This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Browser redirect, McAfee update/website blocked

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I first noticed the problem when using Google to search for websites. IWhen I clicked on the links provided I was taken to advertising sites instead of the intended one. Clicking the back button would often (but not always) return me to the site I wanted. My preferred browser is Firefox, which first exhibited the problem, but I have noticed it as well with IE. Both programs will now crash unexpectedly. When I noticed the problem I saw that McAfee Security Center was not working properly. I attempted to update it, but it was not able to download the update. I tried their website, and it timed out each time I tried.

I tried to run the hijackthis log through a couple of the online analyzers (knowing that they would likely miss alot, but curious what they would find). One came up with some questionable, but no "bad" entries. Another came up with some questionable entries and the two "bad" entries below…

O3 - Toolbar: WeatherBug Browser Bar - powered by MyWebSearch - {8EAB99C9-F9EC-4b64-A4BA-D9BCAE8779C2} - C:\Program Files\MyWebSearchWB\bar\1.bin\W6BAR.DLL (file missing)
File Missing
When a file is missing, you should always have HijackThis fix the item.


O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
Ctfmon.exe
"CoolWebSearch Ctfmon32 parasite variant"

I did not act on the "information" knowing is may be inaccurate, but I thought it might help to mention it. The full log is provided below…

________________________________________________________________________________
_____________

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:47:09 PM, on 4/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CSHelper.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.netzero.net/s/sp?r=al&cf=sp&…amp;O=A&UT=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Popup-Blocker Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\x1IEBHO.dll
O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\SearchSuggest\YSearchSuggest.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: CDelHotkeys Object - {78875F5C-A685-4405-8DC5-D48DC65452B0} - C:\Program Files\Delicious Add-on for Internet Explorer\DeliciousExtension.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: WeatherBug Browser Bar - powered by MyWebSearch - {8EAB99C9-F9EC-4b64-A4BA-D9BCAE8779C2} - C:\Program Files\MyWebSearchWB\bar\1.bin\W6BAR.DLL (file missing)
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Delicious Toolbar - {61D1C847-DF80-423A-8C6D-DC03B97E6EBE} - C:\Program Files\Delicious Add-on for Internet Explorer\DeliciousExtension.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - Global Startup: $McRebootA5E6DEAA56$.lnk = C:\WINDOWS\system32\cmd.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: Event Planner Reminder 2009.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Delicious - {2C887991-08F0-11DC-A9B2-0012F0B227DD} - C:\Program Files\Delicious Add-on for Internet Explorer\DeliciousExtension.dll
O9 - Extra button: Bookmarks - {2C887992-08F0-11DC-A9B2-0012F0B227DD} - C:\Program Files\Delicious Add-on for Internet Explorer\DeliciousExtension.dll
O9 - Extra button: Tag - {2C887993-08F0-11DC-A9B2-0012F0B227DD} - C:\Program Files\Delicious Add-on for Internet Explorer\DeliciousExtension.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.mcafee.com
O15 - Trusted Zone: http://*.turbotax.com
O15 - Trusted Zone: http://www.wahm.com
O16 - DPF: Photobucket Publisher - http://pic.photobucket.com/plugins/csve/ph…t_publisher.CAB
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://www.worldwinner.com/games/v47/share…GamesLoader.cab
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/US/install.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/41.22/uploader2.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/…loadcontrol.cab
O16 - DPF: {AE6C4705-0F11-4ACB-BDD4-37F138BEF289} (Image Uploader Control) - http://meijer.lifepics.com/net/Uploader/LPUploader41.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/in…l/installer.exe
O16 - DPF: {EBF85371-A38F-485B-B28F-0B4C82D25937} (CUpdateCtl Object) - http://update.hpphoto.com/download/HPSWUpdate.ocx
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:\WINDOWS\system32\CSHelper.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Update Service (gupdate1c9b6f041015082) (gupdate1c9b6f041015082) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe

–
End of file - 17887 bytes
Hi,

Please do the following:

  • Open HiJackThis
  • Click on Do a system scan only
  • Check the boxes next to ONLY the entries listed below (if still present):

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
O3 - Toolbar: WeatherBug Browser Bar - powered by MyWebSearch - {8EAB99C9-F9EC-4b64-A4BA-D9BCAE8779C2} - C:\Program Files\MyWebSearchWB\bar\1.bin\W6BAR.DLL (file missing)
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab


  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.

>>>NEXT<<<

Please do the following

Please download ATF Cleaner by Atribune.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
    • If you use Firefox browser
    • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
It's normal after running ATF cleaner that the PC will be slower to boot the first time.



>>>NEXT<<<

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


In your next reply I need

  • MBAM Log
  • FreshHJT Log
Thanks for the help! Okay here goes….

None of the items in HJT that you mentioned were still there when I ran it.
Ran ATF Cleaner
Ran MBAM, and it detected nothing bad to clean. Log is included below.
Ran HJT again and included the log below.

I check my browser, and am still experiencing the same problem (browser redirect in google, and mcaffe.com blocked)

______________________________________

Here is the MBAM log..


Malwarebytes' Anti-Malware 1.36
Database version: 1945
Windows 5.1.2600 Service Pack 2

4/18/2009 1:23:19 PM
mbam-log-2009-04-18 (13-23-19).txt

Scan type: Quick Scan
Objects scanned: 81651
Time elapsed: 4 minute(s), 46 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

__________________________________________

Here is the new HJT log…


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:24:28 PM, on 4/18/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\OPLIMIT\ocrawr32.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
F3 - REG:win.ini: load=C:\OPLIMIT\ocraware.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBarBHO.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: Aurigma Image Uploader 2.0 - http://www.photogize.com/PhotogizeImageUploader.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/45.19/uploader2.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…96/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - Unknown owner - c:\program files\mcafee.com\agent\mcdetect.exe (file missing)
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/BRIANM~1/LOCALS~1/Temp/msohtml1/01/clip_image002.gif

–
End of file - 12563 bytes
Hi,

Please do this:

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Double-click GooredFix.exe to run it.
  • Select 1. Find Goored (no fix) by typing 1 and pressing Enter.
  • A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).
Note: Do not run Option #2 yet.


>>>NEXT<<<

  • Go to Start > Control Panel, and choose Network Connections.
  • Right click on your default connection, usually Local Area Connection for cable and DSL or Dial-up Connection if you are using Dial-up, and choose Properties.
  • Click the Networking tab
  • Double-click on the Internet Protocol (TCP/IP) item.
  • Write down the settings in case you should need to change them back.
  • Select the radio button that says "Obtain DNS servers automatically".
  • Click OK twice to get out of the properties screen and restart your computer.
  • If not prompted to reboot go ahead and reboot manually.
CAUTION: It's possible that your ISP (Internet Service Provider) requires specific DNS settings here. Make sure you know if you need these settings or not BEFORE you make any changes or you may lose your Internet connection. If you're sure you do not need a specific DNS address, then you may proceed.
  • Now go to Start > Run > type: cmd
  • Press OK or Hit Enter.
  • At the command prompt, type or copy/paste: ipconfig /flushdns (note the space between “..g /f…” it needs to be there)
  • Hit Enter.
  • You will get a confirmation that the flush was successful.
  • Close the command box.


>>>NEXT<<<


  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt.
    Note:These logs can be located in the OTListIt2. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
okay… I ran gooredfix which produced the log below… GooredFix v1.92 by jpshortstuff Log created at 13:59 on 18/04/2009 running Option #1 (Brian McCrohan) Firefox version 3.0.8 (en-US) =====Suspect Goored Entries===== =====Dumping Registry Values===== [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.8\extensions] "Plugins"="C:\Program Files\Mozilla Firefox\plugins" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.8\extensions] "Components"="C:\Program Files\Mozilla Firefox\components" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions] "[removed]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions] "{B7082FAA-CB62-4872-9106-E42DD88EDE45}"="C:\Program Files\McAfee\SiteAdvisor" ________________________________________________________________________________ ___ Next I checked the properties of my default connection (which is a wireless connection) and saw that "Obtain DNS servers automatically" was already checked. Oddly enough though, when I went to run and typed "cmd" the command prompt didn't pop up. What happens is this… the screen (except my desktop wallpaper) blanks for a moment, and then the desktop repopulates itself. Additionally, when I attempted to start it through Start > All Programs > Accessories > Command Prompt I get the same results. With this unexpected glitch I thought I would stop and check in. Thoughts?
I noticed that the next step was simply another scan, so I went ahead and ran the OTListIt2. I am including the two logs below. Hope this helps…

OTListIt.txt

OTListIt logfile created on: 4/18/2009 3:25:07 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Brian McCrohan\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.98 Mb Total Physical Memory | 258.91 Mb Available Physical Memory | 50.67% Memory free
1.22 Gb Paging File | 0.73 Gb Available in Paging File | 59.79% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.53 Gb Total Space | 4.15 Gb Free Space | 21.23% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Unable to calculate disk information.
Drive F: | 19.53 Gb Total Space | 1.41 Gb Free Space | 7.20% Space Free | Partition Type: NTFS
Drive G: | 19.53 Gb Total Space | 19.47 Gb Free Space | 99.67% Space Free | Partition Type: NTFS
Drive H: | 19.53 Gb Total Space | 7.00 Gb Free Space | 35.85% Space Free | Partition Type: NTFS
Drive I: | 19.53 Gb Total Space | 19.46 Gb Free Space | 99.61% Space Free | Partition Type: NTFS
Drive J: | 14.04 Gb Total Space | 13.96 Gb Free Space | 99.45% Space Free | Partition Type: NTFS
Drive K: | 232.83 Gb Total Space | 74.43 Gb Free Space | 31.97% Space Free | Partition Type: FAT32

Computer Name: HAL
Current User Name: Brian McCrohan
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\system32\ntvdm.exe (Microsoft Corporation)
PRC - C:\WINDOWS\BCMSMMSG.exe (Broadcom Corporation)
PRC - C:\WINDOWS\SM1BG.EXE (Cypress Semiconductor)
PRC - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LMIGuardian.exe (LogMeIn, Inc.)
PRC - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe (Musicmatch, Inc.)
PRC - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe (Musicmatch, Inc.)
PRC - C:\OPLIMIT\ocrawr32.exe (Caere Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LMIGuardian.exe (LogMeIn, Inc.)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MSK\MskSrver.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\wltrysvc.exe ()
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\WINDOWS\system32\cidaemon.exe (Microsoft Corporation)
PRC - C:\Program Files\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\bcmwltry.exe (Belkin Corporation)
PRC - C:\Documents and Settings\Brian McCrohan\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (CCALib8 [Auto | Running]) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (LMIMaint [Auto | Running]) – C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (LogMeIn [Auto | Running]) – C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (MBackMonitor [On_Demand | Stopped]) – C:\Program Files\McAfee\MBK\MBackMonitor.exe (McAfee)
SRV - (McAfee SiteAdvisor Service [Auto | Running]) – C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
SRV - (McDetect.exe [Auto | Stopped]) – File not found
SRV - (mcmscsvc [Auto | Running]) – C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (McNASvc [Auto | Running]) – c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
SRV - (McODS [On_Demand | Stopped]) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McProxy [Auto | Running]) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McShield [Unknown | Running]) – C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon [Disabled | Stopped]) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (mcupdmgr.exe [On_Demand | Stopped]) – File not found
SRV - (MpfService [Auto | Running]) – C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (MSK80Service [Auto | Running]) – C:\Program Files\McAfee\MSK\MskSrver.exe (McAfee, Inc.)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (Pml Driver HPZ12 [On_Demand | Stopped]) – C:\WINDOWS\System32\HPZipm12.exe (HP)
SRV - (sprtsvc_ddoctorv2 [Auto | Running]) – C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (UleadBurningHelper [Auto | Running]) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (UMWdf [Auto | Running]) – C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
SRV - (WLTRYSVC [Auto | Running]) – C:\WINDOWS\System32\wltrysvc.exe ()

========== Driver Services (SafeList) ==========

DRV - (61883 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\61883.sys (Microsoft Corporation)
DRV - (AFS2K [System | Running]) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (AnyDVD [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (Aspi32 [Auto | Running]) – C:\WINDOWS\System32\drivers\aspi32.BAK (Adaptec)
DRV - (Avc [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\avc.sys (Microsoft Corporation)
DRV - (BCM43XX [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\bcmwl5.sys (Broadcom Corporation)
DRV - (BCMModem [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\BCMSM.sys (Broadcom Corporation)
DRV - (Cdr4_xp [System | Stopped]) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (Cdralw2k [System | Stopped]) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (cdudf_xp [System | Running]) – C:\WINDOWS\System32\drivers\Cdudf_xp.sys (Roxio)
DRV - (DVDVRRdr_xp [System | Running]) – C:\WINDOWS\System32\drivers\DVDVRRdr_xp.sys (Windows ® 2000 DDK provider)
DRV - (dvd_2K [On_Demand | Running]) – C:\WINDOWS\System32\drivers\dvd_2k.sys (Roxio)
DRV - (E100B [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (ElbyCDIO [Auto | Running]) – C:\WINDOWS\System32\Drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HPZid412 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HPZius12.sys (HP)
DRV - (itchfltr [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\itchfltr.sys (Logitech, Inc.)
DRV - (L8042pr2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\L8042pr2.Sys (Logitech, Inc.)
DRV - (LMIInfo [Auto | Running]) – C:\Program Files\LogMeIn\x86\RaInfo.sys (LogMeIn, Inc.)
DRV - (LMImirr [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\LMImirr.sys (LogMeIn, Inc.)
DRV - (LMIRfsClientNP [Disabled | Stopped]) – C:\WINDOWS\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (LMIRfsDriver [Auto | Running]) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMouFlt2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\LMouFlt2.Sys (Logitech, Inc.)
DRV - (MDC8021X [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (mfeavfk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfebopk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk [System | Running]) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (mfesmfk [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mmc_2K [On_Demand | Running]) – C:\WINDOWS\System32\drivers\mmc_2k.sys (Roxio)
DRV - (MODEMCSA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (MPFP [System | Running]) – C:\WINDOWS\System32\Drivers\Mpfp.sys (McAfee, Inc.)
DRV - (MSDV [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\msdv.sys (Microsoft Corporation)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (NwlnkIpx [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\nwlnkipx.sys (Microsoft Corporation)
DRV - (NwlnkNb [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\nwlnkspx.sys (Microsoft Corporation)
DRV - (OMCI [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
DRV - (P16X [On_Demand | Running]) – C:\WINDOWS\system32\drivers\P16X.sys (Creative Technology Ltd.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (pwd_2k [System | Running]) – C:\WINDOWS\System32\drivers\Pwd_2k.sys (Roxio)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (SASDIFSV [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM [On_Demand | Running]) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (TVICHW32 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS (EnTech Taiwan)
DRV - (UDFReadr [System | Running]) – C:\WINDOWS\System32\drivers\Udfreadr.sys (Roxio)
DRV - (UdfReadr_xp [System | Running]) – C:\WINDOWS\System32\drivers\udfreadr_xp.sys (Roxio)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://home.microsoft.com/access/autosearch.asp?p=%s
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1;localhost;*.local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:2.6.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.406
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:2.9
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.07076007
FF - prefs.js..extensions.enabledItems: unplug@compunach:1.6.06
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8

FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\PROGRAM FILES\MCAFEE\SITEADVISOR [2009/03/31 07:34:00 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2008/12/13 15:47:53 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/10 21:08:41 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/31 13:04:25 | 00,000,000 | —D | M]

[2009/01/10 09:39:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\mozilla\Extensions
[2009/01/10 09:39:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/18 13:19:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\mozilla\Firefox\Profiles\74hu8np7.default\extensions
[2008/07/21 08:48:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\mozilla\Firefox\Profiles\74hu8np7.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2007/05/04 08:50:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\mozilla\Firefox\Profiles\74hu8np7.default\extensions\{DD99D76F-5129-4fd3-A2DC-AB41D6FBCF98}
[2009/02/19 10:18:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\mozilla\Firefox\Profiles\74hu8np7.default\extensions\[removed]
[2008/03/03 21:46:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\mozilla\Firefox\Profiles\74hu8np7.default\extensions\[removed]
[2008/01/10 16:22:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\mozilla\Firefox\Profiles\74hu8np7.default\extensions\unplug@compunach
[2007/12/13 14:04:21 | 00,002,386 | —- | M] () – C:\Documents and Settings\Brian McCrohan\Application Data\Mozilla\FireFox\Profiles\74hu8np7.default\searchplugins\siteadvisor.xml
[2009/04/16 09:04:00 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/03/31 13:04:25 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/04/25 20:08:16 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
[2007/08/30 07:24:05 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
[2007/11/02 08:12:33 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2008/03/27 08:04:35 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/07/27 07:17:53 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2008/12/13 15:48:36 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
[2008/12/27 10:00:34 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/03/30 19:39:16 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/03/31 13:04:18 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/31 13:04:18 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/01/10 09:39:07 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/01/10 09:39:07 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/01/10 09:39:07 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/01/10 09:39:07 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/01/10 09:39:08 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/01/10 09:39:08 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/01/10 09:39:08 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Viewpoint Toolbar BHO) - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBarBHO.dll (Viewpoint Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {8EAB99C9-F9EC-4B64-A4BA-D9BCAE8779C2} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [BCMSMMSG] BCMSMMSG.exe (Broadcom Corporation)
O4 - HKLM..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2 (SupportSoft, Inc.)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" (LogMeIn, Inc.)
O4 - HKLM..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey (McAfee, Inc.)
O4 - HKLM..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide (McAfee, Inc.)
O4 - HKLM..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE (Cypress Semiconductor)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKCU..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
O4 - HKCU..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit (NVIDIA Corporation)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1 (Adobe Systems Incorporated)
O4 - HKCU..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1 (AWS Convergence Technologies, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit, Inc.)
F3 - HKCU WinNT: Load - (C:\OPLIMIT\ocraware.exe) - C:\OPLIMIT\ocraware.exe (Caere Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\WINDOWS\system32\GPhotos.scr/200 (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: microsoft.com ([office] http in Trusted sites)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe (Reg Error: Key error.)
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} http://picasaweb.google.com/s/v/45.19/uploader2.cab (UploadListView Class)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…96/mcinsctl.cab (McAfee.com Operating System Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…7743.6453587963 (Reg Error: Key error.)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab (DwnldGroupMgr Class)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/RACtrl.cab (Performance Viewer Activex Control)
O16 - DPF: Aurigma Image Uploader 2.0 http://www.photogize.com/PhotogizeImageUploader.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\system32\LMIinit.dll (LogMeIn, Inc.)
O20 - Winlogon\Notify\WgaLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop Components:0 () - file:///C:/DOCUME~1/BRIANM~1/LOCALS~1/Temp/msohtml1/01/clip_image002.gif
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O32 - Autorun File - K:\autorun [2007/01/24 15:25:04 | 00,000,000 | —D | M] - [ FAT32 ]
O32 - Autorun File - K:\autorun.inf () - [ FAT32 ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\Documents and Settings\All Users\Application Data\*.tmp files]
[2 C:\Documents and Settings\Brian McCrohan\My Documents\*.tmp files]
[2009/04/18 15:22:02 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Brian McCrohan\Desktop\OTListIt2.exe
[2009/04/18 13:58:32 | 00,094,208 | —- | C] () – C:\Documents and Settings\Brian McCrohan\Desktop\GooredFix.exe
[2009/04/16 14:54:03 | 00,000,000 | —D | C] – C:\Documents and Settings\Brian McCrohan\Desktop\Malware
[2009/04/15 11:04:32 | 00,396,239 | —- | C] () – C:\Documents and Settings\Brian McCrohan\Desktop\502.pdf
[2009/04/14 11:54:41 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/04/14 11:53:52 | 00,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2009/04/14 11:53:52 | 00,000,000 | —D | C] – C:\Documents and Settings\Brian McCrohan\Application Data\SUPERAntiSpyware.com
[2009/04/14 11:53:04 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2009/04/14 10:30:09 | 00,000,000 | —D | C] – C:\Program Files\CCleaner
[2009/04/14 08:30:08 | 00,000,000 | —D | C] – C:\Documents and Settings\Brian McCrohan\Application Data\Malwarebytes
[2009/04/14 08:30:04 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/14 08:30:02 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/14 08:30:00 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/14 08:29:59 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/04/14 03:00:44 | 00,000,260 | —- | C] () – C:\WINDOWS\tasks\WGASetup.job
[2009/04/14 03:00:44 | 00,000,000 | —D | C] – C:\WINDOWS\System32\KB905474
[2009/04/11 06:27:19 | 00,025,088 | —- | C] () – C:\Documents and Settings\Brian McCrohan\Desktop\I offer a unique approach to psychotherapy.doc
[2009/04/10 08:40:48 | 00,044,032 | —- | C] () – C:\Documents and Settings\Brian McCrohan\Desktop\new info for website.doc
[2009/04/08 12:08:05 | 00,090,112 | —- | C] () – C:\Documents and Settings\Brian McCrohan\Desktop\Brian McCrohan - CV(2).doc
[2009/04/06 08:37:20 | 00,458,595 | —- | C] () – C:\Documents and Settings\Brian McCrohan\Desktop\kickball schedule.htm
[2009/04/06 08:03:03 | 00,225,280 | —- | C] () – C:\WINDOWS\System32\nvwrsda.dll
[2009/04/03 09:47:54 | 00,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2009/04/03 09:44:06 | 00,000,000 | —D | C] – C:\WINDOWS\WBEM
[2009/04/03 09:41:46 | 00,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2009/04/03 09:41:46 | 00,000,000 | —D | C] – C:\WINDOWS\System32\en-US
[2009/04/03 09:34:39 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/04/03 09:28:46 | 16,883,056 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Brian McCrohan\Desktop\IE8-WindowsXP-x86-ENU.exe
[2009/03/26 20:46:31 | 00,000,000 | —D | C] – C:\Documents and Settings\Brian McCrohan\My Documents\Taxes 2008
[2009/03/20 19:25:17 | 00,003,157 | —- | C] () – C:\Documents and Settings\Brian McCrohan\Desktop\march.csv
[2008/01/31 13:43:07 | 00,399,360 | —- | C] () – C:\WINDOWS\System32\Smab.dll
[2008/01/31 13:43:04 | 00,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2008/01/31 13:42:25 | 00,027,648 | -HS- | C] () – C:\WINDOWS\System32\Smab0.dll
[2007/05/22 19:14:58 | 00,008,784 | —- | C] () – C:\WINDOWS\System32\ractrlkeyhook.dll
[2006/11/14 18:47:50 | 00,000,098 | —- | C] () – C:\WINDOWS\QBTIMER.INI
[2006/11/14 18:46:57 | 00,000,064 | —- | C] () – C:\WINDOWS\QBWCD.INI
[2006/11/09 22:48:15 | 00,000,000 | —- | C] () – C:\WINDOWS\pcfriend.INI
[2006/10/22 13:22:00 | 01,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/10/22 13:22:00 | 00,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/10/22 13:22:00 | 00,212,992 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/07/15 12:45:36 | 00,023,552 | —- | C] () – C:\WINDOWS\xobglu32.dll
[2006/07/15 12:45:35 | 00,063,488 | —- | C] () – C:\WINDOWS\xobglu16.dll
[2005/12/15 11:50:02 | 00,745,472 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2005/12/15 11:50:02 | 00,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2005/08/03 14:31:36 | 00,651,264 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2005/08/03 14:31:36 | 00,147,456 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2005/06/11 12:47:00 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\fpprintmon.dll
[2005/04/15 10:59:54 | 00,000,239 | —- | C] () – C:\WINDOWS\IfoEdit.INI
[2005/04/15 10:59:52 | 00,000,107 | —- | C] () – C:\WINDOWS\VobEdit.INI
[2005/02/07 17:51:52 | 00,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/01/23 12:00:01 | 00,001,214 | —- | C] () – C:\WINDOWS\S3D.ini
[2005/01/17 13:05:25 | 00,011,776 | —- | C] () – C:\WINDOWS\System32\ZPORT4AS.dll
[2005/01/17 11:14:39 | 00,071,749 | —- | C] () – C:\WINDOWS\hcextoutput.dll
[2005/01/17 11:14:39 | 00,000,823 | —- | C] () – C:\WINDOWS\tsc.ini
[2005/01/17 11:14:17 | 00,000,170 | —- | C] () – C:\WINDOWS\GetServer.ini
[2004/09/12 22:59:34 | 00,000,536 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/09/12 22:59:14 | 00,000,045 | —- | C] () – C:\WINDOWS\JDCFKLJQ.ini
[2004/07/26 10:24:25 | 00,667,648 | —- | C] () – C:\WINDOWS\System32\Dtwain32.dll
[2004/07/10 00:24:52 | 00,561,152 | R— | C] () – C:\WINDOWS\System32\hpotscl.dll
[2004/01/23 20:02:32 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\Gif89.dll
[2004/01/23 19:35:58 | 00,000,051 | —- | C] () – C:\WINDOWS\iTouch.ini
[2003/11/09 01:13:48 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/10/06 15:16:00 | 00,027,136 | —- | C] () – C:\WINDOWS\System32\nvcod.dll
[2003/08/07 16:01:50 | 00,237,568 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2003/08/02 19:15:33 | 00,000,094 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2003/07/03 00:00:00 | 01,026,560 | —- | C] () – C:\WINDOWS\System32\libmpeg-1.0.2.dll
[2003/07/03 00:00:00 | 00,987,136 | —- | C] () – C:\WINDOWS\System32\liboggvorbis-1.0.0.dll
[2003/07/03 00:00:00 | 00,699,904 | —- | C] () – C:\WINDOWS\System32\ctassist.dll
[2003/07/03 00:00:00 | 00,427,008 | —- | C] () – C:\WINDOWS\System32\libimg-2.2.9.dll
[2003/07/03 00:00:00 | 00,063,488 | —- | C] () – C:\WINDOWS\System32\libmpeg2-enc-1.2.6.dll
[2003/07/03 00:00:00 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\libavi-dd-1.1.1.dll
[2003/06/10 13:47:01 | 00,015,795 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2003/06/07 17:59:26 | 00,000,000 | —- | C] () – C:\WINDOWS\prestopm.INI
[2003/06/07 17:58:09 | 00,000,029 | —- | C] () – C:\WINDOWS\DEBUGSM.INI
[2003/06/07 17:46:53 | 00,000,022 | —- | C] () – C:\WINDOWS\ppdrv.ini
[2003/06/07 17:33:19 | 00,000,716 | —- | C] () – C:\WINDOWS\OPLIMIT.INI
[2003/06/07 17:32:58 | 00,000,602 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2003/06/07 17:30:30 | 00,000,512 | —- | C] () – C:\WINDOWS\ALBUM.INI
[2003/06/07 17:30:30 | 00,000,425 | —- | C] () – C:\WINDOWS\PAEDIT.INI
[2003/06/07 17:29:59 | 00,000,500 | —- | C] () – C:\WINDOWS\Upmagic.ini
[2003/06/07 17:29:51 | 00,000,036 | —- | C] () – C:\WINDOWS\Vss.ini
[2003/06/07 17:28:49 | 00,005,101 | —- | C] () – C:\WINDOWS\IF40LE.INI
[2003/06/07 17:28:49 | 00,000,289 | —- | C] () – C:\WINDOWS\PEXPLORE.INI
[2003/06/07 17:28:12 | 00,011,776 | —- | C] () – C:\WINDOWS\System32\pmsbfn32.dll
[2003/06/07 17:28:12 | 00,000,410 | —- | C] () – C:\WINDOWS\umxaddin.ini
[2003/05/23 12:12:42 | 00,139,264 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2003/05/23 12:12:22 | 00,079,872 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2003/05/23 12:12:07 | 00,287,232 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2003/05/23 12:11:37 | 00,775,168 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2003/05/04 18:13:28 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/05/01 23:20:04 | 00,065,536 | R— | C] ( ) – C:\WINDOWS\System32\A3d.dll
[2003/05/01 23:20:04 | 00,039,936 | R— | C] () – C:\WINDOWS\System32\P16X.dll
[2002/06/28 05:43:44 | 00,438,272 | —- | C] () – C:\WINDOWS\System32\xvid.dll
[2002/05/30 16:00:00 | 00,000,299 | —- | C] () – C:\WINDOWS\LProS.ini
[2002/05/15 19:38:40 | 00,091,136 | —- | C] () – C:\WINDOWS\System32\mp4fil32.dll
[2002/05/04 09:19:00 | 00,049,152 | —- | C] () – C:\WINDOWS\System32\avisynthEx.dll
[2002/04/21 14:30:14 | 00,151,552 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2002/04/01 18:16:30 | 00,454,656 | —- | C] () – C:\WINDOWS\System32\VorbisEnc.dll
[2002/04/01 18:16:14 | 00,118,784 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2002/04/01 18:15:40 | 00,011,264 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2002/02/21 12:41:20 | 00,157,184 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2001/08/23 08:00:00 | 00,001,209 | —- | C] () – C:\WINDOWS\win.ini
[2001/08/23 08:00:00 | 00,000,243 | —- | C] () – C:\WINDOWS\SYSTEM.INI
[2001/06/22 07:06:02 | 00,167,936 | —- | C] () – C:\WINDOWS\System32\MPEG2DEC.dll
[2000/07/22 17:49:46 | 00,431,104 | —- | C] () – C:\WINDOWS\System32\VFCodec.dll
[1999/07/23 14:46:48 | 00,000,116 | —- | C] () – C:\WINDOWS\AuHCcup1.ini
[1999/07/23 11:53:20 | 00,129,536 | —- | C] () – C:\WINDOWS\AuHCcup1.dll
[1999/01/22 14:46:58 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\Documents and Settings\All Users\Application Data\*.tmp files]
[2 C:\Documents and Settings\Brian McCrohan\My Documents\*.tmp files]
[2009/04/18 15:22:03 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Brian McCrohan\Desktop\OTListIt2.exe
[2009/04/18 13:58:32 | 00,094,208 | —- | M] () – C:\Documents and Settings\Brian McCrohan\Desktop\GooredFix.exe
[2009/04/18 11:11:02 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/04/16 08:48:31 | 00,000,488 | —- | M] () – C:\hpfr5550.xml
[2009/04/15 11:04:35 | 00,396,239 | —- | M] () – C:\Documents and Settings\Brian McCrohan\Desktop\502.pdf
[2009/04/15 01:23:04 | 00,000,358 | —- | M] () – C:\WINDOWS\tasks\McDefragTask.job
[2009/04/14 17:59:51 | 00,439,552 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/14 17:59:51 | 00,380,350 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/14 17:59:51 | 00,052,764 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/14 17:56:15 | 00,033,111 | —- | M] () – C:\WINDOWS\System32\Config.MPF
[2009/04/14 17:55:28 | 00,000,260 | —- | M] () – C:\WINDOWS\tasks\WGASetup.job
[2009/04/14 17:55:14 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/14 17:55:11 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/04/14 17:49:01 | 00,000,716 | —- | M] () – C:\WINDOWS\OPLIMIT.INI
[2009/04/14 08:21:38 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/04/14 08:14:48 | 06,676,480 | —- | M] () – C:\Documents and Settings\Brian McCrohan\My Documents\My Money reconfig.mny
[2009/04/14 08:14:44 | 06,625,232 | R— | M] () – C:\Documents and Settings\Brian McCrohan\My Documents\My Money reconfig Backup.mbf
[2009/04/11 13:49:32 | 00,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/04/11 13:48:30 | 00,151,040 | —- | M] () – C:\Documents and Settings\Brian McCrohan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/11 06:27:24 | 00,025,088 | —- | M] () – C:\Documents and Settings\Brian McCrohan\Desktop\I offer a unique approach to psychotherapy.doc
[2009/04/10 08:40:49 | 00,044,032 | —- | M] () – C:\Documents and Settings\Brian McCrohan\Desktop\new info for website.doc
[2009/04/09 07:43:51 | 00,062,976 | -HS- | M] () – C:\Documents and Settings\Brian McCrohan\Desktop\Thumbs.db
[2009/04/08 12:08:06 | 00,090,112 | —- | M] () – C:\Documents and Settings\Brian McCrohan\Desktop\Brian McCrohan - CV(2).doc
[2009/04/08 09:53:57 | 00,091,136 | —- | M] () – C:\Documents and Settings\Brian McCrohan\Application Data\GDIPFONTCACHEV1.DAT
[2009/04/08 08:42:00 | 00,002,483 | —- | M] () – C:\Documents and Settings\Brian McCrohan\Desktop\Microsoft Word.lnk
[2009/04/06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/06 08:37:22 | 00,458,595 | —- | M] () – C:\Documents and Settings\Brian McCrohan\Desktop\kickball schedule.htm
[2009/04/06 07:58:49 | 00,088,566 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/04/05 22:37:12 | 00,000,085 | -HS- | M] () – C:\Documents and Settings\Brian McCrohan\My Documents\desktop.ini
[2009/04/03 09:29:19 | 16,883,056 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Brian McCrohan\Desktop\IE8-WindowsXP-x86-ENU.exe
[2009/04/01 01:00:30 | 00,000,350 | —- | M] () – C:\WINDOWS\tasks\McQcTask.job
[2009/03/20 19:25:18 | 00,003,157 | —- | M] () – C:\Documents and Settings\Brian McCrohan\Desktop\march.csv

========== LOP Check ==========

[1 C:\Documents and Settings\All Users\Application Data\*.tmp files]
[2009/04/14 11:54:41 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/02/07 21:01:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/03/23 11:06:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ahead
[2007/09/11 18:43:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2007/06/13 13:44:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/06/30 11:36:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Comcast
[2003/05/11 17:42:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2003/05/02 19:58:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Dell
[2008/09/28 21:15:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2006/12/14 11:45:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2007/01/12 16:43:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2008/09/28 20:55:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kodak
[2008/06/02 07:38:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogMeIn
[2005/12/28 22:38:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Macromedia
[2009/04/14 08:30:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2005/09/04 15:58:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MCA4A.tmp
[2008/10/05 15:23:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2006/01/11 12:38:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2007/04/20 11:00:22 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2004/02/13 20:15:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN Messenger 6.1.0155
[2004/02/13 20:15:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2007/01/21 17:09:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2008/02/28 15:46:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NVIDIA
[2008/02/28 14:41:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\nView_Profiles
[2003/06/09 17:30:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2005/02/19 15:38:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Roxio
[2005/01/22 20:11:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBT
[2008/10/05 15:24:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SiteAdvisor
[2009/04/14 11:54:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2005/09/03 23:00:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Support.com
[2007/06/29 14:55:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2007/06/05 20:28:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/12/13 10:38:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trend Micro
[2007/04/20 10:36:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2008/04/21 08:16:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2005/01/01 15:31:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visual Networks
[2006/05/24 23:06:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/04/11 13:44:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ZoomBrowser
[2009/04/14 11:53:52 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Brian McCrohan\Application Data
[2008/02/09 09:47:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Adobe
[2006/07/29 15:47:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\AdobeAUM
[2008/05/08 19:34:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\AdobeUM
[2007/11/01 14:19:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Ahead
[2006/01/10 00:32:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Apple Computer
[2005/01/01 17:29:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Business Logic
[2003/05/02 00:52:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\CyberLink
[2006/12/15 00:06:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\dvdcss
[2006/02/23 21:28:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Google
[2007/01/12 16:43:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Gtek
[2003/05/04 18:36:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Help
[2004/07/11 01:40:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Hewlett-Packard
[2006/07/01 11:20:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Identities
[2005/11/09 19:11:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Image Zone Express
[2005/01/06 11:45:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Lavasoft
[2004/04/10 11:08:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Leadertech
[2007/05/08 20:23:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Macromedia
[2009/04/14 08:30:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Malwarebytes
[2005/01/02 22:15:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\McAfee
[2005/01/01 16:03:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\McAfee.com
[2009/03/30 16:06:21 | 00,000,000 | –SD | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Microsoft
[2005/01/22 20:10:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Microsoft Web Folders
[2008/03/03 21:46:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Move Networks
[2009/01/10 09:39:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Mozilla
[2005/04/10 19:16:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\MSN6
[2004/02/13 20:18:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\MSNInstaller
[2005/04/10 08:19:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Musicmatch
[2003/05/02 20:12:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Real
[2007/01/27 14:08:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\RipIt4Me
[2005/02/19 14:56:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Roxio
[2005/11/17 22:43:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Seven Zip
[2006/07/03 13:44:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\SlySoft
[2006/12/18 23:47:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\SmartFTP
[2007/03/25 21:36:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Snapfish
[2006/02/20 11:41:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Sun
[2009/04/14 11:53:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\SUPERAntiSpyware.com
[2007/01/30 12:28:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\System Requirements Lab
[2009/04/15 12:14:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\U3
[2007/04/20 10:36:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Ulead Systems
[2008/04/21 08:16:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\Viewpoint
[2005/02/20 12:00:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\vlc
[2009/04/17 14:38:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\WeatherBug
[2007/06/05 18:31:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\WinRAR
[2009/04/11 13:47:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Brian McCrohan\Application Data\ZoomBrowser EX
[2009/04/18 11:11:02 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2001/08/23 08:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2004/10/13 09:03:11 | 00,000,360 | —- | M] () – C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2100 series#1089524353.job
[2009/04/15 01:23:04 | 00,000,358 | —- | M] () – C:\WINDOWS\Tasks\McDefragTask.job
[2009/04/01 01:00:30 | 00,000,350 | —- | M] () – C:\WINDOWS\Tasks\McQcTask.job
[2009/04/14 17:55:14 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2009/04/14 17:55:28 | 00,000,260 | —- | M] () – C:\WINDOWS\Tasks\WGASetup.job

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4B7BEAFF
< End of report >

___________________________________________________________________________

Here is Extras.txt


OTListIt Extras logfile created on: 4/18/2009 3:25:07 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Brian McCrohan\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.98 Mb Total Physical Memory | 258.91 Mb Available Physical Memory | 50.67% Memory free
1.22 Gb Paging File | 0.73 Gb Available in Paging File | 59.79% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.53 Gb Total Space | 4.15 Gb Free Space | 21.23% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Unable to calculate disk information.
Drive F: | 19.53 Gb Total Space | 1.41 Gb Free Space | 7.20% Space Free | Partition Type: NTFS
Drive G: | 19.53 Gb Total Space | 19.47 Gb Free Space | 99.67% Space Free | Partition Type: NTFS
Drive H: | 19.53 Gb Total Space | 7.00 Gb Free Space | 35.85% Space Free | Partition Type: NTFS
Drive I: | 19.53 Gb Total Space | 19.46 Gb Free Space | 99.61% Space Free | Partition Type: NTFS
Drive J: | 14.04 Gb Total Space | 13.96 Gb Free Space | 99.45% Space Free | Partition Type: NTFS
Drive K: | 232.83 Gb Total Space | 74.43 Gb Free Space | 31.97% Space Free | Partition Type: FAT32

Computer Name: HAL
Current User Name: Brian McCrohan
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.js [@ = JSFile] – C:\Program Files\Macromedia\Dreamweaver UltraDev 4\UltraDev.exe (Macromedia, Inc.)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5 File not found
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger (Logitech Inc.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Kazaa Lite\KazaaLite.kpp:*:Enabled:Kazaa Lite File not found
C:\WINDOWS\system32\wjview.exe:*:Disabled:Microsoft® VM Command Line Interpreter (Microsoft Corporation)
C:\Program Files\WebSavingsfromEbates\WebSavingsfromEbates.exe:*:Disabled:WebSavingsfromEbates File not found
C:\Program Files\SmartFTP\SmartFTP.exe:*:Enabled:SmartFTP Client (SmartFTP GmbH)
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5 File not found
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
C:\Program Files\SmartFTP Client 2.0\SmartFTP.exe:*:Enabled:SmartFTP Client 2.0 (SmartSoft Ltd.)
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger (Logitech Inc.)
C:\Program Files\Pando Networks\Pando\pando.exe:*:Disabled:pando File not found
C:\Program Files\Macromedia\Dreamweaver 8\Dreamweaver.exe:*:Enabled:Dreamweaver 8 (Macromedia, Inc.)
C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox (Mozilla Corporation)
C:\Program Files\Java\jre1.5.0_11\bin\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary (Sun Microsystems, Inc.)
C:\Program Files\FTP Commander\Ftpcomm.exe:*:Enabled:Ftpcomm (Internetsoft)
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare File not found
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent (McAfee, Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00040409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Disc 2
"{036AA4D4-6D32-11D4-9875-00105ACE7734}" = Logitech iTouch Software
"{0837A661-FEC3-48B3-876C-91E7D32048A9}" = Macromedia Dreamweaver 8
"{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0B8FF60F-C012-4459-AADF-A3AD4E3757DE}" = Dell Picture Studio - Dell Image Expert
"{11C762F9-95EA-486A-A8E7-683A50C231C1}" = SmartFTP Client
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{11F5D779-7BD9-465A-BBC4-10701386BCB9}" = FW LiveUpdate
"{1E04F83B-2AB9-4301-9EF7-E86307F79C72}" = Google Earth
"{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java™ 6 Update 13
"{2792F12C-3515-4D69-8083-B557AF35F06F}" = LightScribe [removed]
"{2b02f822-a9b9-458c-80e5-3ea8c0de8471}" = QuickBooks Pro Edition 2004
"{2BD5C305-1B27-4D41-B690-7A61172D2FEB}" = Macromedia Flash 8
"{2E0695EE-ED29-4D96-BD77-2A9A17EDF0D6}" = Cypress USB Mass Storage Driver Installation
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{32F66A20-7614-11D4-BD11-00104BD3F987}" = MathPlayer
"{336DE906-74F6-40F2-A084-978B08C551AE}" = Dell Support 3.1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3DE0053C-FD9A-483E-B7C9-B06E4392206E}" = iTunes
"{43DCF766-6838-4F9A-8C91-D92DA586DFA7}" = Microsoft Windows Journal Viewer
"{43FCA273-9534-40DB-B7C5-D7758875616A}" = Dell Support
"{45401A03-BDF0-448F-9B0F-3882B96F6692}" = Belkin Wireless Utility
"{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}" = Bonjour
"{49C88E44-1B38-4FC6-824E-2BDA3063B0E3}" = Apple Mobile Device Support
"{4B9535BF-CC90-4158-AF32-CAF57A8820CA}" = Macromedia Contribute 3.11
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{4C24A8C1-7CFA-4650-AF15-732F5BD7B46D}" = Macromedia Fireworks 8
"{4F1DA6BF-3614-48A1-9970-9E90F646789E}" = Ulead VideoStudio 8.0 SE VCD
"{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}" = Macromedia Extension Manager
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = Logitech MouseWare 9.75
"{609F7AC8-C510-11D4-A788-009027ABA5D0}" = Easy CD Creator 5 Basic
"{625BD732-ACDF-4552-BF22-98EBB413B6F3}" = McAfee Shredder
"{6774F0CF-C7DD-4CB4-BCB2-11C3E08BBA03}" = McAfee Shredder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6ECB39BD-73C2-44DD-B1A0-898207C58D8B}" = HP Photo and Imaging 2.0 - All-in-One Drivers
"{7E2CD3A0-505B-11D4-867E-E56CE477E832}" = CD LabelMaker Easy
"{82DFB852-9594-4668-9C66-28BB6E94BCB2}" = hp psc 2100 series
"{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch® Jukebox
"{885A63EA-382B-4DD4-A755-14809B8557D6}" = Macromedia Flash Player 8
"{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}" = Macromedia Flash 8 Video Encoder
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{9867A917-5D17-40DE-83BA-BEA5293194B1}" = HP Photo and Imaging 2.0 - All-in-One
"{9CD89DD7-234A-4801-9D87-3DE352E146A0}" = TMPGEnc DVD Author 1.6
"{ABDA9912-5D00-11D4-BAE7-9367CA097955}" = Macromedia Dreamweaver UltraDev 4
"{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9
"{B376402D-58EA-45EA-BD50-DD924EB67A70}" = HP Memories Disc
"{BA2D4D22-0B99-4D63-BCEE-D2EA4736F27F}" = LogMeIn
"{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = B57Inst
"{C169D3BB-9A27-43F5-9979-09A0D65FE95C}" = SmartFTP Client 2.0
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CB4544EA-C189-41FE-9E3A-76591DDB852B}" = Roxio Easy Media Creator 7
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CF5193FB-6B37-11D5-B7D2-00AA00A204F1}" = Microsoft Money 2002 System Pack
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{D87149B3-7A1D-4548-9CBF-032B791E5908}" = Desktop Doctor
"{E2FE26B7-4B97-48D9-812B-6A37CC55BD73}" = USB20 setup program
"{E7298FDC-1386-11D5-8D6C-0050DAD32D95}" = Microsoft Money 2002
"{E89D78B8-28F7-412F-8B26-C684739CBBDC}" = Palm Desktop
"{F51D9393-BB14-4566-99BF-D6ED63AEFCD7}" = Natural Color
"Ad-Aware SE Personal" = Ad-Aware SE Personal
"Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Adobe Shockwave Player" = Adobe Shockwave Player
"All To MP3 Converter_is1" = All To MP3 Converter 1.6
"AndreaMosaicVersion3" = AndreaMosaic 3.20
"Applian FLV Player2.0.23" = Applian FLV Player
"BCM V.92 56K Modem" = BCM V.92 56K Modem
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Camera Window DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
"CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"CCleaner" = CCleaner (remove only)
"CSCLIB" = Canon Camera Support Core Library
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"DivX Codec" = DivX Codec
"DivX Player" = DivX Player 2.1
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"Easy Video Converter_is1" = Easy Video Converter 3.1.0
"EOS Utility" = Canon Utilities EOS Utility
"ffdshow" = ffdshow (remove only)
"Frame from AVI v3.1 TRIAL_is1" = Frame from AVI v3.1 TRIAL
"FTP Commander" = FTP Commander
"Fx ReSound" = Fx ReSound
"GSpot" = GSpot Codec Information Appliance
"HijackThis" = HijackThis 2.0.2
"HP Image Zone Express" = HP Image Zone Express
"hp instant support" = hp instant support
"HP PSC 2100 Series" = HP Photo and Imaging 2.0 - hp psc 2100 series
"HUFFYUV" = Huffyuv AVI lossless video codec (Remove Only)
"ie8" = Windows Internet Explorer 8
"if40leUninstall" = Presto! ImageFolio LE
"InstallShield_{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB}" = iPod for Windows 2006-03-23
"InstallShield_{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = Broadcom Driver Installer
"InstallShield_{E2FE26B7-4B97-48D9-812B-6A37CC55BD73}" = USB20 setup program
"InterActual Player" = InterActual Player
"JAlbum" = JAlbum
"Jalbum_0" = Jalbum 8.0
"LameACM" = Lame ACM MP3 Codec
"Logitech Resource Center" = Logitech Resource Center
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox (3.0.8)" = Mozilla Firefox (3.0.8)
"MPEG Video Wizard" = MPEG Video Wizard
"MSC" = McAfee SecurityCenter
"My Web Search WB Uninstall" = WeatherBug Browser Bar - powered by MyWebSearch
"NeroMultiInstaller!UninstallKey" = Nero Suite
"NimoCorp" = Nimo Codecs Pack v5.0 (Remove Only)
"NVIDIA Display Driver" = NVIDIA Display Driver
"NVIDIA Drivers" = NVIDIA Drivers
"PageManager" = Presto! PageManager
"PageType" = Presto! PageType
"PAUninstall" = Presto! PhotoAlbum
"Photo Viewer" = Photo Viewer 2.3
"PhotoStitch" = Canon Utilities PhotoStitch
"Picasa 3" = Picasa 3
"PROSet" = Intel® PRO Ethernet Adapter and Software
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RealPlayer 6.0" = RealPlayer
"RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX
"SC Video Converter_is1" = SC Video Converter [removed]
"Sea3D_is1" = Sea3D 1.2.0a
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SM1FX_AT" = USB Storage Adapter FX (SM1)
"SmartFTP Client 2.0 Setup Files" = SmartFTP Client 2.0 Setup Files (remove only)
"SUPER ©" = SUPER © Version 2008.bld.24 (Jan 18, 2008)
"System Requirements Lab" = System Requirements Lab
"Uninstall VistaShuttle" = VistaShuttle
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"VLC media player" = VideoLAN VLC media player 0.8.1
"WeatherBug" = WeatherBug
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 2
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/11/2009 2:59:27 PM | Computer Name = HAL | Source = Microsoft Office 10 | ID = 1000
Description = Faulting application winword.exe, version 10.0.2627.0, faulting module
unknown, version 0.0.0.0, fault address 0x10011e39.

Error - 4/13/2009 7:37:53 AM | Computer Name = HAL | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 4/13/2009 7:37:53 AM | Computer Name = HAL | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 4/14/2009 8:42:53 AM | Computer Name = HAL | Source = WLTRYSVC | ID = 2
Description = SetServiceStatus() failed

Error - 4/14/2009 9:55:11 AM | Computer Name = HAL | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module urlmon.dll, version 8.0.6001.18702, fault address 0x0004f903.

Error - 4/14/2009 10:54:56 AM | Computer Name = HAL | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x036633b8.

Error - 4/15/2009 11:11:16 AM | Computer Name = HAL | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 4/15/2009 11:11:16 AM | Computer Name = HAL | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 4/15/2009 3:37:51 PM | Computer Name = HAL | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 4/15/2009 3:37:51 PM | Computer Name = HAL | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

[ System Events ]
Error - 4/14/2009 5:50:18 PM | Computer Name = HAL | Source = DCOM | ID = 10010
Description = The server {6A972E27-93E2-4F98-8367-4101B2073814} did not register
with DCOM within the required timeout.

Error - 4/14/2009 5:55:51 PM | Computer Name = HAL | Source = Service Control Manager | ID = 7000
Description = The McAfee WSC Integration service failed to start due to the following
error: %%2

Error - 4/14/2009 5:56:17 PM | Computer Name = HAL | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/14/2009 5:56:53 PM | Computer Name = HAL | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/14/2009 5:57:33 PM | Computer Name = HAL | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/14/2009 5:58:13 PM | Computer Name = HAL | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/14/2009 5:58:54 PM | Computer Name = HAL | Source = DCOM | ID = 10010
Description = The server {6A972E27-93E2-4F98-8367-4101B2073814} did not register
with DCOM within the required timeout.

Error - 4/14/2009 5:59:24 PM | Computer Name = HAL | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.

Error - 4/14/2009 6:00:07 PM | Computer Name = HAL | Source = DCOM | ID = 10010
Description = The server {6A972E27-93E2-4F98-8367-4101B2073814} did not register
with DCOM within the required timeout.

Error - 4/14/2009 6:00:39 PM | Computer Name = HAL | Source = DCOM | ID = 10010
Description = The server {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} did not register
with DCOM within the required timeout.


< End of report >

_____________________________________________________________________
Hi,

Not seeing anything there,

Lets see if there's something hiding from us.

Also can you do a system search for cmd.exe and double click the executable…see if you get the same result?


Please do this:

Please download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a number of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

  • Post the contents of GMER.txt in your next reply.
Okay… I think that I inadvertently did the full scan since that took forever. However, a few interesting things: while the scan was running McAfee suddenly started up and is now in my system tray. Additionally, weatherbug seems like it has spontaneously started up. I thought I would try getting the command prompt again, and it is now working.

Even more interesting… I just tried my browser and I don't seem to be getting the same redirect problem, and now the McAfee website is opening. Seems like good news, but I know it may not be permanent.

Here is the GMER log…

GMER 1.0.15.14966 - http://www.gmer.net
Rootkit scan 2009-04-18 17:53:40
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.15 —-

SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xF6041DF0]

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xF5F859CA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xF5F85978]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xF5F8598C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xF5F85A0A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xF5F85950]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xF5F85964]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xF5F859DE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xF5F859B6]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xF5F859A2]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xF5F85A39]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xF5F85A20]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xF5F859F4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess

—- Kernel code sections - GMER 1.0.15 —-

.text ntoskrnl.exe!ZwYieldExecution 804F8B8D 7 Bytes JMP F5F859F8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtSetInformationProcess 8056BDCD 5 Bytes JMP F5F859A6 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtCreateFile 8056FC78 5 Bytes JMP F5F859CE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnmapViewOfSection 80571F71 5 Bytes JMP F5F85A24 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtMapViewOfSection 805723EC 7 Bytes JMP F5F85A0E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenProcess 80572D86 5 Bytes JMP F5F85954 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwProtectVirtualMemory 80573135 7 Bytes JMP F5F859E2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcessEx 80581F0E 7 Bytes JMP F5F85990 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwTerminateProcess 805847CC 5 Bytes JMP F5F85A3D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenThread 8058C892 5 Bytes JMP F5F85968 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcess 805B0B34 5 Bytes JMP F5F8597C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwSetContextThread 8062C493 5 Bytes JMP F5F859BA \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\AWS\WeatherBug\Weather.exe[184] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10033658
.text C:\Program Files\AWS\WeatherBug\Weather.exe[184] ws2_32.dll!connect 71AB406A 5 Bytes JMP 100335A0
.text C:\Program Files\AWS\WeatherBug\Weather.exe[184] ws2_32.dll!send 71AB428A 5 Bytes JMP 10032E84
.text C:\Program Files\AWS\WeatherBug\Weather.exe[184] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100326A0
.text C:\Program Files\AWS\WeatherBug\Weather.exe[184] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10032624
.text C:\Program Files\AWS\WeatherBug\Weather.exe[184] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10033554
.text C:\WINDOWS\system32\spoolsv.exe[228] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003658
.text C:\WINDOWS\system32\spoolsv.exe[228] ws2_32.dll!connect 71AB406A 5 Bytes JMP 100035A0
.text C:\WINDOWS\system32\spoolsv.exe[228] ws2_32.dll!send 71AB428A 5 Bytes JMP 10002E84
.text C:\WINDOWS\system32\spoolsv.exe[228] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100026A0
.text C:\WINDOWS\system32\spoolsv.exe[228] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002624
.text C:\WINDOWS\system32\spoolsv.exe[228] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003554
.text C:\WINDOWS\System32\cisvc.exe[728] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003658
.text C:\WINDOWS\System32\cisvc.exe[728] ws2_32.dll!connect 71AB406A 5 Bytes JMP 100035A0
.text C:\WINDOWS\System32\cisvc.exe[728] ws2_32.dll!send 71AB428A 5 Bytes JMP 10002E84
.text C:\WINDOWS\System32\cisvc.exe[728] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100026A0
.text C:\WINDOWS\System32\cisvc.exe[728] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002624
.text C:\WINDOWS\System32\cisvc.exe[728] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003554
.text C:\WINDOWS\explorer.exe[732] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 001A0000
.text C:\WINDOWS\explorer.exe[732] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001A0F37
.text C:\WINDOWS\explorer.exe[732] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 001A0F52
.text C:\WINDOWS\explorer.exe[732] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 001A0F79
.text C:\WINDOWS\explorer.exe[732] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 001A0F8A
.text C:\WINDOWS\explorer.exe[732] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 001A0FAF
.text C:\WINDOWS\explorer.exe[732] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 001A0062
.text C:\WINDOWS\explorer.exe[732] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 001A0F1A
.text C:\WINDOWS\explorer.exe[732] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001A0087
.text C:\WINDOWS\explorer.exe[732] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 001A0EEE
.text C:\WINDOWS\explorer.exe[732] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 001A0EDD
.text C:\WINDOWS\explorer.exe[732] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 001A002C
.text C:\WINDOWS\explorer.exe[732] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 001A0011
.text C:\WINDOWS\explorer.exe[732] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 001A0047
.text C:\WINDOWS\explorer.exe[732] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 001A0FC0
.text C:\WINDOWS\explorer.exe[732] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 001A0FD1
.text C:\WINDOWS\explorer.exe[732] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 001A0EFF
.text C:\WINDOWS\explorer.exe[732] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00280FDB
.text C:\WINDOWS\explorer.exe[732] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00280FA5
.text C:\WINDOWS\explorer.exe[732] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00280036
.text C:\WINDOWS\explorer.exe[732] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 0028001B
.text C:\WINDOWS\explorer.exe[732] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 0028006C
.text C:\WINDOWS\explorer.exe[732] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00280FCA
.text C:\WINDOWS\explorer.exe[732] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00280000
.text C:\WINDOWS\explorer.exe[732] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00280051
.text C:\WINDOWS\explorer.exe[732] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0029003D
.text C:\WINDOWS\explorer.exe[732] msvcrt.dll!system 77C293C7 5 Bytes JMP 00290FB2
.text C:\WINDOWS\explorer.exe[732] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00290FCD
.text C:\WINDOWS\explorer.exe[732] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00290FEF
.text C:\WINDOWS\explorer.exe[732] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00290022
.text C:\WINDOWS\explorer.exe[732] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00290FDE
.text C:\WINDOWS\explorer.exe[732] WININET.dll!InternetOpenA 6302B2D5 5 Bytes JMP 002B000A
.text C:\WINDOWS\explorer.exe[732] WININET.dll!InternetOpenW 6302B92E 5 Bytes JMP 002B0025
.text C:\WINDOWS\explorer.exe[732] WININET.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 002B0FEF
.text C:\WINDOWS\explorer.exe[732] WININET.dll!InternetOpenUrlW 63077347 5 Bytes JMP 002B0040
.text C:\WINDOWS\explorer.exe[732] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00DD0000
.text C:\WINDOWS\system32\winlogon.exe[948] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003658
.text C:\WINDOWS\system32\winlogon.exe[948] WS2_32.dll!connect 71AB406A 5 Bytes JMP 100035A0
.text C:\WINDOWS\system32\winlogon.exe[948] WS2_32.dll!send 71AB428A 5 Bytes JMP 10002E84
.text C:\WINDOWS\system32\winlogon.exe[948] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100026A0
.text C:\WINDOWS\system32\winlogon.exe[948] WS2_32.dll!recv 71AB615A 5 Bytes JMP 10002624
.text C:\WINDOWS\system32\winlogon.exe[948] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003554
.text C:\WINDOWS\system32\services.exe[992] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00BC0000
.text C:\WINDOWS\system32\services.exe[992] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00BC0F7E
.text C:\WINDOWS\system32\services.exe[992] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00BC0073
.text C:\WINDOWS\system32\services.exe[992] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00BC0FA5
.text C:\WINDOWS\system32\services.exe[992] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00BC0062
.text C:\WINDOWS\system32\services.exe[992] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00BC0FCA
.text C:\WINDOWS\system32\services.exe[992] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00BC0F48
.text C:\WINDOWS\system32\services.exe[992] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00BC0F63
.text C:\WINDOWS\system32\services.exe[992] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00BC00E1
.text C:\WINDOWS\system32\services.exe[992] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00BC00D0
.text C:\WINDOWS\system32\services.exe[992] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00BC00FC
.text C:\WINDOWS\system32\services.exe[992] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00BC0047
.text C:\WINDOWS\system32\services.exe[992] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00BC0FE5
.text C:\WINDOWS\system32\services.exe[992] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00BC0084
.text C:\WINDOWS\system32\services.exe[992] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00BC0036
.text C:\WINDOWS\system32\services.exe[992] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00BC001B
.text C:\WINDOWS\system32\services.exe[992] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00BC00B5
.text C:\WINDOWS\system32\services.exe[992] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0006004E
.text C:\WINDOWS\system32\services.exe[992] msvcrt.dll!system 77C293C7 5 Bytes JMP 0006003D
.text C:\WINDOWS\system32\services.exe[992] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0006001B
.text C:\WINDOWS\system32\services.exe[992] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00060000
.text C:\WINDOWS\system32\services.exe[992] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0006002C
.text C:\WINDOWS\system32\services.exe[992] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00060FD7
.text C:\WINDOWS\system32\services.exe[992] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00070FC3
.text C:\WINDOWS\system32\services.exe[992] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00070065
.text C:\WINDOWS\system32\services.exe[992] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 0007001E
.text C:\WINDOWS\system32\services.exe[992] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00070FDE
.text C:\WINDOWS\system32\services.exe[992] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00070F9E
.text C:\WINDOWS\system32\services.exe[992] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 0007004A
.text C:\WINDOWS\system32\services.exe[992] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00070FEF
.text C:\WINDOWS\system32\services.exe[992] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00070039
.text C:\WINDOWS\system32\services.exe[992] ws2_32.dll!socket 71AB3B91 5 Bytes JMP 0005000A
.text C:\WINDOWS\system32\services.exe[992] ws2_32.dll!connect 71AB406A 5 Bytes JMP 100035A0
.text C:\WINDOWS\system32\services.exe[992] ws2_32.dll!send 71AB428A 5 Bytes JMP 10002E84
.text C:\WINDOWS\system32\services.exe[992] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100026A0
.text C:\WINDOWS\system32\services.exe[992] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002624
.text C:\WINDOWS\system32\services.exe[992] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003554
.text C:\WINDOWS\system32\services.exe[992] wininet.dll!InternetOpenA 6302B2D5 5 Bytes JMP 00040000
.text C:\WINDOWS\system32\services.exe[992] wininet.dll!InternetOpenW 6302B92E 5 Bytes JMP 00040FE5
.text C:\WINDOWS\system32\services.exe[992] wininet.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 0004001B
.text C:\WINDOWS\system32\services.exe[992] wininet.dll!InternetOpenUrlW 63077347 5 Bytes JMP 00040036
.text C:\WINDOWS\system32\lsass.exe[1004] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00C20FE5
.text C:\WINDOWS\system32\lsass.exe[1004] kernel32.dll!VirtualProtectEx 7C801A5D 1 Byte [E9]
.text C:\WINDOWS\system32\lsass.exe[1004] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00C20F61
.text C:\WINDOWS\system32\lsass.exe[1004] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00C20056
.text C:\WINDOWS\system32\lsass.exe[1004] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00C20F7C
.text C:\WINDOWS\system32\lsass.exe[1004] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00C20F8D
.text C:\WINDOWS\system32\lsass.exe[1004] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00C20F9E
.text C:\WINDOWS\system32\lsass.exe[1004] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00C20F29
.text C:\WINDOWS\system32\lsass.exe[1004] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00C20F3A
.text C:\WINDOWS\system32\lsass.exe[1004] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00C20EEC
.text C:\WINDOWS\system32\lsass.exe[1004] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00C20EFD
.text C:\WINDOWS\system32\lsass.exe[1004] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00C200A0
.text C:\WINDOWS\system32\lsass.exe[1004] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00C2002F
.text C:\WINDOWS\system32\lsass.exe[1004] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00C20FD4
.text C:\WINDOWS\system32\lsass.exe[1004] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00C20071
.text C:\WINDOWS\system32\lsass.exe[1004] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00C2000A
.text C:\WINDOWS\system32\lsass.exe[1004] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00C20FC3
.text C:\WINDOWS\system32\lsass.exe[1004] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00C20F18
.text C:\WINDOWS\system32\lsass.exe[1004] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00BE0FA8
.text C:\WINDOWS\system32\lsass.exe[1004] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00BE002F
.text C:\WINDOWS\system32\lsass.exe[1004] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00BE0FC3
.text C:\WINDOWS\system32\lsass.exe[1004] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00BE0FD4
.text C:\WINDOWS\system32\lsass.exe[1004] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00BE0F72
.text C:\WINDOWS\system32\lsass.exe[1004] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00BE0014
.text C:\WINDOWS\system32\lsass.exe[1004] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00BE0FEF
.text C:\WINDOWS\system32\lsass.exe[1004] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00BE0F8D
.text C:\WINDOWS\system32\lsass.exe[1004] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00BD0FB2
.text C:\WINDOWS\system32\lsass.exe[1004] msvcrt.dll!system 77C293C7 5 Bytes JMP 00BD003D
.text C:\WINDOWS\system32\lsass.exe[1004] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00BD0FDE
.text C:\WINDOWS\system32\lsass.exe[1004] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00BD0FEF
.text C:\WINDOWS\system32\lsass.exe[1004] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00BD0FCD
.text C:\WINDOWS\system32\lsass.exe[1004] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00BD000C
.text C:\WINDOWS\system32\lsass.exe[1004] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00BC0FEF
.text C:\WINDOWS\system32\lsass.exe[1004] WS2_32.dll!connect 71AB406A 5 Bytes JMP 100035A0
.text C:\WINDOWS\system32\lsass.exe[1004] WS2_32.dll!send 71AB428A 5 Bytes JMP 10002E84
.text C:\WINDOWS\system32\lsass.exe[1004] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100026A0
.text C:\WINDOWS\system32\lsass.exe[1004] WS2_32.dll!recv 71AB615A 5 Bytes JMP 10002624
.text C:\WINDOWS\system32\lsass.exe[1004] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003554
.text C:\WINDOWS\system32\lsass.exe[1004] wininet.dll!InternetOpenA 6302B2D5 5 Bytes JMP 00BB0000
.text C:\WINDOWS\system32\lsass.exe[1004] wininet.dll!InternetOpenW 6302B92E 5 Bytes JMP 00BB0FE5
.text C:\WINDOWS\system32\lsass.exe[1004] wininet.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 00BB001B
.text C:\WINDOWS\system32\lsass.exe[1004] wininet.dll!InternetOpenUrlW 63077347 5 Bytes JMP 00BB0FC0
.text C:\WINDOWS\system32\ntvdm.exe[1084] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003658
.text C:\WINDOWS\system32\ntvdm.exe[1084] ws2_32.dll!connect 71AB406A 5 Bytes JMP 100035A0
.text C:\WINDOWS\system32\ntvdm.exe[1084] ws2_32.dll!send 71AB428A 5 Bytes JMP 10002E84
.text C:\WINDOWS\system32\ntvdm.exe[1084] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100026A0
.text C:\WINDOWS\system32\ntvdm.exe[1084] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002624
.text C:\WINDOWS\system32\ntvdm.exe[1084] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003554
.text C:\WINDOWS\system32\svchost.exe[1172] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00BC0000
.text C:\WINDOWS\system32\svchost.exe[1172] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00BC0F35
.text C:\WINDOWS\system32\svchost.exe[1172] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00BC0F46
.text C:\WINDOWS\system32\svchost.exe[1172] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00BC0F57
.text C:\WINDOWS\system32\svchost.exe[1172] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00BC0F68
.text C:\WINDOWS\system32\svchost.exe[1172] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00BC0F9E
.text C:\WINDOWS\system32\svchost.exe[1172] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00BC0F09
.text C:\WINDOWS\system32\svchost.exe[1172] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00BC0051
.text C:\WINDOWS\system32\svchost.exe[1172] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00BC0087
.text C:\WINDOWS\system32\svchost.exe[1172] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00BC0EEE
.text C:\WINDOWS\system32\svchost.exe[1172] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00BC0EDD
.text C:\WINDOWS\system32\svchost.exe[1172] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00BC0F83
.text C:\WINDOWS\system32\svchost.exe[1172] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00BC0FDB
.text C:\WINDOWS\system32\svchost.exe[1172] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00BC0F1A
.text C:\WINDOWS\system32\svchost.exe[1172] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00BC0FAF
.text C:\WINDOWS\system32\svchost.exe[1172] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00BC0FCA
.text C:\WINDOWS\system32\svchost.exe[1172] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00BC006C
.text C:\WINDOWS\system32\svchost.exe[1172] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00BB0FAF
.text C:\WINDOWS\system32\svchost.exe[1172] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00BB0F83
.text C:\WINDOWS\system32\svchost.exe[1172] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00BB0FCA
.text C:\WINDOWS\system32\svchost.exe[1172] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00BB000A
.text C:\WINDOWS\system32\svchost.exe[1172] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00BB0F94
.text C:\WINDOWS\system32\svchost.exe[1172] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00BB0036
.text C:\WINDOWS\system32\svchost.exe[1172] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00BB0FEF
.text C:\WINDOWS\system32\svchost.exe[1172] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00BB001B
.text C:\WINDOWS\system32\svchost.exe[1172] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00BA005C
.text C:\WINDOWS\system32\svchost.exe[1172] msvcrt.dll!system 77C293C7 5 Bytes JMP 00BA004B
.text C:\WINDOWS\system32\svchost.exe[1172] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00BA0FE5
.text C:\WINDOWS\system32\svchost.exe[1172] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00BA0000
.text C:\WINDOWS\system32\svchost.exe[1172] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00BA003A
.text C:\WINDOWS\system32\svchost.exe[1172] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00BA001D
.text C:\WINDOWS\system32\svchost.exe[1172] ws2_32.dll!socket 71AB3B91 5 Bytes JMP 00B90000
.text C:\WINDOWS\system32\svchost.exe[1172] ws2_32.dll!connect 71AB406A 5 Bytes JMP 100035A0
.text C:\WINDOWS\system32\svchost.exe[1172] ws2_32.dll!send 71AB428A 5 Bytes JMP 10002E84
.text C:\WINDOWS\system32\svchost.exe[1172] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100026A0
.text C:\WINDOWS\system32\svchost.exe[1172] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002624
.text C:\WINDOWS\system32\svchost.exe[1172] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003554
.text C:\WINDOWS\system32\svchost.exe[1172] wininet.dll!InternetOpenA 6302B2D5 5 Bytes JMP 00B80FEF
.text C:\WINDOWS\system32\svchost.exe[1172] wininet.dll!InternetOpenW 6302B92E 5 Bytes JMP 00B80FD4
.text C:\WINDOWS\system32\svchost.exe[1172] wininet.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 00B80FC3
.text C:\WINDOWS\system32\svchost.exe[1172] wininet.dll!InternetOpenUrlW 63077347 5 Bytes JMP 00B80FB2
.text C:\WINDOWS\BCMSMMSG.exe[1188] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003658
.text C:\WINDOWS\BCMSMMSG.exe[1188] ws2_32.dll!connect 71AB406A 5 Bytes JMP 100035A0
.text C:\WINDOWS\BCMSMMSG.exe[1188] ws2_32.dll!send 71AB428A 5 Bytes JMP 10002E84
.text C:\WINDOWS\BCMSMMSG.exe[1188] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100026A0
.text C:\WINDOWS\BCMSMMSG.exe[1188] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002624
.text C:\WINDOWS\BCMSMMSG.exe[1188] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003554
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00D00FEF
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00D00F55
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00D00F70
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00D0004A
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00D00F8D
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00D00FC3
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00D00076
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00D00065
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00D00F09
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00D000A2
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00D000B3
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00D00FA8
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00D00000
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00D00F3A
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00D00025
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00D00FD4
.text C:\WINDOWS\system32\svchost.exe[1256] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00D00091
.text C:\WINDOWS\system32\svchost.exe[1256] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00CF000A
.text C:\WINDOWS\system32\svchost.exe[1256] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00CF0F79
.text C:\WINDOWS\system32\svchost.exe[1256] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00CF0FB9
.text C:\WINDOWS\system32\svchost.exe[1256] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00CF0FD4
.text C:\WINDOWS\system32\svchost.exe[1256] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00CF0036
.text C:\WINDOWS\system32\svchost.exe[1256] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00CF001B
.text C:\WINDOWS\system32\svchost.exe[1256] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00CF0FEF
.text C:\WINDOWS\system32\svchost.exe[1256] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00CF0F9E
.text C:\WINDOWS\system32\svchost.exe[1256] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00A60FB9
.text C:\WINDOWS\system32\svchost.exe[1256] msvcrt.dll!system 77C293C7 5 Bytes JMP 00A60044
.text C:\WINDOWS\system32\svchost.exe[1256] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00A60029
.text C:\WINDOWS\system32\svchost.exe[1256] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00A60FEF
.text C:\WINDOWS\system32\svchost.exe[1256] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00A60FD4
.text C:\WINDOWS\system32\svchost.exe[1256] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00A60018
.text C:\WINDOWS\system32\svchost.exe[1256] ws2_32.dll!socket 71AB3B91 5 Bytes JMP 00A50FE5
.text C:\WINDOWS\system32\svchost.exe[1256] ws2_32.dll!connect 71AB406A 5 Bytes JMP 100035A0
.text C:\WINDOWS\system32\svchost.exe[1256] ws2_32.dll!send 71AB428A 5 Bytes JMP 10002E84
.text C:\WINDOWS\system32\svchost.exe[1256] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100026A0
.text C:\WINDOWS\system32\svchost.exe[1256] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002624
.text C:\WINDOWS\system32\svchost.exe[1256] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003554
.text C:\WINDOWS\system32\svchost.exe[1256] wininet.dll!InternetOpenA 6302B2D5 5 Bytes JMP 00A40000
.text C:\WINDOWS\system32\svchost.exe[1256] wininet.dll!InternetOpenW 6302B92E 5 Bytes JMP 00A4001B
.text C:\WINDOWS\system32\svchost.exe[1256] wininet.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 00A40036
.text C:\WINDOWS\system32\svchost.exe[1256] wininet.dll!InternetOpenUrlW 63077347 5 Bytes JMP 00A40FE5
.text C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe[1336] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10023658
.text C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe[1336] WS2_32.dll!connect 71AB406A 5 Bytes JMP 100235A0
.text C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe[1336] WS2_32.dll!send 71AB428A 5 Bytes JMP 10022E84
.text C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe[1336] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100226A0
.text C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe[1336] WS2_32.dll!recv 71AB615A 5 Bytes JMP 10022624
.text C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe[1336] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 10023554
.text C:\WINDOWS\System32\svchost.exe[1404] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 0292000A
.text C:\WINDOWS\System32\svchost.exe[1404] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 02920082
.text C:\WINDOWS\System32\svchost.exe[1404] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 02920F8D
.text C:\WINDOWS\System32\svchost.exe[1404] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 02920F9E
.text C:\WINDOWS\System32\svchost.exe[1404] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 02920FAF
.text C:\WINDOWS\System32\svchost.exe[1404] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 02920040
.text C:\WINDOWS\System32\svchost.exe[1404] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 029200B0
.text C:\WINDOWS\System32\svchost.exe[1404] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 02920F68
.text C:\WINDOWS\System32\svchost.exe[1404] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 029200D5
.text C:\WINDOWS\System32\svchost.exe[1404] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 02920F46
.text C:\WINDOWS\System32\svchost.exe[1404] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 02920F17
.text C:\WINDOWS\System32\svchost.exe[1404] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 02920051
.text C:\WINDOWS\System32\svchost.exe[1404] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 0292001B
.text C:\WINDOWS\System32\svchost.exe[1404] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 02920093
.text C:\WINDOWS\System32\svchost.exe[1404] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 02920FD4
.text C:\WINDOWS\System32\svchost.exe[1404] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 02920FE5
.text C:\WINDOWS\System32\svchost.exe[1404] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 02920F57
.text C:\WINDOWS\System32\svchost.exe[1404] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 02700025
.text C:\WINDOWS\System32\svchost.exe[1404] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 02700087
.text C:\WINDOWS\System32\svchost.exe[1404] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 02700FD4
.text C:\WINDOWS\System32\svchost.exe[1404] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 02700000
.text C:\WINDOWS\System32\svchost.exe[1404] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 0270006C
.text C:\WINDOWS\System32\svchost.exe[1404] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 0270005B
.text C:\WINDOWS\System32\svchost.exe[1404] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 02700FEF
.text C:\WINDOWS\System32\svchost.exe[1404] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 0270004A
.text C:\WINDOWS\System32\svchost.exe[1404] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00E00FB2
.text C:\WINDOWS\System32\svchost.exe[1404] msvcrt.dll!system 77C293C7 5 Bytes JMP 00E00047
.text C:\WINDOWS\System32\svchost.exe[1404] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00E00011
.text C:\WINDOWS\System32\svchost.exe[1404] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00E00FE3
.text C:\WINDOWS\System32\svchost.exe[1404] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00E0002C
.text C:\WINDOWS\System32\svchost.exe[1404] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00E00000
.text C:\WINDOWS\System32\svchost.exe[1404] ws2_32.dll!socket 71AB3B91 5 Bytes JMP 00DF0FEF
.text C:\WINDOWS\System32\svchost.exe[1404] ws2_32.dll!connect 71AB406A 5 Bytes JMP 100035A0
.text C:\WINDOWS\System32\svchost.exe[1404] ws2_32.dll!send 71AB428A 5 Bytes JMP 10002E84
.text C:\WINDOWS\System32\svchost.exe[1404] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100026A0
.text C:\WINDOWS\System32\svchost.exe[1404] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002624
.text C:\WINDOWS\System32\svchost.exe[1404] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003554
.text C:\WINDOWS\System32\svchost.exe[1404] wininet.dll!InternetOpenA 6302B2D5 5 Bytes JMP 00DE0000
.text C:\WINDOWS\System32\svchost.exe[1404] wininet.dll!InternetOpenW 6302B92E 5 Bytes JMP 00DE001B
.text C:\WINDOWS\System32\svchost.exe[1404] wininet.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 00DE0FE5
.text C:\WINDOWS\System32\svchost.exe[1404] wininet.dll!InternetOpenUrlW 63077347 5 Bytes JMP 00DE0FD4
.text C:\WINDOWS\System32\svchost.exe[1464] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00940FEF
.text C:\WINDOWS\System32\svchost.exe[1464] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 0094005D
.text C:\WINDOWS\System32\svchost.exe[1464] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00940F68
.text C:\WINDOWS\System32\svchost.exe[1464] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00940036
.text C:\WINDOWS\System32\svchost.exe[1464] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00940F79
.text C:\WINDOWS\System32\svchost.exe[1464] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00940FB9
.text C:\WINDOWS\System32\svchost.exe[1464] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00940F0B
.text C:\WINDOWS\System32\svchost.exe[1464] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00940F26
.text C:\WINDOWS\System32\svchost.exe[1464] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 009400AE
.text C:\WINDOWS\System32\svchost.exe[1464] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00940089
.text C:\WINDOWS\System32\svchost.exe[1464] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 009400BF
.text C:\WINDOWS\System32\svchost.exe[1464] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00940F9E
.text C:\WINDOWS\System32\svchost.exe[1464] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00940FDE
.text C:\WINDOWS\System32\svchost.exe[1464] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00940F43
.text C:\WINDOWS\System32\svchost.exe[1464] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00940025
.text C:\WINDOWS\System32\svchost.exe[1464] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00940014
.text C:\WINDOWS\System32\svchost.exe[1464] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 0094006E
.text C:\WINDOWS\System32\svchost.exe[1464] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00930FCA
.text C:\WINDOWS\System32\svchost.exe[1464] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 0093006C
.text C:\WINDOWS\System32\svchost.exe[1464] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00930025
.text C:\WINDOWS\System32\svchost.exe[1464] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00930FEF
.text C:\WINDOWS\System32\svchost.exe[1464] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00930051
.text C:\WINDOWS\System32\svchost.exe[1464] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00930040
.text C:\WINDOWS\System32\svchost.exe[1464] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 0093000A
.text C:\WINDOWS\System32\svchost.exe[1464] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00930FAF
.text C:\WINDOWS\System32\svchost.exe[1464] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00920058
.text C:\WINDOWS\System32\svchost.exe[1464] msvcrt.dll!system 77C293C7 5 Bytes JMP 00920FCD
.text C:\WINDOWS\System32\svchost.exe[1464] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00920033
.text C:\WINDOWS\System32\svchost.exe[1464] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00920000
.text C:\WINDOWS\System32\svchost.exe[1464] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00920FDE
.text C:\WINDOWS\System32\svchost.exe[1464] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00920FEF
.text C:\WINDOWS\System32\svchost.exe[1464] ws2_32.dll!socket 71AB3B91 5 Bytes JMP 00910FEF
.text C:\WINDOWS\System32\svchost.exe[1464] ws2_32.dll!connect 71AB406A 5 Bytes JMP 100035A0
.text C:\WINDOWS\System32\svchost.exe[1464] ws2_32.dll!send 71AB428A 5 Bytes JMP 10002E84
.text C:\WINDOWS\System32\svchost.exe[1464] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100026A0
.text C:\WINDOWS\System32\svchost.exe[1464] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002624
.text C:\WINDOWS\System32\svchost.exe[1464] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003554
.text C:\WINDOWS\System32\svchost.exe[1464] wininet.dll!InternetOpenA 6302B2D5 5 Bytes JMP 00900000
.text C:\WINDOWS\System32\svchost.exe[1464] wininet.dll!InternetOpenW 6302B92E 5 Bytes JMP 00900011
.text C:\WINDOWS\System32\svchost.exe[1464] wininet.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 00900022
.text C:\WINDOWS\System32\svchost.exe[1464] wininet.dll!InternetOpenUrlW 63077347 5 Bytes JMP 00900033
.text C:\Program Files\LogMeIn\x86\LogMeIn.exe[1560] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10663658
.text C:\Program Files\LogMeIn\x86\LogMeIn.exe[1560] WS2_32.dll!connect 71AB406A 5 Bytes JMP 106635A0
.text C:\Program Files\LogMeIn\x86\LogMeIn.exe[1560] WS2_32.dll!send 71AB428A 5 Bytes JMP 10662E84
.text C:\Program Files\LogMeIn\x86\LogMeIn.exe[1560] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 106626A0
.text C:\Program Files\LogMeIn\x86\LogMeIn.exe[1560] WS2_32.dll!recv 71AB615A 5 Bytes JMP 10662624
.text C:\Program Files\LogMeIn\x86\LogMeIn.exe[1560] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 10663554
.text C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe[1612] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10033658
.text C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe[1612] WS2_32.dll!connect 71AB406A 5 Bytes JMP 100335A0
.text C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe[1612] WS2_32.dll!send 71AB428A 5 Bytes JMP 10032E84
.text C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe[1612] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100326A0
.text C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe[1612] WS2_32.dll!recv 71AB615A 5 Bytes JMP 10032624
.text C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe[1612] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 10033554
.text C:\WINDOWS\system32\ctfmon.exe[1780] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003658
.text C:\WINDOWS\system32\ctfmon.exe[1780] ws2_32.dll!connect 71AB406A 5 Bytes JMP 100035A0
.text C:\WINDOWS\system32\ctfmon.exe[1780] ws2_32.dll!send 71AB428A 5 Bytes JMP 10002E84
.text C:\WINDOWS\system32\ctfmon.exe[1780] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100026A0
.text C:\WINDOWS\system32\ctfmon.exe[1780] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002624
.text C:\WINDOWS\system32\ctfmon.exe[1780] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003554
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00BC0FEF
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00BC0093
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00BC0082
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00BC005B
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00BC004A
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00BC0FC3
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00BC0F66
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00BC00AE
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00BC0F41
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00BC00E4
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00BC00F5
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00BC0FA8
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00BC0FDE
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00BC0F83
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00BC0025
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00BC0014
.text C:\WINDOWS\System32\svchost.exe[1812] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00BC00C9
.text C:\WINDOWS\System32\svchost.exe[1812] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00BB0FC3
.text C:\WINDOWS\System32\svchost.exe[1812] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00BB0040
.text C:\WINDOWS\System32\svchost.exe[1812] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00BB0FD4
.text C:\WINDOWS\System32\svchost.exe[1812] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00BB000A
.text C:\WINDOWS\System32\svchost.exe[1812] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00BB0F83
.text C:\WINDOWS\System32\svchost.exe[1812] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00BB0025
.text C:\WINDOWS\System32\svchost.exe[1812] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00BB0FEF
.text C:\WINDOWS\System32\svchost.exe[1812] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00BB0FA8
.text C:\WINDOWS\System32\svchost.exe[1812] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00BA0FA4
.text C:\WINDOWS\System32\svchost.exe[1812] msvcrt.dll!system 77C293C7 5 Bytes JMP 00BA002F
.text C:\WINDOWS\System32\svchost.exe[1812] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00BA0FC6
.text C:\WINDOWS\System32\svchost.exe[1812] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00BA0000
.text C:\WINDOWS\System32\svchost.exe[1812] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00BA0FB5
.text C:\WINDOWS\System32\svchost.exe[1812] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00BA0FE3
.text C:\WINDOWS\System32\svchost.exe[1812] ws2_32.dll!socket 71AB3B91 5 Bytes JMP 00B90000
.text C:\WINDOWS\System32\svchost.exe[1812] ws2_32.dll!connect 71AB406A 5 Bytes JMP 100035A0
.text C:\WINDOWS\System32\svchost.exe[1812] ws2_32.dll!send 71AB428A 5 Bytes JMP 10002E84
.text C:\WINDOWS\System32\svchost.exe[1812] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100026A0
.text C:\WINDOWS\System32\svchost.exe[1812] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002624
.text C:\WINDOWS\System32\svchost.exe[1812] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003554
.text C:\WINDOWS\System32\svchost.exe[1812] wininet.dll!InternetOpenA 6302B2D5 5 Bytes JMP 00B8000A
.text C:\WINDOWS\System32\svchost.exe[1812] wininet.dll!InternetOpenW 6302B92E 5 Bytes JMP 00B80025
.text C:\WINDOWS\System32\svchost.exe[1812] wininet.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 00B80036
.text C:\WINDOWS\System32\svchost.exe[1812] wininet.dll!InternetOpenUrlW 63077347 5 Bytes JMP 00B80FE5
.text C:\WINDOWS\System32\svchost.exe[2072] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 001A0FEF
.text C:\WINDOWS\System32\svchost.exe[2072] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001A0F50
.text C:\WINDOWS\System32\svchost.exe[2072] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 001A0F61
.text C:\WINDOWS\System32\svchost.exe[2072] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 001A0045
.text C:\WINDOWS\System32\svchost.exe[2072] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 001A001E
.text C:\WINDOWS\System32\svchost.exe[2072] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 001A0F97
.text C:\WINDOWS\System32\svchost.exe[2072] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 001A0F2B
.text C:\WINDOWS\System32\svchost.exe[2072] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 001A0071
.text C:\WINDOWS\System32\svchost.exe[2072] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003658
.text C:\WINDOWS\System32\svchost.exe[2072] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 001A0F10
.text C:\WINDOWS\System32\svchost.exe[2072] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 001A0EE4
.text C:\WINDOWS\System32\svchost.exe[2072] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 001A0F7C
.text C:\WINDOWS\System32\svchost.exe[2072] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 001A0FD4
.text C:\WINDOWS\System32\svchost.exe[2072] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 001A0060
.text C:\WINDOWS\System32\svchost.exe[2072] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 001A0FA8
.text C:\WINDOWS\System32\svchost.exe[2072] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 001A0FC3
.text C:\WINDOWS\System32\svchost.exe[2072] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 001A008E
.text C:\WINDOWS\System32\svchost.exe[2072] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 0028005B
.text C:\WINDOWS\System32\svchost.exe[2072] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00280087
.text C:\WINDOWS\System32\svchost.exe[2072] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00280040
.text C:\WINDOWS\System32\svchost.exe[2072] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00280025
.text C:\WINDOWS\System32\svchost.exe[2072] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 0028006C
.text C:\WINDOWS\System32\svchost.exe[2072] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00280FCA
.text C:\WINDOWS\System32\svchost.exe[2072] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00280000
.text C:\WINDOWS\System32\svchost.exe[2072] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00280FE5
.text C:\WINDOWS\System32\svchost.exe[2072] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 003D0FB0
.text C:\WINDOWS\System32\svchost.exe[2072] msvcrt.dll!system 77C293C7 5 Bytes JMP 003D0FC1
.text C:\WINDOWS\System32\svchost.exe[2072] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 003D001D
.text C:\WINDOWS\System32\svchost.exe[2072] msvcrt.dll!_open 77C2F566 5 Bytes JMP 003D0000
.text C:\WINDOWS\System32\svchost.exe[2072] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 003D0FD2
.text C:\WINDOWS\System32\svchost.exe[2072] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 003D0FE3
.text C:\WINDOWS\System32\svchost.exe[2072] ws2_32.dll!socket 71AB3B91 5 Bytes JMP 00690FEF
.text C:\WINDOWS\System32\svchost.exe[2072] ws2_32.dll!connect 71AB406A 5 Bytes JMP 100035A0
.text C:\WINDOWS\System32\svchost.exe[2072] ws2_32.dll!send 71AB428A 5 Bytes JMP 10002E84
.text C:\WINDOWS\System32\svchost.exe[2072] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100026A0
.text C:\WINDOWS\System32\svchost.exe[2072] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002624
.text C:\WINDOWS\System32\svchost.exe[2072] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003554
.text C:\WINDOWS\System32\svchost.exe[2072] wininet.dll!InternetOpenA 6302B2D5 5 Bytes JMP 006A0000
.text C:\WINDOWS\System32\svchost.exe[2072] wininet.dll!InternetOpenW 6302B92E 5 Bytes JMP 006A0FEF
.text C:\WINDOWS\System32\svchost.exe[2072] wininet.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 006A0FDE
.text C:\WINDOWS\System32\svchost.exe[2072] wininet.dll!InternetOpenUrlW 63077347 5 Bytes JMP 006A0FCD
.text C:\WINDOWS\System32\alg.exe[2212] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003658
.text C:\WINDOWS\System32\alg.exe[2212] WS2_32.dll!connect 71AB406A 5 Bytes JMP 100035A0
.text C:\WINDOWS\System32\alg.exe[2212] WS2_32.dll!send 71AB428A 5 Bytes JMP 10002E84
.text C:\WINDOWS\System32\alg.exe[2212] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100026A0
.text C:\WINDOWS\System32\alg.exe[2212] WS2_32.dll!recv 71AB615A 5 Bytes JMP 10002624
.text C:\WINDOWS\System32\alg.exe[2212] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003554
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[2252] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003658
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[2252] WS2_32.dll!connect 71AB406A 5 Bytes JMP 100035A0
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[2252] WS2_32.dll!send 71AB428A 5 Bytes JMP 10002E84
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[2252] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100026A0
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[2252] WS2_32.dll!recv 71AB615A 5 Bytes JMP 10002624
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[2252] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003554
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[2344] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10183658
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[2344] WS2_32.dll!connect 71AB406A 5 Bytes JMP 101835A0
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[2344] WS2_32.dll!send 71AB428A 5 Bytes JMP 10182E84
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[2344] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 101826A0
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[2344] WS2_32.dll!recv 71AB615A 5 Bytes JMP 10182624
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[2344] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 10183554
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2372] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 0041BF60 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2372] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 0041BFE0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2456] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003658
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2456] WS2_32.dll!connect 71AB406A 5 Bytes JMP 100035A0
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2456] WS2_32.dll!send 71AB428A 5 Bytes JMP 10002E84
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2456] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100026A0
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2456] WS2_32.dll!recv 71AB615A 5 Bytes JMP 10002624
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2456] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003554
.text C:\Program Files\McAfee\MSK\MskSrver.exe[2568] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003658
.text C:\Program Files\McAfee\MSK\MskSrver.exe[2568] WS2_32.dll!connect 71AB406A 5 Bytes JMP 100035A0
.text C:\Program Files\McAfee\MSK\MskSrver.exe[2568] WS2_32.dll!send 71AB428A 5 Bytes JMP 10002E84
.text C:\Program Files\McAfee\MSK\MskSrver.exe[2568] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100026A0
.text C:\Program Files\McAfee\MSK\MskSrver.exe[2568] WS2_32.dll!recv 71AB615A 5 Bytes JMP 10002624
.text C:\Program Files\McAfee\MSK\MskSrver.exe[2568] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003554
.text C:\WINDOWS\system32\wuauclt.exe[2816] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 001B0000
.text C:\WINDOWS\system32\wuauclt.exe[2816] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001B009D
.text C:\WINDOWS\system32\wuauclt.exe[2816] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 001B0082
.text C:\WINDOWS\system32\wuauclt.exe[2816] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 001B0065
.text C:\WINDOWS\system32\wuauclt.exe[2816] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 001B0FA8
.text C:\WINDOWS\system32\wuauclt.exe[2816] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 001B0FCA
.text C:\WINDOWS\system32\wuauclt.exe[2816] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 001B0F72
.text C:\WINDOWS\system32\wuauclt.exe[2816] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 001B00AE
.text C:\WINDOWS\system32\wuauclt.exe[2816] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003658
.text C:\WINDOWS\system32\wuauclt.exe[2816] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 001B0F61
.text C:\WINDOWS\system32\wuauclt.exe[2816] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 001B0F3F
.text C:\WINDOWS\system32\wuauclt.exe[2816] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 001B0FB9
.text C:\WINDOWS\system32\wuauclt.exe[2816] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 001B0025
.text C:\WINDOWS\system32\wuauclt.exe[2816] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 001B0F83
.text C:\WINDOWS\system32\wuauclt.exe[2816] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 001B0FE5
.text C:\WINDOWS\system32\wuauclt.exe[2816] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 001B0036
.text C:\WINDOWS\system32\wuauclt.exe[2816] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 001B00D5
.text C:\WINDOWS\system32\wuauclt.exe[2816] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00290F97
.text C:\WINDOWS\system32\wuauclt.exe[2816] msvcrt.dll!system 77C293C7 5 Bytes JMP 00290FB2
.text C:\WINDOWS\system32\wuauclt.exe[2816] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00290FDE
.text C:\WINDOWS\system32\wuauclt.exe[2816] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00290FEF
.text C:\WINDOWS\system32\wuauclt.exe[2816] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00290FCD
.text C:\WINDOWS\system32\wuauclt.exe[2816] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00290018
.text C:\WINDOWS\system32\wuauclt.exe[2816] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 002A0FCA
.text C:\WINDOWS\system32\wuauclt.exe[2816] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 002A0F68
.text C:\WINDOWS\system32\wuauclt.exe[2816] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 002A0011
.text C:\WINDOWS\system32\wuauclt.exe[2816] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 002A0000
.text C:\WINDOWS\system32\wuauclt.exe[2816] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 002A0F79
.text C:\WINDOWS\system32\wuauclt.exe[2816] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 002A0F94
.text C:\WINDOWS\system32\wuauclt.exe[2816] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 002A0FE5
.text C:\WINDOWS\system32\wuauclt.exe[2816] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 002A0FA5
.text C:\WINDOWS\system32\wuauclt.exe[2816] ws2_32.dll!socket 71AB3B91 5 Bytes JMP 003B0FEF
.text C:\WINDOWS\system32\wuauclt.exe[2816] ws2_32.dll!connect 71AB406A 5 Bytes JMP 100035A0
.text C:\WINDOWS\system32\wuauclt.exe[2816] ws2_32.dll!send 71AB428A 5 Bytes JMP 10002E84
.text C:\WINDOWS\system32\wuauclt.exe[2816] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100026A0
.text C:\WINDOWS\system32\wuauclt.exe[2816] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002624
.text C:\WINDOWS\system32\wuauclt.exe[2816] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003554
.text C:\WINDOWS\system32\wuauclt.exe[2816] wininet.dll!InternetOpenA 6302B2D5 5 Bytes JMP 003D0FE5
.text C:\WINDOWS\system32\wuauclt.exe[2816] wininet.dll!InternetOpenW 6302B92E 5 Bytes JMP 003D0000
.text C:\WINDOWS\system32\wuauclt.exe[2816] wininet.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 003D001B
.text C:\WINDOWS\system32\wuauclt.exe[2816] wininet.dll!InternetOpenUrlW 63077347 5 Bytes JMP 003D0036
.text C:\WINDOWS\System32\svchost.exe[2992] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00E00FEF
.text C:\WINDOWS\System32\svchost.exe[2992] kernel32.dll!VirtualProtectEx 7C801A5D 1 Byte [E9]
.text C:\WINDOWS\System32\svchost.exe[2992] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00E00F61
.text C:\WINDOWS\System32\svchost.exe[2992] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00E00F7C
.text C:\WINDOWS\System32\svchost.exe[2992] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00E00056
.text C:\WINDOWS\System32\svchost.exe[2992] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00E00F8D
.text C:\WINDOWS\System32\svchost.exe[2992] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00E00FB9
.text C:\WINDOWS\System32\svchost.exe[2992] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00E00F3C
.text C:\WINDOWS\System32\svchost.exe[2992] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00E00078
.text C:\WINDOWS\System32\svchost.exe[2992] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00E00F17
.text C:\WINDOWS\System32\svchost.exe[2992] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00E000BA
.text C:\WINDOWS\System32\svchost.exe[2992] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00E00EFC
.text C:\WINDOWS\System32\svchost.exe[2992] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00E00FA8
.text C:\WINDOWS\System32\svchost.exe[2992] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00E00FD4
.text C:\WINDOWS\System32\svchost.exe[2992] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00E00067
.text C:\WINDOWS\System32\svchost.exe[2992] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00E0002F
.text C:\WINDOWS\System32\svchost.exe[2992] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00E0000A
.text C:\WINDOWS\System32\svchost.exe[2992] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00E0009F
.text C:\WINDOWS\System32\svchost.exe[2992] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00DF0036
.text C:\WINDOWS\System32\svchost.exe[2992] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00DF0F6F
.text C:\WINDOWS\System32\svchost.exe[2992] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00DF0FE5
.text C:\WINDOWS\System32\svchost.exe[2992] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00DF0011
.text C:\WINDOWS\System32\svchost.exe[2992] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00DF0F94
.text C:\WINDOWS\System32\svchost.exe[2992] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00DF0FA5
.text C:\WINDOWS\System32\svchost.exe[2992] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00DF0000
.text C:\WINDOWS\System32\svchost.exe[2992] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00DF0FCA
.text C:\WINDOWS\System32\svchost.exe[2992] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00DE0F90
.text C:\WINDOWS\System32\svchost.exe[2992] msvcrt.dll!system 77C293C7 5 Bytes JMP 00DE0FB5
.text C:\WINDOWS\System32\svchost.exe[2992] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00DE0FD7
.text C:\WINDOWS\System32\svchost.exe[2992] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00DE0000
.text C:\WINDOWS\System32\svchost.exe[2992] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00DE0FC6
.text C:\WINDOWS\System32\svchost.exe[2992] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00DE0011
.text C:\WINDOWS\System32\svchost.exe[2992] ws2_32.dll!socket 71AB3B91 5 Bytes JMP 00DD0000
.text C:\WINDOWS\System32\svchost.exe[2992] ws2_32.dll!connect 71AB406A 5 Bytes JMP 100035A0
.text C:\WINDOWS\System32\svchost.exe[2992] ws2_32.dll!send 71AB428A 5 Bytes JMP 10002E84
.text C:\WINDOWS\System32\svchost.exe[2992] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100026A0
.text C:\WINDOWS\System32\svchost.exe[2992] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002624
.text C:\WINDOWS\System32\svchost.exe[2992] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003554
.text C:\WINDOWS\System32\svchost.exe[2992] wininet.dll!InternetOpenA 6302B2D5 5 Bytes JMP 00DC0FE5
.text C:\WINDOWS\System32\svchost.exe[2992] wininet.dll!InternetOpenW 6302B92E 5 Bytes JMP 00DC0FD4
.text C:\WINDOWS\System32\svchost.exe[2992] wininet.dll!InternetOpenUrlA 6302DEF0 5 Bytes JMP 00DC0FB9
.text C:\WINDOWS\System32\svchost.exe[2992] wininet.dll!InternetOpenUrlW 63077347 5 Bytes JMP 00DC0FA8
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[3368] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10063658
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[3368] WS2_32.dll!connect 71AB406A 5 Bytes JMP 100635A0
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[3368] WS2_32.dll!send 71AB428A 5 Bytes JMP 10062E84
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[3368] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100626A0
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[3368] WS2_32.dll!recv 71AB615A 5 Bytes JMP 10062624
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[3368] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 10063554
.text C:\WINDOWS\system32\cidaemon.exe[3452] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003658
.text C:\WINDOWS\system32\cidaemon.exe[3452] ws2_32.dll!connect 71AB406A 5 Bytes JMP 100035A0
.text C:\WINDOWS\system32\cidaemon.exe[3452] ws2_32.dll!send 71AB428A 5 Bytes JMP 10002E84
.text C:\WINDOWS\system32\cidaemon.exe[3452] ws2_32.dll!WSARecv 71AB4318 5 Bytes JMP 100026A0
.text C:\WINDOWS\system32\cidaemon.exe[3452] ws2_32.dll!recv 71AB615A 5 Bytes JMP 10002624
.text C:\WINDOWS\system32\cidaemon.exe[3452] ws2_32.dll!WSASend 71AB6233 5 Bytes JMP 10003554

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

—- EOF - GMER 1.0.15 —-
Hi,

I recommend that you uninstall WeatherBug and choose one of these free alternatives:
Weather Pulse
Weather Watcher
or use Mozilla Firefox and then get ForecastFox

To uninstall WeatherBug:
Navigate to Start->Control Panel->Add/Remove Programs
Look down the list for Weatherbug and click Remove


>>>NEXT<<<

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer. (version 6, update 13)


>>>NEXT<<<

Download ToolsCleaner2 to your desktop and run it ( by de A.Rothstein & Dj Quiou )
  • Click the Pt. Restauration button and press OK to the prompts.
  • Click the Corbeille button and press OK to the prompt.
  • Click the Fichiers temp button and press OK to the prompt.
  • Click the Recherche button and let it run ( it may look like it freezes but let it continue )
  • Once it is done click the Suppression button and let it remove anything it finds.
  • Close the program


>>>NEXT<<<

Click Start >> Run and then copy/paste the following into the runbox and hit Enter:

"%userprofile%\Desktop\GooredFix.exe" /uninstall

Note: If any of your security programs query a new Registry/AutoStart value being added please allow the changes.


>>>NEXT<<<

Please post a fresh HJT log and advise how your computer is running now
Thanks for the ongoing help! Okay…. a few interesting things…

1. JavaRa crashed right at the end. When I restarted it, it immediately flashed up its "complete" sign.
2. After running JavaRa, installing JRE6u13, and running ToolCleaner2 (wish I had some French), I tested out Firefox. First time crashed when I went to WhattheTech. Second time crashed on start-up. Third time on attempting to access mcafee.com I got a "The specified method is not supported."
3. So I tried Internet Explorer. It was unable to display mcafee.com as well as avast.com, kaspersky.com, and whathetech.com. It would say it was "done" loading the page, but it would be completely blank.
4. So I tried Firefox again, which was able to open avast and kaspersky and whatthetech
5. Even more interesting is the fact that HJT seemed to have been uninstalled. So I went to download it, but all the sites I tried initially were also blocked. I was finally able to download it from within whatthetech.

So here is the new HJT log…

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:07:06 PM, on 4/18/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\OPLIMIT\ocrawr32.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\bcmwltry.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
F3 - REG:win.ini: load=C:\OPLIMIT\ocraware.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBarBHO.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [GooredFixCleanup] C:\WINDOWS\system32\cmd.exe /Q /C "del C:\DOCUME~1\BRIANM~1\LOCALS~1\Temp\_gooredcleanup.bat"
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: Aurigma Image Uploader 2.0 - http://www.photogize.com/PhotogizeImageUploader.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/45.19/uploader2.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…96/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: McAfee Application Installer Cleanup (0203911240092672) (0203911240092672mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\020391~1.EXE (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - Unknown owner - c:\program files\mcafee.com\agent\mcdetect.exe (file missing)
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/BRIANM~1/LOCALS~1/Temp/msohtml1/01/clip_image002.gif

–
End of file - 12693 bytes
Hi,

Can't really see what could be the cause of the browser crashing as nothing is obvious in the logs,

lets take another look,

please do the following:

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Okay… I downloaded and ran ComboFix. I got a small (very small) dialog box titled "ComboFix" with a small green progress bar that when it completed disappeared. A few moments later the computer suddenly restarted itself. I did not get to any of the dialog boxed that you copied into your message, and thus never had the option to install Microsoft Windows Recovery Console, or to run the scan in ComboFix. On reboot I got the following message from windows… Microsoft Windows The system has recovered from a serious error. A log of this error has been created. Error signature BCCode : c2 BCP1 : 00000007 BCP2 : 00000CD4 BCP3 : 00000000 BCP4 : 80561BE4 OSVer : 5_1_2600 SP : 2_0 Product : 256_1 The following files will be included in this error report: C:\DOCUME~1\BRIANM~1\LOCALS~1\Temp\WERcfa9.dir00\Mini041909-01.dmp C:\DOCUME~1\BRIANM~1\LOCALS~1\Temp\WERcfa9.dir00\sysdata.xml I did not "re-run" ComboFix per instructions. Thoughts?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI