe[1312] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00B70FEF
.text C:\WINDOWS\system32\svchost.exe[1312] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00B7000C
.text C:\WINDOWS\system32\svchost.exe[1312] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00B70FD4
.text C:\WINDOWS\system32\svchost.exe[1312] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00B70029
.text C:\WINDOWS\system32\svchost.exe[1312] ws2_32.dll!socket 71AB4211 5 Bytes JMP 00B60000
.text C:\WINDOWS\system32\svchost.exe[1312] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text C:\WINDOWS\system32\svchost.exe[1312] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINDOWS\system32\svchost.exe[1312] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINDOWS\system32\svchost.exe[1312] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINDOWS\system32\svchost.exe[1312] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text C:\WINDOWS\system32\svchost.exe[1312] wininet.dll!InternetOpenA 6302B2D5 5 Bytes JMP 00B50FEF
.text C:\WINDOWS\system32\svchost.exe[1312] wininet.dll!InternetOpenW 6302B92E 5 Bytes JMP 00B5000A
.text C:\WINDOWS\system32\svchost.exe[1312] wininet.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 00B50025
.text C:\WINDOWS\system32\svchost.exe[1312] wininet.dll!InternetOpenUrlW 63077347 5 Bytes JMP 00B50FCA
.text C:\Program Files\McAfee\MSK\MskSrver.exe[1424] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003428
.text C:\Program Files\McAfee\MSK\MskSrver.exe[1424] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text C:\Program Files\McAfee\MSK\MskSrver.exe[1424] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\Program Files\McAfee\MSK\MskSrver.exe[1424] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\Program Files\McAfee\MSK\MskSrver.exe[1424] WS2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\Program Files\McAfee\MSK\MskSrver.exe[1424] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text C:\WINDOWS\system32\wuauclt.exe[1452] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001B0FE5
.text C:\WINDOWS\system32\wuauclt.exe[1452] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001B0F81
.text C:\WINDOWS\system32\wuauclt.exe[1452] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001B0076
.text C:\WINDOWS\system32\wuauclt.exe[1452] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001B0F9C
.text C:\WINDOWS\system32\wuauclt.exe[1452] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001B0FB9
.text C:\WINDOWS\system32\wuauclt.exe[1452] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001B0040
.text C:\WINDOWS\system32\wuauclt.exe[1452] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001B00BF
.text C:\WINDOWS\system32\wuauclt.exe[1452] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001B0098
.text C:\WINDOWS\system32\wuauclt.exe[1452] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001B00FC
.text C:\WINDOWS\system32\wuauclt.exe[1452] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001B00E1
.text C:\WINDOWS\system32\wuauclt.exe[1452] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 001B0F3E
.text C:\WINDOWS\system32\wuauclt.exe[1452] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 001B005B
.text C:\WINDOWS\system32\wuauclt.exe[1452] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 001B0FD4
.text C:\WINDOWS\system32\wuauclt.exe[1452] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 001B0087
.text C:\WINDOWS\system32\wuauclt.exe[1452] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 001B002F
.text C:\WINDOWS\system32\wuauclt.exe[1452] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 001B000A
.text C:\WINDOWS\system32\wuauclt.exe[1452] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 001B00D0
.text C:\WINDOWS\system32\wuauclt.exe[1452] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 002A0064
.text C:\WINDOWS\system32\wuauclt.exe[1452] msvcrt.dll!system 77C293C7 5 Bytes JMP 002A0053
.text C:\WINDOWS\system32\wuauclt.exe[1452] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 002A0027
.text C:\WINDOWS\system32\wuauclt.exe[1452] msvcrt.dll!_open 77C2F566 5 Bytes JMP 002A0000
.text C:\WINDOWS\system32\wuauclt.exe[1452] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 002A0038
.text C:\WINDOWS\system32\wuauclt.exe[1452] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 002A0FEF
.text C:\WINDOWS\system32\wuauclt.exe[1452] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 002B0FE5
.text C:\WINDOWS\system32\wuauclt.exe[1452] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 002B0F94
.text C:\WINDOWS\system32\wuauclt.exe[1452] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 002B0036
.text C:\WINDOWS\system32\wuauclt.exe[1452] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 002B001B
.text C:\WINDOWS\system32\wuauclt.exe[1452] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 002B0051
.text C:\WINDOWS\system32\wuauclt.exe[1452] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 002B0000
.text C:\WINDOWS\system32\wuauclt.exe[1452] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 002B0FAF
.text C:\WINDOWS\system32\wuauclt.exe[1452] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [4B, 88]
.text C:\WINDOWS\system32\wuauclt.exe[1452] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 002B0FCA
.text C:\WINDOWS\system32\wuauclt.exe[1452] WS2_32.dll!socket 71AB4211 5 Bytes JMP 003C000A
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02780000
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 027800B3
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02780FC8
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 027800A2
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02780FE5
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02780062
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02780F86
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 027800CE
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02780104
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 027800F3
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 0278011F
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 0278007D
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 0278001B
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 02780FA3
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 02780051
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 02780036
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 02780F75
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 02770FD4
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 02770F72
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 02770FE5
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 02770011
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 02770F8D
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 02770000
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 02770F9E
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [97, 8A]
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 02770FC3
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00F80025
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] msvcrt.dll!system 77C293C7 5 Bytes JMP 00F80FA4
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00F80FC6
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00F80FE3
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00F80FB5
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00F80000
.text C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe[1516] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00F70FEF
.text C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe[1536] KERNEL32.dll!CreateProcessW 7C802336 5 Bytes JMP 10053428
.text C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe[1536] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10053370
.text C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe[1536] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10052BF8
.text C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe[1536] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10052440
.text C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe[1536] WS2_32.dll!recv 71AB676F 5 Bytes JMP 100523C4
.text C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe[1536] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10053324
.text C:\WINDOWS\system32\spoolsv.exe[1600] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003428
.text C:\WINDOWS\system32\spoolsv.exe[1600] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text C:\WINDOWS\system32\spoolsv.exe[1600] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINDOWS\system32\spoolsv.exe[1600] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINDOWS\system32\spoolsv.exe[1600] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINDOWS\system32\spoolsv.exe[1600] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe[1708] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003428
.text C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe[1708] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe[1708] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe[1708] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe[1708] WS2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe[1708] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text C:\WINDOWS\DOWNLO~1\MyWebEx\319\RAAGTAPP.EXE[1812] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10013428
.text C:\WINDOWS\DOWNLO~1\MyWebEx\319\RAAGTAPP.EXE[1812] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10013370
.text C:\WINDOWS\DOWNLO~1\MyWebEx\319\RAAGTAPP.EXE[1812] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10012BF8
.text C:\WINDOWS\DOWNLO~1\MyWebEx\319\RAAGTAPP.EXE[1812] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10012440
.text C:\WINDOWS\DOWNLO~1\MyWebEx\319\RAAGTAPP.EXE[1812] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100123C4
.text C:\WINDOWS\DOWNLO~1\MyWebEx\319\RAAGTAPP.EXE[1812] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10013324
.text C:\WINDOWS\system32\cisvc.exe[1828] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003428
.text C:\WINDOWS\system32\cisvc.exe[1828] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text C:\WINDOWS\system32\cisvc.exe[1828] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINDOWS\system32\cisvc.exe[1828] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINDOWS\system32\cisvc.exe[1828] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINDOWS\system32\cisvc.exe[1828] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00D10000
.text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00D100BD
.text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00D100A2
.text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00D10FD4
.text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00D10FE5
.text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00D1006C
.text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00D10F81
.text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00D10F92
.text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D100E4
.text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D10F4B
.text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00D10F30
.text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00D1007D
.text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00D10025
.text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00D10FAD
.text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00D1005B
.text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00D10040
.text C:\WINDOWS\system32\svchost.exe[1868] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00D10F70
.text C:\WINDOWS\system32\svchost.exe[1868] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00D00FDE
.text C:\WINDOWS\system32\svchost.exe[1868] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00D00079
.text C:\WINDOWS\system32\svchost.exe[1868] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00D0002F
.text C:\WINDOWS\system32\svchost.exe[1868] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00D00FEF
.text C:\WINDOWS\system32\svchost.exe[1868] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00D00FBC
.text C:\WINDOWS\system32\svchost.exe[1868] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00D0000A
.text C:\WINDOWS\system32\svchost.exe[1868] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00D00054
.text C:\WINDOWS\system32\svchost.exe[1868] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00D00FCD
.text C:\WINDOWS\system32\svchost.exe[1868] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00CF0FB7
.text C:\WINDOWS\system32\svchost.exe[1868] msvcrt.dll!system 77C293C7 5 Bytes JMP 00CF0042
.text C:\WINDOWS\system32\svchost.exe[1868] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00CF001D
.text C:\WINDOWS\system32\svchost.exe[1868] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00CF0000
.text C:\WINDOWS\system32\svchost.exe[1868] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00CF0FD2
.text C:\WINDOWS\system32\svchost.exe[1868] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00CF0FE3
.text C:\WINDOWS\system32\svchost.exe[1868] ws2_32.dll!socket 71AB4211 5 Bytes JMP 00CE0000
.text C:\WINDOWS\system32\svchost.exe[1868] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text C:\WINDOWS\system32\svchost.exe[1868] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINDOWS\system32\svchost.exe[1868] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINDOWS\system32\svchost.exe[1868] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINDOWS\system32\svchost.exe[1868] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text C:\WINDOWS\system32\svchost.exe[1868] wininet.dll!InternetOpenA 6302B2D5 5 Bytes JMP 00CD0000
.text C:\WINDOWS\system32\svchost.exe[1868] wininet.dll!InternetOpenW 6302B92E 5 Bytes JMP 00CD0FEF
.text C:\WINDOWS\system32\svchost.exe[1868] wininet.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 00CD002F
.text C:\WINDOWS\system32\svchost.exe[1868] wininet.dll!InternetOpenUrlW 63077347 5 Bytes JMP 00CD0040
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[2032] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003428
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[2032] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[2032] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[2032] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[2032] WS2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[2032] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text C:\WINDOWS\System32\alg.exe[2096] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003428
.text C:\WINDOWS\System32\alg.exe[2096] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text C:\WINDOWS\System32\alg.exe[2096] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINDOWS\System32\alg.exe[2096] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINDOWS\System32\alg.exe[2096] WS2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINDOWS\System32\alg.exe[2096] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text C:\WINDOWS\explorer.exe[2352] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001A0000
.text C:\WINDOWS\explorer.exe[2352] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001A00B5
.text C:\WINDOWS\explorer.exe[2352] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001A0FCA
.text C:\WINDOWS\explorer.exe[2352] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001A00A4
.text C:\WINDOWS\explorer.exe[2352] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001A007D
.text C:\WINDOWS\explorer.exe[2352] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001A0062
.text C:\WINDOWS\explorer.exe[2352] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001A0F92
.text C:\WINDOWS\explorer.exe[2352] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001A00DA
.text C:\WINDOWS\explorer.exe[2352] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001A0121
.text C:\WINDOWS\explorer.exe[2352] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001A0106
.text C:\WINDOWS\explorer.exe[2352] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 001A0F77
.text C:\WINDOWS\explorer.exe[2352] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 001A0FDB
.text C:\WINDOWS\explorer.exe[2352] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 001A001B
.text C:\WINDOWS\explorer.exe[2352] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 001A0FAF
.text C:\WINDOWS\explorer.exe[2352] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 001A003D
.text C:\WINDOWS\explorer.exe[2352] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 001A002C
.text C:\WINDOWS\explorer.exe[2352] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 001A00F5
.text C:\WINDOWS\explorer.exe[2352] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 0029002C
.text C:\WINDOWS\explorer.exe[2352] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00290087
.text C:\WINDOWS\explorer.exe[2352] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00290FE5
.text C:\WINDOWS\explorer.exe[2352] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 0029001B
.text C:\WINDOWS\explorer.exe[2352] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 0029006C
.text C:\WINDOWS\explorer.exe[2352] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00290000
.text C:\WINDOWS\explorer.exe[2352] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 0029005B
.text C:\WINDOWS\explorer.exe[2352] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00290FCA
.text C:\WINDOWS\explorer.exe[2352] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 002A0FC3
.text C:\WINDOWS\explorer.exe[2352] msvcrt.dll!system 77C293C7 5 Bytes JMP 002A0FD4
.text C:\WINDOWS\explorer.exe[2352] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 002A0029
.text C:\WINDOWS\explorer.exe[2352] msvcrt.dll!_open 77C2F566 5 Bytes JMP 002A0FEF
.text C:\WINDOWS\explorer.exe[2352] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 002A003A
.text C:\WINDOWS\explorer.exe[2352] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 002A0018
.text C:\WINDOWS\explorer.exe[2352] WININET.dll!InternetOpenA 6302B2D5 5 Bytes JMP 002C0FE5
.text C:\WINDOWS\explorer.exe[2352] WININET.dll!InternetOpenW 6302B92E 5 Bytes JMP 002C0FD4
.text C:\WINDOWS\explorer.exe[2352] WININET.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 002C0FC3
.text C:\WINDOWS\explorer.exe[2352] WININET.dll!InternetOpenUrlW 63077347 5 Bytes JMP 002C000A
.text C:\WINDOWS\explorer.exe[2352] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00DF0000
.text C:\WINDOWS\system32\cidaemon.exe[2496] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003428
.text C:\WINDOWS\system32\cidaemon.exe[2496] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text C:\WINDOWS\system32\cidaemon.exe[2496] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINDOWS\system32\cidaemon.exe[2496] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINDOWS\system32\cidaemon.exe[2496] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINDOWS\system32\cidaemon.exe[2496] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2764] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10013428
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2764] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10013370
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2764] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10012BF8
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2764] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10012440
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2764] WS2_32.dll!recv 71AB676F 5 Bytes JMP 100123C4
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2764] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10013324
.text C:\WINDOWS\system32\svchost.exe[2864] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 0088000A
.text C:\WINDOWS\system32\svchost.exe[2864] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 0088006E
.text C:\WINDOWS\system32\svchost.exe[2864] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00880F79
.text C:\WINDOWS\system32\svchost.exe[2864] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00880053
.text C:\WINDOWS\system32\svchost.exe[2864] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00880F8A
.text C:\WINDOWS\system32\svchost.exe[2864] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00880FB6
.text C:\WINDOWS\system32\svchost.exe[2864] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00880F4A
.text C:\WINDOWS\system32\svchost.exe[2864] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00880090
.text C:\WINDOWS\system32\svchost.exe[2864] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 008800C8
.text C:\WINDOWS\system32\svchost.exe[2864] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00880F39
.text C:\WINDOWS\system32\svchost.exe[2864] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 008800D9
.text C:\WINDOWS\system32\svchost.exe[2864] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00880FA5
.text C:\WINDOWS\system32\svchost.exe[2864] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00880FEF
.text C:\WINDOWS\system32\svchost.exe[2864] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 0088007F
.text C:\WINDOWS\system32\svchost.exe[2864] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 0088002C
.text C:\WINDOWS\system32\svchost.exe[2864] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 0088001B
.text C:\WINDOWS\system32\svchost.exe[2864] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 008800AD
.text C:\WINDOWS\system32\svchost.exe[2864] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00870036
.text C:\WINDOWS\system32\svchost.exe[2864] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00870FA8
.text C:\WINDOWS\system32\svchost.exe[2864] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 0087001B
.text C:\WINDOWS\system32\svchost.exe[2864] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00870FE5
.text C:\WINDOWS\system32\svchost.exe[2864] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00870065
.text C:\WINDOWS\system32\svchost.exe[2864] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00870000
.text C:\WINDOWS\system32\svchost.exe[2864] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 00870FB9
.text C:\WINDOWS\system32\svchost.exe[2864] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [A7, 88]
.text C:\WINDOWS\system32\svchost.exe[2864] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00870FCA
.text C:\WINDOWS\system32\svchost.exe[2864] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00860049
.text C:\WINDOWS\system32\svchost.exe[2864] msvcrt.dll!system 77C293C7 5 Bytes JMP 00860038
.text C:\WINDOWS\system32\svchost.exe[2864] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00860FE3
.text C:\WINDOWS\system32\svchost.exe[2864] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00860000
.text C:\WINDOWS\system32\svchost.exe[2864] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00860FC8
.text C:\WINDOWS\system32\svchost.exe[2864] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0086001D
.text C:\WINDOWS\system32\svchost.exe[2864] ws2_32.dll!socket 71AB4211 5 Bytes JMP 00850000
.text C:\WINDOWS\system32\svchost.exe[2864] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text C:\WINDOWS\system32\svchost.exe[2864] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINDOWS\system32\svchost.exe[2864] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINDOWS\system32\svchost.exe[2864] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINDOWS\system32\svchost.exe[2864] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text C:\WINDOWS\system32\svchost.exe[2864] wininet.dll!InternetOpenA 6302B2D5 5 Bytes JMP 00840FE5
.text C:\WINDOWS\system32\svchost.exe[2864] wininet.dll!InternetOpenW 6302B92E 5 Bytes JMP 00840000
.text C:\WINDOWS\system32\svchost.exe[2864] wininet.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 0084001B
.text C:\WINDOWS\system32\svchost.exe[2864] wininet.dll!InternetOpenUrlW 63077347 5 Bytes JMP 0084002C
.text C:\WINDOWS\system32\cidaemon.exe[3944] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003428
.text C:\WINDOWS\system32\cidaemon.exe[3944] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text C:\WINDOWS\system32\cidaemon.exe[3944] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINDOWS\system32\cidaemon.exe[3944] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINDOWS\system32\cidaemon.exe[3944] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINDOWS\system32\cidaemon.exe[3944] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text C:\WINDOWS\system32\ctfmon.exe[3996] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003428
.text C:\WINDOWS\system32\ctfmon.exe[3996] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text C:\WINDOWS\system32\ctfmon.exe[3996] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINDOWS\system32\ctfmon.exe[3996] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINDOWS\system32\ctfmon.exe[3996] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINDOWS\system32\ctfmon.exe[3996] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00250FE5
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 002500A4
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00250089
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00250078
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0025005B
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00250040
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00250F6D
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 002500B5
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10013428
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 002500C6
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 002500F2
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00250FAF
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 0025000A
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00250F94
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 0025002F
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00250FD4
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00250F52
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00350025
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00350F83
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00350014
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00350FD4
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00350F94
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00350FEF
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00350036
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00350FB9
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00360FAD
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] msvcrt.dll!system 77C293C7 5 Bytes JMP 00360FBE
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0036001D
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00360FEF
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0036002E
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0036000C
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] ws2_32.dll!socket 71AB4211 5 Bytes JMP 09F90FE5
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10013370
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10012BF8
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10012440
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100123C4
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10013324
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] wininet.dll!InternetOpenA 6302B2D5 5 Bytes JMP 09FA0FEF
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] wininet.dll!InternetOpenW 6302B92E 5 Bytes JMP 09FA0FDE
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] wininet.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 09FA000A
.text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[4268] wininet.dll!InternetOpenUrlW 63077347 5 Bytes JMP 09FA0FB9
.text C:\WINDOWS\System32\svchost.exe[4468] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001A0000
.text C:\WINDOWS\System32\svchost.exe[4468] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001A007A
.text C:\WINDOWS\System32\svchost.exe[4468] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001A0069
.text C:\WINDOWS\System32\svchost.exe[4468] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001A0058
.text C:\WINDOWS\System32\svchost.exe[4468] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001A0F9B
.text C:\WINDOWS\System32\svchost.exe[4468] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001A0022
.text C:\WINDOWS\System32\svchost.exe[4468] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001A00C3
.text C:\WINDOWS\System32\svchost.exe[4468] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001A00A6
.text C:\WINDOWS\System32\svchost.exe[4468] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003428
.text C:\WINDOWS\System32\svchost.exe[4468] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001A00E5
.text C:\WINDOWS\System32\svchost.exe[4468] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 001A0F42
.text C:\WINDOWS\System32\svchost.exe[4468] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 001A0033
.text C:\WINDOWS\System32\svchost.exe[4468] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 001A0011
.text C:\WINDOWS\System32\svchost.exe[4468] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 001A0095
.text C:\WINDOWS\System32\svchost.exe[4468] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 001A0FB6
.text C:\WINDOWS\System32\svchost.exe[4468] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 001A0FD1
.text C:\WINDOWS\System32\svchost.exe[4468] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 001A00D4
.text C:\WINDOWS\System32\svchost.exe[4468] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00290000
.text C:\WINDOWS\System32\svchost.exe[4468] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00290036
.text C:\WINDOWS\System32\svchost.exe[4468] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00290FB9
.text C:\WINDOWS\System32\svchost.exe[4468] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00290FD4
.text C:\WINDOWS\System32\svchost.exe[4468] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00290F79
.text C:\WINDOWS\System32\svchost.exe[4468] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00290FEF
.text C:\WINDOWS\System32\svchost.exe[4468] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00290011
.text C:\WINDOWS\System32\svchost.exe[4468] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00290F8A
.text C:\WINDOWS\System32\svchost.exe[4468] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 003E0FA1
.text C:\WINDOWS\System32\svchost.exe[4468] msvcrt.dll!system 77C293C7 5 Bytes JMP 003E0022
.text C:\WINDOWS\System32\svchost.exe[4468] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 003E0FCD
.text C:\WINDOWS\System32\svchost.exe[4468] msvcrt.dll!_open 77C2F566 5 Bytes JMP 003E0000
.text C:\WINDOWS\System32\svchost.exe[4468] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 003E0FB2
.text C:\WINDOWS\System32\svchost.exe[4468] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 003E0011
.text C:\WINDOWS\System32\svchost.exe[4468] ws2_32.dll!socket 71AB4211 5 Bytes JMP 006A0000
.text C:\WINDOWS\System32\svchost.exe[4468] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text C:\WINDOWS\System32\svchost.exe[4468] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINDOWS\System32\svchost.exe[4468] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINDOWS\System32\svchost.exe[4468] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINDOWS\System32\svchost.exe[4468] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text C:\WINDOWS\System32\svchost.exe[4468] wininet.dll!InternetOpenA 6302B2D5 5 Bytes JMP 006B0FEF
.text C:\WINDOWS\System32\svchost.exe[4468] wininet.dll!InternetOpenW 6302B92E 5 Bytes JMP 006B000A
.text C:\WINDOWS\System32\svchost.exe[4468] wininet.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 006B001B
.text C:\WINDOWS\System32\svchost.exe[4468] wininet.dll!InternetOpenUrlW 63077347 5 Bytes JMP 006B0036
.text C:\WINDOWS\system32\svchost.exe[5272] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001A0000
.text C:\WINDOWS\system32\svchost.exe[5272] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001A0F5F
.text C:\WINDOWS\system32\svchost.exe[5272] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001A0F7A
.text C:\WINDOWS\system32\svchost.exe[5272] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001A0F97
.text C:\WINDOWS\system32\svchost.exe[5272] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001A0FA8
.text C:\WINDOWS\system32\svchost.exe[5272] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001A0FD4
.text C:\WINDOWS\system32\svchost.exe[5272] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001A0094
.text C:\WINDOWS\system32\svchost.exe[5272] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001A0F4E
.text C:\WINDOWS\system32\svchost.exe[5272] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003428
.text C:\WINDOWS\system32\svchost.exe[5272] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001A0F16
.text C:\WINDOWS\system32\svchost.exe[5272] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 001A00CA
.text C:\WINDOWS\system32\svchost.exe[5272] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 001A0FC3
.text C:\WINDOWS\system32\svchost.exe[5272] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 001A001B
.text C:\WINDOWS\system32\svchost.exe[5272] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 001A006F
.text C:\WINDOWS\system32\svchost.exe[5272] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 001A0FE5
.text C:\WINDOWS\system32\svchost.exe[5272] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 001A0036
.text C:\WINDOWS\system32\svchost.exe[5272] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 001A0F31
.text C:\WINDOWS\system32\svchost.exe[5272] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 0029003D
.text C:\WINDOWS\system32\svchost.exe[5272] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00290062
.text C:\WINDOWS\system32\svchost.exe[5272] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 0029002C
.text C:\WINDOWS\system32\svchost.exe[5272] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 0029001B
.text C:\WINDOWS\system32\svchost.exe[5272] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00290FA5
.text C:\WINDOWS\system32\svchost.exe[5272] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00290000
.text C:\WINDOWS\system32\svchost.exe[5272] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 00290FC0
.text C:\WINDOWS\system32\svchost.exe[5272] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [49, 88]
.text C:\WINDOWS\system32\svchost.exe[5272] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00290FD1
.text C:\WINDOWS\system32\svchost.exe[5272] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 003E0FB4
.text C:\WINDOWS\system32\svchost.exe[5272] msvcrt.dll!system 77C293C7 5 Bytes JMP 003E003F
.text C:\WINDOWS\system32\svchost.exe[5272] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 003E001D
.text C:\WINDOWS\system32\svchost.exe[5272] msvcrt.dll!_open 77C2F566 5 Bytes JMP 003E0FEF
.text C:\WINDOWS\system32\svchost.exe[5272] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 003E002E
.text C:\WINDOWS\system32\svchost.exe[5272] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 003E000C
.text C:\WINDOWS\system32\svchost.exe[5272] ws2_32.dll!socket 71AB4211 5 Bytes JMP 00930000
.text C:\WINDOWS\system32\svchost.exe[5272] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003370
.text C:\WINDOWS\system32\svchost.exe[5272] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10002BF8
.text C:\WINDOWS\system32\svchost.exe[5272] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 10002440
.text C:\WINDOWS\system32\svchost.exe[5272] ws2_32.dll!recv 71AB676F 5 Bytes JMP 100023C4
.text C:\WINDOWS\system32\svchost.exe[5272] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003324
.text C:\WINDOWS\system32\svchost.exe[5272] wininet.dll!InternetOpenA 6302B2D5 5 Bytes JMP 00940000
.text C:\WINDOWS\system32\svchost.exe[5272] wininet.dll!InternetOpenW 6302B92E 5 Bytes JMP 00940FEF
.text C:\WINDOWS\system32\svchost.exe[5272] wininet.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 0094001B
.text C:\WINDOWS\system32\svchost.exe[5272] wininet.dll!InternetOpenUrlW 63077347 5 Bytes JMP 00940FD4

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)

Device \FileSystem\Fastfat \Fat A7EC5D20

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

—- EOF - GMER 1.0.15 —-


Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midimapper"="midimap.dll"
"msacm.imaadpcm"="imaadp32.acm"
"msacm.msadpcm"="msadp32.acm"
"msacm.msg711"="msg711.acm"
"msacm.msgsm610"="msgsm32.acm"
"msacm.trspch"="tssoft32.acm"
"vidc.cvid"="iccvid.dll"
"VIDC.I420"="msh263.drv"
"vidc.iv31"="ir32_32.dll"
"vidc.iv32"="ir32_32.dll"
"vidc.iv41"="ir41_32.ax"
"VIDC.IYUV"="iyuv_32.dll"
"vidc.mrle"="msrle32.dll"
"vidc.msvc"="msvidc32.dll"
"VIDC.UYVY"="msyuv.dll"
"VIDC.YUY2"="msyuv.dll"
"VIDC.YVU9"="tsbyuv.dll"
"VIDC.YVYU"="msyuv.dll"
"wavemapper"="msacm32.drv"
"msacm.msg723"="msg723.acm"
"vidc.M263"="msh263.drv"
"vidc.M261"="msh261.drv"
"msacm.msaudio1"="msaud32.acm"
"msacm.sl_anet"="sl_anet.acm"
"msacm.iac2"="C:\\WINDOWS\\system32\\iac25_32.ax"
"vidc.iv50"="ir50_32.dll"
"msacm.l3acm"="C:\\WINDOWS\\system32\\l3codeca.acm"
"wave"="wdmaud.drv"
"midi"="wdmaud.drv"
"mixer"="wdmaud.drv"
"MSVideo8"="VfWWDM32.dll"
"msacm.siren"="sirenacm.dll"
"aux"="C:\\WINDOWS\\system32\\..\\vpnfp.bwq"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32\Terminal Server]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32\Terminal Server\RDP]
"wave"="rdpsnd.dll"
"mixer"="rdpsnd.dll"
"MaxBandwidth"=dword:000056b9
"wavemapper"="msacm32.drv"
"EnableMP3Codec"=dword:00000001
"midimapper"="midimap.dll"

——
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:02:02 AM, on 4/3/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\DOWNLO~1\MyWebEx\319\atnthost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\DOWNLO~1\MyWebEx\319\RAAGTAPP.EXE
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\explorer.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1061118
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msnbc.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1061118
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [eFax 4.3] "C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\3.19.0.16\PlaxoHelper_en.exe -a
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [PlaxoSysTray] C:\Program Files\Plaxo\3.19.0.16\PlaxoSysTray.exe
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan
O4 - HKCU\..\Run: [DelayShred] c:\PROGRA~1\mcafee\mshr\ShrCL.EXE /P1 /q C:\WINDOWS\system32\wdmaud.SH!
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-21-687441275-498809504-2873672193-1011\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe (User 'QBDataServiceUser19')
O4 - HKUS\S-1-5-21-687441275-498809504-2873672193-1011\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup (User 'QBDataServiceUser19')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: eFax 4.3.lnk = C:\Program Files\eFax Messenger 4.3\J2GTray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Remote Access.LNK = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} (ContactExtractor Class) - http://www.facebook.com/controls/contactx.dll
O16 - DPF: {8AA1AE9E-9FB0-41B3-8911-89A1068A7FD1} (Installer Class) - https://www.wirelesssync.vzw.com/en/SyncInstall.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://qb.webex.com/client/v_mywebex-qb20/ra/ieatgpc.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: WebEx Remote Access Agent (atnthost) - WebEx Communications, Inc. - C:\WINDOWS\DOWNLO~1\MyWebEx\319\atnthost.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: QuickBooksDB19 - Intuit, Inc. - C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE (file missing)

–
End of file - 15193 bytes
Hmmm.. still nothing is showing up.

Download and Run ComboFix
Please visit this page to download and run Combofix - http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Save it to your desktop.

  • Double click on ComboFix.exe & follow the prompts.
  • As part of its process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. You will see the following message if Microsoft Windows Recovery Console is not installed.

    [external image: Posted Image]

    With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes to continue scanning for malware.

When finished, a log will be produced. Please post this log in your next reply along with a new HijackThis log.

Do not mouse click on Combofix while it is running. That may cause it to stall.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI