This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Wondering how my laptop's HijackThis logs look

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I was looking to see if there were any bad programs in my computer that my spyware and other programs wern't noticing. I haven't had any specific symptoms, I just want to make sure it looks clean. Thanks for any help.


Logfile of Advanced SystemCare 3 Security Analyzer
Scan saved at 2:10:48 PM, on 7/7/2009
Platform: Windows Vista (WinNT 6.0)
MSIE: Internet Explorer v7.0 (7.0.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\OEM02Mon.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Returnil\Returnil.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\DellTPad\HidFind.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\iTunes\iTunes.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\SearchFilterHost.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: QFX Software KeyScrambler - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: QFX Software KeyScrambler - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: QFX Software KeyScrambler - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: QFX Software KeyScrambler - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: QFX Software KeyScrambler - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: QFX Software KeyScrambler - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Windows Live Toolbar Helper - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Windows Live Toolbar Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [Google Update] "C:\Users\Chris Lindemann\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Rvsystem] C:\PROGRA~1\Returnil\Returnil.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} -
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} -
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} -
O9 - Extra button: &KeyScrambler… - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} -
O9 - Extra button: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_13) - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} (Java Plug-in 1.6.0_04) - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Java Plug-in 1.6.0_05) - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Java Plug-in 1.6.0_07) - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} (Java Plug-in 1.6.0_13) - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_13) - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O23 - Service: Andrea ST Filters Service (AESTFilters) - Unknown - C:\Windows\system32\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: BAAGRHHVEEMC - Unknown - C:\Users\CHRISL~1\AppData\Local\Temp\BAAGRHHVEEMC.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: dlbc_device - Unknown owner - C:\Windows\system32\dlbccoms.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: GoToAssist (gpsvc) - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown - %ProgramFiles%\WinPcap\rpcapd.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown - %ProgramFiles%\Windows Media Player\wmpnetwk.exe
Welcome to What The Tech! My name is Adam and I will be assisting you with getting the malware off of your computer. Please observe the following points before we start:
  • If at any point you don't understand something, please let me know and I will be glad to explain or go more into depth for you. :)
  • Please remember, I am a volunteer and I have a personal life. I go to school full time, have a part time job, and I do sports. A lot of this takes a lot of time.
  • Please keep all of your replies in this topic/thread and do not make a new topic/thread, thanks!
  • Please stick with this, don't stop responding because the symptoms are gone, the infection could still be there. Keep replying to my posts until I give you the All Clean message. ;)
  • If you don't reply within five days after my last instructions this topic will be closed. If you will not be able to reply within five days please tell me so the topic will not be closed.
  • Please do not run other tools to remove the malware unless I ask you to until I give you the all clean. They will just mess up my fixes and make things more complicated, not fix the problem.

RSIT
  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<

Regards,
Adam
Hey Adam thanks very much for helping me. Here are the two logs that RSIT generated:







Logfile of random's system information tool 1.06 (written by random/random)
Run by [removed] at 2009-07-12 14:11:58
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 147 GB (65%) free of 226 GB
Total RAM: 3061 MB (55% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:12:20 PM, on 7/12/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18248)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\OEM02Mon.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Returnil\Returnil.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\DellTPad\HidFind.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Chris Lindemann\Desktop\RSIT.exe
C:\Program Files\trend micro\Chris Lindemann.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Rvsystem] C:\PROGRA~1\Returnil\Returnil.exe
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [Google Update] "C:\Users\Chris Lindemann\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler… - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Unknown owner - C:\Windows\system32\aestsrv.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: BAAGRHHVEEMC - Unknown owner - C:\Users\CHRISL~1\AppData\Local\Temp\BAAGRHHVEEMC.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: dlbc_device - - C:\Windows\system32\dlbccoms.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 13212 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Ad-Aware Update (Weekly).job
C:\Windows\tasks\AWC Startup.job
C:\Windows\tasks\Check Updates for Windows Live Toolbar.job
C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2939173800-4131586745-4067607304-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2939173800-4131586745-4067607304-1000UA.job
C:\Windows\tasks\User_Feed_Synchronization-{FCB795B7-FA1B-4559-861F-3C4FEE8A0C73}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-11-29 436288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2B9F5787-88A5-4945-90E7-C4B18563BC5E}]
KeyScramblerBHO Class - C:\Program Files\KeyScrambler\KeyScramblerIE.dll [2008-11-24 804840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2009-05-19 1107224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll [2009-06-14 1004800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-03-24 668656]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-10-19 546320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
CBrowserHelperObject Object - C:\Program Files\Dell\BAE\BAE.dll [2006-11-09 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-09 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Windows Live Toolbar - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-10-19 546320]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-11-29 436288]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll [2009-06-14 1004800]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-20 1008184]
"ECenter"=C:\Dell\E-Center\EULALauncher.exe [2008-02-29 17920]
"Apoint"=C:\Program Files\DellTPad\Apoint.exe [2008-05-04 167936]
"OEM02Mon.exe"=C:\Windows\OEM02Mon.exe [2008-03-04 36864]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-03-06 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-03-06 166424]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-03-06 133656]
"VolPanel"=C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe [2006-11-27 180224]
"UpdReg"=C:\Windows\UpdReg.EXE [2000-05-11 90112]
"Broadcom Wireless Manager UI"=C:\Windows\system32\WLTRAY.exe [2008-05-19 3444736]
"DELL Webcam Manager"=C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe [2007-07-27 118784]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [2007-03-21 174872]
"dscactivate"=C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe [2008-03-11 16384]
"PCMService"=C:\Program Files\Dell\MediaDirect\PCMService.exe [2007-12-21 184320]
"DellSupportCenter"=C:\Program Files\Dell Support Center\bin\sprtcmd.exe [2008-08-14 206064]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-06-25 1948440]
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2009-05-13 177472]
"Rvsystem"=C:\PROGRA~1\Returnil\Returnil.exe [2008-11-03 2071040]
"Windows Mobile Device Center"=C:\Windows\WindowsMobile\wmdc.exe [2007-05-31 648072]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-09 148888]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-05-26 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-05-30 292136]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"=C:\Program Files\Dell Support Center\bin\sprtcmd.exe [2008-08-14 206064]
"Google Update"=C:\Users\Chris Lindemann\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-15 133104]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-20 125952]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"Aim6"=C:\Program Files\AIM6\aim6.exe [2009-05-19 49968]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2009-05-30 292136]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2009-05-26 413696]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
QuickSet.lnk - C:\Program Files\Dell\QuickSet\quickset.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="avgrsstx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\GoToAssist]
C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll [2008-08-04 10536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-03-06 200704]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\GoToAssist]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1ecee4a3-75fa-11dd-81e4-001fe1e2c91a}]
shell\AutoRun\command - wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2ecbeba3-8bdd-11dd-9bc2-001fe1e2c91a}]
shell\AutoRun\command - F:\LaunchU3.exe -a


======List of files/folders created in the last 1 months======

2009-07-12 14:11:59 —-D—- C:\Program Files\trend micro
2009-07-12 14:11:58 —-D—- C:\rsit
2009-06-25 10:59:56 —-D—- C:\ProgramData\AVG Security Toolbar
2009-06-15 13:18:53 —-D—- C:\ProgramData\AOL Downloads
2009-06-14 11:04:57 —-A—- C:\Windows\system32\EncDec.dll
2009-06-14 11:04:56 —-A—- C:\Windows\system32\psisdecd.dll

======List of files/folders modified in the last 1 months======

2009-07-12 14:12:17 —-D—- C:\Windows\Prefetch
2009-07-12 14:11:59 —-RD—- C:\Program Files
2009-07-12 14:11:51 —-D—- C:\Windows\Temp
2009-07-12 14:00:06 —-D—- C:\Windows\System32
2009-07-12 14:00:06 —-D—- C:\Windows\inf
2009-07-12 14:00:06 —-A—- C:\Windows\system32\PerfStringBackup.INI
2009-07-12 13:57:44 —-D—- C:\Windows\Tasks
2009-07-12 13:57:36 —-D—- C:\ProgramData\Google Updater
2009-07-11 10:27:48 —-SHD—- C:\System Volume Information
2009-07-04 20:55:10 —-D—- C:\Windows\system32\Tasks
2009-07-04 19:32:41 —-D—- C:\Program Files\Mozilla Firefox
2009-07-04 12:56:16 —-D—- C:\Windows\system32\catroot2
2009-07-01 23:48:14 —-D—- C:\Users\Chris Lindemann\AppData\Roaming\uTorrent
2009-06-30 21:35:41 —-D—- C:\Users\Chris Lindemann\AppData\Roaming\Apple Computer
2009-06-25 11:03:51 —-D—- C:\Windows\Microsoft.NET
2009-06-25 11:00:33 —-D—- C:\Windows\system32\drivers
2009-06-25 10:59:56 —-HD—- C:\ProgramData
2009-06-25 10:58:45 —-A—- C:\Windows\system32\avgrsstx.dll
2009-06-25 10:56:13 —-SHD—- C:\Windows\Installer
2009-06-19 21:02:04 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2009-06-19 12:32:00 —-HD—- C:\$AVG8.VAULT$
2009-06-15 13:20:35 —-D—- C:\Program Files\AIM6
2009-06-15 13:20:12 —-D—- C:\ProgramData\Viewpoint
2009-06-15 13:19:50 —-SD—- C:\Windows\Downloaded Program Files
2009-06-15 12:42:53 —-RSD—- C:\Windows\assembly
2009-06-15 12:36:08 —-D—- C:\Windows\ehome
2009-06-15 01:43:42 —-D—- C:\Windows\winsxs
2009-06-14 11:20:47 —-D—- C:\Users\Chris Lindemann\AppData\Roaming\LimeWire
2009-06-14 11:03:09 —-D—- C:\Windows\system32\catroot

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2009-06-25 327688]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2009-06-25 27784]
R1 AvgTdiX;AVG8 Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys [2009-05-19 108552]
R1 FreeOTFE;FreeOTFE; \??\C:\Windows\System32\FreeOTFE.sys [2008-11-20 31856]
R1 FreeOTFECypherAES_ltc;FreeOTFECypherAES_ltc; \??\C:\Windows\System32\FreeOTFECypherAES_ltc.sys [2008-11-20 47600]
R1 FreeOTFECypherBlowfish;FreeOTFECypherBlowfish; \??\C:\Windows\System32\FreeOTFECypherBlowfish.sys [2008-11-20 25200]
R1 FreeOTFECypherCAST5;FreeOTFECypherCAST5; \??\C:\Windows\System32\FreeOTFECypherCAST5.sys [2008-11-20 31088]
R1 FreeOTFECypherCAST6_Gladman;FreeOTFECypherCAST6_Gladman; \??\C:\Windows\System32\FreeOTFECypherCAST6_Gladman.sys [2008-11-20 30576]
R1 FreeOTFECypherDES;FreeOTFECypherDES; \??\C:\Windows\System32\FreeOTFECypherDES.sys [2008-11-20 56816]
R1 FreeOTFECypherMARS_Gladman;FreeOTFECypherMARS_Gladman; \??\C:\Windows\System32\FreeOTFECypherMARS_Gladman.sys [2008-11-20 24944]
R1 FreeOTFECypherRC6_ltc;FreeOTFECypherRC6_ltc; \??\C:\Windows\System32\FreeOTFECypherRC6_ltc.sys [2008-11-20 26480]
R1 FreeOTFECypherSerpent_Gladman;FreeOTFECypherSerpent_Gladman; \??\C:\Windows\System32\FreeOTFECypherSerpent_Gladman.sys [2008-11-20 28528]
R1 FreeOTFECypherTwofish_ltc;FreeOTFECypherTwofish_ltc; \??\C:\Windows\System32\FreeOTFECypherTwofish_ltc.sys [2008-11-20 32112]
R1 FreeOTFEHashMD;FreeOTFEHashMD; \??\C:\Windows\System32\FreeOTFEHashMD.sys [2008-11-20 16752]
R1 FreeOTFEHashRIPEMD;FreeOTFEHashRIPEMD; \??\C:\Windows\System32\FreeOTFEHashRIPEMD.sys [2008-11-20 31856]
R1 FreeOTFEHashSHA;FreeOTFEHashSHA; \??\C:\Windows\System32\FreeOTFEHashSHA.sys [2008-11-20 26096]
R1 FreeOTFEHashTiger;FreeOTFEHashTiger; \??\C:\Windows\System32\FreeOTFEHashTiger.sys [2008-11-20 21872]
R1 FreeOTFEHashWhirlpool;FreeOTFEHashWhirlpool; \??\C:\Windows\System32\FreeOTFEHashWhirlpool.sys [2008-11-20 30448]
R1 SbFw;SbFw; C:\Windows\system32\drivers\SbFw.sys [2008-10-31 270888]
R1 sbhips;Sunbelt HIPS Driver; C:\Windows\system32\drivers\sbhips.sys [2008-06-21 66600]
R1 truecrypt;truecrypt; C:\Windows\System32\drivers\truecrypt.sys [2008-11-19 215616]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 NPF;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2007-11-06 34064]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2007-09-06 39936]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-09-06 42496]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2007-09-06 37376]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-04 8192]
R3 ApfiltrService;Alps Touch Pad Filter Driver for Windows 2000/XP/Vista; C:\Windows\system32\DRIVERS\Apfiltr.sys [2008-05-04 164400]
R3 BCM43XX;Dell Wireless WLAN Card Driver; C:\Windows\system32\DRIVERS\bcmwl6.sys [2008-05-19 1044984]
R3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2008-04-28 19456]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-20 92160]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2008-04-28 29184]
R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2006-11-06 78128]
R3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2006-11-06 80176]
R3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2006-11-06 16560]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-20 14208]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\System32\Drivers\GEARAspiWDM.sys [2009-03-19 23400]
R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2006-11-02 986624]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2006-11-02 206848]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-03-06 2016256]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service; C:\Windows\system32\drivers\IntcHdmi.sys [2008-03-06 111616]
R3 KeyScrambler;KeyScrambler; C:\Windows\System32\drivers\keyscrambler.sys [2008-06-24 113896]
R3 OEM02Dev;Creative Camera OEM002 Driver; C:\Windows\system32\DRIVERS\OEM02Dev.sys [2008-03-04 235648]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver; C:\Windows\system32\DRIVERS\OEM02Vfx.sys [2008-03-04 7424]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2008-01-20 49664]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport; C:\Windows\system32\DRIVERS\sbfwim.sys [2008-06-21 65576]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-20 88576]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2006-11-02 659968]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-20 11264]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2007-12-06 298496]
S3 BCM42RLY;BCM42RLY; C:\Windows\system32\drivers\BCM42RLY.sys []
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2008-04-28 220160]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-20 5632]
S3 e1express;Intel® PRO/1000 PCI Express Network Connection Driver; C:\Windows\system32\DRIVERS\e1e6032.sys [2008-01-20 220672]
S3 EagleNT;EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys []
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-20 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-20 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-20 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-20 6016]
S3 R300;R300; C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 2028032]
S3 STHDA;SigmaTel High Definition Audio CODEC; C:\Windows\system32\drivers\stwrt.sys []
S3 UMPass;Microsoft UMPass Driver; C:\Windows\system32\DRIVERS\umpass.sys [2008-01-20 7680]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2008-07-22 32000]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-20 83328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-20 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-20 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-05-29 144712]
R2 avg8emc;AVG Free8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2009-06-25 906520]
R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-06-25 298776]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-20 21504]
R2 Creative Labs Licensing Service;Creative Labs Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe [2008-08-04 72704]
R2 dlbc_device;dlbc_device; C:\Windows\system32\dlbccoms.exe [2007-03-01 538096]
R2 DockLoginService;Dock Login Service; C:\Program Files\Dell\DellDock\DockLogin.exe [2008-04-28 161048]
R2 IAANTMON;Intel® Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe [2007-03-21 355096]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2008-01-20 21504]
R2 SbPF.Launcher;SbPF.Launcher; C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [2008-10-31 95528]
R2 SBSDWSCService;SBSD Security Center Service; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R2 SPF4;Sunbelt Personal Firewall 4; C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [2008-10-31 1365288]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter); C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2008-08-14 201968]
R2 Viewpoint Manager Service;Viewpoint Manager Service; C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2008-01-20 21504]
R2 wltrysvc;Dell Wireless WLAN Tray Service; C:\Windows\System32\WLTRYSVC.EXE [2008-05-19 24064]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2006-08-04 386560]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-05-30 541992]
S2 AESTFilters;Andrea ST Filters Service; C:\Windows\system32\aestsrv.exe []
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 183280]
S3 BAAGRHHVEEMC;BAAGRHHVEEMC; C:\Users\CHRISL~1\AppData\Local\Temp\BAAGRHHVEEMC.exe []
S3 GoToAssist;GoToAssist; C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe [2008-08-04 16680]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2007-11-06 92792]
S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2008-03-24 74384]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]

—————–EOF—————–
















info.txt logfile of random's system information tool 1.06 2009-07-12 14:12:22

======Uninstall list======

–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2670895A-4E6C-4450-B868-7B7DB80A3357}\setup.exe" -l0x9
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2670895A-4E6C-4450-B868-7B7DB80A3357}\setup.exe" -l0x9 /remove
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9 /remove
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88564CEF-20A5-4EF2-A05F-309F2EBA9B06}\setup.exe" -l0x9
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A1A5BA3E-9ABF-4037-820B-6151022B8ACB}\setup.exe" -l0x9
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}\setup.exe" -l0x9
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AA9944C8-7D34-475E-8C90-2788685B2C47}\setup.exe" -l0x9
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AA9944C8-7D34-475E-8C90-2788685B2C47}\setup.exe" -l0x9 /remove
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AAEF329E-F353-46C9-933D-24A571986093}\setup.exe" -l0x9
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AAEF329E-F353-46C9-933D-24A571986093}\setup.exe" -l0x9 /remove
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AC406C89-7668-46AE-8EFE-75D199C055AB}\setup.exe" -l0x9
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AC406C89-7668-46AE-8EFE-75D199C055AB}\setup.exe" -l0x9 /remove
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D5BA7C09-E523-478C-9C37-A1D86C76383E}\setup.exe" -l0x9
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F6366726-BA44-4D6A-8ECE-476E2E616AD1}\setup.exe" -l0x9
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FBFF2411-D066-4D24-BCE0-893086009E1B}\setup.exe" -l0x9
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FBFF2411-D066-4D24-BCE0-893086009E1B}\setup.exe" -l0x9 /remove
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FCCDA302-32D9-4AE7-A094-4BE677554F26}\setup.exe" -l0x9
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FCCDA302-32D9-4AE7-A094-4BE677554F26}\setup.exe" -l0x9 /remove
Adobe Flash Player 10 Plugin–>C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Player ActiveX–>C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 8.1.3–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81300000003}
Adobe Shockwave Player–>C:\Windows\System32\Adobe\SHOCKW~1\UNWISE.EXE C:\Windows\System32\Adobe\SHOCKW~1\Install.log
Advanced Audio FX Engine–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88564CEF-20A5-4EF2-A05F-309F2EBA9B06}\setup.exe" -l0x9 /remove
Advanced SystemCare 3–>"C:\Program Files\IObit\Advanced SystemCare 3\unins000.exe"
Advanced Video FX Engine–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D5BA7C09-E523-478C-9C37-A1D86C76383E}\setup.exe" -l0x9 /remove
AIM 6–>C:\Program Files\AIM6\uninst.exe
Apple Mobile Device Support–>MsiExec.exe /I{659B48CD-0608-4ED5-94C0-0B6C87114F10}
Apple Software Update–>MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Audacity 1.2.6–>"C:\Program Files\Audacity\unins000.exe"
AVG Free 8.5–>C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
Bonjour–>MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
Browser Address Error Redirector–>MsiExec.exe /I{62230596-37E5-4618-A329-0D21F529A86F}
CCleaner (remove only)–>"C:\Program Files\CCleaner\uninst.exe"
Cisco EAP-FAST Module–>MsiExec.exe /I{BF53252E-4AB2-4C7F-A0FD-6100755745E3}
Cisco LEAP Module–>MsiExec.exe /I{76F9CF97-FC4B-4E20-B363-D127C888448F}
Cisco PEAP Module–>MsiExec.exe /I{4E5386F5-C0F6-4532-A54A-374865AEAB71}
Compatibility Pack for the 2007 Office system–>MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Conexant HDA D330 MDC V.92 Modem–>C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F\HXFSETUP.EXE -U -Idel000fz.inf
Dell DataSafe Online–>MsiExec.exe /I{4D3C9F4B-4B7D-4E5D-99B9-0123AB0D51ED}
Dell Dock–>MsiExec.exe /I{F6CB42B9-F033-4152-8813-FF11DA8E6A78}
Dell Support Center (Support Software)–>MsiExec.exe /X{E3BFEE55-39E2-4BE0-B966-89FE583822C1}
Dell Touchpad–>C:\Program Files\DellTPad\Uninstap.exe ADDREMOVE
Dell Webcam Center–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A1A5BA3E-9ABF-4037-820B-6151022B8ACB}\setup.exe" -l0x9 /remove
Dell Webcam Manager–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F6366726-BA44-4D6A-8ECE-476E2E616AD1}\setup.exe" -l0x9 /remove
Dell Wireless WLAN Card–>"C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="C:\Program Files\Dell\Dell Wireless WLAN Card"
Digital Line Detect–>C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x0009 -removeonly
EDocs–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6B7B6D4D-8F9B-4CB3-8CA4-BCA9CC4C1A22}\setup.exe"
ExtractNow–>"C:\Program Files\ExtractNow\unins000.exe"
Free Mp3/Wma/Ogg Converter 4.0.1–>"C:\Program Files\Free Mp3WmaOgg Converter\unins000.exe"
FreeMind–>"C:\Program Files\FreeMind\unins000.exe"
FreeOTFE–>"C:\Program Files\FreeOTFE\uninstall.exe"
Gimp 2.6.0–>"C:\Program Files\Gimp-2.0\setup\unins000.exe"
Google Earth–>MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
Google Updater–>"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
GoToAssist 8.0.0.514–>C:\Program Files\Citrix\GoToAssist\514\G2AUninstaller.exe /uninstall
HammerHead Rhythm Station–>C:\Program Files\HammerHead\Uninstall.exe
Highlight Viewer (Windows Live Toolbar)–>MsiExec.exe /X{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}
HijackThis 2.0.2–>"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)–>C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)–>C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
ImgBurn–>"C:\Program Files\ImgBurn\uninstall.exe"
Intel® Matrix Storage Manager–>C:\Windows\System32\Imsmudlg.exe
IrfanView (remove only)–>C:\Program Files\IrfanView\iv_uninstall.exe
iTunes–>MsiExec.exe /I{CC5702D7-86E2-45A8-99D7-E8B976ADCC56}
Jarte 3.3–>"C:\Program Files\Jarte\unins000.exe"
Java™ 6 Update 13–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216012FF}
Java™ 6 Update 4–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
Java™ 6 Update 5–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java™ 6 Update 7–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
KeyScrambler–>C:\Program Files\KeyScrambler\uninstall.exe
Laptop Integrated Webcam Driver (1.04.01.1011) –>C:\Windows\CtDrvIns.exe -uninstall -script OEM002.uns -plugin OEM02Pin.dll -pluginres OEM02Pin.crl -nodisconprompt -langid 0x0409
LimeWire 5.1.3–>"C:\Program Files\LimeWire\uninstall.exe"
Live 7.0.10–>C:\PROGRA~1\Ableton\LIVE70~1.10\Install\UNWISE.EXE C:\PROGRA~1\Ableton\LIVE70~1.10\Install\INSTALL.LOG
Live! Cam Avatar Creator–>C:\Program Files\InstallShield Installation Information\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}\setup.exe -runfromtemp -l0x0009 -removeonly /remove
Live! Cam Avatar v1.0–>C:\Program Files\InstallShield Installation Information\{1D5E29AD-39A9-4D0A-A8B6-46A6FCD8C995}\setup.exe -runfromtemp -l0x0009 -removeonly /remove
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Map Button (Windows Live Toolbar)–>MsiExec.exe /X{7745B7A9-F323-4BB9-9811-01BF57A028DA}
MediaDirect–>C:\Program Files\InstallShield Installation Information\{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}\setup.exe -runfromtemp -l0x0009 -cluninstall
Microsoft .NET Framework 3.5 SP1–>c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1–>MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Games for Windows - LIVE Redistributable–>MsiExec.exe /X{929CE49F-1CA7-4CF3-A9A1-6D757443C63F}
Microsoft Office Live Add-in 1.3–>MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
Microsoft Office XP Professional with FrontPage–>MsiExec.exe /I{90280409-6000-11D3-8CFE-0050048383C9}
Microsoft Silverlight–>MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft VC9 runtime libraries–>MsiExec.exe /I{C4124E95-5061-4776-8D5D-E3D931C778E1}
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Works–>MsiExec.exe /I{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}
mIRC–>C:\Program Files\mIRC\uninstall.exe _?=C:\Program Files\mIRC
MobileMe Control Panel–>MsiExec.exe /I{DDBB28C8-B2AA-45A1-8DCE-059A798509FB}
Modem Diagnostic Tool–>MsiExec.exe /I{F63A3748-B93D-4360-9AD4-B064481A5C7B}
Mozilla Firefox (3.0.5)–>C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB941833)–>MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
MSXML 4.0 SP2 (KB954430)–>MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
NetWaiting–>C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x0009 -removeonly
Network Stumbler 0.4.0 (remove only)–>"C:\Program Files\Network Stumbler\uninst.exe"
OpenOffice.org 2.4–>MsiExec.exe /I{2CD2C0DB-81C3-416B-9FA6-589B9235359B}
PuTTY version 0.60–>"C:\Program Files\PuTTY\unins000.exe"
QuickSet–>MsiExec.exe /I{4B6AD248-D3BF-426A-8D64-847288154F13}
QuickTime–>MsiExec.exe /I{C78EAC6F-7A73-452E-8134-DBB2165C5A68}
Returnil Virtual System Personal Edition–>C:\Program files\Returnil\Uninstall.exe /REMOVE
Roxio Creator Audio–>MsiExec.exe /I{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}
Roxio Creator Copy–>MsiExec.exe /I{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}
Roxio Creator Data–>MsiExec.exe /I{08E81ABD-79F7-49C2-881F-FD6CB0975693}
Roxio Creator DE–>C:\ProgramData\Uninstall\{09760D42-E223-42AD-8C3E-55B47D0DDAC3}\setup.exe /x {09760D42-E223-42AD-8C3E-55B47D0DDAC3}
Roxio Creator DE–>MsiExec.exe /I{ED439A64-F018-4DD4-8BA5-328D85AB09AB}
Roxio Creator Tools–>MsiExec.exe /I{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}
Roxio Express Labeler 3–>MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
Roxio Update Manager–>MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
Safari–>MsiExec.exe /I{9C48DCA4-00C2-449C-88D8-B1EE1692B44F}
SecondLife (remove only)–>"C:\Program Files\SecondLife\uninst.exe" /P="SecondLife"
Skype™ 3.8–>MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
Smart Menus (Windows Live Toolbar)–>MsiExec.exe /X{F084395C-40FB-4DB3-981C-B51E74E1E83D}
Sound Blaster Audigy ADVANCED MB–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{53C6D09E-EAB6-49E5-BA4C-BA7FF13830FB}\Setup.exe" -l0x9 /remove
Spelling Dictionaries Support For Adobe Reader 8–>MsiExec.exe /I{AC76BA86-7AD7-5464-3428-800000000003}
Spybot - Search & Destroy–>"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Sunbelt Personal Firewall–>MsiExec.exe /X{82B1150E-9B37-49FC-83EB-D52197D900D0}
The KMPlayer (remove only)–>"C:\Program Files\The KMPlayer\uninstall.exe"
TrueCrypt–>"C:\Program Files\TrueCrypt\TrueCrypt Setup.exe" /u
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)–>C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Viewpoint Media Player–>C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
Visual C++ 2008 x86 Runtime - (v9.0.30729)–>MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
Visual C++ 2008 x86 Runtime - v9.0.30729.01–>C:\Windows\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
WIDCOMM Bluetooth Software 6.0.1.3100–>MsiExec.exe /X{A13E07E1-A423-44FB-9DEE-B24C75C1BAF2}
Windows Live Favorites for Windows Live Toolbar–>MsiExec.exe /X{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}
Windows Live installer–>MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Mail–>MsiExec.exe /I{184E7118-0295-43C4-B72C-1D54AA75AAF7}
Windows Live Messenger–>MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Sign-in Assistant–>MsiExec.exe /I{9422C8EA-B0C6-4197-B8FC-DC797658CA00}
Windows Live Toolbar Extension (Windows Live Toolbar)–>MsiExec.exe /X{341201D4-4F61-4ADB-987E-9CCE4D83A58D}
Windows Live Toolbar–>"C:\Program Files\Windows Live Toolbar\UnInstall.exe" {D5A145FC-D00C-4F1A-9119-EB4D9D659750}
Windows Live Toolbar–>MsiExec.exe /X{D5A145FC-D00C-4F1A-9119-EB4D9D659750}
Windows Live Writer–>MsiExec.exe /X{9176251A-4CC1-4DDB-B343-B487195EB397}
Windows Mobile Device Center–>MsiExec.exe /X{904CCF62-818D-4675-BC76-D37EB399F917}
WinPcap 4.0.2–>C:\Program Files\WinPcap\uninstall.exe
WinRAR archiver–>C:\Program Files\WinRAR\uninstall.exe
Wireshark 1.0.5–>"C:\Program Files\Wireshark\uninstall.exe"
Yahoo! Install Manager–>C:\Windows\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
Yahoo! Messenger–>C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG

======Security center information======

AV: AVG Anti-Virus Free
FW: Sunbelt Personal Firewall
AS: AVG Anti-Virus Free (disabled)
AS: Spybot - Search and Destroy (outdated)
AS: Windows Defender

======System event log======

Computer Name: Lindemann-Chris
Event Code: 7000
Message: The BCM42RLY service failed to start due to the following error:
The system cannot find the file specified.
Record Number: 12863
Source Name: Service Control Manager
Time Written: 20080825055744.000000-000
Event Type: Error
User:

Computer Name: Lindemann-Chris
Event Code: 7000
Message: The BCM42RLY service failed to start due to the following error:
The system cannot find the file specified.
Record Number: 12865
Source Name: Service Control Manager
Time Written: 20080825055746.000000-000
Event Type: Error
User:

Computer Name: Lindemann-Chris
Event Code: 7000
Message: The BCM42RLY service failed to start due to the following error:
The system cannot find the file specified.
Record Number: 12866
Source Name: Service Control Manager
Time Written: 20080825055746.000000-000
Event Type: Error
User:

Computer Name: Lindemann-Chris
Event Code: 7000
Message: The BCM42RLY service failed to start due to the following error:
The system cannot find the file specified.
Record Number: 12867
Source Name: Service Control Manager
Time Written: 20080825055747.000000-000
Event Type: Error
User:

Computer Name: Lindemann-Chris
Event Code: 6008
Message: The previous system shutdown at 1:57:32 AM on 8/25/2008 was unexpected.
Record Number: 12875
Source Name: EventLog
Time Written: 20080825055912.000000-000
Event Type: Error
User:

=====Application event log=====

Computer Name: Lindemann-Chris
Event Code: 10
Message: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Record Number: 18196
Source Name: Microsoft-Windows-WMI
Time Written: 20090709134648.000000-000
Event Type: Error
User:

Computer Name: Lindemann-Chris
Event Code: 4621
Message: The COM+ Event System could not remove the EventSystem.EventSubscription object {AA44355E-6911-4447-BA5D-6720480579AF}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. The HRESULT was 80070005.
Record Number: 18223
Source Name: Microsoft-Windows-EventSystem
Time Written: 20090710051431.000000-000
Event Type: Error
User:

Computer Name: Lindemann-Chris
Event Code: 10
Message: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Record Number: 18240
Source Name: Microsoft-Windows-WMI
Time Written: 20090710125018.000000-000
Event Type: Error
User:

Computer Name: Lindemann-Chris
Event Code: 10
Message: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Record Number: 18275
Source Name: Microsoft-Windows-WMI
Time Written: 20090711133815.000000-000
Event Type: Error
User:

Computer Name: Lindemann-Chris
Event Code: 10
Message: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Record Number: 18311
Source Name: Microsoft-Windows-WMI
Time Written: 20090712175523.000000-000
Event Type: Error
User:

=====Security event log=====

Computer Name: Lindemann-Chris
Event Code: 4672
Message: Special privileges assigned to new logon.

Subject:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7

Privileges: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 33504
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090712175824.028406-000
Event Type: Audit Success
User:

Computer Name: Lindemann-Chris
Event Code: 4648
Message: A logon was attempted using explicit credentials.

Subject:
Security ID: S-1-5-18
Account Name: LINDEMANN-CHRIS$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}

Account Whose Credentials Were Used:
Account Name: Chris Lindemann
Account Domain: Lindemann-Chris
Logon GUID: {00000000-0000-0000-0000-000000000000}

Target Server:
Target Server Name: localhost
Additional Information: localhost

Process Information:
Process ID: 0x34c
Process Name: C:\Windows\System32\winlogon.exe

Network Information:
Network Address: 127.0.0.1
Port: 0

This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
Record Number: 33505
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090712180019.296806-000
Event Type: Audit Success
User:

Computer Name: Lindemann-Chris
Event Code: 4624
Message: An account was successfully logged on.

Subject:
Security ID: S-1-5-18
Account Name: LINDEMANN-CHRIS$
Account Domain: WORKGROUP
Logon ID: 0x3e7

Logon Type: 2

New Logon:
Security ID: S-1-5-21-2939173800-4131586745-4067607304-1000
Account Name: Chris Lindemann
Account Domain: Lindemann-Chris
Logon ID: 0xe58e8
Logon GUID: {00000000-0000-0000-0000-000000000000}

Process Information:
Process ID: 0x34c
Process Name: C:\Windows\System32\winlogon.exe

Network Information:
Workstation Name: LINDEMANN-CHRIS
Source Network Address: 127.0.0.1
Source Port: 0

Detailed Authentication Information:
Logon Process: User32
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 33506
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090712180019.296806-000
Event Type: Audit Success
User:

Computer Name: Lindemann-Chris
Event Code: 4624
Message: An account was successfully logged on.

Subject:
Security ID: S-1-5-18
Account Name: LINDEMANN-CHRIS$
Account Domain: WORKGROUP
Logon ID: 0x3e7

Logon Type: 2

New Logon:
Security ID: S-1-5-21-2939173800-4131586745-4067607304-1000
Account Name: Chris Lindemann
Account Domain: Lindemann-Chris
Logon ID: 0xe5911
Logon GUID: {00000000-0000-0000-0000-000000000000}

Process Information:
Process ID: 0x34c
Process Name: C:\Windows\System32\winlogon.exe

Network Information:
Workstation Name: LINDEMANN-CHRIS
Source Network Address: 127.0.0.1
Source Port: 0

Detailed Authentication Information:
Logon Process: User32
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 33507
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090712180019.296806-000
Event Type: Audit Success
User:

Computer Name: Lindemann-Chris
Event Code: 4672
Message: Special privileges assigned to new logon.

Subject:
Security ID: S-1-5-21-2939173800-4131586745-4067607304-1000
Account Name: Chris Lindemann
Account Domain: Lindemann-Chris
Logon ID: 0xe58e8

Privileges: SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 33508
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090712180019.296806-000
Event Type: Audit Success
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\10.0\DLLShared\;C:\Program Files\QuickTime\QTSystem\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
"PROCESSOR_REVISION"=0f0d
"NUMBER_OF_PROCESSORS"=2
"TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
"DFSTRACINGON"=FALSE
"RoxioCentral"=C:\Program Files\Common Files\Roxio Shared\10.0\Roxio Central36\
"CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

—————–EOF—————–
Hi there,

You have/had Limewire, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm

If you wish to keep it, please do not use it until your computer is cleaned.

I would recommend that you uninstall Limewire, however that choice is up to you.

Download and Run ComboFix
Please visit this page to download and run Combofix - http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Save it to your desktop.

  • Double click on ComboFix.exe & follow the prompts.
  • As part of its process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. You will see the following message if Microsoft Windows Recovery Console is not installed.

    [external image: Posted Image]

    With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes to continue scanning for malware.

When finished, a log will be produced. Please post this log in your next reply.

Do not mouse click on Combofix while it is running. That may cause it to stall.

Run GMER
Please download gmer.zip from Gmer and save it to your desktop.

  • Right click on gmer.zip and select Extract All….
  • Click Next on seeing the Welcome to the Compressed (zipped) Folders Extraction Wizard.
  • Click on the Browse button. Click on Desktop. Then click OK.
  • Click Next. It will start extracting.
  • Once done, check (tick) the Show extracted files box and click Finish.
  • Double click on gmer.exe to run it.
  • Select the Rootkit tab.
  • On the right hand side, check all the items to be scanned, but leave Show All box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click on the Scan button.
  • When the scan is finished, click Copy to save the scan log to the Windows clipboard.
  • Open Notepad or a similar text editor.
  • Paste the clipboard contents into the text editor.
  • Save the Gmer scan log and post it in your next reply.
  • Close Gmer.
  • Open Command Prompt by going to Start > Run and type in cmd. Press Enter.
  • In Command Prompt, type in net stop gmer. Press Enter.
  • Type in exit to close Command Prompt.

Note: Do not run any programs while Gmer is running.

Run HijackThis
  • Browse to C:\Program Files\Trend Micro
  • Now start HijackThis.
  • Click Do a system scan and save a log file.
  • Post the log file here. (Notepad will automatically open with the log file once HijackThis! has finished scanning). Do not attach the log file.

In your next reply, please include:
  • ComboFix log
  • GMER log
  • A new HijackThis log

Regards,
Adam
Thanks for the quick response Adam. Here are the three logs:







ComboFix 09-07-12.01 - Chris Lindemann 07/12/2009 17:58.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3061.1840 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Sunbelt Personal Firewall *enabled* {82B1150E-9B37-49FC-83EB-D52197D900D0}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *enabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-2773397201-2855733099-4214572315-500
c:\$recycle.bin\S-1-5-21-2939173800-4131586745-4067607304-500

.
((((((((((((((((((((((((( Files Created from 2009-06-12 to 2009-07-12 )))))))))))))))))))))))))))))))
.

2009-07-12 22:05 . 2009-07-12 22:06 ——– d—–w- c:\users\Chris Lindemann\AppData\Local\temp
2009-07-12 18:11 . 2009-07-12 18:12 ——– d—–w- c:\program files\trend micro
2009-07-12 18:11 . 2009-07-12 18:12 ——– d—–w- C:\rsit
2009-07-01 01:30 . 2009-07-01 18:48 ——– d—–w- c:\users\Chris Lindemann\New Folder
2009-06-28 14:15 . 2009-06-28 14:15 746744 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-06-25 15:17 . 2009-06-25 15:17 ——– d—–w- c:\users\Chris Lindemann\AppData\Local\AVG Security Toolbar
2009-06-25 15:00 . 2009-06-25 14:58 832144 —-a-w- c:\programdata\Avg8\update\backup\AVGToolbarInstall.exe
2009-06-25 14:59 . 2009-06-25 14:59 ——– d—–w- c:\programdata\AVG Security Toolbar
2009-06-14 15:04 . 2009-04-30 12:37 428544 —-a-w- c:\windows\system32\EncDec.dll
2009-06-14 15:04 . 2009-04-30 12:37 293376 —-a-w- c:\windows\system32\psisdecd.dll
2009-06-13 05:03 . 2009-06-13 05:03 ——– d—–w- c:\users\Chris Lindemann\dwhelper

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-12 21:15 . 2008-08-04 10:38 2484 —-a-w- c:\windows\bthservsdp.dat
2009-07-12 21:01 . 2009-01-25 08:09 ——– d—–w- c:\program files\LimeWire
2009-07-12 17:57 . 2008-11-23 19:44 ——– d—–w- c:\programdata\Google Updater
2009-07-02 03:48 . 2008-10-13 01:03 ——– d—–w- c:\users\Chris Lindemann\AppData\Roaming\uTorrent
2009-07-01 01:35 . 2008-08-10 03:58 ——– d—–w- c:\users\Chris Lindemann\AppData\Roaming\Apple Computer
2009-06-25 14:58 . 2008-10-19 09:00 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-06-25 14:58 . 2008-10-19 09:00 327688 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-25 14:58 . 2008-10-19 09:00 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-20 01:02 . 2008-11-22 23:17 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-20 01:01 . 2008-12-30 01:04 3561743 —-a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-17 15:27 . 2008-11-22 23:17 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 15:27 . 2008-11-22 23:17 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-15 17:20 . 2008-08-10 04:29 ——– d—–w- c:\program files\AIM6
2009-06-15 17:20 . 2008-08-10 04:30 ——– d—–w- c:\programdata\Viewpoint
2009-06-15 17:18 . 2009-06-15 17:18 ——– d—–w- c:\programdata\AOL Downloads
2009-06-14 15:20 . 2009-01-25 08:10 ——– d—–w- c:\users\Chris Lindemann\AppData\Roaming\LimeWire
2009-06-12 16:35 . 2008-08-04 16:09 ——– d—–w- c:\program files\Microsoft Works
2009-06-09 05:03 . 2009-01-17 03:12 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2009-06-09 05:03 . 2009-01-25 02:33 ——– d—–w- c:\program files\Lavasoft
2009-06-09 05:03 . 2008-08-10 02:41 ——– d—–w- c:\programdata\Lavasoft
2009-06-08 18:00 . 2009-06-11 20:12 110592 —-a-w- c:\users\Chris Lindemann\AppData\Roaming\Mozilla\Firefox\Profiles\yrt9z7cd.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
2009-06-06 23:21 . 2009-06-06 23:21 ——– d—–w- c:\program files\iTunes
2009-06-06 23:21 . 2009-06-06 23:21 ——– d—–w- c:\program files\iPod
2009-06-06 23:21 . 2008-08-10 03:44 ——– d—–w- c:\program files\Common Files\Apple
2009-06-06 23:19 . 2009-06-06 23:19 ——– d—–w- c:\program files\QuickTime
2009-06-06 23:03 . 2009-06-06 23:03 75048 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-04 19:32 . 2009-06-04 19:31 ——– d—–w- c:\program files\Free Mp3WmaOgg Converter
2009-05-30 23:04 . 2009-05-30 23:03 ——– d—–w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-30 23:02 . 2009-05-30 23:02 ——– d—–w- c:\program files\Bonjour
2009-05-30 22:35 . 2009-05-30 22:35 ——– d—–w- c:\program files\Safari
2009-05-28 17:23 . 2008-08-04 15:48 ——– d—–w- c:\program files\Java
2009-05-19 17:29 . 2009-02-04 16:36 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-19 06:20 . 2008-08-04 15:49 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-05-19 05:36 . 2009-06-15 17:18 97072 —-a-w- c:\programdata\AOL Downloads\SUD4426\bsetutil.exe
2009-05-19 05:36 . 2009-06-15 17:18 2884832 —-a-w- c:\programdata\AOL Downloads\SUD4426\vwpt.exe
2009-05-19 05:36 . 2009-06-15 17:18 28 —-a-w- c:\programdata\AOL Downloads\SUD4426\unregister.bat
2009-05-19 05:36 . 2009-06-15 17:18 25 —-a-w- c:\programdata\AOL Downloads\SUD4426\register.bat
2009-05-19 05:36 . 2009-06-15 17:18 1484856 —-a-w- c:\programdata\AOL Downloads\SUD4426\toolbar.exe
2009-05-19 05:36 . 2009-06-15 17:18 142040 —-a-w- c:\programdata\AOL Downloads\SUD4426\alsetup.exe
2009-05-19 05:36 . 2009-06-15 17:18 30512 —-a-w- c:\programdata\AOL Downloads\SUD4426\Uninstaller.exe
2009-05-19 05:36 . 2009-06-15 17:18 111920 —-a-w- c:\programdata\AOL Downloads\SUD4426\AOLSearch.dll
2009-05-16 00:06 . 2009-05-16 00:06 416128 —-a-w- c:\programdata\Microsoft\eHome\Packages\NetTV\Browse\NetTVResources.dll
2009-05-14 07:00 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-04-24 16:05 . 2009-06-11 16:28 827904 —-a-w- c:\windows\system32\wininet.dll
2009-04-24 16:02 . 2009-06-11 16:28 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-04-24 13:44 . 2009-06-11 16:28 26624 —-a-w- c:\windows\system32\ieUnatt.exe
2009-04-23 12:43 . 2009-06-11 16:28 784896 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:42 . 2009-06-11 16:28 636928 —-a-w- c:\windows\system32\localspl.dll
2009-04-21 11:55 . 2009-06-11 16:28 2033152 —-a-w- c:\windows\system32\win32k.sys
2008-08-04 15:54 . 2008-08-04 15:54 76 –sh–r- c:\windows\CT4CET.bin
2008-08-04 18:30 . 2008-08-04 18:30 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 20:07 1004800 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"Google Update"="c:\users\Chris Lindemann\AppData\Local\Google\Update\GoogleUpdate.exe" [2008-09-15 133104]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-29 17920]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-05-04 167936]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2008-03-04 36864]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-06 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-06 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-06 133656]
"VolPanel"="c:\program files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" [2006-11-27 180224]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-05-19 3444736]
"DELL Webcam Manager"="c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 118784]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-12-21 184320]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-25 1948440]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-14 177472]
"Rvsystem"="c:\progra~1\Returnil\Returnil.exe" [2008-11-04 2071040]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-05-30 292136]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-8-4 50688]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-2-22 1193240]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-08-04 16:13 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{EB00B42A-C4EF-43DF-9BBF-BF92E0C6352A}"= c:\program files\Dell\MediaDirect\MediaDirect.exe:Dell MediaDirect
"{16840399-7467-49FB-A8D9-811F529C379F}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program
"{10083886-1B66-46BC-9576-561C6C9FFAB2}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{008F72DD-BA82-4E7A-85DF-BC08FF2D59DA}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"{94365828-80BF-4786-B905-2A31DBE1D316}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{211F0709-9EAB-40CE-A5E5-1C1A7C632CFD}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{0F280C9E-3566-46A0-B998-66AF13608717}"= UDP:c:\program files\AIM6\aim6.exe:AIM
"{B6656779-4223-4ACC-B874-F98E61B90549}"= TCP:c:\program files\AIM6\aim6.exe:AIM
"{BAABF74E-954F-4342-9460-07E4AB6001A4}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{FBDE3586-9AD2-4D53-939D-848A3B95EF66}c:\\program files\\aim6\\aim6.exe"= UDP:c:\program files\aim6\aim6.exe:AIM
"UDP Query User{7012E816-19F2-448D-B8BD-39DDB8A792C4}c:\\program files\\aim6\\aim6.exe"= TCP:c:\program files\aim6\aim6.exe:AIM
"{5C995906-71B8-442A-A5AC-8A6AE74FB369}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{732713D3-74AD-45AA-83BB-5FF9D154AEBC}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{D9ACB148-8390-45C3-BD21-734E9E417CDC}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{27B0A277-1A5E-4203-99DE-1AA662AE4423}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{20329BD4-36A5-4956-8698-58076EBA0BB0}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{AEA0FE0E-78B9-45DE-B191-2385ADB3DE67}"= UDP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{08F1119E-B01D-43CE-938B-45F13085111A}"= TCP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{F69EA0BB-8A67-4C19-8FAB-21523C370289}"= UDP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{6A50ACB5-B8D7-4D5D-9273-F2BB671741A8}"= TCP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{5F72A3A9-1A10-4D6E-94F9-B60F90167323}"= UDP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{BF8B794C-4C4C-4038-8982-AB117151CCC3}"= TCP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{7E73B944-21B7-4FD0-A454-7CAC212D2C3F}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{060B24AC-82C1-482C-AE98-D6AC1FE0A4A2}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{4FB7D275-B794-4BD8-B50B-27E9B1DFB137}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"{F9924592-E4A7-484D-AD15-AC9F0608CFC1}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"TCP Query User{605F2D05-49A0-4524-A370-5479DC210BBD}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{EF52AB41-FBA3-4171-9E3C-102803EC60CE}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{837E25DF-AC03-45E5-AD76-3367F512047C}c:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= UDP:c:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"UDP Query User{E1B928D4-3643-425C-A343-E9ECB45DB077}c:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= TCP:c:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"TCP Query User{3E54C644-A15B-4A11-AB5D-22F09F86AA84}c:\\program files\\sunbelt software\\personal firewall\\sbpfcl.exe"= UDP:c:\program files\sunbelt software\personal firewall\sbpfcl.exe:Sunbelt Firewall GUI
"UDP Query User{5AF6C8D5-F84D-4630-9135-BFB7BD05F66E}c:\\program files\\sunbelt software\\personal firewall\\sbpfcl.exe"= TCP:c:\program files\sunbelt software\personal firewall\sbpfcl.exe:Sunbelt Firewall GUI
"{ED546654-4F72-48DA-BB44-C771587919EB}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{99A86A20-731F-49AC-845E-01E8A5ABC26D}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{7B01776E-A749-4652-945F-F2932898C011}"= UDP:c:\windows\System32\dlbccoms.exe:Photo Printer 720 Server
"{227644DF-2841-41B0-A938-EF44569DA9EC}"= TCP:c:\windows\System32\dlbccoms.exe:Photo Printer 720 Server
"TCP Query User{DA2C50D9-A93A-4CC9-A859-FD548B209708}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{CB214D8F-73E3-415A-B6DA-D933BE20F916}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire
"{A5D9653B-F82D-448E-8249-7C2C3184CD8A}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{9F3963D3-1A7D-4E25-91E7-858481D53AC9}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{1F2CE80F-D20D-449A-8D95-68A440857912}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{0424984B-DD00-4D7E-B542-5EA548803659}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{20368C55-D5BC-4C4D-881E-A0AC916C3B27}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{3B1CD197-C07C-4DFF-8DAC-33FE991C7695}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R0 RVSDISK;RVSDISK;c:\windows\System32\drivers\RVSDISK.sys [11/3/2008 10:40 PM 11904]
R0 RVSYSTEM;RVSYSTEM;c:\windows\System32\drivers\RVSYSTEM.sys [11/3/2008 10:40 PM 38272]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [10/19/2008 5:00 AM 327688]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [2/4/2009 12:36 PM 108552]
R1 FreeOTFE;FreeOTFE;c:\windows\System32\FreeOTFE.sys [12/8/2008 2:14 AM 31856]
R1 FreeOTFECypherAES_ltc;FreeOTFECypherAES_ltc;c:\windows\System32\FreeOTFECypherAES_ltc.sys [12/8/2008 2:14 AM 47600]
R1 FreeOTFECypherBlowfish;FreeOTFECypherBlowfish;c:\windows\System32\FreeOTFECypherBlowfish.sys [12/8/2008 2:14 AM 25200]
R1 FreeOTFECypherCAST5;FreeOTFECypherCAST5;c:\windows\System32\FreeOTFECypherCAST5.sys [12/8/2008 2:14 AM 31088]
R1 FreeOTFECypherCAST6_Gladman;FreeOTFECypherCAST6_Gladman;c:\windows\System32\FreeOTFECypherCAST6_Gladman.sys [12/8/2008 2:14 AM 30576]
R1 FreeOTFECypherDES;FreeOTFECypherDES;c:\windows\System32\FreeOTFECypherDES.sys [12/8/2008 2:14 AM 56816]
R1 FreeOTFECypherMARS_Gladman;FreeOTFECypherMARS_Gladman;c:\windows\System32\FreeOTFECypherMARS_Gladman.sys [12/8/2008 2:14 AM 24944]
R1 FreeOTFECypherRC6_ltc;FreeOTFECypherRC6_ltc;c:\windows\System32\FreeOTFECypherRC6_ltc.sys [12/8/2008 2:14 AM 26480]
R1 FreeOTFECypherSerpent_Gladman;FreeOTFECypherSerpent_Gladman;c:\windows\System32\FreeOTFECypherSerpent_Gladman.sys [12/8/2008 2:14 AM 28528]
R1 FreeOTFECypherTwofish_ltc;FreeOTFECypherTwofish_ltc;c:\windows\System32\FreeOTFECypherTwofish_ltc.sys [12/8/2008 2:14 AM 32112]
R1 FreeOTFEHashMD;FreeOTFEHashMD;c:\windows\System32\FreeOTFEHashMD.sys [12/8/2008 2:14 AM 16752]
R1 FreeOTFEHashRIPEMD;FreeOTFEHashRIPEMD;c:\windows\System32\FreeOTFEHashRIPEMD.sys [12/8/2008 2:14 AM 31856]
R1 FreeOTFEHashSHA;FreeOTFEHashSHA;c:\windows\System32\FreeOTFEHashSHA.sys [12/8/2008 2:14 AM 26096]
R1 FreeOTFEHashTiger;FreeOTFEHashTiger;c:\windows\System32\FreeOTFEHashTiger.sys [12/8/2008 2:14 AM 21872]
R1 FreeOTFEHashWhirlpool;FreeOTFEHashWhirlpool;c:\windows\System32\FreeOTFEHashWhirlpool.sys [12/8/2008 2:14 AM 30448]
R1 SbFw;SbFw;c:\windows\System32\drivers\SbFw.sys [10/31/2008 8:09 AM 270888]
R1 sbhips;Sunbelt HIPS Driver;c:\windows\System32\drivers\sbhips.sys [6/21/2008 5:54 AM 66600]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [10/19/2008 5:00 AM 906520]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [10/19/2008 5:00 AM 298776]
R2 dlbc_device;dlbc_device;c:\windows\system32\dlbccoms.exe -service –> c:\windows\system32\dlbccoms.exe -service [?]
R2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [4/28/2008 5:56 PM 161048]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\System32\drivers\npf.sys [11/6/2007 4:22 PM 34064]
R2 SbPF.Launcher;SbPF.Launcher;c:\program files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [10/31/2008 8:24 AM 95528]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [1/16/2009 11:12 PM 1153368]
R2 SPF4;Sunbelt Personal Firewall 4;c:\program files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [10/31/2008 8:24 AM 1365288]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [8/10/2008 12:30 AM 24652]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\System32\drivers\IntcHdmi.sys [8/4/2008 2:31 PM 111616]
R3 KeyScrambler;KeyScrambler;c:\windows\System32\drivers\keyscrambler.sys [10/14/2008 9:59 PM 113896]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\System32\drivers\OEM02Dev.sys [8/4/2008 2:31 PM 235648]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\System32\drivers\OEM02Vfx.sys [8/4/2008 2:31 PM 7424]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\System32\drivers\SbFwIm.sys [12/7/2008 4:02 PM 65576]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe –> c:\windows\system32\aestsrv.exe [?]
S3 BAAGRHHVEEMC;BAAGRHHVEEMC;c:\users\CHRISL~1\AppData\Local\Temp\BAAGRHHVEEMC.exe –> c:\users\CHRISL~1\AppData\Local\Temp\BAAGRHHVEEMC.exe [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contents of the 'Scheduled Tasks' folder

2009-07-12 c:\windows\Tasks\AWC Startup.job
- c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2009-06-28 13:55]

2008-09-14 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 15:20]

2009-07-12 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-23 01:28]

2009-07-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2939173800-4131586745-4067607304-1000Core.job
- c:\users\Chris Lindemann\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-15 06:43]

2009-07-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2939173800-4131586745-4067607304-1000UA.job
- c:\users\Chris Lindemann\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-15 06:43]

2009-07-12 c:\windows\Tasks\User_Feed_Synchronization-{FCB795B7-FA1B-4559-861F-3C4FEE8A0C73}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=3080804
uInternet Settings,ProxyOverride = *.local
IE: &Windows; Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Send image to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\users\Chris Lindemann\AppData\Roaming\Mozilla\Firefox\Profiles\yrt9z7cd.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 8118
FF - prefs.js: network.proxy.socks - 127.0.0.1
FF - prefs.js: network.proxy.socks_port - 9050
FF - prefs.js: network.proxy.ssl - 127.0.0.1
FF - prefs.js: network.proxy.ssl_port - 8118
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\users\Chris Lindemann\AppData\Roaming\Mozilla\Firefox\Profiles\yrt9z7cd.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
FF - component: c:\users\Chris Lindemann\AppData\Roaming\Mozilla\Firefox\Profiles\yrt9z7cd.default\extensions\[removed]\components\KeyScramblerIE.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\programdata\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\users\Chris Lindemann\AppData\Local\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\users\Chris Lindemann\AppData\Local\HuluDesktop\instances\0.9.3.1\npHDPlg.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-12 18:06
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-07-12 18:09
ComboFix-quarantined-files.txt 2009-07-12 22:09

Pre-Run: 153,437,888,512 bytes free
Post-Run: 155,772,358,656 bytes free

309 — E O F — 2009-06-25 14:56











ComboFix 09-07-12.01 - Chris Lindemann 07/12/2009 17:58.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3061.1840 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Sunbelt Personal Firewall *enabled* {82B1150E-9B37-49FC-83EB-D52197D900D0}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *enabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-2773397201-2855733099-4214572315-500
c:\$recycle.bin\S-1-5-21-2939173800-4131586745-4067607304-500

.
((((((((((((((((((((((((( Files Created from 2009-06-12 to 2009-07-12 )))))))))))))))))))))))))))))))
.

2009-07-12 22:05 . 2009-07-12 22:06 ——– d—–w- c:\users\Chris Lindemann\AppData\Local\temp
2009-07-12 18:11 . 2009-07-12 18:12 ——– d—–w- c:\program files\trend micro
2009-07-12 18:11 . 2009-07-12 18:12 ——– d—–w- C:\rsit
2009-07-01 01:30 . 2009-07-01 18:48 ——– d—–w- c:\users\Chris Lindemann\New Folder
2009-06-28 14:15 . 2009-06-28 14:15 746744 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-06-25 15:17 . 2009-06-25 15:17 ——– d—–w- c:\users\Chris Lindemann\AppData\Local\AVG Security Toolbar
2009-06-25 15:00 . 2009-06-25 14:58 832144 —-a-w- c:\programdata\Avg8\update\backup\AVGToolbarInstall.exe
2009-06-25 14:59 . 2009-06-25 14:59 ——– d—–w- c:\programdata\AVG Security Toolbar
2009-06-14 15:04 . 2009-04-30 12:37 428544 —-a-w- c:\windows\system32\EncDec.dll
2009-06-14 15:04 . 2009-04-30 12:37 293376 —-a-w- c:\windows\system32\psisdecd.dll
2009-06-13 05:03 . 2009-06-13 05:03 ——– d—–w- c:\users\Chris Lindemann\dwhelper

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-12 21:15 . 2008-08-04 10:38 2484 —-a-w- c:\windows\bthservsdp.dat
2009-07-12 21:01 . 2009-01-25 08:09 ——– d—–w- c:\program files\LimeWire
2009-07-12 17:57 . 2008-11-23 19:44 ——– d—–w- c:\programdata\Google Updater
2009-07-02 03:48 . 2008-10-13 01:03 ——– d—–w- c:\users\Chris Lindemann\AppData\Roaming\uTorrent
2009-07-01 01:35 . 2008-08-10 03:58 ——– d—–w- c:\users\Chris Lindemann\AppData\Roaming\Apple Computer
2009-06-25 14:58 . 2008-10-19 09:00 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-06-25 14:58 . 2008-10-19 09:00 327688 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-25 14:58 . 2008-10-19 09:00 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-20 01:02 . 2008-11-22 23:17 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-20 01:01 . 2008-12-30 01:04 3561743 —-a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-17 15:27 . 2008-11-22 23:17 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 15:27 . 2008-11-22 23:17 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-15 17:20 . 2008-08-10 04:29 ——– d—–w- c:\program files\AIM6
2009-06-15 17:20 . 2008-08-10 04:30 ——– d—–w- c:\programdata\Viewpoint
2009-06-15 17:18 . 2009-06-15 17:18 ——– d—–w- c:\programdata\AOL Downloads
2009-06-14 15:20 . 2009-01-25 08:10 ——– d—–w- c:\users\Chris Lindemann\AppData\Roaming\LimeWire
2009-06-12 16:35 . 2008-08-04 16:09 ——– d—–w- c:\program files\Microsoft Works
2009-06-09 05:03 . 2009-01-17 03:12 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2009-06-09 05:03 . 2009-01-25 02:33 ——– d—–w- c:\program files\Lavasoft
2009-06-09 05:03 . 2008-08-10 02:41 ——– d—–w- c:\programdata\Lavasoft
2009-06-08 18:00 . 2009-06-11 20:12 110592 —-a-w- c:\users\Chris Lindemann\AppData\Roaming\Mozilla\Firefox\Profiles\yrt9z7cd.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
2009-06-06 23:21 . 2009-06-06 23:21 ——– d—–w- c:\program files\iTunes
2009-06-06 23:21 . 2009-06-06 23:21 ——– d—–w- c:\program files\iPod
2009-06-06 23:21 . 2008-08-10 03:44 ——– d—–w- c:\program files\Common Files\Apple
2009-06-06 23:19 . 2009-06-06 23:19 ——– d—–w- c:\program files\QuickTime
2009-06-06 23:03 . 2009-06-06 23:03 75048 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-04 19:32 . 2009-06-04 19:31 ——– d—–w- c:\program files\Free Mp3WmaOgg Converter
2009-05-30 23:04 . 2009-05-30 23:03 ——– d—–w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-30 23:02 . 2009-05-30 23:02 ——– d—–w- c:\program files\Bonjour
2009-05-30 22:35 . 2009-05-30 22:35 ——– d—–w- c:\program files\Safari
2009-05-28 17:23 . 2008-08-04 15:48 ——– d—–w- c:\program files\Java
2009-05-19 17:29 . 2009-02-04 16:36 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-19 06:20 . 2008-08-04 15:49 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-05-19 05:36 . 2009-06-15 17:18 97072 —-a-w- c:\programdata\AOL Downloads\SUD4426\bsetutil.exe
2009-05-19 05:36 . 2009-06-15 17:18 2884832 —-a-w- c:\programdata\AOL Downloads\SUD4426\vwpt.exe
2009-05-19 05:36 . 2009-06-15 17:18 28 —-a-w- c:\programdata\AOL Downloads\SUD4426\unregister.bat
2009-05-19 05:36 . 2009-06-15 17:18 25 —-a-w- c:\programdata\AOL Downloads\SUD4426\register.bat
2009-05-19 05:36 . 2009-06-15 17:18 1484856 —-a-w- c:\programdata\AOL Downloads\SUD4426\toolbar.exe
2009-05-19 05:36 . 2009-06-15 17:18 142040 —-a-w- c:\programdata\AOL Downloads\SUD4426\alsetup.exe
2009-05-19 05:36 . 2009-06-15 17:18 30512 —-a-w- c:\programdata\AOL Downloads\SUD4426\Uninstaller.exe
2009-05-19 05:36 . 2009-06-15 17:18 111920 —-a-w- c:\programdata\AOL Downloads\SUD4426\AOLSearch.dll
2009-05-16 00:06 . 2009-05-16 00:06 416128 —-a-w- c:\programdata\Microsoft\eHome\Packages\NetTV\Browse\NetTVResources.dll
2009-05-14 07:00 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-04-24 16:05 . 2009-06-11 16:28 827904 —-a-w- c:\windows\system32\wininet.dll
2009-04-24 16:02 . 2009-06-11 16:28 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-04-24 13:44 . 2009-06-11 16:28 26624 —-a-w- c:\windows\system32\ieUnatt.exe
2009-04-23 12:43 . 2009-06-11 16:28 784896 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:42 . 2009-06-11 16:28 636928 —-a-w- c:\windows\system32\localspl.dll
2009-04-21 11:55 . 2009-06-11 16:28 2033152 —-a-w- c:\windows\system32\win32k.sys
2008-08-04 15:54 . 2008-08-04 15:54 76 –sh–r- c:\windows\CT4CET.bin
2008-08-04 18:30 . 2008-08-04 18:30 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 20:07 1004800 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"Google Update"="c:\users\Chris Lindemann\AppData\Local\Google\Update\GoogleUpdate.exe" [2008-09-15 133104]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-29 17920]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-05-04 167936]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2008-03-04 36864]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-06 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-06 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-06 133656]
"VolPanel"="c:\program files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" [2006-11-27 180224]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-05-19 3444736]
"DELL Webcam Manager"="c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 118784]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-12-21 184320]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-25 1948440]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-14 177472]
"Rvsystem"="c:\progra~1\Returnil\Returnil.exe" [2008-11-04 2071040]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-05-30 292136]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-8-4 50688]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-2-22 1193240]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-08-04 16:13 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{EB00B42A-C4EF-43DF-9BBF-BF92E0C6352A}"= c:\program files\Dell\MediaDirect\MediaDirect.exe:Dell MediaDirect
"{16840399-7467-49FB-A8D9-811F529C379F}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program
"{10083886-1B66-46BC-9576-561C6C9FFAB2}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{008F72DD-BA82-4E7A-85DF-BC08FF2D59DA}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"{94365828-80BF-4786-B905-2A31DBE1D316}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{211F0709-9EAB-40CE-A5E5-1C1A7C632CFD}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{0F280C9E-3566-46A0-B998-66AF13608717}"= UDP:c:\program files\AIM6\aim6.exe:AIM
"{B6656779-4223-4ACC-B874-F98E61B90549}"= TCP:c:\program files\AIM6\aim6.exe:AIM
"{BAABF74E-954F-4342-9460-07E4AB6001A4}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{FBDE3586-9AD2-4D53-939D-848A3B95EF66}c:\\program files\\aim6\\aim6.exe"= UDP:c:\program files\aim6\aim6.exe:AIM
"UDP Query User{7012E816-19F2-448D-B8BD-39DDB8A792C4}c:\\program files\\aim6\\aim6.exe"= TCP:c:\program files\aim6\aim6.exe:AIM
"{5C995906-71B8-442A-A5AC-8A6AE74FB369}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{732713D3-74AD-45AA-83BB-5FF9D154AEBC}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{D9ACB148-8390-45C3-BD21-734E9E417CDC}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{27B0A277-1A5E-4203-99DE-1AA662AE4423}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{20329BD4-36A5-4956-8698-58076EBA0BB0}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{AEA0FE0E-78B9-45DE-B191-2385ADB3DE67}"= UDP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{08F1119E-B01D-43CE-938B-45F13085111A}"= TCP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{F69EA0BB-8A67-4C19-8FAB-21523C370289}"= UDP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{6A50ACB5-B8D7-4D5D-9273-F2BB671741A8}"= TCP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{5F72A3A9-1A10-4D6E-94F9-B60F90167323}"= UDP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{BF8B794C-4C4C-4038-8982-AB117151CCC3}"= TCP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{7E73B944-21B7-4FD0-A454-7CAC212D2C3F}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{060B24AC-82C1-482C-AE98-D6AC1FE0A4A2}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{4FB7D275-B794-4BD8-B50B-27E9B1DFB137}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"{F9924592-E4A7-484D-AD15-AC9F0608CFC1}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"TCP Query User{605F2D05-49A0-4524-A370-5479DC210BBD}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{EF52AB41-FBA3-4171-9E3C-102803EC60CE}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{837E25DF-AC03-45E5-AD76-3367F512047C}c:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= UDP:c:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"UDP Query User{E1B928D4-3643-425C-A343-E9ECB45DB077}c:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= TCP:c:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"TCP Query User{3E54C644-A15B-4A11-AB5D-22F09F86AA84}c:\\program files\\sunbelt software\\personal firewall\\sbpfcl.exe"= UDP:c:\program files\sunbelt software\personal firewall\sbpfcl.exe:Sunbelt Firewall GUI
"UDP Query User{5AF6C8D5-F84D-4630-9135-BFB7BD05F66E}c:\\program files\\sunbelt software\\personal firewall\\sbpfcl.exe"= TCP:c:\program files\sunbelt software\personal firewall\sbpfcl.exe:Sunbelt Firewall GUI
"{ED546654-4F72-48DA-BB44-C771587919EB}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{99A86A20-731F-49AC-845E-01E8A5ABC26D}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{7B01776E-A749-4652-945F-F2932898C011}"= UDP:c:\windows\System32\dlbccoms.exe:Photo Printer 720 Server
"{227644DF-2841-41B0-A938-EF44569DA9EC}"= TCP:c:\windows\System32\dlbccoms.exe:Photo Printer 720 Server
"TCP Query User{DA2C50D9-A93A-4CC9-A859-FD548B209708}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{CB214D8F-73E3-415A-B6DA-D933BE20F916}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire
"{A5D9653B-F82D-448E-8249-7C2C3184CD8A}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{9F3963D3-1A7D-4E25-91E7-858481D53AC9}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{1F2CE80F-D20D-449A-8D95-68A440857912}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{0424984B-DD00-4D7E-B542-5EA548803659}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{20368C55-D5BC-4C4D-881E-A0AC916C3B27}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{3B1CD197-C07C-4DFF-8DAC-33FE991C7695}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R0 RVSDISK;RVSDISK;c:\windows\System32\drivers\RVSDISK.sys [11/3/2008 10:40 PM 11904]
R0 RVSYSTEM;RVSYSTEM;c:\windows\System32\drivers\RVSYSTEM.sys [11/3/2008 10:40 PM 38272]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [10/19/2008 5:00 AM 327688]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [2/4/2009 12:36 PM 108552]
R1 FreeOTFE;FreeOTFE;c:\windows\System32\FreeOTFE.sys [12/8/2008 2:14 AM 31856]
R1 FreeOTFECypherAES_ltc;FreeOTFECypherAES_ltc;c:\windows\System32\FreeOTFECypherAES_ltc.sys [12/8/2008 2:14 AM 47600]
R1 FreeOTFECypherBlowfish;FreeOTFECypherBlowfish;c:\windows\System32\FreeOTFECypherBlowfish.sys [12/8/2008 2:14 AM 25200]
R1 FreeOTFECypherCAST5;FreeOTFECypherCAST5;c:\windows\System32\FreeOTFECypherCAST5.sys [12/8/2008 2:14 AM 31088]
R1 FreeOTFECypherCAST6_Gladman;FreeOTFECypherCAST6_Gladman;c:\windows\System32\FreeOTFECypherCAST6_Gladman.sys [12/8/2008 2:14 AM 30576]
R1 FreeOTFECypherDES;FreeOTFECypherDES;c:\windows\System32\FreeOTFECypherDES.sys [12/8/2008 2:14 AM 56816]
R1 FreeOTFECypherMARS_Gladman;FreeOTFECypherMARS_Gladman;c:\windows\System32\FreeOTFECypherMARS_Gladman.sys [12/8/2008 2:14 AM 24944]
R1 FreeOTFECypherRC6_ltc;FreeOTFECypherRC6_ltc;c:\windows\System32\FreeOTFECypherRC6_ltc.sys [12/8/2008 2:14 AM 26480]
R1 FreeOTFECypherSerpent_Gladman;FreeOTFECypherSerpent_Gladman;c:\windows\System32\FreeOTFECypherSerpent_Gladman.sys [12/8/2008 2:14 AM 28528]
R1 FreeOTFECypherTwofish_ltc;FreeOTFECypherTwofish_ltc;c:\windows\System32\FreeOTFECypherTwofish_ltc.sys [12/8/2008 2:14 AM 32112]
R1 FreeOTFEHashMD;FreeOTFEHashMD;c:\windows\System32\FreeOTFEHashMD.sys [12/8/2008 2:14 AM 16752]
R1 FreeOTFEHashRIPEMD;FreeOTFEHashRIPEMD;c:\windows\System32\FreeOTFEHashRIPEMD.sys [12/8/2008 2:14 AM 31856]
R1 FreeOTFEHashSHA;FreeOTFEHashSHA;c:\windows\System32\FreeOTFEHashSHA.sys [12/8/2008 2:14 AM 26096]
R1 FreeOTFEHashTiger;FreeOTFEHashTiger;c:\windows\System32\FreeOTFEHashTiger.sys [12/8/2008 2:14 AM 21872]
R1 FreeOTFEHashWhirlpool;FreeOTFEHashWhirlpool;c:\windows\System32\FreeOTFEHashWhirlpool.sys [12/8/2008 2:14 AM 30448]
R1 SbFw;SbFw;c:\windows\System32\drivers\SbFw.sys [10/31/2008 8:09 AM 270888]
R1 sbhips;Sunbelt HIPS Driver;c:\windows\System32\drivers\sbhips.sys [6/21/2008 5:54 AM 66600]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [10/19/2008 5:00 AM 906520]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [10/19/2008 5:00 AM 298776]
R2 dlbc_device;dlbc_device;c:\windows\system32\dlbccoms.exe -service –> c:\windows\system32\dlbccoms.exe -service [?]
R2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [4/28/2008 5:56 PM 161048]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\System32\drivers\npf.sys [11/6/2007 4:22 PM 34064]
R2 SbPF.Launcher;SbPF.Launcher;c:\program files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [10/31/2008 8:24 AM 95528]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [1/16/2009 11:12 PM 1153368]
R2 SPF4;Sunbelt Personal Firewall 4;c:\program files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [10/31/2008 8:24 AM 1365288]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [8/10/2008 12:30 AM 24652]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\System32\drivers\IntcHdmi.sys [8/4/2008 2:31 PM 111616]
R3 KeyScrambler;KeyScrambler;c:\windows\System32\drivers\keyscrambler.sys [10/14/2008 9:59 PM 113896]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\System32\drivers\OEM02Dev.sys [8/4/2008 2:31 PM 235648]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\System32\drivers\OEM02Vfx.sys [8/4/2008 2:31 PM 7424]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\System32\drivers\SbFwIm.sys [12/7/2008 4:02 PM 65576]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe –> c:\windows\system32\aestsrv.exe [?]
S3 BAAGRHHVEEMC;BAAGRHHVEEMC;c:\users\CHRISL~1\AppData\Local\Temp\BAAGRHHVEEMC.exe –> c:\users\CHRISL~1\AppData\Local\Temp\BAAGRHHVEEMC.exe [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contents of the 'Scheduled Tasks' folder

2009-07-12 c:\windows\Tasks\AWC Startup.job
- c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2009-06-28 13:55]

2008-09-14 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 15:20]

2009-07-12 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-23 01:28]

2009-07-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2939173800-4131586745-4067607304-1000Core.job
- c:\users\Chris Lindemann\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-15 06:43]

2009-07-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2939173800-4131586745-4067607304-1000UA.job
- c:\users\Chris Lindemann\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-15 06:43]

2009-07-12 c:\windows\Tasks\User_Feed_Synchronization-{FCB795B7-FA1B-4559-861F-3C4FEE8A0C73}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=3080804
uInternet Settings,ProxyOverride = *.local
IE: &Windows; Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Send image to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\users\Chris Lindemann\AppData\Roaming\Mozilla\Firefox\Profiles\yrt9z7cd.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 8118
FF - prefs.js: network.proxy.socks - 127.0.0.1
FF - prefs.js: network.proxy.socks_port - 9050
FF - prefs.js: network.proxy.ssl - 127.0.0.1
FF - prefs.js: network.proxy.ssl_port - 8118
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\users\Chris Lindemann\AppData\Roaming\Mozilla\Firefox\Profiles\yrt9z7cd.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
FF - component: c:\users\Chris Lindemann\AppData\Roaming\Mozilla\Firefox\Profiles\yrt9z7cd.default\extensions\[removed]\components\KeyScramblerIE.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\programdata\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\users\Chris Lindemann\AppData\Local\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\users\Chris Lindemann\AppData\Local\HuluDesktop\instances\0.9.3.1\npHDPlg.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-12 18:06
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-07-12 18:09
ComboFix-quarantined-files.txt 2009-07-12 22:09

Pre-Run: 153,437,888,512 bytes free
Post-Run: 155,772,358,656 bytes free

309 — E O F — 2009-06-25 14:56










Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:00:29 PM, on 7/12/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18248)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\OEM02Mon.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Returnil\Returnil.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\CF12335.exe
C:\Windows\Explorer.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Rvsystem] C:\PROGRA~1\Returnil\Returnil.exe
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [Google Update] "C:\Users\Chris Lindemann\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: &Windows; Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth; Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth; Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler;… - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\Windows\System32\avgrsstx.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Unknown owner - C:\Windows\system32\aestsrv.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: BAAGRHHVEEMC - Unknown owner - C:\Users\CHRISL~1\AppData\Local\Temp\BAAGRHHVEEMC.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: dlbc_device - - C:\Windows\system32\dlbccoms.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 12518 bytes
Sorry about that. Here it is:







GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-12 19:38:34
Windows 6.0.6001 Service Pack 1


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwClose [0x8F01B160]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwCreateFile [0x8F01A868]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwCreateKey [0x8F017320]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwCreateProcess [0x8F019E90]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwCreateProcessEx [0x8F019D9C]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwCreateThread [0x8F01A3FC]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwDeleteFile [0x8F01B210]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwDeleteKey [0x8F017786]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwDeleteValueKey [0x8F017846]
SSDT \SystemRoot\system32\drivers\sbhips.sys (Sunbelt Personal Firewall Host Intrusion Prevention Driver/Sunbelt Software, Inc.) ZwLoadDriver [0x8F2BC01C]
SSDT \SystemRoot\system32\drivers\sbhips.sys (Sunbelt Personal Firewall Host Intrusion Prevention Driver/Sunbelt Software, Inc.) ZwMapViewOfSection [0x8F2BC168]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwOpenFile [0x8F01AB54]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwOpenKey [0x8F0175CA]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwResumeThread [0x8F01A4EC]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwSetInformationFile [0x8F01AE8C]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwSetValueKey [0x8F0179BC]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwWriteFile [0x8F01ADE0]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwCreateThreadEx [0x8F01A48E]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwCreateUserProcess [0x8F019F82]

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!KeSetTimerEx + 3DC 824F19A0 4 Bytes [60, B1, 01, 8F]
.text ntkrnlpa.exe!KeSetTimerEx + 40C 824F19D0 4 Bytes [68, A8, 01, 8F]
.text ntkrnlpa.exe!KeSetTimerEx + 41C 824F19E0 4 Bytes [20, 73, 01, 8F]
.text ntkrnlpa.exe!KeSetTimerEx + 43C 824F1A00 8 Bytes [90, 9E, 01, 8F, 9C, 9D, 01, …] {NOP ; SAHF ; ADD [EDI-0x70fe6264], ECX}
.text ntkrnlpa.exe!KeSetTimerEx + 454 824F1A18 4 Bytes [FC, A3, 01, 8F]
.text …
? C:\Windows\system32\Drivers\PROCEXP90.SYS The system cannot find the file specified. !
? C:\Users\CHRISL~1\AppData\Local\Temp\catchme.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\Returnil\Returnil.exe[580] user32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\Returnil\Returnil.exe[580] user32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\iTunes\iTunesHelper.exe[596] WININET.dll!InternetConnectA 779F112E 5 Bytes JMP 00130F54
.text C:\Program Files\iTunes\iTunesHelper.exe[596] WININET.dll!InternetOpenA 77A003ED 5 Bytes JMP 00130D24
.text C:\Program Files\iTunes\iTunesHelper.exe[596] WININET.dll!InternetOpenUrlA 77A020B3 5 Bytes JMP 00130E3C
.text C:\Program Files\iTunes\iTunesHelper.exe[596] WININET.dll!InternetOpenW 77A02A68 5 Bytes JMP 00130DB0
.text C:\Program Files\iTunes\iTunesHelper.exe[596] WININET.dll!InternetConnectW 77A03E11 5 Bytes JMP 00130FE0
.text C:\Program Files\iTunes\iTunesHelper.exe[596] WININET.dll!InternetOpenUrlW 77A4B131 5 Bytes JMP 00130EC8
.text C:\Program Files\iTunes\iTunesHelper.exe[596] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\iTunes\iTunesHelper.exe[596] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\iTunes\iTunesHelper.exe[596] WS2_32.dll!socket 775E36D1 5 Bytes JMP 001308C4
.text C:\Program Files\iTunes\iTunesHelper.exe[596] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00130950
.text C:\Program Files\iTunes\iTunesHelper.exe[596] WS2_32.dll!bind 775E652F 5 Bytes JMP 00130838
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] WS2_32.dll!socket 775E36D1 5 Bytes JMP 001308C4
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00130950
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] WS2_32.dll!bind 775E652F 5 Bytes JMP 00130838
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Windows\system32\csrss.exe[660] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001107AC
.text C:\Windows\system32\csrss.exe[660] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00110720
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001102C0
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00110234
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00110694
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00110090
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001101A8
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001103D8
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0011034C
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!CreateThread 764146C8 5 Bytes JMP 0011057C
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001104F0
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0011011C
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00110004
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!WinExec 764654FF 5 Bytes JMP 00110464
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!SetThreadContext 76467087 5 Bytes JMP 00110608
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000702C0
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00070234
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00070694
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00070090
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000701A8
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000703D8
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0007034C
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0007057C
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000704F0
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0007011C
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00070004
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00070464
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00070608
.text C:\Windows\system32\svchost.exe[664] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000707AC
.text C:\Windows\system32\svchost.exe[664] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00070720
.text C:\Windows\system32\svchost.exe[664] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000708C4
.text C:\Windows\system32\svchost.exe[664] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00070950
.text C:\Windows\system32\svchost.exe[664] WS2_32.dll!bind 775E652F 5 Bytes JMP 00070838
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\wininit.exe[704] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\wininit.exe[704] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\wininit.exe[704] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\wininit.exe[704] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\wininit.exe[704] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\system32\csrss.exe[712] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001107AC
.text C:\Windows\system32\csrss.exe[712] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00110720
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001102C0
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00110234
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00110694
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00110090
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001101A8
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001103D8
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0011034C
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!CreateThread 764146C8 5 Bytes JMP 0011057C
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001104F0
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0011011C
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00110004
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!WinExec 764654FF 5 Bytes JMP 00110464
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!SetThreadContext 76467087 5 Bytes JMP 00110608
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\system32\services.exe[756] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\services.exe[756] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\services.exe[756] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\services.exe[756] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\services.exe[756] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\services.exe[756] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\services.exe[756] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\services.exe[756] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\services.exe[756] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\services.exe[756] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\services.exe[756] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\services.exe[756] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\services.exe[756] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\services.exe[756] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\services.exe[756] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\services.exe[756] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\services.exe[756] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\services.exe[756] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\lsass.exe[768] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\lsass.exe[768] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\lsass.exe[768] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\lsass.exe[768] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\lsass.exe[768] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\lsm.exe[776] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\lsm.exe[776] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\lsm.exe[776] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\lsm.exe[776] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\lsm.exe[776] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\winlogon.exe[852] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\winlogon.exe[852] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\winlogon.exe[852] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\winlogon.exe[852] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\winlogon.exe[852] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Windows\system32\dlbccoms.exe[948] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Windows\system32\dlbccoms.exe[948] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Windows\system32\dlbccoms.exe[948] ws2_32.dll!socket 775E36D1 5 Bytes JMP 001308C4
.text C:\Windows\system32\dlbccoms.exe[948] ws2_32.dll!connect 775E40D9 5 Bytes JMP 00130950
.text C:\Windows\system32\dlbccoms.exe[948] ws2_32.dll!bind 775E652F 5 Bytes JMP 00130838
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\ehome\ehtray.exe[968] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\ehome\ehtray.exe[968] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\svchost.exe[1016] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\svchost.exe[1016] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\svchost.exe[1016] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\svchost.exe[1016] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\svchost.exe[1016] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\svchost.exe[1076] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\svchost.exe[1076] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\svchost.exe[1076] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\system32\svchost.exe[1076] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\svchost.exe[1076] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\System32\svchost.exe[1212] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\System32\svchost.exe[1212] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\System32\svchost.exe[1212] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\System32\svchost.exe[1212] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\System32\svchost.exe[1212] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] user32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] user32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] WS2_32.dll!socket 775E36D1 5 Bytes JMP 001308C4
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00130950
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] WS2_32.dll!bind 775E652F 5 Bytes JMP 00130838
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] wininet.dll!InternetConnectA 779F112E 5 Bytes JMP 00130F54
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] wininet.dll!InternetOpenA 77A003ED 5 Bytes JMP 00130D24
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] wininet.dll!InternetOpenUrlA 77A020B3 5 Bytes JMP 00130E3C
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] wininet.dll!InternetOpenW 77A02A68 5 Bytes JMP 00130DB0
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] wininet.dll!InternetConnectW 77A03E11 5 Bytes JMP 00130FE0
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] wininet.dll!InternetOpenUrlW 77A4B131 5 Bytes JMP 00130EC8
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\System32\svchost.exe[1252] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\System32\svchost.exe[1252] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\System32\svchost.exe[1252] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\System32\svchost.exe[1252] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\System32\svchost.exe[1252] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\svchost.exe[1284] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\svchost.exe[1284] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\svchost.exe[1284] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\svchost.exe[1284] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\svchost.exe[1284] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\AUDIODG.EXE[1352] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\AUDIODG.EXE[1352] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\AUDIODG.EXE[1352] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\AUDIODG.EXE[1352] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\AUDIODG.EXE[1352] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\svchost.exe[1468] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\svchost.exe[1468] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\svchost.exe[1468] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\svchost.exe[1468] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\svchost.exe[1468] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] WININET.dll!InternetConnectA 779F112E 5 Bytes JMP 00130F54
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] WININET.dll!InternetOpenA 77A003ED 5 Bytes JMP 00130D24
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] WININET.dll!InternetOpenUrlA 77A020B3 5 Bytes JMP 00130E3C
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] WININET.dll!InternetOpenW 77A02A68 5 Bytes JMP 00130DB0
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] WININET.dll!InternetConnectW 77A03E11 5 Bytes JMP 00130FE0
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] WININET.dll!InternetOpenUrlW 77A4B131 5 Bytes JMP 00130EC8
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] WS2_32.dll!socket 775E36D1 5 Bytes JMP 001308C4
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00130950
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] WS2_32.dll!bind 775E652F 5 Bytes JMP 00130838
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] WS2_32.dll!socket 775E36D1 5 Bytes JMP 001308C4
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00130950
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] WS2_32.dll!bind 775E652F 5 Bytes JMP 00130838
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\svchost.exe[1616] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\svchost.exe[1616] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\svchost.exe[1616] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\svchost.exe[1616] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\svchost.exe[1616] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Windows\System32\WLTRYSVC.EXE[1724] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Windows\System32\WLTRYSVC.EXE[1724] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\WLANExt.exe[1732] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\WLANExt.exe[1732] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\WLANExt.exe[1732] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\WLANExt.exe[1732] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\WLANExt.exe[1732] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Windows\System32\bcmwltry.exe[1744] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Windows\System32\bcmwltry.exe[1744] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Windows\System32\bcmwltry.exe[1744] WININET.dll!InternetConnectA 779F112E 5 Bytes JMP 00130F54
.text C:\Windows\System32\bcmwltry.exe[1744] WININET.dll!InternetOpenA 77A003ED 5 Bytes JMP 00130D24
.text C:\Windows\System32\bcmwltry.exe[1744] WININET.dll!InternetOpenUrlA 77A020B3 5 Bytes JMP 00130E3C
.text C:\Windows\System32\bcmwltry.exe[1744] WININET.dll!InternetOpenW 77A02A68 5 Bytes JMP 00130DB0
.text C:\Windows\System32\bcmwltry.exe[1744] WININET.dll!InternetConnectW 77A03E11 5 Bytes JMP 00130FE0
.text C:\Windows\System32\bcmwltry.exe[1744] WININET.dll!InternetOpenUrlW 77A4B131 5 Bytes JMP 00130EC8
.text C:\Windows\System32\bcmwltry.exe[1744] WS2_32.dll!socket 775E36D1 5 Bytes JMP 001308C4
.text C:\Windows\System32\bcmwltry.exe[1744] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00130950
.text C:\Windows\System32\bcmwltry.exe[1744] WS2_32.dll!bind 775E652F 5 Bytes JMP 00130838
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] WS2_32.dll!socket 775E36D1 5 Bytes JMP 001308C4
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00130950
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] WS2_32.dll!bind 775E652F 5 Bytes JMP 00130838
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\System32\spoolsv.exe[1844] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\System32\spoolsv.exe[1844] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\System32\spoolsv.exe[1844] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\System32\spoolsv.exe[1844] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\System32\spoolsv.exe[1844] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Windows\system32\igfxsrvc.exe[1852] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Windows\system32\igfxsrvc.exe[1852] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Windows\system32\igfxsrvc.exe[1852] WS2_32.dll!socket 775E36D1 5 Bytes JMP 001308C4
.text C:\Windows\system32\igfxsrvc.exe[1852] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00130950
.text C:\Windows\system32\igfxsrvc.exe[1852] WS2_32.dll!bind 775E652F 5 Bytes JMP 00130838
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\svchost.exe[1896] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\svchost.exe[1896] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\svchost.exe[1896] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\svchost.exe[1896] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\svchost.exe[1896] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\DellTPad\Apoint.exe[2004] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\DellTPad\Apoint.exe[2004] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] WININET.dll!InternetConnectA 779F112E 5 Bytes JMP 00130F54
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] WININET.dll!InternetOpenA 77A003ED 5 Bytes JMP 00130D24
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] WININET.dll!InternetOpenUrlA 77A020B3 5 Bytes JMP 00130E3C
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] WININET.dll!InternetOpenW 77A02A68 5 Bytes JMP 00130DB0
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] WININET.dll!InternetConnectW 77A03E11 5 Bytes JMP 00130FE0
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] WININET.dll!InternetOpenUrlW 77A4B131 5 Bytes JMP 00130EC8
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] ws2_32.dll!socket 775E36D1 5 Bytes JMP 001308C4
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] ws2_32.dll!connect 775E40D9 5 Bytes JMP 00130950
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] ws2_32.dll!bind 775E652F 5 Bytes JMP 00130838
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] wininet.dll!InternetConnectA 779F112E 5 Bytes JMP 00130F54
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] wininet.dll!InternetOpenA 77A003ED 5 Bytes JMP 00130D24
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] wininet.dll!InternetOpenUrlA 77A020B3 5 Bytes JMP 00130E3C
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] wininet.dll!InternetOpenW 77A02A68 5 Bytes JMP 00130DB0
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] wininet.dll!InternetConnectW 77A03E11 5 Bytes JMP 00130FE0
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] wininet.dll!InternetOpenUrlW 77A4B131 5 Bytes JMP 00130EC8
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\svchost.exe[2088] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\svchost.exe[2088] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\svchost.exe[2088] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\svchost.exe[2088] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\svchost.exe[2088] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
Hi there,

Fix HijackThis lines

  • Run HijackThis!
  • Click on Do a System Scan only
  • Place a tick next to the following lines:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
Close all open windows and click on Fix checked and when you get a popup window click on Yes.

Run ComboFix

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the codebox below into it:

File::
c:\users\CHRISL~1\AppData\Local\Temp\BAAGRHHVEEMC.exe 
Driver::
BAAGRHHVEEMC
RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Kaspersky Online Scanner
Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

In your next reply, please include:
  • ComboFix log
  • Kaspersky report
  • A new HijackThis log

Regards,
Adam
Hello,

THREE DAY BUMP!

It has been three days since my last post.
  • Do you still need help with this?
  • Do you need more time?
  • Are you having problems following my instructions?

If after 48 hours you have not replied to this thread, then it will have to be closed!

Regards,
Adam

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI