This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

www.domredi.com/1/ Home Page Change

44 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

Every Morning my IE7 home page is different, when I go to the Internet Tools to correct it the page is www.domredi.com\1\

Please can you look at my HiJackThis log.

Thank You

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 09:32:08, on 04/03/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17095)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe
D:\WINDOWS\dwrcs\DWRCS.EXE
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Intel\AMT\LMS.exe
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
D:\Program Files\Sophos\AutoUpdate\ALsvc.exe
D:\Program Files\Sophos\Remote Management System\RouterNT.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe
D:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
D:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
D:\WINDOWS\dwrcs\DWRCST.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
D:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe
D:\Program Files\Analog Devices\Core\smax4pnp.exe
D:\Program Files\Documentum\AppConnector\Documentum.AppConnector.CredentialManager.exe
D:\Program Files\Sophos\AutoUpdate\almon.exe
D:\Program Files\Google\Gmail Notifier\gnotify.exe
D:\Documents and Settings\ucyzdun\Local Settings\Application Data\gersai.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\MMTaskbar\MultiMon.exe
D:\Program Files\PrintKey2000\Printkey2000.exe
D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
D:\Program Files\Documentum\AppConnector\EventServer.exe
D:\WINDOWS\system32\rundll32.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ucl.ac.uk/
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Sophos Web Content Scanner - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - D:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - D:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - D:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IAAnotif] D:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [picon] "D:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe" -startup
O4 - HKLM\..\Run: [SoundMAXPnP] D:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [AeXAgentLogon] D:\Program Files\Altiris\Altiris Agent\AeXAgentActivate.exe /logon
O4 - HKLM\..\Run: [ISUSPM Startup] D:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "D:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [IgfxTray] D:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] D:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] D:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [AppConnectorCredentialMgr] D:\Program Files\Documentum\AppConnector\Documentum.AppConnector.CredentialManager.exe
O4 - HKLM\..\Run: [nwiz] D:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [OFARegisterOCX2] D:\WINDOWS\system32\regsvr32.exe /s D:\WINDOWS\system32\spin32.ocx
O4 - HKLM\..\Run: [OFARegisterOCX1] D:\WINDOWS\system32\regsvr32.exe /s D:\WINDOWS\system32\flp32x20.ocx
O4 - HKLM\..\Run: [OFARegisterOCX] D:\WINDOWS\system32\regsvr32.exe /s D:\OraHome1\olap\bin\rdonly.ocx
O4 - HKLM\..\Run: [OFARegisterOCX3] D:\WINDOWS\system32\regsvr32.exe /s D:\OraHome1\olap\bin\snapiocx.ocx
O4 - HKLM\..\Run: [OFARegisterOCX4] D:\WINDOWS\system32\regsvr32.exe /s D:\OraHome1\olap\bin\xwcmdwin.ocx
O4 - HKLM\..\Run: [OFARegisterOCX5] D:\WINDOWS\system32\regsvr32.exe /s D:\OraHome1\olap\bin\oracd32.ocx
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Sophos AutoUpdate Monitor] D:\Program Files\Sophos\AutoUpdate\almon.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] D:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [DameWare MRC Agent] D:\WINDOWS\dwrcs\DWRCST.exe
O4 - HKLM\..\Run: [hpgcrybc] D:\Documents and Settings\ucyzdun\Local Settings\Application Data\gersai.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [hpgcrybc] D:\Documents and Settings\ucyzdun\Local Settings\Application Data\gersai.exe
O4 - HKCU\..\Run: [swg] "D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-57989841-507921405-1060284298-14327\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-57989841-507921405-1060284298-2439\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-21-57989841-507921405-1060284298-2439\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User '?')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Startup: frilm.exe
O4 - Startup: peyci.exe
O4 - Global Startup: MultiMon Taskbar.lnk = D:\Program Files\MMTaskbar\MultiMon.exe
O4 - Global Startup: Printkey2000.lnk = D:\Program Files\PrintKey2000\Printkey2000.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://D:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Append the content of the link to existing PDF file - res://D:\Program Files\Nuance\PDF Professional 7\Bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
O8 - Extra context menu item: Append the content of the selected links to existing PDF file - res://D:\Program Files\Nuance\PDF Professional 7\Bin\ZeonIEFavClient.dll/ZeonIEAppendSelLinks.HTML
O8 - Extra context menu item: Append to existing PDF file - res://D:\Program Files\Nuance\PDF Professional 7\Bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
O8 - Extra context menu item: Create PDF file - res://D:\Program Files\Nuance\PDF Professional 7\Bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
O8 - Extra context menu item: Create PDF file from the content of the link - res://D:\Program Files\Nuance\PDF Professional 7\Bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
O8 - Extra context menu item: Create PDF files from the selected links - res://D:\Program Files\Nuance\PDF Professional 7\Bin\ZeonIEFavClient.dll/ZeonIECaptureSelLinks.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://D:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O8 - Extra context menu item: Open with Nuance PDF Converter 5.0 - res://D:\Program Files\Nuance\PDF Professional 5\cnvres_eng.dll /100
O8 - Extra context menu item: Open with Nuance PDF Converter 6.0 - res://D:\Program Files\Nuance\PDF Professional 6\cnvres_eng.dll /100
O8 - Extra context menu item: Open with Nuance PDF Converter 7.0 - res://D:\Program Files\Nuance\PDF Professional 7\cnvres_eng.dll /100
O8 - Extra context menu item: Open with PDF Professional 7 - res://D:\Program Files\Nuance\PDF Professional 7\Bin\PlusIEContextMenu.dll/PlusIEContextMenu.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab
O16 - DPF: {36F17E17-AC00-42BC-A6D9-294AD4E7DCD6} (Altiris ClientBootstraper Class) - http://ads3-adm/Altiris/NS/NSCap/Bin/Win32…ntBootstrap.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1232534038015
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1294225834643
O16 - DPF: {CAFECAFE-0013-0001-0022-ABCDEFABCDEF} (JInitiator 1.3.1.22) -
O16 - DPF: {CAFECAFE-0013-0001-0023-ABCDEFABCDEF} (JInitiator [removed]) -
O16 - DPF: {CAFECAFE-0013-0001-0029-ABCDEFABCDEF} (JInitiator 1.3.1.29) -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = adm.ucl.ac.uk
O17 - HKLM\Software\..\Telephony: DomainName = adm.ucl.ac.uk
O17 - HKLM\System\CCS\Services\Tcpip\..\{77E2BF43-DB30-4501-BCAB-5E30D5544635}: NameServer = 128.40.203.38,128.40.118.139,128.40.203.97,193.60.232.31,193.60.242.9
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = adm.ucl.ac.uk
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = adm.ucl.ac.uk
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = adm.ucl.ac.uk
O20 - AppInit_DLLs: D:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
O20 - Winlogon Notify: MRCNotify - D:\WINDOWS\dwrcs\DWRCWXL.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\system32\browseui.dll
O23 - Service: Altiris Agent (AeXNSClient) - Altiris, Inc. - D:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: DameWare Mini Remote Control (dwmrcs) - DameWare Development LLC - D:\WINDOWS\dwrcs\DWRCS.EXE
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - D:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - D:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel® Active Management Technology Local Management Service (LMS) - Intel Corporation - D:\Program Files\Intel\AMT\LMS.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - D:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - D:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos Agent - Sophos Plc - D:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - D:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sophos Message Router - Sophos Plc - D:\Program Files\Sophos\Remote Management System\RouterNT.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - D:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Sophos Web Intelligence Service (swi_service) - Sophos Plc - D:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
O23 - Service: Intel® Active Management Technology User Notification Service (UNS) - Intel Corporation - D:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe

–
End of file - 14566 bytes
Hi,

:welcome:

My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
As I'm still in training at What The Tech, all my posts needs to be checked by an expert first. This may cause a delay, but I will do my best to keep it as short as possible.
Hi gtbear,

Please do the following:

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

In your next post, please include the following:
  • OTL log
  • MBRCheck log
  • GMER log
Thanks Noodle Texh,

Here's the first OTL report

OTL logfile created on: 07/03/2011 09:16:30 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = D:\Documents and Settings\ucyzdun\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 56.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 4096 4096 [binary data]

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 31.25 Gb Total Space | 26.21 Gb Free Space | 83.88% Space Free | Partition Type: NTFS
Drive D: | 122.24 Gb Total Space | 95.37 Gb Free Space | 78.01% Space Free | Partition Type: NTFS
Drive E: | 79.33 Gb Total Space | 78.47 Gb Free Space | 98.91% Space Free | Partition Type: NTFS
Drive M: | 326.75 Gb Total Space | 47.43 Gb Free Space | 14.52% Space Free | Partition Type: NTFS
Drive W: | 5.03 Gb Total Space | 1.25 Gb Free Space | 24.82% Space Free | Partition Type: NTFS
Drive X: | 5.03 Gb Total Space | 1.25 Gb Free Space | 24.82% Space Free | Partition Type: NTFS
Drive Y: | 326.75 Gb Total Space | 47.43 Gb Free Space | 14.52% Space Free | Partition Type: NTFS
Drive Z: | 353.52 Gb Total Space | 23.98 Gb Free Space | 6.78% Space Free | Partition Type: NTFS

Computer Name: H7N80CFJ-HR | User Name: ucyzdun | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/03/07 09:15:42 | 000,580,608 | —- | M] (OldTimer Tools) – D:\Documents and Settings\ucyzdun\Desktop\OTL.exe
PRC - [2011/02/25 21:20:02 | 000,128,512 | RHS- | M] () – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\gersai.exe
PRC - [2011/02/21 15:15:46 | 000,806,912 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\Remote Management System\RouterNT.exe
PRC - [2011/02/21 15:15:43 | 000,282,624 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
PRC - [2011/02/09 17:08:06 | 000,273,784 | —- | M] (DameWare Development) – D:\WINDOWS\dwrcs\DWRCST.EXE
PRC - [2011/02/09 17:07:58 | 000,576,888 | —- | M] (DameWare Development LLC) – D:\WINDOWS\dwrcs\DWRCS.EXE
PRC - [2010/11/23 15:34:19 | 001,541,360 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
PRC - [2010/11/23 15:34:11 | 000,097,520 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
PRC - [2010/11/23 15:34:07 | 000,163,056 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
PRC - [2010/09/30 12:08:31 | 000,439,536 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\AutoUpdate\ALMon.exe
PRC - [2010/09/30 12:08:30 | 000,230,640 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\AutoUpdate\ALsvc.exe
PRC - [2008/12/04 13:00:26 | 000,354,840 | —- | M] (Intel Corporation) – D:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/12/04 13:00:20 | 000,186,904 | —- | M] (Intel Corporation) – D:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/11/12 10:12:40 | 000,152,064 | —- | M] (Documentum, a division of EMC Corporation) – D:\Program Files\Documentum\AppConnector\EventServer.exe
PRC - [2008/11/12 10:12:40 | 000,045,056 | —- | M] (Documentum, a division of EMC Corporation) – D:\Program Files\Documentum\AppConnector\Documentum.AppConnector.CredentialManager.exe
PRC - [2008/07/23 09:56:14 | 002,054,680 | —- | M] (Intel Corporation) – D:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe
PRC - [2008/07/23 09:56:14 | 000,773,144 | —- | M] (Intel Corporation) – D:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe
PRC - [2008/07/23 09:56:12 | 000,174,616 | —- | M] (Intel Corporation) – D:\Program Files\Intel\AMT\LMS.exe
PRC - [2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) – D:\WINDOWS\explorer.exe
PRC - [2008/01/31 03:09:30 | 001,277,952 | —- | M] (Altiris, Inc.) – D:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe
PRC - [2005/11/09 15:34:10 | 000,294,912 | —- | M] () – D:\Program Files\MMTaskbar\MultiMon.exe
PRC - [2005/07/15 21:48:33 | 000,479,232 | —- | M] (Google Inc.) – D:\Program Files\Google\Gmail Notifier\gnotify.exe
PRC - [1999/09/30 21:31:38 | 000,869,376 | —- | M] (Fred's Software) – D:\Program Files\PrintKey2000\Printkey2000.exe


========== Modules (SafeList) ==========

MOD - [2011/03/07 09:15:42 | 000,580,608 | —- | M] (OldTimer Tools) – D:\Documents and Settings\ucyzdun\Desktop\OTL.exe
MOD - [2011/02/21 15:16:23 | 000,234,408 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\Sophos Anti-Virus\sophos_detoured.dll
MOD - [2010/08/23 16:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – D:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2003/09/02 14:15:16 | 000,057,344 | —- | M] () – D:\Program Files\MMTaskbar\shellhook.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/02/21 15:15:46 | 000,806,912 | —- | M] (Sophos Plc) [Auto | Running] – D:\Program Files\Sophos\Remote Management System\RouterNT.exe – (Sophos Message Router)
SRV - [2011/02/21 15:15:43 | 000,282,624 | —- | M] (Sophos Plc) [Auto | Running] – D:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe – (Sophos Agent)
SRV - [2011/02/09 17:07:58 | 000,576,888 | —- | M] (DameWare Development LLC) [Auto | Running] – D:\WINDOWS\dwrcs\DWRCS.EXE – (dwmrcs)
SRV - [2010/11/23 15:34:19 | 001,541,360 | —- | M] (Sophos Plc) [Auto | Running] – D:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe – (swi_service)
SRV - [2010/11/23 15:34:11 | 000,097,520 | —- | M] (Sophos Plc) [Unknown | Running] – D:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe – (SAVService)
SRV - [2010/11/23 15:34:07 | 000,163,056 | —- | M] (Sophos Plc) [Unknown | Running] – D:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe – (SAVAdminService)
SRV - [2010/09/30 12:08:30 | 000,230,640 | —- | M] (Sophos Plc) [Auto | Running] – D:\Program Files\Sophos\AutoUpdate\ALsvc.exe – (Sophos AutoUpdate Service)
SRV - [2008/12/04 13:00:26 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – D:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®
SRV - [2008/07/23 09:56:14 | 002,054,680 | —- | M] (Intel Corporation) [Auto | Running] – D:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe – (UNS) Intel®
SRV - [2008/07/23 09:56:12 | 000,174,616 | —- | M] (Intel Corporation) [Auto | Running] – D:\Program Files\Intel\AMT\LMS.exe – (LMS) Intel®
SRV - [2008/01/31 03:09:30 | 001,277,952 | —- | M] (Altiris, Inc.) [Auto | Running] – D:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe – (AeXNSClient)


========== Driver Services (SafeList) ==========

DRV - [2010/11/23 15:34:16 | 000,024,064 | —- | M] (Sophos Plc) [File_System | System | Running] – D:\WINDOWS\system32\drivers\savonaccessfilter.sys – (SAVOnAccessFilter)
DRV - [2010/11/23 15:34:14 | 000,014,976 | —- | M] (Sophos Plc) [Kernel | Disabled | Stopped] – D:\WINDOWS\system32\drivers\SophosBootDriver.sys – (SophosBootDriver)
DRV - [2010/11/23 15:34:12 | 000,023,928 | —- | M] (Sophos Plc) [Kernel | On_Demand | Stopped] – D:\WINDOWS\system32\drivers\sdcfilter.sys – (sdcfilter)
DRV - [2010/11/23 15:34:11 | 000,153,344 | —- | M] (Sophos Plc) [File_System | System | Running] – D:\WINDOWS\system32\drivers\savonaccesscontrol.sys – (SAVOnAccessControl)
DRV - [2008/12/01 22:13:40 | 003,452,928 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – D:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2008/07/23 09:42:30 | 000,040,832 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – D:\WINDOWS\system32\drivers\HECI.sys – (HECI) Intel®
DRV - [2008/06/05 11:58:18 | 000,144,480 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – D:\WINDOWS\system32\drivers\e1k5132.sys – (e1kexpress) Intel®
DRV - [2008/03/28 10:14:02 | 000,024,064 | —- | M] (Sonic Focus, Inc) [Kernel | Boot | Running] – D:\WINDOWS\system32\drivers\sfaudio.sys – (SFAUDIO)
DRV - [2007/02/15 16:00:00 | 000,026,624 | —- | M] (DameWare) [Kernel | System | Running] – D:\WINDOWS\system32\drivers\dwvkbd.sys – (dwvkbd)
DRV - [2007/02/07 16:00:00 | 000,003,712 | —- | M] (DameWare Development, LLC) [Kernel | On_Demand | Running] – D:\WINDOWS\system32\drivers\DamewareMini.sys – (DwMirror)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://uk.news.yahoo.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://domredi.com/1/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "DAEMON Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.ucl.ac.uk"
FF - prefs.js..extensions.enabledItems: [removed]:1.19
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2011/03/01 12:23:10 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2011/03/01 12:23:10 | 000,000,000 | —D | M]

[2010/04/19 08:38:34 | 000,000,000 | —D | M] (No name found) – D:\Documents and Settings\ucyzdun\Application Data\Mozilla\Extensions
[2011/03/01 12:23:23 | 000,000,000 | —D | M] (No name found) – D:\Documents and Settings\ucyzdun\Application Data\Mozilla\Firefox\Profiles\bpzezwgb.default\extensions
[2010/07/27 14:21:31 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – D:\Documents and Settings\ucyzdun\Application Data\Mozilla\Firefox\Profiles\bpzezwgb.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/15 10:20:54 | 000,000,000 | —D | M] (Joomla! Admin) – D:\Documents and Settings\ucyzdun\Application Data\Mozilla\Firefox\Profiles\bpzezwgb.default\extensions\[removed]
[2010/09/15 10:20:54 | 000,000,000 | —D | M] (No name found) – D:\Documents and Settings\ucyzdun\Application Data\Mozilla\Firefox\Profiles\bpzezwgb.default\extensions\staged-xpis
[2011/03/01 12:23:23 | 000,000,000 | —D | M] (No name found) – D:\Program Files\Mozilla Firefox\extensions
[2011/02/22 10:39:43 | 000,000,000 | —D | M] (Java Console) – D:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/04/13 11:36:00 | 000,000,000 | —D | M] (British English Dictionary) – D:\Program Files\Mozilla Firefox\extensions\[removed]
[2011/01/06 12:34:29 | 000,000,000 | —D | M] (Java Quick Starter) – D:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/08/14 11:33:22 | 000,070,488 | —- | M] (Citrix Systems, Inc.) – D:\Program Files\Mozilla Firefox\plugins\CgpCore.dll
[2009/08/14 11:33:30 | 000,091,480 | —- | M] () – D:\Program Files\Mozilla Firefox\plugins\confmgr.dll
[2009/08/14 11:33:26 | 000,020,824 | —- | M] () – D:\Program Files\Mozilla Firefox\plugins\ctxlogging.dll
[2007/03/16 16:33:48 | 000,479,232 | —- | M] (Microsoft Corporation) – D:\Program Files\Mozilla Firefox\plugins\msvcm80.dll
[2007/03/16 16:33:48 | 000,548,864 | —- | M] (Microsoft Corporation) – D:\Program Files\Mozilla Firefox\plugins\msvcp80.dll
[2007/03/16 16:33:50 | 000,626,688 | —- | M] (Microsoft Corporation) – D:\Program Files\Mozilla Firefox\plugins\msvcr80.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – D:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/08/14 11:35:40 | 000,427,344 | —- | M] () – D:\Program Files\Mozilla Firefox\plugins\npicaN.dll
[2005/04/05 04:38:20 | 000,053,355 | —- | M] (Oracle Corporation) – D:\Program Files\Mozilla Firefox\plugins\NPJinit13122.dll
[2005/09/19 23:00:08 | 000,053,355 | —- | M] (Oracle Corporation) – D:\Program Files\Mozilla Firefox\plugins\NPJinit13123.dll
[2007/08/07 01:37:06 | 000,053,355 | —- | M] (Oracle Corporation) – D:\Program Files\Mozilla Firefox\plugins\NPJinit13129.dll
[2009/08/14 11:33:22 | 000,023,896 | —- | M] (Citrix Systems, Inc.) – D:\Program Files\Mozilla Firefox\plugins\TcpPServ.dll
[2010/12/03 17:47:02 | 000,001,538 | —- | M] () – D:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/12/03 17:47:02 | 000,000,947 | —- | M] () – D:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/12/03 17:47:02 | 000,000,769 | —- | M] () – D:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/12/03 17:47:02 | 000,001,135 | —- | M] () – D:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2001/08/23 11:00:00 | 000,000,734 | —- | M]) - D:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Sophos Web Content Scanner) - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - D:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll (Sophos Plc)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {3D89FF0D-3232-4116-867F-6D89B9711B5A} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {796AF358-6E53-4E90-AB45-503C3C8D2891} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BC4FFE41-DE9F-46FA-B455-AAD49B9F9938} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] D:\Program Files\Google\Gmail Notifier\gnotify.exe (Google Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] D:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AeXAgentLogon] D:\Program Files\Altiris\Altiris Agent\AeXAgentActivate.exe (Altiris, Inc.)
O4 - HKLM..\Run: [AppConnectorCredentialMgr] D:\Program Files\Documentum\AppConnector\Documentum.AppConnector.CredentialManager.exe (Documentum, a division of EMC Corporation)
O4 - HKLM..\Run: [DameWare MRC Agent] D:\WINDOWS\dwrcs\DWRCST.EXE (DameWare Development)
O4 - HKLM..\Run: [hpgcrybc] D:\Documents and Settings\ucyzdun\Local Settings\Application Data\gersai.exe ()
O4 - HKLM..\Run: [IAAnotif] D:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] File not found
O4 - HKLM..\Run: [NvMediaCenter] D:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] D:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [OFARegisterOCX] D:\OraHome1\olap\bin\RDONLY.OCX (Oracle Corporation)
O4 - HKLM..\Run: [OFARegisterOCX1] D:\WINDOWS\system32\FLP32X20.OCX (FarPoint Technologies, Inc.)
O4 - HKLM..\Run: [OFARegisterOCX2] D:\WINDOWS\system32\SPIN32.OCX (Outrider Systems, Inc.)
O4 - HKLM..\Run: [OFARegisterOCX3] D:\OraHome1\olap\bin\SNAPIOCX.OCX (Oracle Corporation)
O4 - HKLM..\Run: [OFARegisterOCX4] D:\OraHome1\olap\bin\XWCMDWIN.OCX (Oracle)
O4 - HKLM..\Run: [OFARegisterOCX5] D:\OraHome1\olap\bin\ORACD32.OCX (Oracle Corporation.)
O4 - HKLM..\Run: [picon] D:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe (Intel Corporation)
O4 - HKLM..\Run: [Sophos AutoUpdate Monitor] D:\Program Files\Sophos\AutoUpdate\ALMon.exe (Sophos Plc)
O4 - HKLM..\Run: [SunJavaUpdateSched] File not found
O4 - HKCU..\Run: [hpgcrybc] D:\Documents and Settings\ucyzdun\Local Settings\Application Data\gersai.exe ()
O4 - HKCU..\Run: [QuickTime Task] File not found
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\MultiMon Taskbar.lnk = D:\Program Files\MMTaskbar\MultiMon.exe ()
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Printkey2000.lnk = D:\Program Files\PrintKey2000\Printkey2000.exe (Fred's Software)
O4 - Startup: D:\Documents and Settings\ucyzdun\Start Menu\Programs\Startup\frilm.exe ()
O4 - Startup: D:\Documents and Settings\ucyzdun\Start Menu\Programs\Startup\peyci.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceStartMenuLogOff = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAutoUpdate = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConnectHomeDirToRoot = 0
O15 - HKCU\..Trusted Domains: ucl.ac.uk ([*.adcom] * in Local intranet)
O15 - HKCU\..Trusted Domains: ucl.ac.uk ([*.adm] * in Local intranet)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {36F17E17-AC00-42BC-A6D9-294AD4E7DCD6} http://ads3-adm/Altiris/NS/NSCap/Bin/Win32…ntBootstrap.cab (Altiris ClientBootstraper Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1232534038015 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1294225834643 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFECAFE-0013-0001-0022-ABCDEFABCDEF} Reg Error: Value error. (JInitiator 1.3.1.22)
O16 - DPF: {CAFECAFE-0013-0001-0023-ABCDEFABCDEF} Reg Error: Value error. (JInitiator [removed])
O16 - DPF: {CAFECAFE-0013-0001-0029-ABCDEFABCDEF} Reg Error: Value error. (JInitiator 1.3.1.29)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = adm.ucl.ac.uk
O20 - AppInit_DLLs: (D:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL) - D:\Program Files\Sophos\Sophos Anti-Virus\sophos_detoured.dll (Sophos Plc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - D:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\MRCNotify: DllName - D:\WINDOWS\dwrcs\DWRCWXL.dll - D:\WINDOWS\dwrcs\DWRCWXL.dll (DameWare Development LLC)
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/20 15:58:26 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{ff63e1c0-1fc1-11e0-9be0-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{ff63e1c0-1fc1-11e0-9be0-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ff63e1c0-1fc1-11e0-9be0-806d6172696f}\Shell\AutoRun\command - "" = G:\SETUP.EXE
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - D:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - D:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - D:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - D:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - D:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - D:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - D:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - D:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - D:\WINDOWS\System32\ir50_32.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (0)

========== Files/Folders - Created Within 30 Days ==========

[2011/03/07 09:15:38 | 000,580,608 | —- | C] (OldTimer Tools) – D:\Documents and Settings\ucyzdun\Desktop\OTL.exe
[2011/03/04 13:21:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Google
[2011/03/04 09:12:26 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\PCFix
[2011/03/03 13:45:09 | 000,000,000 | —D | C] – D:\Documents and Settings\LocalService\Application Data\McAfee
[2011/03/03 09:38:51 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\Excel
[2011/03/01 15:33:59 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Microsoft Help
[2011/03/01 12:40:16 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2011/03/01 12:40:15 | 000,000,000 | —D | C] – D:\Program Files\CCleaner
[2011/03/01 12:23:16 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Mozilla
[2011/03/01 12:23:13 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox
[2011/03/01 09:29:41 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
[2011/03/01 09:29:38 | 000,000,000 | —D | C] – D:\Program Files\Microsoft Silverlight
[2011/02/28 14:29:25 | 000,000,000 | —D | C] – D:\Program Files\Trend Micro
[2011/02/28 14:29:25 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\HiJackThis
[2011/02/28 13:09:52 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Temp
[2011/02/28 13:08:41 | 000,000,000 | —D | C] – D:\Program Files\Common Files\Adobe
[2011/02/28 11:36:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Sophos
[2011/02/28 08:53:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\AAT
[2011/02/23 15:35:49 | 000,000,000 | —D | C] – D:\Program Files\PrintKey2000
[2011/02/23 15:32:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\My eBooks
[2011/02/23 13:37:24 | 000,038,224 | —- | C] (Malwarebytes Corporation) – D:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/02/23 13:37:24 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/02/23 13:37:24 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/02/23 13:37:21 | 000,020,952 | —- | C] (Malwarebytes Corporation) – D:\WINDOWS\System32\drivers\mbam.sys
[2011/02/23 13:37:21 | 000,000,000 | —D | C] – D:\Program Files\Malwarebytes' Anti-Malware
[2011/02/22 13:01:01 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\org.madan.air.ada
[2011/02/22 13:00:59 | 000,000,000 | —D | C] – D:\Program Files\ada
[2011/02/22 12:57:41 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Adobe
[2011/02/22 12:30:46 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\MultiMon Taskbar
[2011/02/22 12:30:45 | 000,000,000 | —D | C] – D:\Program Files\MMTaskbar
[2011/02/22 12:13:28 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Downloaded Installations
[2011/02/22 12:01:59 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\BusinessObjects XI 3.1
[2011/02/22 11:58:48 | 000,000,000 | —D | C] – D:\Program Files\Business Objects XI
[2011/02/22 10:39:42 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – D:\WINDOWS\System32\javaws.exe
[2011/02/22 10:39:42 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – D:\WINDOWS\System32\javaw.exe
[2011/02/22 10:39:42 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – D:\WINDOWS\System32\java.exe
[2011/02/22 10:39:11 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\McAfee
[2011/02/22 10:33:54 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2011/02/22 10:24:44 | 000,000,000 | —D | C] – D:\Program Files\Microsoft Visual Studio 8
[2011/02/22 10:07:57 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\Downloads
[2011/02/22 10:07:50 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\PC_Drivers_Headquarters
[2011/02/22 09:24:03 | 000,000,000 | —D | C] – D:\WINDOWS\dwrcs
[2011/02/22 08:54:35 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Documentum
[2011/02/22 08:48:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\ApplicationHistory
[2011/02/22 08:46:00 | 000,000,000 | -H-D | C] – D:\Documents and Settings\ucyzdun\Local Settings
[2011/02/22 08:46:00 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Microsoft
[2011/02/22 08:44:54 | 000,005,632 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\ptpusb.dll
[2011/02/22 08:44:53 | 000,159,232 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\ptpusd.dll
[2011/02/22 08:44:53 | 000,015,104 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\dllcache\usbscan.sys
[2011/02/22 08:43:11 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\.alice2
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Broken Sword 2.5
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\BBC Alerts
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\AVS4YOU
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\ATI
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\ArcSoft
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Apple Computer
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\AdobeUM
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Adobe
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Lycos
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Logitech
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Leadertech
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Kontiki
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Identities
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\ICAClient
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Help
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\gtk-2.0
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Google
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\GetRightToGo
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\FreeFixer
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\FMA
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\ElevatedDiagnostics
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\EA
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\dvdcss
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\DivX
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\DAEMON Tools Lite
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\CyberLink
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\CoreFTP
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Cogniview
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Business Objects
[2011/02/22 08:43:08 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Media Player Classic
[2011/02/22 08:43:08 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Malwarebytes
[2011/02/22 08:43:08 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Macromedia
[2011/02/22 08:43:06 | 000,000,000 | –SD | C] – D:\Documents and Settings\ucyzdun\Application Data\Microsoft
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Real
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\ProIV Technology Inc
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\PC Suite
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Nuance
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\NSeries
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Nokia Multimedia Player
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Nokia
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Mozilla
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Sony Online Entertainment
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Sony Ericsson
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Sony
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\SmartDraw
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\shockwave.com
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\SharePod
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Seven Zip
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\ScanSoft
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Roxio
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\WinRAR
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\WindSolutions
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Windows Search
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Windows Desktop Search
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\webex
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Ulead Systems
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\ubi.com
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\tidysongs16
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\TextPad
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Teleca
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Sun
[2011/02/22 08:43:03 | 000,000,000 | –SD | C] – D:\Documents and Settings\ucyzdun\My Documents\My Webs
[2011/02/22 08:43:03 | 000,000,000 | –SD | C] – D:\Documents and Settings\ucyzdun\My Documents\My Web Sites
[2011/02/22 08:43:03 | 000,000,000 | –SD | C] – D:\Documents and Settings\ucyzdun\My Documents\My Data Sources
[2011/02/22 08:43:03 | 000,000,000 | RH-D | C] – D:\Documents and Settings\ucyzdun\Application Data
[2011/02/22 08:43:03 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\My Documents\My Videos
[2011/02/22 08:43:03 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\My Documents\My Pictures
[2011/02/22 08:43:03 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\My Documents\My Music
[2011/02/22 08:43:03 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\My Documents
[2011/02/22 08:43:03 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\Favorites
[2011/02/22 08:43:03 | 000,000,000 | -HSD | C] – D:\Documents and Settings\ucyzdun\Cookies
[2011/02/22 08:43:03 | 000,000,000 | -HSD | C] – D:\Documents and Settings\ucyzdun\Desktop\%USERPROFILE%
[2011/02/22 08:43:03 | 000,000,000 | -H-D | C] – D:\Documents and Settings\ucyzdun\InstallAnywhere
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Zeon
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\WebEx
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\Updater5
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\PrintScreen Files
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\PDF Favorites
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\My Business Objects Documents
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Documentum
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Desktop
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Contacts
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Citrix
[2011/02/22 08:43:02 | 000,000,000 | RH-D | C] – D:\Documents and Settings\ucyzdun\SendTo
[2011/02/22 08:43:02 | 000,000,000 | RH-D | C] – D:\Documents and Settings\ucyzdun\Recent
[2011/02/22 08:43:02 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Startup
[2011/02/22 08:43:02 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\Start Menu
[2011/02/22 08:43:02 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Administrative Tools
[2011/02/22 08:43:02 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Accessories
[2011/02/22 08:43:02 | 000,000,000 | -HSD | C] – D:\Documents and Settings\ucyzdun\UserData
[2011/02/22 08:43:02 | 000,000,000 | -H-D | C] – D:\Documents and Settings\ucyzdun\Templates
[2011/02/22 08:43:02 | 000,000,000 | -H-D | C] – D:\Documents and Settings\ucyzdun\PrintHood
[2011/02/22 08:43:02 | 000,000,000 | -H-D | C] – D:\Documents and Settings\ucyzdun\NetHood
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\WinRAR
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\System
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Real
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\PrintKey2000
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\pnlinks
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\PHP 5
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\pdfFactory
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\NorthgateArinso
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Internet
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Google Chrome
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Gmail Notifier
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\FreeFixer
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Express ClickYes
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\CopyTrans Suite
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\CCleaner
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\7-Zip
[2011/02/21 16:49:33 | 000,000,000 | —D | C] – D:\Program Files\SystemRequirementsLab
[2011/02/21 16:45:43 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2011/02/21 15:51:06 | 000,000,000 | —D | C] – D:\Program Files\ATI Technologies
[2011/02/21 15:51:04 | 000,000,000 | —D | C] – D:\Program Files\ATI
[3 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
[1 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/07 09:15:42 | 000,580,608 | —- | M] (OldTimer Tools) – D:\Documents and Settings\ucyzdun\Desktop\OTL.exe
[2011/03/07 09:08:48 | 000,002,206 | —- | M] () – D:\WINDOWS\System32\wpa.dbl
[2011/03/07 09:08:45 | 000,000,882 | —- | M] () – D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/07 08:49:00 | 000,000,886 | —- | M] () – D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/07 05:00:00 | 000,000,530 | —- | M] () – D:\WINDOWS\tasks\Scheduled Daily Scan @ 5am.job
[2011/03/04 17:21:06 | 000,009,684 | RHS- | M] () – D:\Documents and Settings\ucyzdun\ntuser.pol
[2011/03/04 17:13:10 | 000,000,754 | —- | M] () – D:\WINDOWS\WORDPAD.INI
[2011/03/04 16:08:05 | 000,260,917 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\Arsenal World.url
[2011/03/04 11:06:25 | 000,000,225 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\SELF SERVICE.url
[2011/03/04 09:33:25 | 000,000,327 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\Resource Link on the NET.url
[2011/03/02 09:53:16 | 000,000,204 | —- | M] () – D:\WINDOWS\hpbafd.ini
[2011/03/01 12:40:16 | 000,000,682 | —- | M] () – D:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/03/01 12:23:13 | 000,001,620 | —- | M] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/01 12:23:13 | 000,001,602 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/03/01 09:14:00 | 000,505,972 | —- | M] () – D:\WINDOWS\System32\perfh009.dat
[2011/03/01 09:14:00 | 000,089,244 | —- | M] () – D:\WINDOWS\System32\perfc009.dat
[2011/03/01 09:09:20 | 000,002,048 | –S- | M] () – D:\WINDOWS\bootstat.dat
[2011/02/28 16:45:34 | 000,000,251 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\KnowBase.url
[2011/02/28 14:36:49 | 000,000,815 | —- | M] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/02/28 14:29:25 | 000,001,988 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\HiJackThis.lnk
[2011/02/28 13:09:02 | 000,001,734 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/02/25 21:20:03 | 000,128,512 | R-S- | M] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Startup\frilm.exe
[2011/02/25 21:20:02 | 000,128,512 | RHS- | M] () – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\gersai.exe
[2011/02/23 15:35:49 | 000,000,682 | —- | M] () – D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Printkey2000.lnk
[2011/02/23 15:15:16 | 000,263,824 | —- | M] () – D:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/23 13:37:24 | 000,000,784 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/22 16:07:11 | 000,000,298 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\Payslips & P60's.url
[2011/02/22 16:05:29 | 000,000,455 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\InfoView.url
[2011/02/22 13:00:59 | 000,000,568 | —- | M] () – D:\Documents and Settings\All Users\Desktop\ada.lnk
[2011/02/22 12:30:46 | 000,000,647 | —- | M] () – D:\Documents and Settings\All Users\Start Menu\Programs\Startup\MultiMon Taskbar.lnk
[2011/02/22 12:30:46 | 000,000,635 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\MultiMon Taskbar.lnk
[2011/02/22 12:09:39 | 000,001,139 | —- | M] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\BusinessObjects 6.1 (2).lnk
[2011/02/22 12:01:32 | 000,000,804 | —- | M] () – D:\WINDOWS\ODBC.INI
[2011/02/22 11:30:01 | 000,000,792 | —- | M] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2011/02/22 10:42:38 | 000,128,512 | R-S- | M] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Startup\peyci.exe
[2011/02/22 10:39:45 | 000,000,664 | —- | M] () – D:\WINDOWS\System32\d3d9caps.dat
[2011/02/22 08:48:09 | 000,000,130 | —- | M] () – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\fusioncache.dat
[2011/02/21 16:49:34 | 000,000,768 | —- | M] () – D:\WINDOWS\System32\d3d8caps.dat
[2011/02/21 15:16:22 | 000,131,824 | —- | M] (Sophos Plc) – D:\WINDOWS\System32\sdccoinstaller.dll
[2011/02/21 15:16:05 | 000,028,912 | —- | M] (Sophos Plc) – D:\WINDOWS\System32\SophosBootTasks.exe
[2011/02/18 10:21:37 | 000,001,374 | —- | M] () – D:\WINDOWS\imsins.BAK
[2011/02/17 14:07:41 | 000,011,810 | —- | M] () – D:\Documents and Settings\ucyzdun\My Documents\cc_20110217_140739.reg
[2011/02/17 09:19:20 | 000,020,910 | —- | M] () – D:\Documents and Settings\ucyzdun\My Documents\cc_20110217_091907.reg
[2011/02/16 11:45:11 | 000,000,205 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\HR Helpdesk Webform.url
[2011/02/15 10:41:41 | 000,071,292 | —- | M] () – D:\Documents and Settings\ucyzdun\My Documents\Anders.bgl
[2011/02/14 14:50:21 | 000,452,651 | —- | M] () – D:\Documents and Settings\ucyzdun\My Documents\Mock 72.pdf
[2011/02/09 15:12:34 | 000,000,122 | —- | M] () – D:\Documents and Settings\ucyzdun\My Documents\schema.ini
[3 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
[1 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/03/04 17:13:10 | 000,000,754 | —- | C] () – D:\WINDOWS\WORDPAD.INI
[2011/03/01 12:40:16 | 000,000,682 | —- | C] () – D:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/03/01 12:23:13 | 000,001,620 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/01 12:23:13 | 000,001,602 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/02/28 14:36:49 | 000,000,815 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/02/28 14:29:25 | 000,001,988 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\HiJackThis.lnk
[2011/02/28 13:09:02 | 000,001,734 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/02/28 13:09:01 | 000,001,804 | —- | C] () – D:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2011/02/25 21:20:03 | 000,128,512 | R-S- | C] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Startup\frilm.exe
[2011/02/23 15:35:49 | 000,000,682 | —- | C] () – D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Printkey2000.lnk
[2011/02/23 15:33:09 | 000,128,512 | RHS- | C] () – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\gersai.exe
[2011/02/23 15:32:12 | 000,128,512 | R-S- | C] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Startup\peyci.exe
[2011/02/23 15:32:12 | 000,000,738 | —- | C] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Outlook Express.lnk
[2011/02/23 13:37:24 | 000,000,784 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/22 13:00:59 | 000,000,574 | —- | C] () – D:\Documents and Settings\All Users\Start Menu\Programs\ada.lnk
[2011/02/22 13:00:59 | 000,000,568 | —- | C] () – D:\Documents and Settings\All Users\Desktop\ada.lnk
[2011/02/22 12:30:46 | 000,000,647 | —- | C] () – D:\Documents and Settings\All Users\Start Menu\Programs\Startup\MultiMon Taskbar.lnk
[2011/02/22 12:30:46 | 000,000,635 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\MultiMon Taskbar.lnk
[2011/02/22 10:27:41 | 000,593,920 | —- | C] () – D:\WINDOWS\System32\ati2sgag.exe
[2011/02/22 08:48:36 | 000,000,204 | —- | C] () – D:\WINDOWS\hpbafd.ini
[2011/02/22 08:48:09 | 000,000,130 | —- | C] () – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\fusioncache.dat
[2011/02/22 08:45:11 | 000,000,870 | —- | C] () – D:\Documents and Settings\ucyzdun\.recently-used.xbel
[2011/02/22 08:43:46 | 000,010,825 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Comma Separated Values (Windows).CAL
[2011/02/22 08:43:46 | 000,009,399 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Comma Separated Values (DOS).EML
[2011/02/22 08:43:38 | 000,001,139 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\BusinessObjects 6.1 (2).lnk
[2011/02/22 08:43:38 | 000,000,992 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Word.lnk
[2011/02/22 08:43:38 | 000,000,990 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Excel.lnk
[2011/02/22 08:43:38 | 000,000,792 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2011/02/22 08:43:38 | 000,000,079 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/02/22 08:43:31 | 000,009,355 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft Excel.EML
[2011/02/22 08:43:19 | 000,260,917 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\Arsenal World.url
[2011/02/22 08:43:19 | 000,245,283 | —- | C] () – D:\Documents and Settings\ucyzdun\Casual open.rep
[2011/02/22 08:43:19 | 000,029,930 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\Arsenal.url
[2011/02/22 08:43:19 | 000,000,751 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\KB Links.lnk
[2011/02/22 08:43:19 | 000,000,455 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\InfoView.url
[2011/02/22 08:43:19 | 000,000,327 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\Resource Link on the NET.url
[2011/02/22 08:43:19 | 000,000,298 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\Payslips & P60's.url
[2011/02/22 08:43:19 | 000,000,292 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\Birmingham UPAY.url
[2011/02/22 08:43:19 | 000,000,251 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\KnowBase.url
[2011/02/22 08:43:19 | 000,000,248 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\WTS Page.url
[2011/02/22 08:43:19 | 000,000,225 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\SELF SERVICE.url
[2011/02/22 08:43:19 | 000,000,205 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\HR Helpdesk Webform.url
[2011/02/22 08:43:19 | 000,000,140 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\MyView TEST.url
[2011/02/22 08:43:19 | 000,000,127 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\Work Station Assessment Form.url
[2011/02/22 08:43:18 | 000,452,651 | —- | C] () – D:\Documents and Settings\ucyzdun\My Documents\Mock 72.pdf
[2011/02/22 08:43:18 | 000,071,292 | —- | C] () – D:\Documents and Settings\ucyzdun\My Documents\Anders.bgl
[2011/02/22 08:43:18 | 000,061,224 | —- | C] () – D:\Documents and Settings\ucyzdun\GoToAssistDownloadHelper.exe
[2011/02/22 08:43:18 | 000,020,910 | —- | C] () – D:\Documents and Settings\ucyzdun\My Documents\cc_20110217_091907.reg
[2011/02/22 08:43:18 | 000,011,810 | —- | C] () – D:\Documents and Settings\ucyzdun\My Documents\cc_20110217_140739.reg
[2011/02/22 08:43:18 | 000,001,273 | —- | C] () – D:\Documents and Settings\ucyzdun\jinitiator13129.trace
[2011/02/22 08:43:18 | 000,000,912 | —- | C] () – D:\Documents and Settings\ucyzdun\jinitiator1319.trace
[2011/02/22 08:43:18 | 000,000,910 | —- | C] () – D:\Documents and Settings\ucyzdun\jinitiator13122.trace
[2011/02/22 08:43:18 | 000,000,032 | R— | C] () – D:\Documents and Settings\ucyzdun\hash.dat
[2011/02/22 08:43:13 | 000,504,038 | —- | C] () – D:\Documents and Settings\ucyzdun\My Documents\sqlite3.dll
[2011/02/22 08:43:13 | 000,000,122 | —- | C] () – D:\Documents and Settings\ucyzdun\My Documents\schema.ini
[2011/02/22 08:43:11 | 000,002,331 | —- | C] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Windows Install Clean Up.lnk
[2011/02/22 08:43:11 | 000,001,599 | —- | C] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Remote Assistance.lnk
[2011/02/22 08:43:11 | 000,000,803 | —- | C] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Internet Explorer.lnk
[2011/02/22 08:43:11 | 000,000,788 | —- | C] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Windows Media Player.lnk
[2011/02/22 08:43:02 | 000,009,684 | RHS- | C] () – D:\Documents and Settings\ucyzdun\ntuser.pol
[2011/02/21 16:49:34 | 000,000,768 | —- | C] () – D:\WINDOWS\System32\d3d8caps.dat
[2011/01/05 12:14:28 | 000,000,698 | —- | C] () – D:\WINDOWS\System32\DWRCCMDError.ini
[2010/11/25 10:31:37 | 000,000,038 | —- | C] () – D:\WINDOWS\XOBJECTS.INI
[2010/11/23 15:26:21 | 000,236,588 | —- | C] () – D:\WINDOWS\System32\nvdrsdb0.bin
[2010/11/23 15:26:20 | 000,236,588 | —- | C] () – D:\WINDOWS\System32\nvdrsdb1.bin
[2010/11/23 15:26:20 | 000,000,001 | —- | C] () – D:\WINDOWS\System32\nvdrssel.bin
[2010/11/23 15:25:56 | 002,195,350 | —- | C] () – D:\WINDOWS\System32\nvdata.bin
[2009/03/24 15:04:46 | 002,026,604 | —- | C] () – D:\WINDOWS\System32\igkrng500.bin
[2009/03/24 15:04:45 | 000,442,964 | —- | C] () – D:\WINDOWS\System32\igcompkrng500.bin
[2009/03/24 15:04:45 | 000,147,456 | —- | C] () – D:\WINDOWS\System32\igfxCoIn_v4977.dll
[2009/02/18 12:20:36 | 000,000,664 | —- | C] () – D:\WINDOWS\System32\d3d9caps.dat
[2009/02/18 12:01:02 | 000,000,168 | —- | C] () – D:\WINDOWS\wininit.ini
[2009/01/21 16:22:54 | 000,000,061 | —- | C] () – D:\WINDOWS\smscfg.ini
[2009/01/21 13:08:30 | 000,000,000 | —- | C] () – D:\WINDOWS\nsreg.dat
[2009/01/21 11:15:47 | 000,036,962 | —- | C] () – D:\WINDOWS\System32\ActPanel.dll
[2009/01/21 10:59:25 | 000,000,804 | —- | C] () – D:\WINDOWS\ODBC.INI
[2009/01/21 10:24:07 | 000,000,000 | —- | C] () – D:\WINDOWS\ativpsrm.bin
[2009/01/21 10:18:27 | 000,876,544 | —- | C] () – D:\WINDOWS\System32\TEACico2.dll
[2009/01/20 16:59:24 | 000,002,048 | –S- | C] () – D:\WINDOWS\bootstat.dat
[2009/01/20 16:56:52 | 000,021,640 | —- | C] () – D:\WINDOWS\System32\emptyregdb.dat
[2009/01/20 16:53:49 | 000,004,332 | —- | C] () – D:\WINDOWS\ODBCINST.INI
[2009/01/20 16:53:07 | 000,263,824 | —- | C] () – D:\WINDOWS\System32\FNTCACHE.DAT
[2008/12/01 20:11:21 | 003,107,788 | —- | C] () – D:\WINDOWS\System32\ativvaxx.dat
[2008/12/01 20:11:21 | 003,107,788 | —- | C] () – D:\WINDOWS\System32\ativva5x.dat
[2008/12/01 20:11:21 | 000,887,724 | —- | C] () – D:\WINDOWS\System32\ativva6x.dat
[2008/10/30 14:45:42 | 000,180,720 | —- | C] () – D:\WINDOWS\System32\atiicdxx.dat
[2008/04/14 04:55:28 | 000,001,804 | —- | C] () – D:\WINDOWS\System32\Dcache.bin
[2008/04/14 04:41:56 | 000,755,200 | —- | C] () – D:\WINDOWS\System32\ir50_32.dll
[2008/04/14 04:41:56 | 000,338,432 | —- | C] () – D:\WINDOWS\System32\ir41_qcx.dll
[2008/04/14 04:41:56 | 000,200,192 | —- | C] () – D:\WINDOWS\System32\ir50_qc.dll
[2008/04/14 04:41:56 | 000,183,808 | —- | C] () – D:\WINDOWS\System32\ir50_qcx.dll
[2008/04/14 04:41:56 | 000,120,320 | —- | C] () – D:\WINDOWS\System32\ir41_qc.dll
[2008/02/04 18:23:10 | 000,693,792 | —- | C] () – D:\WINDOWS\System32\OGACheckControl.DLL
[2007/05/17 16:54:00 | 000,113,664 | —- | C] () – D:\WINDOWS\System32\See32.dll
[2006/12/31 06:57:08 | 000,004,569 | —- | C] () – D:\WINDOWS\System32\secupd.dat
[2001/08/23 11:00:00 | 013,107,200 | —- | C] () – D:\WINDOWS\System32\oembios.bin
[2001/08/23 11:00:00 | 000,673,088 | —- | C] () – D:\WINDOWS\System32\mlang.dat
[2001/08/23 11:00:00 | 000,505,972 | —- | C] () – D:\WINDOWS\System32\perfh009.dat
[2001/08/23 11:00:00 | 000,272,128 | —- | C] () – D:\WINDOWS\System32\perfi009.dat
[2001/08/23 11:00:00 | 000,218,003 | —- | C] () – D:\WINDOWS\System32\dssec.dat
[2001/08/23 11:00:00 | 000,089,244 | —- | C] () – D:\WINDOWS\System32\perfc009.dat
[2001/08/23 11:00:00 | 000,046,258 | —- | C] () – D:\WINDOWS\System32\mib.bin
[2001/08/23 11:00:00 | 000,028,626 | —- | C] () – D:\WINDOWS\System32\perfd009.dat
[2001/08/23 11:00:00 | 000,004,463 | —- | C] () – D:\WINDOWS\System32\oembios.dat
[2001/08/23 11:00:00 | 000,000,741 | —- | C] () – D:\WINDOWS\System32\noise.dat

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2005/09/22 20:38:00 | 000,458,752 | R— | M] (Inner Media, Inc.) – D:\adfactry.dll
[2005/09/22 20:38:00 | 000,015,872 | R— | M] (Inner Media, Inc.) – D:\adreg32.exe
[2011/03/07 09:08:54 | 000,001,362 | —- | M] () – D:\deploy.log
[2005/09/22 20:38:00 | 000,073,216 | R— | M] (Inner Media, Inc.) – D:\sfxbe321.dll
[2005/09/22 20:38:00 | 000,078,336 | R— | M] (Inner Media, Inc.) – D:\sfxbe322.dll
[2005/09/22 20:38:00 | 000,053,760 | R— | M] (Inner Media, Inc.) – D:\sfxfe32.exe
[2009/01/13 11:00:57 | 000,000,584 | —- | M] () – D:\sysprep.inf

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – D:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – D:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – D:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – D:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/01/20 16:58:14 | 000,000,067 | -HS- | M] () – D:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 12:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – D:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – D:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 10:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – D:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2010/01/26 10:14:41 | 000,001,634 | -H– | M] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/01/20 16:52:43 | 000,094,208 | —- | M] () – D:\WINDOWS\system32\config\default.sav
[2009/01/20 16:52:43 | 001,089,536 | —- | M] () – D:\WINDOWS\system32\config\software.sav
[2009/01/20 16:52:43 | 000,933,888 | —- | M] () – D:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/01/20 16:58:26 | 000,000,294 | -HS- | M] () – D:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/07/31 10:51:36 | 000,000,119 | -HS- | M] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/07/05 14:52:31 | 000,000,079 | —- | M] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/03/07 09:15:42 | 000,580,608 | —- | M] (OldTimer Tools) – D:\Documents and Settings\ucyzdun\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >
[2009/12/14 11:32:09 | 000,061,224 | —- | M] () – D:\Documents and Settings\ucyzdun\GoToAssistDownloadHelper.exe

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2009/07/31 10:51:36 | 000,000,122 | -HS- | M] () – D:\Documents and Settings\ucyzdun\Favorites\Desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >
[2011/01/05 10:39:20 | 000,030,058 | RHS- | M] () – D:\Documents and Settings\All Users\ntuser.pol

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2011/03/01 09:28:33 | 000,000,067 | -HS- | M] () – D:\Documents and Settings\ucyzdun\Cookies\desktop.ini
[2011/03/07 09:15:10 | 000,475,136 | -HS- | M] () – D:\Documents and Settings\ucyzdun\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"NoAutoUpdate" = 0
"AUOptions" = 4
"ScheduledInstallDay" = 0
"ScheduledInstallTime" = 5
"UseWUServer" = 1

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-02-25 05:00:41

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 143 bytes -> D:\Documents and Settings\ucyzdun\Application Data\Microsoft Excel.EML:OECustomProperty
@Alternate Data Stream - 143 bytes -> D:\Documents and Settings\ucyzdun\Application Data\Comma Separated Values (DOS).EML:OECustomProperty

< End of report >

Second one to follow.
Here's the Extras OTL report

OTL Extras logfile created on: 07/03/2011 09:16:30 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = D:\Documents and Settings\ucyzdun\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 56.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 4096 4096 [binary data]

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 31.25 Gb Total Space | 26.21 Gb Free Space | 83.88% Space Free | Partition Type: NTFS
Drive D: | 122.24 Gb Total Space | 95.37 Gb Free Space | 78.01% Space Free | Partition Type: NTFS
Drive E: | 79.33 Gb Total Space | 78.47 Gb Free Space | 98.91% Space Free | Partition Type: NTFS
Drive M: | 326.75 Gb Total Space | 47.43 Gb Free Space | 14.52% Space Free | Partition Type: NTFS
Drive W: | 5.03 Gb Total Space | 1.25 Gb Free Space | 24.82% Space Free | Partition Type: NTFS
Drive X: | 5.03 Gb Total Space | 1.25 Gb Free Space | 24.82% Space Free | Partition Type: NTFS
Drive Y: | 326.75 Gb Total Space | 47.43 Gb Free Space | 14.52% Space Free | Partition Type: NTFS
Drive Z: | 353.52 Gb Total Space | 23.98 Gb Free Space | 6.78% Space Free | Partition Type: NTFS

Computer Name: H7N80CFJ-HR | User Name: ucyzdun | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
"" =
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\AuthorizedApplications]
"AllowUserPrefMerge" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts]
"AllowUserPrefMerge" = 0
"Enabled" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\GloballyOpenPorts\List]
"137:TCP:128.40.203.0/24,128.40.192.0/25,128.40.118.0/24:enabled:NameSrvcforDameware" = 137:TCP:128.40.203.0/24,128.40.192.0/25,128.40.118.0/24:enabled:NameSrvcforDameware
"26675:TCP:169.254.2.0/24:Enabled:AsyncSvc" = 26675:TCP:169.254.2.0/24:Enabled:AsyncSvc
"6129:TCP:128.40.203.0/24,128.40.192.0/25,128.40.118.0/24:Enabled:DameWareRemControl" = 6129:TCP:128.40.203.0/24,128.40.192.0/25,128.40.118.0/24:Enabled:DameWareRemControl
"8192:TCP:128.40.203.0/24:enabled:Sophos8192" = 8192:TCP:128.40.203.0/24:enabled:Sophos8192
"8193:TCP:128.40.203.0/24:enabled:Sophos8193" = 8193:TCP:128.40.203.0/24:enabled:Sophos8193
"8194:TCP:128.40.203.0/24:enabled:Sophos8194" = 8194:TCP:128.40.203.0/24:enabled:Sophos8194
"990:TCP:169.254.2.0/24:Enabled:AsyncRapiMgr" = 990:TCP:169.254.2.0/24:Enabled:AsyncRapiMgr

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\IcmpSettings]
"AllowOutboundDestinationUnreachable" = 0
"AllowOutboundSourceQuench" = 0
"AllowRedirect" = 0
"AllowInboundEchoRequest" = 1
"AllowInboundRouterRequest" = 0
"AllowOutboundTimeExceeded" = 0
"AllowOutboundParameterProblem" = 0
"AllowInboundTimestampRequest" = 0
"AllowInboundMaskRequest" = 0
"AllowOutboundPacketTooBig" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Logging]
"LogDroppedPackets" = 1
"LogSuccessfulConnections" = 1
"LogFilePath" = c:\adsfwall.log – ()
"LogFileSize" = 10240

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\RemoteAdminSettings]
"Enabled" = 1
"RemoteAddresses" = 128.40.203.0/24,128.40.192.0/25,128.40.118.0/24

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\FileAndPrint]
"Enabled" = 1
"RemoteAddresses" = 128.40.203.0/24,128.40.192.0/25,localsubnet,128.40.118.0/24

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\Services\RemoteDesktop]
"Enabled" = 1
"RemoteAddresses" = 128.40.203.0/24,128.40.192.0/25,128.40.118.0/24

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings]
"AllowOutboundDestinationUnreachable" = 0
"AllowOutboundSourceQuench" = 0
"AllowRedirect" = 0
"AllowInboundEchoRequest" = 1
"AllowInboundRouterRequest" = 0
"AllowOutboundTimeExceeded" = 0
"AllowOutboundParameterProblem" = 0
"AllowInboundTimestampRequest" = 0
"AllowInboundMaskRequest" = 0
"AllowOutboundPacketTooBig" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management
"80:TCP" = 80:TCP:*:Disabled:Windows Remote Management - Compatibility Mode (HTTP-In)
"6129:TCP" = 6129:TCP:*:Enabled:DameWare Mini Remote Control Service
"6129:UDP" = 6129:UDP:*:Enabled:DameWare Mini Remote Control Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"6129:TCP" = 6129:TCP:*:Enabled:DameWare Mini Remote Control Service
"6129:UDP" = 6129:UDP:*:Enabled:DameWare Mini Remote Control Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"D:\Program Files\Documentum\AppConnector\Documentum.AppConnector.CredentialManager.exe" = D:\Program Files\Documentum\AppConnector\Documentum.AppConnector.CredentialManager.exe:*:Enabled:Documentum.AppConne
ctor.CredentialManager – (Documentum, a division of EMC Corporation)
"D:\Program Files\Java\jre6\bin\java.exe" = D:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"D:\Program Files\NorthgateArinso\Client\proiv.exe" = D:\Program Files\NorthgateArinso\Client\proiv.exe:*:Enabled:Client ActiveX Document Server – (NorthgateIS)
"C:\TEMP\OraInstall2010-12-22_04-12-51PM\jre\1.4.2\bin\javaw.exe" = C:\TEMP\OraInstall2010-12-22_04-12-51PM\jre\1.4.2\bin\javaw.exe:*:Enabled:javaw

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"D:\Program Files\Documentum\AppConnector\Documentum.AppConnector.CredentialManager.exe" = D:\Program Files\Documentum\AppConnector\Documentum.AppConnector.CredentialManager.exe:*:Enabled:Documentum.AppConne
ctor.CredentialManager – (Documentum, a division of EMC Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" = Google Gmail Notifier
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE 10.3
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{15C418EB-7675-42be-B2B3-281952DA014D}" = Sophos AutoUpdate
"{172423F9-522A-483A-AD65-03600CE4CA4F}" = Microsoft Works 6-9 Converter
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 24
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{438A6B90-C80E-22EF-4103-2C2C140E2E26}" = ATI Catalyst Install Manager
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{6AA003BF-73E5-4911-ADB7-71DD5674DDD4}" = Oracle Data Provider for .NET Help
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{86A9E225-AC8D-48D3-A838-1C05F94162C0}" = BusinessObjects Planning Professional Edition
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0522ADB8-2B57-4824-AB06-4747AB0A603D}" =
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-0052-0409-0000-0000000FF1CE}" = Microsoft Office Visio Viewer 2007
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9ACB414D-9347-40B6-A453-5EFB2DB59DFA}" = Sophos Anti-Virus
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A534480F-5D91-4025-93C9-FF68432A1CA7}" = EMC Documentum Application Connectors 6.0
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA9D3A4B-D4D6-8F3D-37E2-6B6553B35240}" = ada
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1CCF2E9-4851-4783-8076-D9C3F7DDD487}" = Citrix XenApp Plugin for Hosted Apps
"{CAFECAFE-0013-0001-0122-ABCDEFABCDEF}" = Oracle JInitiator 1.3.1.22
"{CAFECAFE-0013-0001-0123-ABCDEFABCDEF}" = Oracle JInitiator [removed]
"{CAFECAFE-0013-0001-0129-ABCDEFABCDEF}" = Oracle JInitiator [removed]
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DAEF4F05-C369-4910-87C8-819C5B3D43E2}" = BusinessObjects Enterprise XI 3.1 Client Tools
"{DECF949A-0ED2-4AB8-9031-952A1FAFE4DE}" = NorthgateArinso Windows Client 6.2
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE 10.3
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{FED1005D-CBC8-45D5-A288-FFC7BB304121}" = Sophos Remote Management System
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"ATI Display Driver" = ATI Display Driver
"CCleaner" = CCleaner
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"ENTERPRISE" = Microsoft Office Enterprise 2007
"HDMI" = Intel® Graphics Media Accelerator Driver
"HECI" = Intel® Management Engine Interface
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MESOL" = Intel® Active Management Technology
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MultiMon TaskBar_is1" = MultiMon TaskBar 2.1
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"org.madan.air.ada" = ada
"PrintKey2000" = PrintKey2000
"PROPLUS" = Microsoft Office Professional Plus 2007
"PROSet" = Intel® Network Connections Drivers
"SystemRequirementsLab" = System Requirements Lab
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 07/01/2011 08:15:35 | Computer Name = G9BDV4J-FIN | Source = Documentum AppConnector COM Add-in Shim | ID = 1
Description = Failed to create instance of COM Add-in based Application Connector:
-
Assembly name: Documentum.AppConnector.Office.Outlook,PublicKeyToken=d8533ca61944ee9d
-
Connect class name: Documentum.AppConnector.Office.Outlook.Connect - Error: No such
interface supported

Error - 07/01/2011 08:20:25 | Computer Name = G9BDV4J-FIN | Source = Documentum AppConnector COM Add-in Shim | ID = 1
Description = Failed to create instance of COM Add-in based Application Connector:
-
Assembly name: Documentum.AppConnector.Office.Word,PublicKeyToken=d8533ca61944ee9d
-
Connect class name: Documentum.AppConnector.Office.Word.Connect - Error: No such
interface supported

Error - 07/01/2011 08:20:43 | Computer Name = G9BDV4J-FIN | Source = Documentum AppConnector COM Add-in Shim | ID = 1
Description = Failed to create instance of COM Add-in based Application Connector:
-
Assembly name: Documentum.AppConnector.Office.Word,PublicKeyToken=d8533ca61944ee9d
-
Connect class name: Documentum.AppConnector.Office.Word.Connect - Error: No such
interface supported

Error - 07/01/2011 08:21:04 | Computer Name = G9BDV4J-FIN | Source = Documentum AppConnector COM Add-in Shim | ID = 1
Description = Failed to create instance of COM Add-in based Application Connector:
-
Assembly name: Documentum.AppConnector.Office.Word,PublicKeyToken=d8533ca61944ee9d
-
Connect class name: Documentum.AppConnector.Office.Word.Connect - Error: No such
interface supported

Error - 07/01/2011 08:34:21 | Computer Name = G9BDV4J-FIN | Source = Documentum AppConnector COM Add-in Shim | ID = 1
Description = Failed to create instance of COM Add-in based Application Connector:
-
Assembly name: - Connect class name: - Error: The parameter is incorrect.

Error - 07/01/2011 08:34:37 | Computer Name = G9BDV4J-FIN | Source = Documentum AppConnector COM Add-in Shim | ID = 1
Description = Failed to create instance of COM Add-in based Application Connector:
-
Assembly name: Documentum.AppConnector.Office.Word,PublicKeyToken=d8533ca61944ee9d
-
Connect class name: Documentum.AppConnector.Office.Word.Connect - Error: No such
interface supported

Error - 10/01/2011 05:31:16 | Computer Name = G9BDV4J-FIN | Source = Documentum AppConnector COM Add-in Shim | ID = 1
Description = Failed to create instance of COM Add-in based Application Connector:
-
Assembly name: Documentum.AppConnector.Office.Outlook,PublicKeyToken=d8533ca61944ee9d
-
Connect class name: Documentum.AppConnector.Office.Outlook.Connect - Error: No such
interface supported

Error - 10/01/2011 05:33:37 | Computer Name = G9BDV4J-FIN | Source = Outlook | ID = 27
Description = OAB ModDif failed. (Details record in event data).

Error - 10/01/2011 06:00:30 | Computer Name = G9BDV4J-FIN | Source = Documentum AppConnector COM Add-in Shim | ID = 1
Description = Failed to create instance of COM Add-in based Application Connector:
-
Assembly name: Documentum.AppConnector.Office.Word,PublicKeyToken=d8533ca61944ee9d
-
Connect class name: Documentum.AppConnector.Office.Word.Connect - Error: No such
interface supported

Error - 10/01/2011 06:48:01 | Computer Name = G9BDV4J-FIN | Source = Documentum AppConnector COM Add-in Shim | ID = 1
Description = Failed to create instance of COM Add-in based Application Connector:
-
Assembly name: - Connect class name: - Error: The parameter is incorrect.

[ System Events ]
Error - 05/01/2011 07:13:39 | Computer Name = G9BDV4J-FIN | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.


< End of report >
Here's the MBRCheck Sadly, I was unable to turn off Sophos MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Professional Windows Information: Service Pack 3 (build 2600) Logical Drives Mask: 0x03c0101d Kernel Drivers (total 119): 0x804D7000 \WINDOWS\system32\ntkrnlpa.exe 0x806E5000 \WINDOWS\system32\hal.dll 0xB85A8000 \WINDOWS\system32\KDCOM.DLL 0xB84B8000 \WINDOWS\system32\BOOTVID.dll 0xB7F79000 ACPI.sys 0xB85AA000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xB7F68000 pci.sys 0xB80A8000 isapnp.sys 0xB8670000 pciide.sys 0xB8328000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xB80B8000 MountMgr.sys 0xB7F49000 ftdisk.sys 0xB85AC000 dmload.sys 0xB7F23000 dmio.sys 0xB8330000 PartMgr.sys 0xB80C8000 VolSnap.sys 0xB7F0B000 atapi.sys 0xB7E31000 iaStor.sys 0xB80D8000 disk.sys 0xB80E8000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xB7E11000 fltMgr.sys 0xB7DFF000 sr.sys 0xB80F8000 PxHelp20.sys 0xB7DE8000 KSecDD.sys 0xB7D5B000 Ntfs.sys 0xB7D2E000 NDIS.sys 0xB8108000 sfaudio.sys 0xB7D14000 Mup.sys 0xB8268000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xB8564000 \SystemRoot\system32\DRIVERS\wmiacpi.sys 0xB7787000 \SystemRoot\system32\DRIVERS\ati2mtag.sys 0xB7773000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xB8278000 \SystemRoot\system32\DRIVERS\HECI.sys 0xB8288000 \SystemRoot\system32\DRIVERS\serial.sys 0xB8568000 \SystemRoot\system32\DRIVERS\serenum.sys 0xB774E000 \SystemRoot\system32\DRIVERS\e1k5132.sys 0xB83D0000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0xB772A000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xB83D8000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xB7702000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0xB83E0000 \SystemRoot\system32\DRIVERS\fdc.sys 0xB76EE000 \SystemRoot\system32\DRIVERS\parport.sys 0xB8755000 \SystemRoot\system32\DRIVERS\DamewareMini.sys 0xB8298000 \SystemRoot\system32\DRIVERS\dwvkbd.sys 0xB83E8000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xB8757000 \SystemRoot\system32\DRIVERS\audstub.sys 0xB82A8000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xB856C000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xB76D7000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xB82B8000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xB82C8000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xB83F0000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xB76C6000 \SystemRoot\system32\DRIVERS\psched.sys 0xB82D8000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xB83F8000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xB8400000 \SystemRoot\system32\DRIVERS\raspti.sys 0xB7696000 \SystemRoot\system32\DRIVERS\rdpdr.sys 0xB82E8000 \SystemRoot\system32\DRIVERS\termdd.sys 0xB8408000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xB85C6000 \SystemRoot\system32\DRIVERS\swenum.sys 0xB764B000 \SystemRoot\system32\DRIVERS\ks.sys 0xB75ED000 \SystemRoot\system32\DRIVERS\update.sys 0xB8584000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xB8318000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xB8128000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xB85D0000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xAB48C000 \SystemRoot\system32\drivers\ADIHdAud.sys 0xAB468000 \SystemRoot\system32\drivers\portcls.sys 0xB8138000 \SystemRoot\system32\drivers\drmk.sys 0xB8428000 \SystemRoot\system32\DRIVERS\flpydisk.sys 0xB8430000 \SystemRoot\system32\DRIVERS\savonaccessfilter.sys 0xAB442000 \SystemRoot\system32\DRIVERS\savonaccesscontrol.sys 0xB85E8000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xB87BD000 \SystemRoot\System32\Drivers\Null.SYS 0xB85EA000 \SystemRoot\System32\Drivers\Beep.SYS 0xB8440000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xB8448000 \SystemRoot\System32\drivers\vga.sys 0xB85EC000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xB85EE000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xB8450000 \SystemRoot\System32\Drivers\Msfs.SYS 0xB8458000 \SystemRoot\System32\Drivers\Npfs.SYS 0xB8558000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xAB3E7000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xAB38E000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xAB366000 \SystemRoot\system32\DRIVERS\netbt.sys 0xAB340000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xAB31E000 \SystemRoot\System32\drivers\afd.sys 0xB8178000 \SystemRoot\system32\DRIVERS\netbios.sys 0xB8188000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xAB2F3000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xAB283000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xB81B8000 \SystemRoot\System32\Drivers\Fips.SYS 0xB7672000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xB81D8000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xAB59F000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0xBF800000 \SystemRoot\System32\win32k.sys 0xAB587000 \SystemRoot\System32\drivers\Dxapi.sys 0xB8480000 \SystemRoot\System32\watchdog.sys 0xBD000000 \SystemRoot\System32\drivers\dxg.sys 0xB86CF000 \SystemRoot\System32\drivers\dxgthk.sys 0xBD012000 \SystemRoot\System32\ati2dvag.dll 0xBD063000 \SystemRoot\System32\ati2cqag.dll 0xBD0F0000 \SystemRoot\System32\atikvmag.dll 0xBD163000 \SystemRoot\System32\atiok3x2.dll 0xBD1AD000 \SystemRoot\System32\ati3duag.dll 0xBD59B000 \SystemRoot\System32\ativvaxx.dll 0xBD7FD000 \SystemRoot\System32\ATMFD.DLL 0xA8CEF000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xA8B2F000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xA88A7000 \SystemRoot\system32\DRIVERS\srv.sys 0xB8498000 \SystemRoot\System32\Drivers\TDTCP.SYS 0xA8244000 \SystemRoot\System32\Drivers\RDPWD.SYS 0xA8167000 \SystemRoot\system32\drivers\wdmaud.sys 0xA874F000 \SystemRoot\system32\drivers\sysaudio.sys 0xA7BF8000 \SystemRoot\System32\Drivers\HTTP.sys 0xA6C52000 \SystemRoot\System32\Drivers\Fastfat.SYS 0xA6C46000 \SystemRoot\system32\DRIVERS\mouhid.sys 0xA5E05000 \SystemRoot\system32\drivers\kmixer.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 48): 0 System Idle Process 4 System 648 D:\WINDOWS\system32\smss.exe 704 csrss.exe 736 D:\WINDOWS\system32\winlogon.exe 780 D:\WINDOWS\system32\services.exe 792 D:\WINDOWS\system32\lsass.exe 996 D:\WINDOWS\system32\ati2evxx.exe 1020 D:\WINDOWS\system32\svchost.exe 1088 svchost.exe 1188 D:\WINDOWS\system32\svchost.exe 1640 svchost.exe 1696 svchost.exe 1816 D:\WINDOWS\system32\spoolsv.exe 1900 svchost.exe 1976 D:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe 180 D:\WINDOWS\dwrcs\DWRCS.EXE 264 D:\Program Files\Java\jre6\bin\jqs.exe 372 D:\Program Files\Intel\AMT\LMS.exe 468 D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE 560 D:\WINDOWS\system32\svchost.exe 692 D:\WINDOWS\system32\svchost.exe 1540 D:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe 2228 D:\Program Files\Sophos\AutoUpdate\ALsvc.exe 2316 D:\Program Files\Sophos\Remote Management System\RouterNT.exe 2364 D:\WINDOWS\system32\svchost.exe 2592 D:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe 2868 D:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe 3216 alg.exe 3868 SavService.exe 3384 D:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe 3704 swi_service.exe 2756 D:\WINDOWS\dwrcs\DWRCST.EXE 1360 D:\WINDOWS\system32\ati2evxx.exe 5708 D:\WINDOWS\explorer.exe 4956 D:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe 5868 D:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe 4292 D:\Program Files\Analog Devices\Core\smax4pnp.exe 4504 D:\Program Files\Documentum\AppConnector\Documentum.AppConnector.CredentialManager.exe 3740 D:\Program Files\Sophos\AutoUpdate\ALMon.exe 5476 D:\Program Files\Google\Gmail Notifier\gnotify.exe 4284 D:\Documents and Settings\ucyzdun\Local Settings\Application Data\gersai.exe 5912 D:\WINDOWS\system32\ctfmon.exe 5312 D:\Program Files\MMTaskbar\MultiMon.exe 5316 D:\Program Files\PrintKey2000\Printkey2000.exe 1060 D:\Documents and Settings\ucyzdun\Desktop\OTL.exe 4936 D:\Program Files\Internet Explorer\iexplore.exe 192 D:\Documents and Settings\ucyzdun\Local Settings\Temporary Internet Files\Content.IE5\RTAIYC6D\MBRCheck[1].exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) \\.\D: –> \\.\PhysicalDrive0 at offset 0x00000007`cfcadc00 (NTFS) \\.\E: –> \\.\PhysicalDrive0 at offset 0x00000026`5f708800 (NTFS) PhysicalDrive0 Model Number: ST3250318AS, Rev: CC46 Size Device Name MBR Status ——————————————– 232 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A Done!
Hi gtbear,

Run OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTL
    O4 - HKLM..\Run: [hpgcrybc] D:\Documents and Settings\ucyzdun\Local Settings\Application Data\gersai.exe ()
    O4 - HKCU..\Run: [hpgcrybc] D:\Documents and Settings\ucyzdun\Local Settings\Application Data\gersai.exe ()
    O4 - Startup: D:\Documents and Settings\ucyzdun\Start Menu\Programs\Startup\frilm.exe ()
    O4 - Startup: D:\Documents and Settings\ucyzdun\Start Menu\Programs\Startup\peyci.exe ()
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://domredi.com/1/
    
    :Commands
    [createrestorepoint]
    [purity]
    [emptytemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
===================================================

Next, I need you to run Malwarebytes Antimalware.
  • Click the Update tab then click Check for Updates.
  • If an update is found, it will download and install the latest version.
  • Next, click the Scanner tab and select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
===================================================

Scan With RootKitUnHooker

  • Please choose one link and download Rootkit Unhooker and save it to your desktop.
    Link 1
    Link 2
    Link 3
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"


===================================================

In your next post, please post the following:
  • OTL log
  • MBAM log
  • Rootkit Unhooker log
Hi,

Thanks for looking at everything,. heres the OTL log.

OTL logfile created on: 08/03/2011 09:07:56 - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = D:\Documents and Settings\ucyzdun\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 63.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 4096 4096 [binary data]

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 31.25 Gb Total Space | 26.29 Gb Free Space | 84.14% Space Free | Partition Type: NTFS
Drive D: | 122.24 Gb Total Space | 96.05 Gb Free Space | 78.58% Space Free | Partition Type: NTFS
Drive E: | 79.33 Gb Total Space | 78.47 Gb Free Space | 98.91% Space Free | Partition Type: NTFS
Drive M: | 326.75 Gb Total Space | 47.29 Gb Free Space | 14.47% Space Free | Partition Type: NTFS
Drive W: | 5.03 Gb Total Space | 1.25 Gb Free Space | 24.83% Space Free | Partition Type: NTFS
Drive X: | 5.03 Gb Total Space | 1.25 Gb Free Space | 24.83% Space Free | Partition Type: NTFS
Drive Y: | 326.75 Gb Total Space | 47.29 Gb Free Space | 14.47% Space Free | Partition Type: NTFS
Drive Z: | 353.52 Gb Total Space | 45.04 Gb Free Space | 12.74% Space Free | Partition Type: NTFS

Computer Name: H7N80CFJ-HR | User Name: ucyzdun | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/03/07 09:15:42 | 000,580,608 | —- | M] (OldTimer Tools) – D:\Documents and Settings\ucyzdun\Desktop\OTL.exe
PRC - [2011/02/21 15:15:46 | 000,806,912 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\Remote Management System\RouterNT.exe
PRC - [2011/02/21 15:15:43 | 000,282,624 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
PRC - [2011/02/09 17:08:06 | 000,273,784 | —- | M] (DameWare Development) – D:\WINDOWS\dwrcs\DWRCST.EXE
PRC - [2011/02/09 17:07:58 | 000,576,888 | —- | M] (DameWare Development LLC) – D:\WINDOWS\dwrcs\DWRCS.EXE
PRC - [2010/11/23 15:34:19 | 001,541,360 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
PRC - [2010/11/23 15:34:11 | 000,097,520 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
PRC - [2010/11/23 15:34:07 | 000,163,056 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
PRC - [2010/09/30 12:08:31 | 000,439,536 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\AutoUpdate\ALMon.exe
PRC - [2010/09/30 12:08:30 | 000,230,640 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\AutoUpdate\ALsvc.exe
PRC - [2008/12/04 13:00:26 | 000,354,840 | —- | M] (Intel Corporation) – D:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/12/04 13:00:20 | 000,186,904 | —- | M] (Intel Corporation) – D:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/11/12 10:12:40 | 000,045,056 | —- | M] (Documentum, a division of EMC Corporation) – D:\Program Files\Documentum\AppConnector\Documentum.AppConnector.CredentialManager.exe
PRC - [2008/07/23 09:56:14 | 002,054,680 | —- | M] (Intel Corporation) – D:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe
PRC - [2008/07/23 09:56:14 | 000,773,144 | —- | M] (Intel Corporation) – D:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe
PRC - [2008/07/23 09:56:12 | 000,174,616 | —- | M] (Intel Corporation) – D:\Program Files\Intel\AMT\LMS.exe
PRC - [2008/04/14 04:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) – D:\WINDOWS\explorer.exe
PRC - [2008/01/31 03:09:30 | 001,277,952 | —- | M] (Altiris, Inc.) – D:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe
PRC - [2005/11/09 15:34:10 | 000,294,912 | —- | M] () – D:\Program Files\MMTaskbar\MultiMon.exe
PRC - [2005/07/15 21:48:33 | 000,479,232 | —- | M] (Google Inc.) – D:\Program Files\Google\Gmail Notifier\gnotify.exe
PRC - [1999/09/30 21:31:38 | 000,869,376 | —- | M] (Fred's Software) – D:\Program Files\PrintKey2000\Printkey2000.exe


========== Modules (SafeList) ==========

MOD - [2011/03/07 09:15:42 | 000,580,608 | —- | M] (OldTimer Tools) – D:\Documents and Settings\ucyzdun\Desktop\OTL.exe
MOD - [2011/02/21 15:16:23 | 000,234,408 | —- | M] (Sophos Plc) – D:\Program Files\Sophos\Sophos Anti-Virus\sophos_detoured.dll
MOD - [2010/08/23 16:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – D:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2003/09/02 14:15:16 | 000,057,344 | —- | M] () – D:\Program Files\MMTaskbar\shellhook.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/02/21 15:15:46 | 000,806,912 | —- | M] (Sophos Plc) [Auto | Running] – D:\Program Files\Sophos\Remote Management System\RouterNT.exe – (Sophos Message Router)
SRV - [2011/02/21 15:15:43 | 000,282,624 | —- | M] (Sophos Plc) [Auto | Running] – D:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe – (Sophos Agent)
SRV - [2011/02/09 17:07:58 | 000,576,888 | —- | M] (DameWare Development LLC) [Auto | Running] – D:\WINDOWS\dwrcs\DWRCS.EXE – (dwmrcs)
SRV - [2010/11/23 15:34:19 | 001,541,360 | —- | M] (Sophos Plc) [Auto | Running] – D:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe – (swi_service)
SRV - [2010/11/23 15:34:11 | 000,097,520 | —- | M] (Sophos Plc) [Unknown | Running] – D:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe – (SAVService)
SRV - [2010/11/23 15:34:07 | 000,163,056 | —- | M] (Sophos Plc) [Unknown | Running] – D:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe – (SAVAdminService)
SRV - [2010/09/30 12:08:30 | 000,230,640 | —- | M] (Sophos Plc) [Auto | Running] – D:\Program Files\Sophos\AutoUpdate\ALsvc.exe – (Sophos AutoUpdate Service)
SRV - [2008/12/04 13:00:26 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – D:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®
SRV - [2008/07/23 09:56:14 | 002,054,680 | —- | M] (Intel Corporation) [Auto | Running] – D:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe – (UNS) Intel®
SRV - [2008/07/23 09:56:12 | 000,174,616 | —- | M] (Intel Corporation) [Auto | Running] – D:\Program Files\Intel\AMT\LMS.exe – (LMS) Intel®
SRV - [2008/01/31 03:09:30 | 001,277,952 | —- | M] (Altiris, Inc.) [Auto | Running] – D:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe – (AeXNSClient)


========== Driver Services (SafeList) ==========

DRV - [2010/11/23 15:34:16 | 000,024,064 | —- | M] (Sophos Plc) [File_System | System | Running] – D:\WINDOWS\system32\drivers\savonaccessfilter.sys – (SAVOnAccessFilter)
DRV - [2010/11/23 15:34:14 | 000,014,976 | —- | M] (Sophos Plc) [Kernel | Disabled | Stopped] – D:\WINDOWS\system32\drivers\SophosBootDriver.sys – (SophosBootDriver)
DRV - [2010/11/23 15:34:12 | 000,023,928 | —- | M] (Sophos Plc) [Kernel | On_Demand | Stopped] – D:\WINDOWS\system32\drivers\sdcfilter.sys – (sdcfilter)
DRV - [2010/11/23 15:34:11 | 000,153,344 | —- | M] (Sophos Plc) [File_System | System | Running] – D:\WINDOWS\system32\drivers\savonaccesscontrol.sys – (SAVOnAccessControl)
DRV - [2008/12/01 22:13:40 | 003,452,928 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – D:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2008/07/23 09:42:30 | 000,040,832 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – D:\WINDOWS\system32\drivers\HECI.sys – (HECI) Intel®
DRV - [2008/06/05 11:58:18 | 000,144,480 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – D:\WINDOWS\system32\drivers\e1k5132.sys – (e1kexpress) Intel®
DRV - [2008/03/28 10:14:02 | 000,024,064 | —- | M] (Sonic Focus, Inc) [Kernel | Boot | Running] – D:\WINDOWS\system32\drivers\sfaudio.sys – (SFAUDIO)
DRV - [2007/02/15 16:00:00 | 000,026,624 | —- | M] (DameWare) [Kernel | System | Running] – D:\WINDOWS\system32\drivers\dwvkbd.sys – (dwvkbd)
DRV - [2007/02/07 16:00:00 | 000,003,712 | —- | M] (DameWare Development, LLC) [Kernel | On_Demand | Running] – D:\WINDOWS\system32\drivers\DamewareMini.sys – (DwMirror)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://uk.news.yahoo.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "DAEMON Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.ucl.ac.uk"
FF - prefs.js..extensions.enabledItems: [removed]:1.19
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2011/03/01 12:23:10 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2011/03/01 12:23:10 | 000,000,000 | —D | M]

[2010/04/19 08:38:34 | 000,000,000 | —D | M] (No name found) – D:\Documents and Settings\ucyzdun\Application Data\Mozilla\Extensions
[2011/03/01 12:23:23 | 000,000,000 | —D | M] (No name found) – D:\Documents and Settings\ucyzdun\Application Data\Mozilla\Firefox\Profiles\bpzezwgb.default\extensions
[2010/07/27 14:21:31 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – D:\Documents and Settings\ucyzdun\Application Data\Mozilla\Firefox\Profiles\bpzezwgb.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/15 10:20:54 | 000,000,000 | —D | M] (Joomla! Admin) – D:\Documents and Settings\ucyzdun\Application Data\Mozilla\Firefox\Profiles\bpzezwgb.default\extensions\[removed]
[2010/09/15 10:20:54 | 000,000,000 | —D | M] (No name found) – D:\Documents and Settings\ucyzdun\Application Data\Mozilla\Firefox\Profiles\bpzezwgb.default\extensions\staged-xpis
[2011/03/01 12:23:23 | 000,000,000 | —D | M] (No name found) – D:\Program Files\Mozilla Firefox\extensions
[2011/02/22 10:39:43 | 000,000,000 | —D | M] (Java Console) – D:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/04/13 11:36:00 | 000,000,000 | —D | M] (British English Dictionary) – D:\Program Files\Mozilla Firefox\extensions\[removed]
[2011/01/06 12:34:29 | 000,000,000 | —D | M] (Java Quick Starter) – D:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/08/14 11:33:22 | 000,070,488 | —- | M] (Citrix Systems, Inc.) – D:\Program Files\Mozilla Firefox\plugins\CgpCore.dll
[2009/08/14 11:33:30 | 000,091,480 | —- | M] () – D:\Program Files\Mozilla Firefox\plugins\confmgr.dll
[2009/08/14 11:33:26 | 000,020,824 | —- | M] () – D:\Program Files\Mozilla Firefox\plugins\ctxlogging.dll
[2007/03/16 16:33:48 | 000,479,232 | —- | M] (Microsoft Corporation) – D:\Program Files\Mozilla Firefox\plugins\msvcm80.dll
[2007/03/16 16:33:48 | 000,548,864 | —- | M] (Microsoft Corporation) – D:\Program Files\Mozilla Firefox\plugins\msvcp80.dll
[2007/03/16 16:33:50 | 000,626,688 | —- | M] (Microsoft Corporation) – D:\Program Files\Mozilla Firefox\plugins\msvcr80.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – D:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/08/14 11:35:40 | 000,427,344 | —- | M] () – D:\Program Files\Mozilla Firefox\plugins\npicaN.dll
[2005/04/05 04:38:20 | 000,053,355 | —- | M] (Oracle Corporation) – D:\Program Files\Mozilla Firefox\plugins\NPJinit13122.dll
[2005/09/19 23:00:08 | 000,053,355 | —- | M] (Oracle Corporation) – D:\Program Files\Mozilla Firefox\plugins\NPJinit13123.dll
[2007/08/07 01:37:06 | 000,053,355 | —- | M] (Oracle Corporation) – D:\Program Files\Mozilla Firefox\plugins\NPJinit13129.dll
[2009/08/14 11:33:22 | 000,023,896 | —- | M] (Citrix Systems, Inc.) – D:\Program Files\Mozilla Firefox\plugins\TcpPServ.dll
[2010/12/03 17:47:02 | 000,001,538 | —- | M] () – D:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/12/03 17:47:02 | 000,000,947 | —- | M] () – D:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/12/03 17:47:02 | 000,000,769 | —- | M] () – D:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/12/03 17:47:02 | 000,001,135 | —- | M] () – D:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2001/08/23 11:00:00 | 000,000,734 | —- | M]) - D:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Sophos Web Content Scanner) - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - D:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll (Sophos Plc)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {3D89FF0D-3232-4116-867F-6D89B9711B5A} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {796AF358-6E53-4E90-AB45-503C3C8D2891} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BC4FFE41-DE9F-46FA-B455-AAD49B9F9938} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] D:\Program Files\Google\Gmail Notifier\gnotify.exe (Google Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] D:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AeXAgentLogon] D:\Program Files\Altiris\Altiris Agent\AeXAgentActivate.exe (Altiris, Inc.)
O4 - HKLM..\Run: [AppConnectorCredentialMgr] D:\Program Files\Documentum\AppConnector\Documentum.AppConnector.CredentialManager.exe (Documentum, a division of EMC Corporation)
O4 - HKLM..\Run: [DameWare MRC Agent] D:\WINDOWS\dwrcs\DWRCST.EXE (DameWare Development)
O4 - HKLM..\Run: [IAAnotif] D:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [NvMediaCenter] D:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] D:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [OFARegisterOCX] D:\OraHome1\olap\bin\RDONLY.OCX (Oracle Corporation)
O4 - HKLM..\Run: [OFARegisterOCX1] D:\WINDOWS\system32\FLP32X20.OCX (FarPoint Technologies, Inc.)
O4 - HKLM..\Run: [OFARegisterOCX2] D:\WINDOWS\system32\SPIN32.OCX (Outrider Systems, Inc.)
O4 - HKLM..\Run: [OFARegisterOCX3] D:\OraHome1\olap\bin\SNAPIOCX.OCX (Oracle Corporation)
O4 - HKLM..\Run: [OFARegisterOCX4] D:\OraHome1\olap\bin\XWCMDWIN.OCX (Oracle)
O4 - HKLM..\Run: [OFARegisterOCX5] D:\OraHome1\olap\bin\ORACD32.OCX (Oracle Corporation.)
O4 - HKLM..\Run: [picon] D:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe (Intel Corporation)
O4 - HKLM..\Run: [Sophos AutoUpdate Monitor] D:\Program Files\Sophos\AutoUpdate\ALMon.exe (Sophos Plc)
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\MultiMon Taskbar.lnk = D:\Program Files\MMTaskbar\MultiMon.exe ()
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Printkey2000.lnk = D:\Program Files\PrintKey2000\Printkey2000.exe (Fred's Software)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceStartMenuLogOff = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAutoUpdate = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConnectHomeDirToRoot = 0
O15 - HKCU\..Trusted Domains: ucl.ac.uk ([*.adcom] * in Local intranet)
O15 - HKCU\..Trusted Domains: ucl.ac.uk ([*.adm] * in Local intranet)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {36F17E17-AC00-42BC-A6D9-294AD4E7DCD6} http://ads3-adm/Altiris/NS/NSCap/Bin/Win32…ntBootstrap.cab (Altiris ClientBootstraper Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1232534038015 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1294225834643 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFECAFE-0013-0001-0022-ABCDEFABCDEF} Reg Error: Value error. (JInitiator 1.3.1.22)
O16 - DPF: {CAFECAFE-0013-0001-0023-ABCDEFABCDEF} Reg Error: Value error. (JInitiator [removed])
O16 - DPF: {CAFECAFE-0013-0001-0029-ABCDEFABCDEF} Reg Error: Value error. (JInitiator 1.3.1.29)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = adm.ucl.ac.uk
O20 - AppInit_DLLs: (D:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL) - D:\Program Files\Sophos\Sophos Anti-Virus\sophos_detoured.dll (Sophos Plc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - D:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\MRCNotify: DllName - D:\WINDOWS\dwrcs\DWRCWXL.dll - D:\WINDOWS\dwrcs\DWRCWXL.dll (DameWare Development LLC)
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/20 15:58:26 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{ff63e1c0-1fc1-11e0-9be0-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{ff63e1c0-1fc1-11e0-9be0-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ff63e1c0-1fc1-11e0-9be0-806d6172696f}\Shell\AutoRun\command - "" = G:\SETUP.EXE
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/03/08 08:55:33 | 000,000,000 | —D | C] – D:\_OTL
[2011/03/07 09:15:38 | 000,580,608 | —- | C] (OldTimer Tools) – D:\Documents and Settings\ucyzdun\Desktop\OTL.exe
[2011/03/04 13:21:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Google
[2011/03/04 09:12:26 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\PCFix
[2011/03/03 13:45:09 | 000,000,000 | —D | C] – D:\Documents and Settings\LocalService\Application Data\McAfee
[2011/03/03 09:38:51 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\Excel
[2011/03/01 15:33:59 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Microsoft Help
[2011/03/01 12:40:16 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2011/03/01 12:40:15 | 000,000,000 | —D | C] – D:\Program Files\CCleaner
[2011/03/01 12:23:16 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Mozilla
[2011/03/01 12:23:13 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox
[2011/03/01 09:29:41 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
[2011/03/01 09:29:38 | 000,000,000 | —D | C] – D:\Program Files\Microsoft Silverlight
[2011/02/28 14:29:25 | 000,000,000 | —D | C] – D:\Program Files\Trend Micro
[2011/02/28 14:29:25 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\HiJackThis
[2011/02/28 13:09:52 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Temp
[2011/02/28 13:08:41 | 000,000,000 | —D | C] – D:\Program Files\Common Files\Adobe
[2011/02/28 11:36:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Sophos
[2011/02/28 08:53:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\AAT
[2011/02/23 15:35:49 | 000,000,000 | —D | C] – D:\Program Files\PrintKey2000
[2011/02/23 15:32:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\My eBooks
[2011/02/23 13:37:24 | 000,038,224 | —- | C] (Malwarebytes Corporation) – D:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/02/23 13:37:24 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/02/23 13:37:24 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/02/23 13:37:21 | 000,020,952 | —- | C] (Malwarebytes Corporation) – D:\WINDOWS\System32\drivers\mbam.sys
[2011/02/23 13:37:21 | 000,000,000 | —D | C] – D:\Program Files\Malwarebytes' Anti-Malware
[2011/02/22 13:01:01 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\org.madan.air.ada
[2011/02/22 13:00:59 | 000,000,000 | —D | C] – D:\Program Files\ada
[2011/02/22 12:57:41 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Adobe
[2011/02/22 12:30:46 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\MultiMon Taskbar
[2011/02/22 12:30:45 | 000,000,000 | —D | C] – D:\Program Files\MMTaskbar
[2011/02/22 12:13:28 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Downloaded Installations
[2011/02/22 12:01:59 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\BusinessObjects XI 3.1
[2011/02/22 11:58:48 | 000,000,000 | —D | C] – D:\Program Files\Business Objects XI
[2011/02/22 10:39:42 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – D:\WINDOWS\System32\javaws.exe
[2011/02/22 10:39:42 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – D:\WINDOWS\System32\javaw.exe
[2011/02/22 10:39:42 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – D:\WINDOWS\System32\java.exe
[2011/02/22 10:39:11 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\McAfee
[2011/02/22 10:33:54 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2011/02/22 10:24:44 | 000,000,000 | —D | C] – D:\Program Files\Microsoft Visual Studio 8
[2011/02/22 10:07:57 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\Downloads
[2011/02/22 10:07:50 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\PC_Drivers_Headquarters
[2011/02/22 09:24:03 | 000,000,000 | —D | C] – D:\WINDOWS\dwrcs
[2011/02/22 08:54:35 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Documentum
[2011/02/22 08:48:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\ApplicationHistory
[2011/02/22 08:46:00 | 000,000,000 | -H-D | C] – D:\Documents and Settings\ucyzdun\Local Settings
[2011/02/22 08:46:00 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\Microsoft
[2011/02/22 08:44:54 | 000,005,632 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\ptpusb.dll
[2011/02/22 08:44:53 | 000,159,232 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\ptpusd.dll
[2011/02/22 08:44:53 | 000,015,104 | —- | C] (Microsoft Corporation) – D:\WINDOWS\System32\dllcache\usbscan.sys
[2011/02/22 08:43:11 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\.alice2
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Broken Sword 2.5
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\BBC Alerts
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\AVS4YOU
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\ATI
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\ArcSoft
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Apple Computer
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\AdobeUM
[2011/02/22 08:43:10 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Adobe
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Lycos
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Logitech
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Leadertech
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Kontiki
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Identities
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\ICAClient
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Help
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\gtk-2.0
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Google
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\GetRightToGo
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\FreeFixer
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\FMA
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\ElevatedDiagnostics
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\EA
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\dvdcss
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\DivX
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\DAEMON Tools Lite
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\CyberLink
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\CoreFTP
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Cogniview
[2011/02/22 08:43:09 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Business Objects
[2011/02/22 08:43:08 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Media Player Classic
[2011/02/22 08:43:08 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Malwarebytes
[2011/02/22 08:43:08 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Macromedia
[2011/02/22 08:43:06 | 000,000,000 | –SD | C] – D:\Documents and Settings\ucyzdun\Application Data\Microsoft
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Real
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\ProIV Technology Inc
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\PC Suite
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Nuance
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\NSeries
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Nokia Multimedia Player
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Nokia
[2011/02/22 08:43:06 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Mozilla
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Sony Online Entertainment
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Sony Ericsson
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Sony
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\SmartDraw
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\shockwave.com
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\SharePod
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Seven Zip
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\ScanSoft
[2011/02/22 08:43:05 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Roxio
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\WinRAR
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\WindSolutions
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Windows Search
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Windows Desktop Search
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\webex
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Ulead Systems
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\ubi.com
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\tidysongs16
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\TextPad
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Teleca
[2011/02/22 08:43:04 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Sun
[2011/02/22 08:43:03 | 000,000,000 | –SD | C] – D:\Documents and Settings\ucyzdun\My Documents\My Webs
[2011/02/22 08:43:03 | 000,000,000 | –SD | C] – D:\Documents and Settings\ucyzdun\My Documents\My Web Sites
[2011/02/22 08:43:03 | 000,000,000 | –SD | C] – D:\Documents and Settings\ucyzdun\My Documents\My Data Sources
[2011/02/22 08:43:03 | 000,000,000 | RH-D | C] – D:\Documents and Settings\ucyzdun\Application Data
[2011/02/22 08:43:03 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\My Documents\My Videos
[2011/02/22 08:43:03 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\My Documents\My Pictures
[2011/02/22 08:43:03 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\My Documents\My Music
[2011/02/22 08:43:03 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\My Documents
[2011/02/22 08:43:03 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\Favorites
[2011/02/22 08:43:03 | 000,000,000 | -HSD | C] – D:\Documents and Settings\ucyzdun\Cookies
[2011/02/22 08:43:03 | 000,000,000 | -HSD | C] – D:\Documents and Settings\ucyzdun\Desktop\%USERPROFILE%
[2011/02/22 08:43:03 | 000,000,000 | -H-D | C] – D:\Documents and Settings\ucyzdun\InstallAnywhere
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Application Data\Zeon
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\WebEx
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\Updater5
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\PrintScreen Files
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\PDF Favorites
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\My Documents\My Business Objects Documents
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Documentum
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Desktop
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Contacts
[2011/02/22 08:43:03 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Citrix
[2011/02/22 08:43:02 | 000,000,000 | RH-D | C] – D:\Documents and Settings\ucyzdun\SendTo
[2011/02/22 08:43:02 | 000,000,000 | RH-D | C] – D:\Documents and Settings\ucyzdun\Recent
[2011/02/22 08:43:02 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Startup
[2011/02/22 08:43:02 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\Start Menu
[2011/02/22 08:43:02 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Administrative Tools
[2011/02/22 08:43:02 | 000,000,000 | R–D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Accessories
[2011/02/22 08:43:02 | 000,000,000 | -HSD | C] – D:\Documents and Settings\ucyzdun\UserData
[2011/02/22 08:43:02 | 000,000,000 | -H-D | C] – D:\Documents and Settings\ucyzdun\Templates
[2011/02/22 08:43:02 | 000,000,000 | -H-D | C] – D:\Documents and Settings\ucyzdun\PrintHood
[2011/02/22 08:43:02 | 000,000,000 | -H-D | C] – D:\Documents and Settings\ucyzdun\NetHood
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\WinRAR
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\System
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Real
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\PrintKey2000
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\pnlinks
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\PHP 5
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\pdfFactory
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\NorthgateArinso
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Internet
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Google Chrome
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Gmail Notifier
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\FreeFixer
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Express ClickYes
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\CopyTrans Suite
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\CCleaner
[2011/02/22 08:43:02 | 000,000,000 | —D | C] – D:\Documents and Settings\ucyzdun\Start Menu\Programs\7-Zip
[2011/02/21 16:49:33 | 000,000,000 | —D | C] – D:\Program Files\SystemRequirementsLab
[2011/02/21 16:45:43 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2011/02/21 15:51:06 | 000,000,000 | —D | C] – D:\Program Files\ATI Technologies
[2011/02/21 15:51:04 | 000,000,000 | —D | C] – D:\Program Files\ATI

========== Files - Modified Within 30 Days ==========

[2011/03/08 09:06:18 | 000,505,972 | —- | M] () – D:\WINDOWS\System32\perfh009.dat
[2011/03/08 09:06:18 | 000,089,244 | —- | M] () – D:\WINDOWS\System32\perfc009.dat
[2011/03/08 09:04:23 | 000,002,206 | —- | M] () – D:\WINDOWS\System32\wpa.dbl
[2011/03/08 09:04:06 | 000,000,882 | —- | M] () – D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/08 09:00:53 | 000,002,048 | –S- | M] () – D:\WINDOWS\bootstat.dat
[2011/03/08 08:58:04 | 000,009,684 | RHS- | M] () – D:\Documents and Settings\ucyzdun\ntuser.pol
[2011/03/08 08:51:41 | 000,000,182 | —- | M] () – D:\WINDOWS\hpbafd.ini
[2011/03/08 08:49:00 | 000,000,886 | —- | M] () – D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/08 05:00:00 | 000,000,530 | —- | M] () – D:\WINDOWS\tasks\Scheduled Daily Scan @ 5am.job
[2011/03/07 11:40:07 | 000,000,455 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\InfoView.url
[2011/03/07 11:36:15 | 000,000,327 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\Resource Link on the NET.url
[2011/03/07 10:57:25 | 000,098,098 | —- | M] () – D:\Documents and Settings\ucyzdun\My Documents\cc_20110307_105722.reg
[2011/03/07 10:11:58 | 000,263,824 | —- | M] () – D:\WINDOWS\System32\FNTCACHE.DAT
[2011/03/07 10:00:31 | 000,262,690 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\Arsenal World.url
[2011/03/07 09:15:42 | 000,580,608 | —- | M] (OldTimer Tools) – D:\Documents and Settings\ucyzdun\Desktop\OTL.exe
[2011/03/04 17:13:10 | 000,000,754 | —- | M] () – D:\WINDOWS\WORDPAD.INI
[2011/03/04 11:06:25 | 000,000,225 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\SELF SERVICE.url
[2011/03/01 12:40:16 | 000,000,682 | —- | M] () – D:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/03/01 12:23:13 | 000,001,620 | —- | M] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/01 12:23:13 | 000,001,602 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/02/28 16:45:34 | 000,000,251 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\KnowBase.url
[2011/02/28 14:36:49 | 000,000,815 | —- | M] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/02/28 14:29:25 | 000,001,988 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\HiJackThis.lnk
[2011/02/28 13:09:02 | 000,001,734 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/02/23 15:35:49 | 000,000,682 | —- | M] () – D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Printkey2000.lnk
[2011/02/23 13:37:24 | 000,000,784 | —- | M] () – D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/22 16:07:11 | 000,000,298 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\Payslips & P60's.url
[2011/02/22 13:00:59 | 000,000,568 | —- | M] () – D:\Documents and Settings\All Users\Desktop\ada.lnk
[2011/02/22 12:30:46 | 000,000,647 | —- | M] () – D:\Documents and Settings\All Users\Start Menu\Programs\Startup\MultiMon Taskbar.lnk
[2011/02/22 12:30:46 | 000,000,635 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\MultiMon Taskbar.lnk
[2011/02/22 12:09:39 | 000,001,139 | —- | M] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\BusinessObjects 6.1 (2).lnk
[2011/02/22 12:01:32 | 000,000,804 | —- | M] () – D:\WINDOWS\ODBC.INI
[2011/02/22 11:30:01 | 000,000,792 | —- | M] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2011/02/22 10:39:45 | 000,000,664 | —- | M] () – D:\WINDOWS\System32\d3d9caps.dat
[2011/02/22 08:48:09 | 000,000,130 | —- | M] () – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\fusioncache.dat
[2011/02/21 16:49:34 | 000,000,768 | —- | M] () – D:\WINDOWS\System32\d3d8caps.dat
[2011/02/21 15:16:22 | 000,131,824 | —- | M] (Sophos Plc) – D:\WINDOWS\System32\sdccoinstaller.dll
[2011/02/21 15:16:05 | 000,028,912 | —- | M] (Sophos Plc) – D:\WINDOWS\System32\SophosBootTasks.exe
[2011/02/18 10:21:37 | 000,001,374 | —- | M] () – D:\WINDOWS\imsins.BAK
[2011/02/17 14:07:41 | 000,011,810 | —- | M] () – D:\Documents and Settings\ucyzdun\My Documents\cc_20110217_140739.reg
[2011/02/17 09:19:20 | 000,020,910 | —- | M] () – D:\Documents and Settings\ucyzdun\My Documents\cc_20110217_091907.reg
[2011/02/16 11:45:11 | 000,000,205 | —- | M] () – D:\Documents and Settings\ucyzdun\Desktop\HR Helpdesk Webform.url
[2011/02/15 10:41:41 | 000,071,292 | —- | M] () – D:\Documents and Settings\ucyzdun\My Documents\Anders.bgl
[2011/02/14 14:50:21 | 000,452,651 | —- | M] () – D:\Documents and Settings\ucyzdun\My Documents\Mock 72.pdf
[2011/02/09 15:12:34 | 000,000,122 | —- | M] () – D:\Documents and Settings\ucyzdun\My Documents\schema.ini

========== Files Created - No Company Name ==========

[2011/03/07 10:57:23 | 000,098,098 | —- | C] () – D:\Documents and Settings\ucyzdun\My Documents\cc_20110307_105722.reg
[2011/03/04 17:13:10 | 000,000,754 | —- | C] () – D:\WINDOWS\WORDPAD.INI
[2011/03/01 12:40:16 | 000,000,682 | —- | C] () – D:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/03/01 12:23:13 | 000,001,620 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/01 12:23:13 | 000,001,602 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/02/28 14:36:49 | 000,000,815 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/02/28 14:29:25 | 000,001,988 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\HiJackThis.lnk
[2011/02/28 13:09:02 | 000,001,734 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2011/02/28 13:09:01 | 000,001,804 | —- | C] () – D:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2011/02/23 15:35:49 | 000,000,682 | —- | C] () – D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Printkey2000.lnk
[2011/02/23 15:32:12 | 000,000,738 | —- | C] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Outlook Express.lnk
[2011/02/23 13:37:24 | 000,000,784 | —- | C] () – D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/22 13:00:59 | 000,000,574 | —- | C] () – D:\Documents and Settings\All Users\Start Menu\Programs\ada.lnk
[2011/02/22 13:00:59 | 000,000,568 | —- | C] () – D:\Documents and Settings\All Users\Desktop\ada.lnk
[2011/02/22 12:30:46 | 000,000,647 | —- | C] () – D:\Documents and Settings\All Users\Start Menu\Programs\Startup\MultiMon Taskbar.lnk
[2011/02/22 12:30:46 | 000,000,635 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\MultiMon Taskbar.lnk
[2011/02/22 10:27:41 | 000,593,920 | —- | C] () – D:\WINDOWS\System32\ati2sgag.exe
[2011/02/22 08:48:36 | 000,000,182 | —- | C] () – D:\WINDOWS\hpbafd.ini
[2011/02/22 08:48:09 | 000,000,130 | —- | C] () – D:\Documents and Settings\ucyzdun\Local Settings\Application Data\fusioncache.dat
[2011/02/22 08:45:11 | 000,000,870 | —- | C] () – D:\Documents and Settings\ucyzdun\.recently-used.xbel
[2011/02/22 08:43:46 | 000,010,825 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Comma Separated Values (Windows).CAL
[2011/02/22 08:43:46 | 000,009,399 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Comma Separated Values (DOS).EML
[2011/02/22 08:43:38 | 000,001,139 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\BusinessObjects 6.1 (2).lnk
[2011/02/22 08:43:38 | 000,000,992 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Word.lnk
[2011/02/22 08:43:38 | 000,000,990 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Excel.lnk
[2011/02/22 08:43:38 | 000,000,792 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2011/02/22 08:43:38 | 000,000,079 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/02/22 08:43:31 | 000,009,355 | —- | C] () – D:\Documents and Settings\ucyzdun\Application Data\Microsoft Excel.EML
[2011/02/22 08:43:19 | 000,262,690 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\Arsenal World.url
[2011/02/22 08:43:19 | 000,245,283 | —- | C] () – D:\Documents and Settings\ucyzdun\Casual open.rep
[2011/02/22 08:43:19 | 000,029,930 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\Arsenal.url
[2011/02/22 08:43:19 | 000,000,751 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\KB Links.lnk
[2011/02/22 08:43:19 | 000,000,455 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\InfoView.url
[2011/02/22 08:43:19 | 000,000,327 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\Resource Link on the NET.url
[2011/02/22 08:43:19 | 000,000,298 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\Payslips & P60's.url
[2011/02/22 08:43:19 | 000,000,292 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\Birmingham UPAY.url
[2011/02/22 08:43:19 | 000,000,251 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\KnowBase.url
[2011/02/22 08:43:19 | 000,000,248 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\WTS Page.url
[2011/02/22 08:43:19 | 000,000,225 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\SELF SERVICE.url
[2011/02/22 08:43:19 | 000,000,205 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\HR Helpdesk Webform.url
[2011/02/22 08:43:19 | 000,000,140 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\MyView TEST.url
[2011/02/22 08:43:19 | 000,000,127 | —- | C] () – D:\Documents and Settings\ucyzdun\Desktop\Work Station Assessment Form.url
[2011/02/22 08:43:18 | 000,452,651 | —- | C] () – D:\Documents and Settings\ucyzdun\My Documents\Mock 72.pdf
[2011/02/22 08:43:18 | 000,071,292 | —- | C] () – D:\Documents and Settings\ucyzdun\My Documents\Anders.bgl
[2011/02/22 08:43:18 | 000,061,224 | —- | C] () – D:\Documents and Settings\ucyzdun\GoToAssistDownloadHelper.exe
[2011/02/22 08:43:18 | 000,020,910 | —- | C] () – D:\Documents and Settings\ucyzdun\My Documents\cc_20110217_091907.reg
[2011/02/22 08:43:18 | 000,011,810 | —- | C] () – D:\Documents and Settings\ucyzdun\My Documents\cc_20110217_140739.reg
[2011/02/22 08:43:18 | 000,001,273 | —- | C] () – D:\Documents and Settings\ucyzdun\jinitiator13129.trace
[2011/02/22 08:43:18 | 000,000,912 | —- | C] () – D:\Documents and Settings\ucyzdun\jinitiator1319.trace
[2011/02/22 08:43:18 | 000,000,910 | —- | C] () – D:\Documents and Settings\ucyzdun\jinitiator13122.trace
[2011/02/22 08:43:18 | 000,000,032 | R— | C] () – D:\Documents and Settings\ucyzdun\hash.dat
[2011/02/22 08:43:13 | 000,504,038 | —- | C] () – D:\Documents and Settings\ucyzdun\My Documents\sqlite3.dll
[2011/02/22 08:43:13 | 000,000,122 | —- | C] () – D:\Documents and Settings\ucyzdun\My Documents\schema.ini
[2011/02/22 08:43:11 | 000,002,331 | —- | C] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Windows Install Clean Up.lnk
[2011/02/22 08:43:11 | 000,001,599 | —- | C] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Remote Assistance.lnk
[2011/02/22 08:43:11 | 000,000,803 | —- | C] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Internet Explorer.lnk
[2011/02/22 08:43:11 | 000,000,788 | —- | C] () – D:\Documents and Settings\ucyzdun\Start Menu\Programs\Windows Media Player.lnk
[2011/02/22 08:43:02 | 000,009,684 | RHS- | C] () – D:\Documents and Settings\ucyzdun\ntuser.pol
[2011/02/21 16:49:34 | 000,000,768 | —- | C] () – D:\WINDOWS\System32\d3d8caps.dat
[2011/01/05 12:14:28 | 000,000,698 | —- | C] () – D:\WINDOWS\System32\DWRCCMDError.ini
[2010/11/25 10:31:37 | 000,000,038 | —- | C] () – D:\WINDOWS\XOBJECTS.INI
[2010/11/23 15:26:21 | 000,236,588 | —- | C] () – D:\WINDOWS\System32\nvdrsdb0.bin
[2010/11/23 15:26:20 | 000,236,588 | —- | C] () – D:\WINDOWS\System32\nvdrsdb1.bin
[2010/11/23 15:26:20 | 000,000,001 | —- | C] () – D:\WINDOWS\System32\nvdrssel.bin
[2010/11/23 15:25:56 | 002,195,350 | —- | C] () – D:\WINDOWS\System32\nvdata.bin
[2009/03/24 15:04:46 | 002,026,604 | —- | C] () – D:\WINDOWS\System32\igkrng500.bin
[2009/03/24 15:04:45 | 000,442,964 | —- | C] () – D:\WINDOWS\System32\igcompkrng500.bin
[2009/03/24 15:04:45 | 000,147,456 | —- | C] () – D:\WINDOWS\System32\igfxCoIn_v4977.dll
[2009/02/18 12:20:36 | 000,000,664 | —- | C] () – D:\WINDOWS\System32\d3d9caps.dat
[2009/02/18 12:01:02 | 000,000,168 | —- | C] () – D:\WINDOWS\wininit.ini
[2009/01/21 16:22:54 | 000,000,061 | —- | C] () – D:\WINDOWS\smscfg.ini
[2009/01/21 13:08:30 | 000,000,000 | —- | C] () – D:\WINDOWS\nsreg.dat
[2009/01/21 11:15:47 | 000,036,962 | —- | C] () – D:\WINDOWS\System32\ActPanel.dll
[2009/01/21 10:59:25 | 000,000,804 | —- | C] () – D:\WINDOWS\ODBC.INI
[2009/01/21 10:24:07 | 000,000,000 | —- | C] () – D:\WINDOWS\ativpsrm.bin
[2009/01/21 10:18:27 | 000,876,544 | —- | C] () – D:\WINDOWS\System32\TEACico2.dll
[2009/01/20 16:59:24 | 000,002,048 | –S- | C] () – D:\WINDOWS\bootstat.dat
[2009/01/20 16:56:52 | 000,021,640 | —- | C] () – D:\WINDOWS\System32\emptyregdb.dat
[2009/01/20 16:53:49 | 000,004,332 | —- | C] () – D:\WINDOWS\ODBCINST.INI
[2009/01/20 16:53:07 | 000,263,824 | —- | C] () – D:\WINDOWS\System32\FNTCACHE.DAT
[2008/12/01 20:11:21 | 003,107,788 | —- | C] () – D:\WINDOWS\System32\ativvaxx.dat
[2008/12/01 20:11:21 | 003,107,788 | —- | C] () – D:\WINDOWS\System32\ativva5x.dat
[2008/12/01 20:11:21 | 000,887,724 | —- | C] () – D:\WINDOWS\System32\ativva6x.dat
[2008/10/30 14:45:42 | 000,180,720 | —- | C] () – D:\WINDOWS\System32\atiicdxx.dat
[2008/04/14 04:55:28 | 000,001,804 | —- | C] () – D:\WINDOWS\System32\Dcache.bin
[2008/02/04 18:23:10 | 000,693,792 | —- | C] () – D:\WINDOWS\System32\OGACheckControl.DLL
[2007/05/17 16:54:00 | 000,113,664 | —- | C] () – D:\WINDOWS\System32\See32.dll
[2006/12/31 06:57:08 | 000,004,569 | —- | C] () – D:\WINDOWS\System32\secupd.dat
[2001/08/23 11:00:00 | 013,107,200 | —- | C] () – D:\WINDOWS\System32\oembios.bin
[2001/08/23 11:00:00 | 000,673,088 | —- | C] () – D:\WINDOWS\System32\mlang.dat
[2001/08/23 11:00:00 | 000,505,972 | —- | C] () – D:\WINDOWS\System32\perfh009.dat
[2001/08/23 11:00:00 | 000,272,128 | —- | C] () – D:\WINDOWS\System32\perfi009.dat
[2001/08/23 11:00:00 | 000,218,003 | —- | C] () – D:\WINDOWS\System32\dssec.dat
[2001/08/23 11:00:00 | 000,089,244 | —- | C] () – D:\WINDOWS\System32\perfc009.dat
[2001/08/23 11:00:00 | 000,046,258 | —- | C] () – D:\WINDOWS\System32\mib.bin
[2001/08/23 11:00:00 | 000,028,626 | —- | C] () – D:\WINDOWS\System32\perfd009.dat
[2001/08/23 11:00:00 | 000,004,463 | —- | C] () – D:\WINDOWS\System32\oembios.dat
[2001/08/23 11:00:00 | 000,000,741 | —- | C] () – D:\WINDOWS\System32\noise.dat

========== Alternate Data Streams ==========

@Alternate Data Stream - 143 bytes -> D:\Documents and Settings\ucyzdun\Application Data\Microsoft Excel.EML:OECustomProperty
@Alternate Data Stream - 143 bytes -> D:\Documents and Settings\ucyzdun\Application Data\Comma Separated Values (DOS).EML:OECustomProperty

< End of report >
The Malware scan was clear. Here's the log Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5987 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 08/03/2011 09:50:46 mbam-log-2011-03-08 (09-50-46).txt Scan type: Quick scan Objects scanned: 306837 Time elapsed: 13 minute(s), 38 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
and here's the rootkit report. RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows XP Version 5.1.2600 (Service Pack 3) Number of processors #2 ============================================== >SSDT State ============================================== ntkrnlpa.exe–>NtCreateKey, Type: Address change 0x806240F0–>A14A83BA [D:\WINDOWS\system32\DRIVERS\savonaccesscontrol.sys] ntkrnlpa.exe–>NtCreateThread, Type: Address change 0x805D1018–>A14A88A4 [D:\WINDOWS\system32\DRIVERS\savonaccesscontrol.sys] ntkrnlpa.exe–>NtDeleteKey, Type: Address change 0x8062458C–>A14A8510 [D:\WINDOWS\system32\DRIVERS\savonaccesscontrol.sys] ntkrnlpa.exe–>NtSetSystemInformation, Type: Address change 0x8060FD06–>A14A8BCE [D:\WINDOWS\system32\DRIVERS\savonaccesscontrol.sys] ntkrnlpa.exe–>NtSetValueKey, Type: Address change 0x80622662–>A14A8576 [D:\WINDOWS\system32\DRIVERS\savonaccesscontrol.sys] ============================================== >Shadow ============================================== ============================================== >Processes ============================================== 0x8A8A19C8 [4] System 0x8A4DA758 [236] D:\WINDOWS\dwrcs\DWRCS.EXE (DameWare Development LLC, DameWare Mini Remote Client Agent) 0x8A7D3328 [248] D:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe (Sophos Plc, Sophos Agent) 0x89E7E020 [432] D:\WINDOWS\dwrcs\DWRCST.EXE (DameWare Development, DameWare Mini Remote Control User Interface) 0x8A5275F8 [452] D:\WINDOWS\system32\svchost.exe (Microsoft Corporation, Generic Host Process for Win32 Services) 0x8A61E650 [512] D:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Plc, Sophos Administrator Service) 0x89FF85E8 [616] D:\Program Files\Sophos\Remote Management System\RouterNT.exe (Sophos Plc, Sophos Message Router) 0x8A590A88 [648] D:\WINDOWS\system32\smss.exe (Microsoft Corporation, Windows NT Session Manager) 0x8A5DD950 [704] D:\WINDOWS\system32\csrss.exe (Microsoft Corporation, Client Server Runtime Process) 0x8A5D95D0 [736] D:\WINDOWS\system32\winlogon.exe (Microsoft Corporation, Windows NT Logon Application) 0x8A661020 [780] D:\WINDOWS\system32\services.exe (Microsoft Corporation, Services and Controller app) 0x8A5ED6F0 [792] D:\WINDOWS\system32\lsass.exe (Microsoft Corporation, LSA Shell (Export Version)) 0x89957020 [988] D:\Documents and Settings\ucyzdun\Local Settings\Temporary Internet Files\Content.IE5\0RQXLB2M\RKUnhookerLE[1].EXE (UG North, RKULE, SR2 Normandy) 0x8A4D63A8 [1004] D:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc., ATI External Event Utility EXE Module) 0x8A559818 [1028] D:\WINDOWS\system32\svchost.exe (Microsoft Corporation, Generic Host Process for Win32 Services) 0x8A550970 [1052] D:\Program Files\Sophos\AutoUpdate\ALsvc.exe (Sophos Plc, Sophos AutoUpdate Service.) 0x8A665DA0 [1100] D:\WINDOWS\system32\svchost.exe (Microsoft Corporation, Generic Host Process for Win32 Services) 0x8A552390 [1188] D:\WINDOWS\system32\svchost.exe (Microsoft Corporation, Generic Host Process for Win32 Services) 0x8A568BE0 [1252] D:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc., ATI External Event Utility EXE Module) 0x8A525B28 [1284] D:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Plc, Performs virus scanning and disinfection functions) 0x89E01960 [1292] D:\Program Files\PrintKey2000\Printkey2000.exe (Fred's Software, -) 0x8A4D8960 [1352] D:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc., Java™ Quick Starter Service) 0x89F91420 [1636] D:\WINDOWS\system32\svchost.exe (Microsoft Corporation, Generic Host Process for Win32 Services) 0x8A4845B8 [1644] D:\WINDOWS\system32\svchost.exe (Microsoft Corporation, Generic Host Process for Win32 Services) 0x8A4C2260 [1672] D:\Program Files\Intel\AMT\LMS.exe (Intel Corporation, Local Manageability Service) 0x8A5636A8 [1700] D:\WINDOWS\system32\svchost.exe (Microsoft Corporation, Generic Host Process for Win32 Services) 0x8A52F420 [1788] D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation, Machine Debug Manager) 0x8A4D2DA0 [1828] D:\WINDOWS\system32\spoolsv.exe (Microsoft Corporation, Spooler SubSystem App) 0x8A4DF9E0 [1912] D:\WINDOWS\system32\svchost.exe (Microsoft Corporation, Generic Host Process for Win32 Services) 0x8A4C2A28 [1968] D:\WINDOWS\system32\svchost.exe (Microsoft Corporation, Generic Host Process for Win32 Services) 0x8A4986B8 [2004] D:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe (Altiris, Inc., Altiris Agent) 0x89F8EDA0 [2076] D:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Sophos Plc, Sophos Web Intelligence) 0x89F8CDA0 [2180] D:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe (Intel Corporation, User Notification Service) 0x89E835A8 [2260] D:\Program Files\Sophos\AutoUpdate\ALMon.exe (Sophos Plc, Sophos Endpoint Security and Control) 0x89F67520 [2328] D:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation, RAID Monitor) 0x898A9DA0 [2448] D:\Program Files\Documentum\AppConnector\EventServer.exe (Documentum, a division of EMC Corporation, Documentum Application Connector Event Server) 0x89EEC3B8 [2632] D:\WINDOWS\explorer.exe (Microsoft Corporation, Windows Explorer) 0x8A531850 [2728] D:\WINDOWS\system32\alg.exe (Microsoft Corporation, Application Layer Gateway Service) 0x89CA0470 [2768] D:\PROGRA~1\BUSINE~2\BUSINE~1.0\WIN32_~1\busobj.exe (Business Objects, Business Objects) 0x8985A7E0 [2952] D:\WINDOWS\system32\notepad.exe (Microsoft Corporation, Notepad) 0x89E303B0 [2976] D:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation, CTF Loader) 0x89E177D0 [2980] D:\Program Files\MMTaskbar\MultiMon.exe (-, MultiMon MFC Application) 0x89EDD9F0 [3156] D:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation, Internet Explorer) 0x89EEF328 [3512] D:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation, Event Monitor User Notification Tool) 0x89EAF600 [3520] D:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe (Intel Corporation, Intel® Management and Security) 0x89E5D3B8 [3524] D:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc., SMax4PNP) 0x89E9DAA8 [3824] D:\Program Files\Documentum\AppConnector\Documentum.AppConnector.CredentialManager.exe (Documentum, a division of EMC Corporation, Documentum.AppConnector.CredentialManager) 0x89E3E9E0 [4008] D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE (Microsoft Corporation, Microsoft Office Outlook) 0x89EA9DA0 [4068] D:\Program Files\Google\Gmail Notifier\gnotify.exe (Google Inc., Gmail Notifier) ============================================== >Drivers ============================================== 0xAD6EA000 D:\WINDOWS\system32\DRIVERS\ati2mtag.sys 5455872 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Miniport Driver) 0xBD1AD000 D:\WINDOWS\System32\ati3duag.dll 4120576 bytes (ATI Technologies Inc. , ati3duag.dll) 0xBD59B000 D:\WINDOWS\System32\ativvaxx.dll 2498560 bytes (ATI Technologies Inc. , Radeon Video Acceleration Universal Driver) 0x804D7000 D:\WINDOWS\system32\ntkrnlpa.exe 2154496 bytes (Microsoft Corporation, NT Kernel & System) 0x804D7000 PnpManager 2154496 bytes 0x804D7000 RAW 2154496 bytes 0x804D7000 WMIxWDM 2154496 bytes 0xBF800000 Win32k 1855488 bytes 0xBF800000 D:\WINDOWS\System32\win32k.sys 1855488 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0xB7E31000 iaStor.sys 892928 bytes (Intel Corporation, Intel Matrix Storage Manager driver - ia32) 0xBD063000 D:\WINDOWS\System32\ati2cqag.dll 577536 bytes (ATI Technologies Inc., Central Memory Manager / Queue Server Module) 0xB7D5B000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver) 0xBD0F0000 D:\WINDOWS\System32\atikvmag.dll 471040 bytes (ATI Technologies Inc., Virtual Command And Memory Manager) 0xA12D6000 D:\WINDOWS\system32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0xAD578000 D:\WINDOWS\system32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver) 0xA13E1000 D:\WINDOWS\system32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver) 0x9EB52000 D:\WINDOWS\system32\DRIVERS\srv.sys 360448 bytes (Microsoft Corporation, Server driver) 0xA14DF000 D:\WINDOWS\system32\drivers\ADIHdAud.sys 356352 bytes (Analog Devices, Inc., High Definition Audio Function Driver) 0xBD012000 D:\WINDOWS\System32\ati2dvag.dll 331776 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Display Driver) 0xBD163000 D:\WINDOWS\System32\atiok3x2.dll 303104 bytes (ATI Technologies Inc., Ring 0 x2 component) 0xBD7FD000 D:\WINDOWS\System32\ATMFD.DLL 290816 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver) 0x9E1F3000 D:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack) 0xAD5F9000 D:\WINDOWS\system32\DRIVERS\rdpdr.sys 196608 bytes (Microsoft Corporation, Microsoft RDP Device redirector) 0xB7F79000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT) 0xB7D2E000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver) 0x9EE02000 D:\WINDOWS\system32\DRIVERS\mrxdav.sys 180224 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0x9DE08000 D:\WINDOWS\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer) 0xA1346000 D:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0xAD665000 D:\WINDOWS\system32\DRIVERS\HDAudBus.sys 163840 bytes (Windows ® Server 2003 DDK provider, High Definition Audio Bus Driver v1.0a) 0xA13B9000 D:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver) 0xB7F23000 dmio.sys 155648 bytes (Microsoft Corp., Veritas Software, NT Disk Manager I/O Driver) 0xA1393000 D:\WINDOWS\system32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator) 0xA1495000 D:\WINDOWS\system32\DRIVERS\savonaccesscontrol.sys 155648 bytes (Sophos Plc, SAV On-access and HIPS for Windows XP (x86)) 0xAD6B1000 D:\WINDOWS\system32\DRIVERS\e1k5132.sys 151552 bytes (Intel Corporation, Intel® Gigabit Adapter NDIS 5.x driver) 0xA14BB000 D:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0xAD68D000 D:\WINDOWS\system32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0xAD5D6000 D:\WINDOWS\system32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library) 0x9E567000 D:\WINDOWS\System32\Drivers\RDPWD.SYS 143360 bytes (Microsoft Corporation, RDP Terminal Stack Driver (US/Canada Only, Not for Export)) 0xA1371000 D:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0x806E5000 ACPI_HAL 134400 bytes 0x806E5000 D:\WINDOWS\system32\hal.dll 134400 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0xB7E11000 fltMgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0xB7F49000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver) 0xB7D14000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0xB7F0B000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver) 0xB7DE8000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0xAD63A000 D:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0x9E552000 D:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper) 0xAD651000 D:\WINDOWS\system32\DRIVERS\parport.sys 81920 bytes (Microsoft Corporation, Parallel Port Driver) 0xAD6D6000 D:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver) 0xA143A000 D:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver) 0xBD000000 D:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver) 0xB7DFF000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver) 0xB7F68000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0xAD629000 D:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler) 0xAEEBB000 D:\WINDOWS\system32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver) 0xB8148000 D:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0xAEECB000 D:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter) 0xB8248000 D:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB) 0xB80E8000 D:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll) 0xB82D8000 D:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0xB80C8000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0xB82F8000 D:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0xB46E0000 D:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, FIPS Crypto Driver) 0xB80B8000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager) 0xB82E8000 D:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0xB8108000 sfaudio.sys 45056 bytes (Sonic Focus, Inc, Sonic Focus DSP driver for ADI) 0xAEE7B000 D:\WINDOWS\system32\DRIVERS\dwvkbd.sys 40960 bytes (DameWare, DameWare Virtual Keyboard Driver) 0xAEE8B000 D:\WINDOWS\system32\DRIVERS\HECI.sys 40960 bytes (Intel Corporation, Intel® Management Engine Interface) 0xB80A8000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bus Driver) 0xB8138000 D:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy) 0xAEE6B000 D:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver) 0xB80D8000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver) 0xB46B0000 D:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS 36864 bytes (Microsoft Corporation, Hid Class Library) 0xAEEAB000 D:\WINDOWS\system32\DRIVERS\intelppm.sys 36864 bytes (Microsoft Corporation, Processor Device Driver) 0xB8308000 D:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier) 0xB8188000 D:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver) 0x9E324000 D:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0xB80F8000 PxHelp20.sys 36864 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP) 0xB8198000 D:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0xB49D3000 D:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver) 0xB84A0000 D:\WINDOWS\system32\DRIVERS\usbehci.sys 32768 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0xB8480000 D:\WINDOWS\system32\DRIVERS\fdc.sys 28672 bytes (Microsoft Corporation, Floppy Disk Controller Driver) 0xB49C3000 D:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library) 0xB8328000 D:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0xB84B0000 D:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver) 0xB8380000 D:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver) 0xB8398000 D:\WINDOWS\system32\DRIVERS\savonaccessfilter.sys 24576 bytes (Sophos Plc, SAV On-access and HIPS for Windows XP (x86)) 0xB499B000 D:\WINDOWS\System32\Drivers\TDTCP.SYS 24576 bytes (Microsoft Corporation, TCP Transport Driver) 0xB8498000 D:\WINDOWS\system32\DRIVERS\usbuhci.sys 24576 bytes (Microsoft Corporation, UHCI USB Miniport Driver) 0xB8488000 D:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0xB8390000 D:\WINDOWS\system32\DRIVERS\flpydisk.sys 20480 bytes (Microsoft Corporation, Floppy Driver) 0xB8490000 D:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver) 0xB8330000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager) 0xB498B000 D:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library) 0xB8408000 D:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver) 0xB8340000 D:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper) 0xB83E0000 D:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver) 0xB8590000 D:\WINDOWS\system32\DRIVERS\kbdhid.sys 16384 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0xB7CD3000 D:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver) 0x9EEF6000 D:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver) 0xB859C000 D:\WINDOWS\system32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator) 0xB84B8000 D:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver) 0xB2EE7000 D:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver) 0xB2ED7000 D:\WINDOWS\system32\DRIVERS\hidusb.sys 12288 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices) 0xB8594000 D:\WINDOWS\system32\DRIVERS\mouhid.sys 12288 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0xB85A0000 D:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0xB856C000 D:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0xB8558000 D:\WINDOWS\system32\DRIVERS\wmiacpi.sys 12288 bytes (Microsoft Corporation, Windows Management Interface for ACPI) 0xB862E000 D:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver) 0xB85AC000 dmload.sys 8192 bytes (Microsoft Corp., Veritas Software., NT Disk Manager Startup Driver) 0xB860C000 D:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver) 0xB85A8000 D:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0xB860E000 D:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator) 0xB8610000 D:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport) 0xB8624000 D:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0xB8628000 D:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) 0xB85AA000 D:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0xB87D5000 D:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver) 0xB8696000 D:\WINDOWS\system32\DRIVERS\DamewareMini.sys 4096 bytes (DameWare Development, LLC, DameWare Development Mirror Miniport Driver) 0xB8774000 D:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk) 0xB86F6000 D:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver) 0xB8670000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver) ============================================== >Stealth ============================================== 0x03630000 Hidden Image–>PrivacyIconClient.resources.dll [ EPROCESS 0x89EAF600 ] PID: 3520, 36864 bytes ============================================== >Files ============================================== ============================================== >Hooks ============================================== ntkrnlpa.exe+0x0002D85C, Type: Inline - RelativeJump 0x8050485C–>805047E7 [ntkrnlpa.exe] ntkrnlpa.exe+0x0006ECEE, Type: Inline - RelativeJump 0x80545CEE–>80545CF5 [ntkrnlpa.exe] [1028]svchost.exe–>kernel32.dll–>CreateFileA, Type: Inline - RelativeJump 0x7C801A28–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>kernel32.dll–>CreateProcessA, Type: Inline - RelativeJump 0x7C80236B–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>kernel32.dll–>CreateProcessInternalA, Type: Inline - RelativeJump 0x7C81D54E–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>kernel32.dll–>ExitProcess, Type: Inline - RelativeJump 0x7C81CB12–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - RelativeJump 0x7C80C0F8–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FD [unknown_code_page] [1028]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FE [unknown_code_page] [1028]svchost.exe–>kernel32.dll–>FreeLibrary, Type: Inline - RelativeJump 0x7C80AC7E–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>kernel32.dll–>GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>kernel32.dll–>GetThreadContext, Type: Inline - RelativeJump 0x7C83973D–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - RelativeJump 0x7C80FDCD–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD2 [unknown_code_page] [1028]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD3 [unknown_code_page] [1028]svchost.exe–>kernel32.dll–>LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>kernel32.dll–>LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page] [1028]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page] [1028]svchost.exe–>kernel32.dll–>LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>kernel32.dll–>ResumeThread, Type: Inline - RelativeJump 0x7C832927–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>kernel32.dll–>SetThreadContext, Type: Inline - RelativeJump 0x7C863C09–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>kernel32.dll–>VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>kernel32.dll–>VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A61–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>kernel32.dll–>WinExec, Type: Inline - RelativeJump 0x7C86250D–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - RelativeJump 0x7C810E27–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2C [unknown_code_page] [1028]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2D [unknown_code_page] [1028]svchost.exe–>kernel32.dll–>WriteFileEx, Type: Inline - RelativeJump 0x7C85D6D9–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>kernel32.dll–>WriteProcessMemory, Type: Inline - RelativeJump 0x7C802213–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x7C90E47C–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E481 [unknown_code_page] [1028]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E482 [unknown_code_page] [1028]svchost.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>ws2_32.dll–>accept, Type: Inline - RelativeJump 0x71AC1040–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>ws2_32.dll–>bind, Type: Inline - RelativeJump 0x71AB4480–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>ws2_32.dll–>connect, Type: Inline - RelativeJump 0x71AB4A07–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>ws2_32.dll–>getpeername, Type: Inline - RelativeJump 0x71AC0B68–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>ws2_32.dll–>listen, Type: Inline - RelativeJump 0x71AB8CD3–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>ws2_32.dll–>WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - RelativeJump 0x71AB6A55–>00000000 [sophos_detoured.dll] [1028]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5A [unknown_code_page] [1028]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5B [unknown_code_page] [1100]svchost.exe–>kernel32.dll–>CreateFileA, Type: Inline - RelativeJump 0x7C801A28–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>kernel32.dll–>CreateProcessA, Type: Inline - RelativeJump 0x7C80236B–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>kernel32.dll–>CreateProcessInternalA, Type: Inline - RelativeJump 0x7C81D54E–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>kernel32.dll–>ExitProcess, Type: Inline - RelativeJump 0x7C81CB12–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - RelativeJump 0x7C80C0F8–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FD [unknown_code_page] [1100]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FE [unknown_code_page] [1100]svchost.exe–>kernel32.dll–>FreeLibrary, Type: Inline - RelativeJump 0x7C80AC7E–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>kernel32.dll–>GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>kernel32.dll–>GetThreadContext, Type: Inline - RelativeJump 0x7C83973D–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - RelativeJump 0x7C80FDCD–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD2 [unknown_code_page] [1100]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD3 [unknown_code_page] [1100]svchost.exe–>kernel32.dll–>LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>kernel32.dll–>LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page] [1100]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page] [1100]svchost.exe–>kernel32.dll–>LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>kernel32.dll–>ResumeThread, Type: Inline - RelativeJump 0x7C832927–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>kernel32.dll–>SetThreadContext, Type: Inline - RelativeJump 0x7C863C09–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>kernel32.dll–>VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>kernel32.dll–>VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A61–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>kernel32.dll–>WinExec, Type: Inline - RelativeJump 0x7C86250D–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - RelativeJump 0x7C810E27–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2C [unknown_code_page] [1100]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2D [unknown_code_page] [1100]svchost.exe–>kernel32.dll–>WriteFileEx, Type: Inline - RelativeJump 0x7C85D6D9–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>kernel32.dll–>WriteProcessMemory, Type: Inline - RelativeJump 0x7C802213–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x7C90E47C–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E481 [unknown_code_page] [1100]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E482 [unknown_code_page] [1100]svchost.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>ws2_32.dll–>accept, Type: Inline - RelativeJump 0x71AC1040–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>ws2_32.dll–>bind, Type: Inline - RelativeJump 0x71AB4480–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>ws2_32.dll–>connect, Type: Inline - RelativeJump 0x71AB4A07–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>ws2_32.dll–>getpeername, Type: Inline - RelativeJump 0x71AC0B68–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>ws2_32.dll–>listen, Type: Inline - RelativeJump 0x71AB8CD3–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>ws2_32.dll–>WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - RelativeJump 0x71AB6A55–>00000000 [sophos_detoured.dll] [1100]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5A [unknown_code_page] [1100]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5B [unknown_code_page] [1188]svchost.exe–>kernel32.dll–>CreateFileA, Type: Inline - RelativeJump 0x7C801A28–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>kernel32.dll–>CreateProcessA, Type: Inline - RelativeJump 0x7C80236B–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>kernel32.dll–>CreateProcessInternalA, Type: Inline - RelativeJump 0x7C81D54E–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>kernel32.dll–>ExitProcess, Type: Inline - RelativeJump 0x7C81CB12–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - RelativeJump 0x7C80C0F8–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FD [unknown_code_page] [1188]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FE [unknown_code_page] [1188]svchost.exe–>kernel32.dll–>FreeLibrary, Type: Inline - RelativeJump 0x7C80AC7E–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>kernel32.dll–>GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>kernel32.dll–>GetThreadContext, Type: Inline - RelativeJump 0x7C83973D–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - RelativeJump 0x7C80FDCD–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD2 [unknown_code_page] [1188]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD3 [unknown_code_page] [1188]svchost.exe–>kernel32.dll–>LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>kernel32.dll–>LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page] [1188]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page] [1188]svchost.exe–>kernel32.dll–>LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>kernel32.dll–>ResumeThread, Type: Inline - RelativeJump 0x7C832927–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>kernel32.dll–>SetThreadContext, Type: Inline - RelativeJump 0x7C863C09–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>kernel32.dll–>VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>kernel32.dll–>VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A61–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>kernel32.dll–>WinExec, Type: Inline - RelativeJump 0x7C86250D–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - RelativeJump 0x7C810E27–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2C [unknown_code_page] [1188]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2D [unknown_code_page] [1188]svchost.exe–>kernel32.dll–>WriteFileEx, Type: Inline - RelativeJump 0x7C85D6D9–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>kernel32.dll–>WriteProcessMemory, Type: Inline - RelativeJump 0x7C802213–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x7C90E47C–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E481 [unknown_code_page] [1188]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E482 [unknown_code_page] [1188]svchost.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>wininet.dll–>InternetOpenA, Type: Inline - RelativeJump 0x3D953081–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>wininet.dll–>InternetOpenUrlA, Type: Inline - RelativeJump 0x3D956F5A–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>wininet.dll–>InternetQueryDataAvailable, Type: Inline - RelativeJump 0x3D951615–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>wininet.dll–>InternetReadFile, Type: Inline - RelativeJump 0x3D9513D4–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>ws2_32.dll–>accept, Type: Inline - RelativeJump 0x71AC1040–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>ws2_32.dll–>bind, Type: Inline - RelativeJump 0x71AB4480–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>ws2_32.dll–>connect, Type: Inline - RelativeJump 0x71AB4A07–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>ws2_32.dll–>getpeername, Type: Inline - RelativeJump 0x71AC0B68–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>ws2_32.dll–>listen, Type: Inline - RelativeJump 0x71AB8CD3–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>ws2_32.dll–>WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - RelativeJump 0x71AB6A55–>00000000 [sophos_detoured.dll] [1188]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5A [unknown_code_page] [1188]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5B [unknown_code_page] [1636]svchost.exe–>kernel32.dll–>CreateFileA, Type: Inline - RelativeJump 0x7C801A28–>00000000 [sophos_detoured.dll] [1636]svchost.exe–>kernel32.dll–>CreateProcessA, Type: Inline - RelativeJump 0x7C80236B–>00000000 [sophos_detoured.dll] [1636]svchost.exe–>kernel32.dll–>CreateProcessInternalA, Type: Inline - RelativeJump 0x7C81D54E–>00000000 [sophos_detoured.dll] [1636]svchost.exe–>kernel32.dll–>ExitProcess, Type: Inline - RelativeJump 0x7C81CB12–>00000000 [sophos_detoured.dll] [1636]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - RelativeJump 0x7C80C0F8–>00000000 [sophos_detoured.dll] [1636]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FD [unknown_code_page] [1636]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FE [unknown_code_page] [1636]svchost.exe–>kernel32.dll–>FreeLibrary, Type: Inline - RelativeJump 0x7C80AC7E–>00000000 [sophos_detoured.dll] [1636]svchost.exe–>kernel32.dll–>GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40–>00000000 [sophos_detoured.dll] [1636]svchost.exe–>kernel32.dll–>GetThreadContext, Type: Inline - RelativeJump 0x7C83973D–>00000000 [sophos_detoured.dll] [1636]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - RelativeJump 0x7C80FDCD–>00000000 [sophos_detoured.dll] [1636]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD2 [unknown_code_page] [1636]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD3 [unknown_code_page] [1636]svchost.exe–>kernel32.dll–>LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B–>00000000 [sophos_detoured.dll] [1636]svchost.exe–>kernel32.dll–>LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53–>00000000 [sophos_detoured.dll] [1636]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5–>00000000 [sophos_detoured.dll] [1636]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page] [1636]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page] [1636]svchost.exe–>kernel32.dll–>LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB–>00000000 [sophos_detoured.dll] [1636]svchost.exe–>kernel32.dll–>ResumeThread, Type: Inline - RelativeJump 0x7C832927–>00000000 [sophos_detoured.dll] [1636]svchost.exe–>kernel32.dll–>SetThreadContext, Type: Inline - RelativeJump 0x7C863C09–>00000000 [sophos_detoured.dll] [1636]svchost.exe–>kernel32.dll–>VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4–>00000000 [sophos_detoured.dll] [1636]svchost.exe–>kernel32.dll–>VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A61–>00000000 [sophos_detoured.dll] [1636]svchost.exe–>kernel32.dll–>WinExec, Type: Inline - RelativeJump 0x7C86250D–>00000000 [sophos_detoured.dll] [1636]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - RelativeJump 0x7C810E27–>00000000 [sophos_detoured.dll] [1636]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2C [unknown_code_page] [1636]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2D [unknown_code_page] [1636]svchost.exe–>kernel32.dll–>WriteFileEx, Type: Inline - RelativeJump 0x7C85D6D9–>00000000 [sophos_detoured.dll] [1636]svchost.exe–>kernel32.dll–>WriteProcessMemory, Type: Inline - RelativeJump 0x7C802213–>00000000 [sophos_detoured.dll] [1636]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x7C90E47C–>00000000 [sophos_detoured.dll] [1636]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E481 [unknown_code_page] [1636]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E482 [unknown_code_page] [1636]svchost.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>kernel32.dll–>CreateFileA, Type: Inline - RelativeJump 0x7C801A28–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>kernel32.dll–>CreateProcessA, Type: Inline - RelativeJump 0x7C80236B–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>kernel32.dll–>CreateProcessInternalA, Type: Inline - RelativeJump 0x7C81D54E–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>kernel32.dll–>ExitProcess, Type: Inline - RelativeJump 0x7C81CB12–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - RelativeJump 0x7C80C0F8–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FD [unknown_code_page] [1644]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FE [unknown_code_page] [1644]svchost.exe–>kernel32.dll–>FreeLibrary, Type: Inline - RelativeJump 0x7C80AC7E–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>kernel32.dll–>GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>kernel32.dll–>GetThreadContext, Type: Inline - RelativeJump 0x7C83973D–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - RelativeJump 0x7C80FDCD–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD2 [unknown_code_page] [1644]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD3 [unknown_code_page] [1644]svchost.exe–>kernel32.dll–>LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>kernel32.dll–>LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page] [1644]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page] [1644]svchost.exe–>kernel32.dll–>LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>kernel32.dll–>ResumeThread, Type: Inline - RelativeJump 0x7C832927–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>kernel32.dll–>SetThreadContext, Type: Inline - RelativeJump 0x7C863C09–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>kernel32.dll–>VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>kernel32.dll–>VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A61–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>kernel32.dll–>WinExec, Type: Inline - RelativeJump 0x7C86250D–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - RelativeJump 0x7C810E27–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2C [unknown_code_page] [1644]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2D [unknown_code_page] [1644]svchost.exe–>kernel32.dll–>WriteFileEx, Type: Inline - RelativeJump 0x7C85D6D9–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>kernel32.dll–>WriteProcessMemory, Type: Inline - RelativeJump 0x7C802213–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x7C90E47C–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E481 [unknown_code_page] [1644]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E482 [unknown_code_page] [1644]svchost.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>ws2_32.dll–>accept, Type: Inline - RelativeJump 0x71AC1040–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>ws2_32.dll–>bind, Type: Inline - RelativeJump 0x71AB4480–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>ws2_32.dll–>connect, Type: Inline - RelativeJump 0x71AB4A07–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>ws2_32.dll–>getpeername, Type: Inline - RelativeJump 0x71AC0B68–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>ws2_32.dll–>listen, Type: Inline - RelativeJump 0x71AB8CD3–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>ws2_32.dll–>WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - RelativeJump 0x71AB6A55–>00000000 [sophos_detoured.dll] [1644]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5A [unknown_code_page] [1644]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5B [unknown_code_page] [1700]svchost.exe–>kernel32.dll–>CreateFileA, Type: Inline - RelativeJump 0x7C801A28–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>kernel32.dll–>CreateProcessA, Type: Inline - RelativeJump 0x7C80236B–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>kernel32.dll–>CreateProcessInternalA, Type: Inline - RelativeJump 0x7C81D54E–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>kernel32.dll–>ExitProcess, Type: Inline - RelativeJump 0x7C81CB12–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - RelativeJump 0x7C80C0F8–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FD [unknown_code_page] [1700]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FE [unknown_code_page] [1700]svchost.exe–>kernel32.dll–>FreeLibrary, Type: Inline - RelativeJump 0x7C80AC7E–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>kernel32.dll–>GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>kernel32.dll–>GetThreadContext, Type: Inline - RelativeJump 0x7C83973D–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - RelativeJump 0x7C80FDCD–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD2 [unknown_code_page] [1700]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD3 [unknown_code_page] [1700]svchost.exe–>kernel32.dll–>LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>kernel32.dll–>LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page] [1700]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page] [1700]svchost.exe–>kernel32.dll–>LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>kernel32.dll–>ResumeThread, Type: Inline - RelativeJump 0x7C832927–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>kernel32.dll–>SetThreadContext, Type: Inline - RelativeJump 0x7C863C09–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>kernel32.dll–>VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>kernel32.dll–>VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A61–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>kernel32.dll–>WinExec, Type: Inline - RelativeJump 0x7C86250D–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - RelativeJump 0x7C810E27–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2C [unknown_code_page] [1700]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2D [unknown_code_page] [1700]svchost.exe–>kernel32.dll–>WriteFileEx, Type: Inline - RelativeJump 0x7C85D6D9–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>kernel32.dll–>WriteProcessMemory, Type: Inline - RelativeJump 0x7C802213–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x7C90E47C–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E481 [unknown_code_page] [1700]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E482 [unknown_code_page] [1700]svchost.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>ws2_32.dll–>accept, Type: Inline - RelativeJump 0x71AC1040–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>ws2_32.dll–>bind, Type: Inline - RelativeJump 0x71AB4480–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>ws2_32.dll–>connect, Type: Inline - RelativeJump 0x71AB4A07–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>ws2_32.dll–>getpeername, Type: Inline - RelativeJump 0x71AC0B68–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>ws2_32.dll–>listen, Type: Inline - RelativeJump 0x71AB8CD3–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>ws2_32.dll–>WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - RelativeJump 0x71AB6A55–>00000000 [sophos_detoured.dll] [1700]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5A [unknown_code_page] [1700]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5B [unknown_code_page] [1912]svchost.exe–>kernel32.dll–>CreateFileA, Type: Inline - RelativeJump 0x7C801A28–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>kernel32.dll–>CreateProcessA, Type: Inline - RelativeJump 0x7C80236B–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>kernel32.dll–>CreateProcessInternalA, Type: Inline - RelativeJump 0x7C81D54E–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>kernel32.dll–>ExitProcess, Type: Inline - RelativeJump 0x7C81CB12–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - RelativeJump 0x7C80C0F8–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FD [unknown_code_page] [1912]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FE [unknown_code_page] [1912]svchost.exe–>kernel32.dll–>FreeLibrary, Type: Inline - RelativeJump 0x7C80AC7E–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>kernel32.dll–>GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>kernel32.dll–>GetThreadContext, Type: Inline - RelativeJump 0x7C83973D–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - RelativeJump 0x7C80FDCD–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD2 [unknown_code_page] [1912]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD3 [unknown_code_page] [1912]svchost.exe–>kernel32.dll–>LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>kernel32.dll–>LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page] [1912]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page] [1912]svchost.exe–>kernel32.dll–>LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>kernel32.dll–>ResumeThread, Type: Inline - RelativeJump 0x7C832927–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>kernel32.dll–>SetThreadContext, Type: Inline - RelativeJump 0x7C863C09–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>kernel32.dll–>VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>kernel32.dll–>VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A61–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>kernel32.dll–>WinExec, Type: Inline - RelativeJump 0x7C86250D–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - RelativeJump 0x7C810E27–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2C [unknown_code_page] [1912]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2D [unknown_code_page] [1912]svchost.exe–>kernel32.dll–>WriteFileEx, Type: Inline - RelativeJump 0x7C85D6D9–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>kernel32.dll–>WriteProcessMemory, Type: Inline - RelativeJump 0x7C802213–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x7C90E47C–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E481 [unknown_code_page] [1912]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E482 [unknown_code_page] [1912]svchost.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>wininet.dll–>InternetOpenA, Type: Inline - RelativeJump 0x3D953081–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>wininet.dll–>InternetOpenUrlA, Type: Inline - RelativeJump 0x3D956F5A–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>wininet.dll–>InternetQueryDataAvailable, Type: Inline - RelativeJump 0x3D951615–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>wininet.dll–>InternetReadFile, Type: Inline - RelativeJump 0x3D9513D4–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>ws2_32.dll–>accept, Type: Inline - RelativeJump 0x71AC1040–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>ws2_32.dll–>bind, Type: Inline - RelativeJump 0x71AB4480–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>ws2_32.dll–>connect, Type: Inline - RelativeJump 0x71AB4A07–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>ws2_32.dll–>getpeername, Type: Inline - RelativeJump 0x71AC0B68–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>ws2_32.dll–>listen, Type: Inline - RelativeJump 0x71AB8CD3–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>ws2_32.dll–>WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - RelativeJump 0x71AB6A55–>00000000 [sophos_detoured.dll] [1912]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5A [unknown_code_page] [1912]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5B [unknown_code_page] [1968]svchost.exe–>kernel32.dll–>CreateFileA, Type: Inline - RelativeJump 0x7C801A28–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>kernel32.dll–>CreateProcessA, Type: Inline - RelativeJump 0x7C80236B–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>kernel32.dll–>CreateProcessInternalA, Type: Inline - RelativeJump 0x7C81D54E–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>kernel32.dll–>ExitProcess, Type: Inline - RelativeJump 0x7C81CB12–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - RelativeJump 0x7C80C0F8–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FD [unknown_code_page] [1968]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FE [unknown_code_page] [1968]svchost.exe–>kernel32.dll–>FreeLibrary, Type: Inline - RelativeJump 0x7C80AC7E–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>kernel32.dll–>GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>kernel32.dll–>GetThreadContext, Type: Inline - RelativeJump 0x7C83973D–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - RelativeJump 0x7C80FDCD–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD2 [unknown_code_page] [1968]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD3 [unknown_code_page] [1968]svchost.exe–>kernel32.dll–>LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>kernel32.dll–>LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page] [1968]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page] [1968]svchost.exe–>kernel32.dll–>LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>kernel32.dll–>ResumeThread, Type: Inline - RelativeJump 0x7C832927–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>kernel32.dll–>SetThreadContext, Type: Inline - RelativeJump 0x7C863C09–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>kernel32.dll–>VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>kernel32.dll–>VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A61–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>kernel32.dll–>WinExec, Type: Inline - RelativeJump 0x7C86250D–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - RelativeJump 0x7C810E27–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2C [unknown_code_page] [1968]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2D [unknown_code_page] [1968]svchost.exe–>kernel32.dll–>WriteFileEx, Type: Inline - RelativeJump 0x7C85D6D9–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>kernel32.dll–>WriteProcessMemory, Type: Inline - RelativeJump 0x7C802213–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x7C90E47C–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E481 [unknown_code_page] [1968]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E482 [unknown_code_page] [1968]svchost.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>ws2_32.dll–>accept, Type: Inline - RelativeJump 0x71AC1040–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>ws2_32.dll–>bind, Type: Inline - RelativeJump 0x71AB4480–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>ws2_32.dll–>connect, Type: Inline - RelativeJump 0x71AB4A07–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>ws2_32.dll–>getpeername, Type: Inline - RelativeJump 0x71AC0B68–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>ws2_32.dll–>listen, Type: Inline - RelativeJump 0x71AB8CD3–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>ws2_32.dll–>WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - RelativeJump 0x71AB6A55–>00000000 [sophos_detoured.dll] [1968]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5A [unknown_code_page] [1968]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5B [unknown_code_page] [2440]EXCEL.EXE–>kernel32.dll–>CreateFileA, Type: Inline - RelativeJump 0x7C801A28–>00000000 [sophos_detoured.dll] [2440]EXCEL.EXE–>kernel32.dll–>CreateProcessA, Type: Inline - RelativeJump 0x7C80236B–>00000000 [sophos_detoured.dll] [2440]EXCEL.EXE–>kernel32.dll–>CreateProcessInternalA, Type: Inline - RelativeJump 0x7C81D54E–>00000000 [sophos_detoured.dll] [2440]EXCEL.EXE–>kernel32.dll–>ExitProcess, Type: Inline - RelativeJump 0x7C81CB12–>00000000 [sophos_detoured.dll] [2440]EXCEL.EXE–>kernel32.dll–>ExitThread, Type: Inline - RelativeJump 0x7C80C0F8–>00000000 [sophos_detoured.dll] [2440]EXCEL.EXE–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FD [unknown_code_page] [2440]EXCEL.EXE–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FE [unknown_code_page] [2440]EXCEL.EXE–>kernel32.dll–>FreeLibrary, Type: Inline - RelativeJump 0x7C80AC7E–>00000000 [sophos_detoured.dll] [2440]EXCEL.EXE–>kernel32.dll–>GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40–>00000000 [sophos_detoured.dll] [2440]EXCEL.EXE–>kernel32.dll–>GetThreadContext, Type: Inline - RelativeJump 0x7C83973D–>00000000 [sophos_detoured.dll] [2440]EXCEL.EXE–>kernel32.dll–>GlobalAlloc, Type: Inline - RelativeJump 0x7C80FDCD–>00000000 [sophos_detoured.dll] [2440]EXCEL.EXE–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD2 [unknown_code_page] [2440]EXCEL.EXE–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD3 [unknown_code_page] [2440]EXCEL.EXE–>kernel32.dll–>LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B–>00000000 [sophos_detoured.dll] [2440]EXCEL.EXE–>kernel32.dll–>LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53–>00000000 [sophos_detoured.dll] [2440]EXCEL.EXE–>kernel32.dll–>LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5–>00000000 [sophos_detoured.dll] [2440]EXCEL.EXE–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page] [2440]EXCEL.EXE–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page] [2440]EXCEL.EXE–>kernel32.dll–>LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB–>00000000 [sophos_detoured.dll] [2440]EXCEL.EXE–>kernel32.dll–>ResumeThread, Type: Inline - RelativeJump 0x7C832927–>00000000 [sophos_detoured.dll] [2440]EXCEL.EXE–>kernel32.dll–>SetThreadContext, Type: Inline - RelativeJump 0x7C863C09–>00000000 [sophos_detoured.dll] [2440]EXCEL.EXE–>kernel32.dll–>SetUnhandledExceptionFilter, Type: Inline - RelativeJump 0x7C84495D–>00000000 [MSO.DLL] [2440]EXCEL.EXE–>kernel32.dll–>VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4–>00000000 [sophos_detoured.dll] [2440]EXCEL.EXE–>kernel32.dll–>VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A61–>00000000 [sophos_detoured.dll] [2440]EXCEL.EXE–>kernel32.dll–>WinExec, Type: Inline - RelativeJump 0x7C86250D–>00000000 [sophos_detoured.dll] [2440]EXCEL.EXE–>kernel32.dll–>WriteFile, Type: Inline - RelativeJump 0x7C810E27–>00000000 [sophos_detoured.dll] [2440]EXCEL.EXE–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2C [unknown_code_page] [2440]EXCEL.EXE–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2D [unknown_code_page] [2440]EXCEL.EXE–>kernel32.dll–>WriteFileEx, Type: Inline - RelativeJump 0x7C85D6D9–>00000000 [sophos_detoured.dll] [2440]EXCEL.EXE–>kernel32.dll–>WriteProcessMemory, Type: Inline - RelativeJump 0x7C802213–>00000000 [sophos_detoured.dll] [2440]EXCEL.EXE–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x7C90E47C–>00000000 [sophos_detoured.dll] [2440]EXCEL.EXE–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E481 [unknown_code_page] [2440]EXCEL.EXE–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E482 [unknown_code_page] [2440]EXCEL.EXE–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>advapi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77DD1218–>00000000 [shimeng.dll] [2632]explorer.exe–>gdi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77F110B4–>00000000 [shimeng.dll] [2632]explorer.exe–>kernel32.dll–>CopyFileExW, Type: Inline - RelativeJump 0x7C827B32–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>kernel32.dll–>CopyFileExW, Type: Inline - SEH 0x7C827B37 [unknown_code_page] [2632]explorer.exe–>kernel32.dll–>CopyFileExW, Type: Inline - SEH 0x7C827B38 [unknown_code_page] [2632]explorer.exe–>kernel32.dll–>CreateFileA, Type: Inline - RelativeJump 0x7C801A28–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>kernel32.dll–>CreateProcessA, Type: Inline - RelativeJump 0x7C80236B–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>kernel32.dll–>CreateProcessInternalA, Type: Inline - RelativeJump 0x7C81D54E–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>kernel32.dll–>ExitProcess, Type: Inline - RelativeJump 0x7C81CB12–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>kernel32.dll–>ExitThread, Type: Inline - RelativeJump 0x7C80C0F8–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FD [unknown_code_page] [2632]explorer.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FE [unknown_code_page] [2632]explorer.exe–>kernel32.dll–>FreeLibrary, Type: Inline - RelativeJump 0x7C80AC7E–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x01001268–>00000000 [shimeng.dll] [2632]explorer.exe–>kernel32.dll–>GetThreadContext, Type: Inline - RelativeJump 0x7C83973D–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - RelativeJump 0x7C80FDCD–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD2 [unknown_code_page] [2632]explorer.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD3 [unknown_code_page] [2632]explorer.exe–>kernel32.dll–>LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>kernel32.dll–>LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page] [2632]explorer.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page] [2632]explorer.exe–>kernel32.dll–>LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>kernel32.dll–>MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F72E–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>kernel32.dll–>ResumeThread, Type: Inline - RelativeJump 0x7C832927–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>kernel32.dll–>SetThreadContext, Type: Inline - RelativeJump 0x7C863C09–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>kernel32.dll–>VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>kernel32.dll–>VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A61–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>kernel32.dll–>WinExec, Type: Inline - RelativeJump 0x7C86250D–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>kernel32.dll–>WriteFile, Type: Inline - RelativeJump 0x7C810E27–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2C [unknown_code_page] [2632]explorer.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2D [unknown_code_page] [2632]explorer.exe–>kernel32.dll–>WriteFileEx, Type: Inline - RelativeJump 0x7C85D6D9–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>kernel32.dll–>WriteProcessMemory, Type: Inline - RelativeJump 0x7C802213–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x7C90E47C–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E481 [unknown_code_page] [2632]explorer.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E482 [unknown_code_page] [2632]explorer.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>shell32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x7C9C15A4–>00000000 [shimeng.dll] [2632]explorer.exe–>user32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x7E41133C–>00000000 [shimeng.dll] [2632]explorer.exe–>wininet.dll–>InternetOpenA, Type: Inline - RelativeJump 0x3D953081–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>wininet.dll–>InternetOpenUrlA, Type: Inline - RelativeJump 0x3D956F5A–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>wininet.dll–>InternetQueryDataAvailable, Type: Inline - RelativeJump 0x3D951615–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>wininet.dll–>InternetReadFile, Type: Inline - RelativeJump 0x3D9513D4–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>wininet.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x3D931480–>00000000 [shimeng.dll] [2632]explorer.exe–>ws2_32.dll–>accept, Type: Inline - RelativeJump 0x71AC1040–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>ws2_32.dll–>bind, Type: Inline - RelativeJump 0x71AB4480–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>ws2_32.dll–>connect, Type: Inline - RelativeJump 0x71AB4A07–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>ws2_32.dll–>getpeername, Type: Inline - RelativeJump 0x71AC0B68–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>ws2_32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x71AB109C–>00000000 [shimeng.dll] [2632]explorer.exe–>ws2_32.dll–>listen, Type: Inline - RelativeJump 0x71AB8CD3–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>ws2_32.dll–>WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>ws2_32.dll–>WSAStartup, Type: Inline - RelativeJump 0x71AB6A55–>00000000 [sophos_detoured.dll] [2632]explorer.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5A [unknown_code_page] [2632]explorer.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5B [unknown_code_page] [2852]HRSMail.exe–>advapi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77DD1218–>00000000 [shimeng.dll] [2852]HRSMail.exe–>advapi32.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x77DD1214–>00000000 [aclayers.dll] [2852]HRSMail.exe–>advapi32.dll–>kernel32.dll–>LoadLibraryExW, Type: IAT modification 0x77DD105C–>00000000 [aclayers.dll] [2852]HRSMail.exe–>advapi32.dll–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x77DD11E0–>00000000 [aclayers.dll] [2852]HRSMail.exe–>gdi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77F110B4–>00000000 [shimeng.dll] [2852]HRSMail.exe–>gdi32.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x77F11084–>00000000 [aclayers.dll] [2852]HRSMail.exe–>gdi32.dll–>kernel32.dll–>LoadLibraryExW, Type: IAT modification 0x77F11078–>00000000 [aclayers.dll] [2852]HRSMail.exe–>gdi32.dll–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x77F110B8–>00000000 [aclayers.dll] [2852]HRSMail.exe–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x004AA1DC–>00000000 [shimeng.dll] [2852]HRSMail.exe–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x004AA354–>00000000 [shimeng.dll] [2852]HRSMail.exe–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x004AA2EC–>00000000 [aclayers.dll] [2852]HRSMail.exe–>kernel32.dll–>LoadLibraryExA, Type: IAT modification 0x004AA1D0–>00000000 [aclayers.dll] [2852]HRSMail.exe–>shell32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x7C9C15A4–>00000000 [shimeng.dll] [2852]HRSMail.exe–>shell32.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x7C9C13E8–>00000000 [aclayers.dll] [2852]HRSMail.exe–>shell32.dll–>kernel32.dll–>LoadLibraryExA, Type: IAT modification 0x7C9C163C–>00000000 [aclayers.dll] [2852]HRSMail.exe–>shell32.dll–>kernel32.dll–>LoadLibraryExW, Type: IAT modification 0x7C9C161C–>00000000 [aclayers.dll] [2852]HRSMail.exe–>shell32.dll–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x7C9C15A0–>00000000 [aclayers.dll] [2852]HRSMail.exe–>user32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x7E41133C–>00000000 [shimeng.dll] [2852]HRSMail.exe–>user32.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x7E4112F4–>00000000 [aclayers.dll] [2852]HRSMail.exe–>user32.dll–>kernel32.dll–>LoadLibraryExW, Type: IAT modification 0x7E411208–>00000000 [aclayers.dll] [2852]HRSMail.exe–>user32.dll–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x7E411340–>00000000 [aclayers.dll] [3156]iexplore.exe–>advapi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77DD1218–>00000000 [shimeng.dll] [3156]iexplore.exe–>advapi32.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x77DD1214–>00000000 [aclayers.dll] [3156]iexplore.exe–>advapi32.dll–>kernel32.dll–>LoadLibraryExW, Type: IAT modification 0x77DD105C–>00000000 [aclayers.dll] [3156]iexplore.exe–>advapi32.dll–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x77DD11E0–>00000000 [aclayers.dll] [3156]iexplore.exe–>gdi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77F110B4–>00000000 [shimeng.dll] [3156]iexplore.exe–>gdi32.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x77F11084–>00000000 [aclayers.dll] [3156]iexplore.exe–>gdi32.dll–>kernel32.dll–>LoadLibraryExW, Type: IAT modification 0x77F11078–>00000000 [aclayers.dll] [3156]iexplore.exe–>gdi32.dll–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x77F110B8–>00000000 [aclayers.dll] [3156]iexplore.exe–>kernel32.dll–>CreateActCtxW, Type: Inline - RelativeJump 0x7C8154FC–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>kernel32.dll–>CreateFileA, Type: Inline - RelativeJump 0x7C801A28–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>kernel32.dll–>CreateFileW, Type: Inline - RelativeJump 0x7C810800–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>kernel32.dll–>CreateProcessA, Type: Inline - RelativeJump 0x7C80236B–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>kernel32.dll–>CreateProcessInternalA, Type: Inline - RelativeJump 0x7C81D54E–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>kernel32.dll–>ExitProcess, Type: Inline - RelativeJump 0x7C81CB12–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>kernel32.dll–>ExitThread, Type: Inline - RelativeJump 0x7C80C0F8–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FD [unknown_code_page] [3156]iexplore.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FE [unknown_code_page] [3156]iexplore.exe–>kernel32.dll–>FreeLibrary, Type: Inline - RelativeJump 0x7C80AC7E–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x0040111C–>00000000 [shimeng.dll] [3156]iexplore.exe–>kernel32.dll–>GetThreadContext, Type: Inline - RelativeJump 0x7C83973D–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - RelativeJump 0x7C80FDCD–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD2 [unknown_code_page] [3156]iexplore.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD3 [unknown_code_page] [3156]iexplore.exe–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x00401060–>00000000 [aclayers.dll] [3156]iexplore.exe–>kernel32.dll–>LoadLibraryExW, Type: IAT modification 0x004010B8–>00000000 [aclayers.dll] [3156]iexplore.exe–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x00401078–>00000000 [aclayers.dll] [3156]iexplore.exe–>kernel32.dll–>ReplaceFile, Type: Inline - RelativeJump 0x7C836C6C–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>kernel32.dll–>ResumeThread, Type: Inline - RelativeJump 0x7C832927–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>kernel32.dll–>SetThreadContext, Type: Inline - RelativeJump 0x7C863C09–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>kernel32.dll–>VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>kernel32.dll–>VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A61–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>kernel32.dll–>WinExec, Type: Inline - RelativeJump 0x7C86250D–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>kernel32.dll–>WriteFile, Type: Inline - RelativeJump 0x7C810E27–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2C [unknown_code_page] [3156]iexplore.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2D [unknown_code_page] [3156]iexplore.exe–>kernel32.dll–>WriteFileEx, Type: Inline - RelativeJump 0x7C85D6D9–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>kernel32.dll–>WriteProcessMemory, Type: Inline - RelativeJump 0x7C802213–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>mswsock.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x71A51178–>00000000 [shimeng.dll] [3156]iexplore.exe–>mswsock.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x71A51184–>00000000 [aclayers.dll] [3156]iexplore.exe–>mswsock.dll–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x71A511A0–>00000000 [aclayers.dll] [3156]iexplore.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x7C90E47C–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E481 [unknown_code_page] [3156]iexplore.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E482 [unknown_code_page] [3156]iexplore.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>shell32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x7C9C15A4–>00000000 [shimeng.dll] [3156]iexplore.exe–>shell32.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x7C9C13E8–>00000000 [aclayers.dll] [3156]iexplore.exe–>shell32.dll–>kernel32.dll–>LoadLibraryExA, Type: IAT modification 0x7C9C163C–>00000000 [aclayers.dll] [3156]iexplore.exe–>shell32.dll–>kernel32.dll–>LoadLibraryExW, Type: IAT modification 0x7C9C161C–>00000000 [aclayers.dll] [3156]iexplore.exe–>shell32.dll–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x7C9C15A0–>00000000 [aclayers.dll] [3156]iexplore.exe–>shell32.dll–>SHExtractIconsW, Type: Inline - RelativeJump 0x7CA05712–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>user32.dll–>CreateWindowExW, Type: Inline - RelativeJump 0x7E42D0A3–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>user32.dll–>DialogBoxIndirectParamA, Type: Inline - RelativeJump 0x7E456D7D–>00000000 [ieframe.dll] [3156]iexplore.exe–>user32.dll–>DialogBoxIndirectParamW, Type: Inline - RelativeJump 0x7E432072–>00000000 [ieframe.dll] [3156]iexplore.exe–>user32.dll–>DialogBoxParamA, Type: Inline - RelativeJump 0x7E43B144–>00000000 [ieframe.dll] [3156]iexplore.exe–>user32.dll–>DialogBoxParamW, Type: Inline - RelativeJump 0x7E4247AB–>00000000 [ieframe.dll] [3156]iexplore.exe–>user32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x7E41133C–>00000000 [shimeng.dll] [3156]iexplore.exe–>user32.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x7E4112F4–>00000000 [aclayers.dll] [3156]iexplore.exe–>user32.dll–>kernel32.dll–>LoadLibraryExW, Type: IAT modification 0x7E411208–>00000000 [aclayers.dll] [3156]iexplore.exe–>user32.dll–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x7E411340–>00000000 [aclayers.dll] [3156]iexplore.exe–>user32.dll–>MessageBoxExA, Type: Inline - RelativeJump 0x7E45085C–>00000000 [ieframe.dll] [3156]iexplore.exe–>user32.dll–>MessageBoxExW, Type: Inline - RelativeJump 0x7E450838–>00000000 [ieframe.dll] [3156]iexplore.exe–>user32.dll–>MessageBoxIndirectA, Type: Inline - RelativeJump 0x7E43A082–>00000000 [ieframe.dll] [3156]iexplore.exe–>user32.dll–>MessageBoxIndirectW, Type: Inline - RelativeJump 0x7E4664D5–>00000000 [ieframe.dll] [3156]iexplore.exe–>wininet.dll–>InternetOpenA, Type: Inline - RelativeJump 0x3D953081–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>wininet.dll–>InternetOpenUrlA, Type: Inline - RelativeJump 0x3D956F5A–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>wininet.dll–>InternetQueryDataAvailable, Type: Inline - RelativeJump 0x3D951615–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>wininet.dll–>InternetReadFile, Type: Inline - RelativeJump 0x3D9513D4–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>wininet.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x3D931480–>00000000 [shimeng.dll] [3156]iexplore.exe–>wininet.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x3D931484–>00000000 [aclayers.dll] [3156]iexplore.exe–>wininet.dll–>kernel32.dll–>LoadLibraryExW, Type: IAT modification 0x3D931418–>00000000 [aclayers.dll] [3156]iexplore.exe–>wininet.dll–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x3D9313EC–>00000000 [aclayers.dll] [3156]iexplore.exe–>ws2_32.dll–>accept, Type: Inline - RelativeJump 0x71AC1040–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>ws2_32.dll–>bind, Type: Inline - RelativeJump 0x71AB4480–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>ws2_32.dll–>connect, Type: Inline - RelativeJump 0x71AB4A07–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>ws2_32.dll–>getpeername, Type: Inline - RelativeJump 0x71AC0B68–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>ws2_32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x71AB109C–>00000000 [shimeng.dll] [3156]iexplore.exe–>ws2_32.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x71AB10A8–>00000000 [aclayers.dll] [3156]iexplore.exe–>ws2_32.dll–>listen, Type: Inline - RelativeJump 0x71AB8CD3–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>ws2_32.dll–>WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>ws2_32.dll–>WSAStartup, Type: Inline - RelativeJump 0x71AB6A55–>00000000 [sophos_detoured.dll] [3156]iexplore.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5A [unknown_code_page] [3156]iexplore.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5B [unknown_code_page] [3704]iexplore.exe–>advapi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77DD1218–>00000000 [shimeng.dll] [3704]iexplore.exe–>advapi32.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x77DD1214–>00000000 [aclayers.dll] [3704]iexplore.exe–>advapi32.dll–>kernel32.dll–>LoadLibraryExW, Type: IAT modification 0x77DD105C–>00000000 [aclayers.dll] [3704]iexplore.exe–>advapi32.dll–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x77DD11E0–>00000000 [aclayers.dll] [3704]iexplore.exe–>gdi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77F110B4–>00000000 [shimeng.dll] [3704]iexplore.exe–>gdi32.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x77F11084–>00000000 [aclayers.dll] [3704]iexplore.exe–>gdi32.dll–>kernel32.dll–>LoadLibraryExW, Type: IAT modification 0x77F11078–>00000000 [aclayers.dll] [3704]iexplore.exe–>gdi32.dll–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x77F110B8–>00000000 [aclayers.dll] [3704]iexplore.exe–>kernel32.dll–>CreateActCtxW, Type: Inline - RelativeJump 0x7C8154FC–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>kernel32.dll–>CreateFileA, Type: Inline - RelativeJump 0x7C801A28–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>kernel32.dll–>CreateFileW, Type: Inline - RelativeJump 0x7C810800–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>kernel32.dll–>CreateProcessA, Type: Inline - RelativeJump 0x7C80236B–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>kernel32.dll–>CreateProcessInternalA, Type: Inline - RelativeJump 0x7C81D54E–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>kernel32.dll–>ExitProcess, Type: Inline - RelativeJump 0x7C81CB12–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>kernel32.dll–>ExitThread, Type: Inline - RelativeJump 0x7C80C0F8–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FD [unknown_code_page] [3704]iexplore.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FE [unknown_code_page] [3704]iexplore.exe–>kernel32.dll–>FreeLibrary, Type: Inline - RelativeJump 0x7C80AC7E–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x0040111C–>00000000 [shimeng.dll] [3704]iexplore.exe–>kernel32.dll–>GetThreadContext, Type: Inline - RelativeJump 0x7C83973D–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - RelativeJump 0x7C80FDCD–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD2 [unknown_code_page] [3704]iexplore.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD3 [unknown_code_page] [3704]iexplore.exe–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x00401060–>00000000 [aclayers.dll] [3704]iexplore.exe–>kernel32.dll–>LoadLibraryExW, Type: IAT modification 0x004010B8–>00000000 [aclayers.dll] [3704]iexplore.exe–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x00401078–>00000000 [aclayers.dll] [3704]iexplore.exe–>kernel32.dll–>ReplaceFile, Type: Inline - RelativeJump 0x7C836C6C–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>kernel32.dll–>ResumeThread, Type: Inline - RelativeJump 0x7C832927–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>kernel32.dll–>SetThreadContext, Type: Inline - RelativeJump 0x7C863C09–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>kernel32.dll–>VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>kernel32.dll–>VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A61–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>kernel32.dll–>WinExec, Type: Inline - RelativeJump 0x7C86250D–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>kernel32.dll–>WriteFile, Type: Inline - RelativeJump 0x7C810E27–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2C [unknown_code_page] [3704]iexplore.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2D [unknown_code_page] [3704]iexplore.exe–>kernel32.dll–>WriteFileEx, Type: Inline - RelativeJump 0x7C85D6D9–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>kernel32.dll–>WriteProcessMemory, Type: Inline - RelativeJump 0x7C802213–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>mswsock.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x71A51178–>00000000 [shimeng.dll] [3704]iexplore.exe–>mswsock.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x71A51184–>00000000 [aclayers.dll] [3704]iexplore.exe–>mswsock.dll–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x71A511A0–>00000000 [aclayers.dll] [3704]iexplore.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x7C90E47C–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E481 [unknown_code_page] [3704]iexplore.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E482 [unknown_code_page] [3704]iexplore.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>shell32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x7C9C15A4–>00000000 [shimeng.dll] [3704]iexplore.exe–>shell32.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x7C9C13E8–>00000000 [aclayers.dll] [3704]iexplore.exe–>shell32.dll–>kernel32.dll–>LoadLibraryExA, Type: IAT modification 0x7C9C163C–>00000000 [aclayers.dll] [3704]iexplore.exe–>shell32.dll–>kernel32.dll–>LoadLibraryExW, Type: IAT modification 0x7C9C161C–>00000000 [aclayers.dll] [3704]iexplore.exe–>shell32.dll–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x7C9C15A0–>00000000 [aclayers.dll] [3704]iexplore.exe–>shell32.dll–>SHExtractIconsW, Type: Inline - RelativeJump 0x7CA05712–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>user32.dll–>CreateWindowExW, Type: Inline - RelativeJump 0x7E42D0A3–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>user32.dll–>DialogBoxIndirectParamA, Type: Inline - RelativeJump 0x7E456D7D–>00000000 [ieframe.dll] [3704]iexplore.exe–>user32.dll–>DialogBoxIndirectParamW, Type: Inline - RelativeJump 0x7E432072–>00000000 [ieframe.dll] [3704]iexplore.exe–>user32.dll–>DialogBoxParamA, Type: Inline - RelativeJump 0x7E43B144–>00000000 [ieframe.dll] [3704]iexplore.exe–>user32.dll–>DialogBoxParamW, Type: Inline - RelativeJump 0x7E4247AB–>00000000 [ieframe.dll] [3704]iexplore.exe–>user32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x7E41133C–>00000000 [shimeng.dll] [3704]iexplore.exe–>user32.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x7E4112F4–>00000000 [aclayers.dll] [3704]iexplore.exe–>user32.dll–>kernel32.dll–>LoadLibraryExW, Type: IAT modification 0x7E411208–>00000000 [aclayers.dll] [3704]iexplore.exe–>user32.dll–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x7E411340–>00000000 [aclayers.dll] [3704]iexplore.exe–>user32.dll–>MessageBoxExA, Type: Inline - RelativeJump 0x7E45085C–>00000000 [ieframe.dll] [3704]iexplore.exe–>user32.dll–>MessageBoxExW, Type: Inline - RelativeJump 0x7E450838–>00000000 [ieframe.dll] [3704]iexplore.exe–>user32.dll–>MessageBoxIndirectA, Type: Inline - RelativeJump 0x7E43A082–>00000000 [ieframe.dll] [3704]iexplore.exe–>user32.dll–>MessageBoxIndirectW, Type: Inline - RelativeJump 0x7E4664D5–>00000000 [ieframe.dll] [3704]iexplore.exe–>wininet.dll–>InternetOpenA, Type: Inline - RelativeJump 0x3D953081–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>wininet.dll–>InternetOpenUrlA, Type: Inline - RelativeJump 0x3D956F5A–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>wininet.dll–>InternetQueryDataAvailable, Type: Inline - RelativeJump 0x3D951615–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>wininet.dll–>InternetReadFile, Type: Inline - RelativeJump 0x3D9513D4–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>wininet.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x3D931480–>00000000 [shimeng.dll] [3704]iexplore.exe–>wininet.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x3D931484–>00000000 [aclayers.dll] [3704]iexplore.exe–>wininet.dll–>kernel32.dll–>LoadLibraryExW, Type: IAT modification 0x3D931418–>00000000 [aclayers.dll] [3704]iexplore.exe–>wininet.dll–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x3D9313EC–>00000000 [aclayers.dll] [3704]iexplore.exe–>ws2_32.dll–>accept, Type: Inline - RelativeJump 0x71AC1040–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>ws2_32.dll–>bind, Type: Inline - RelativeJump 0x71AB4480–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>ws2_32.dll–>connect, Type: Inline - RelativeJump 0x71AB4A07–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>ws2_32.dll–>getpeername, Type: Inline - RelativeJump 0x71AC0B68–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>ws2_32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x71AB109C–>00000000 [shimeng.dll] [3704]iexplore.exe–>ws2_32.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x71AB10A8–>00000000 [aclayers.dll] [3704]iexplore.exe–>ws2_32.dll–>listen, Type: Inline - RelativeJump 0x71AB8CD3–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>ws2_32.dll–>WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>ws2_32.dll–>WSAStartup, Type: Inline - RelativeJump 0x71AB6A55–>00000000 [sophos_detoured.dll] [3704]iexplore.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5A [unknown_code_page] [3704]iexplore.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5B [unknown_code_page] [4008]OUTLOOK.EXE–>kernel32.dll–>CreateActCtxW, Type: Inline - RelativeJump 0x7C8154FC–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>CreateFileA, Type: Inline - RelativeJump 0x7C801A28–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>CreateFileW, Type: Inline - RelativeJump 0x7C810800–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>CreateProcessA, Type: Inline - RelativeJump 0x7C80236B–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>CreateProcessInternalA, Type: Inline - RelativeJump 0x7C81D54E–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>ExitProcess, Type: Inline - RelativeJump 0x7C81CB12–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>ExitThread, Type: Inline - RelativeJump 0x7C80C0F8–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FD [unknown_code_page] [4008]OUTLOOK.EXE–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FE [unknown_code_page] [4008]OUTLOOK.EXE–>kernel32.dll–>FreeLibrary, Type: Inline - RelativeJump 0x7C80AC7E–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>GetThreadContext, Type: Inline - RelativeJump 0x7C83973D–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>GlobalAlloc, Type: Inline - RelativeJump 0x7C80FDCD–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD2 [unknown_code_page] [4008]OUTLOOK.EXE–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD3 [unknown_code_page] [4008]OUTLOOK.EXE–>kernel32.dll–>LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page] [4008]OUTLOOK.EXE–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page] [4008]OUTLOOK.EXE–>kernel32.dll–>LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>ReplaceFile, Type: Inline - RelativeJump 0x7C836C6C–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>ResumeThread, Type: Inline - RelativeJump 0x7C832927–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>SetThreadContext, Type: Inline - RelativeJump 0x7C863C09–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>SetUnhandledExceptionFilter, Type: Inline - RelativeJump 0x7C84495D–>00000000 [MSO.DLL] [4008]OUTLOOK.EXE–>kernel32.dll–>VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A61–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>WinExec, Type: Inline - RelativeJump 0x7C86250D–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>WriteFile, Type: Inline - RelativeJump 0x7C810E27–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2C [unknown_code_page] [4008]OUTLOOK.EXE–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2D [unknown_code_page] [4008]OUTLOOK.EXE–>kernel32.dll–>WriteFileEx, Type: Inline - RelativeJump 0x7C85D6D9–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>kernel32.dll–>WriteProcessMemory, Type: Inline - RelativeJump 0x7C802213–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x7C90E47C–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E481 [unknown_code_page] [4008]OUTLOOK.EXE–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E482 [unknown_code_page] [4008]OUTLOOK.EXE–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>shell32.dll–>SHExtractIconsW, Type: Inline - RelativeJump 0x7CA05712–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>user32.dll–>CreateWindowExW, Type: Inline - RelativeJump 0x7E42D0A3–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>wininet.dll–>InternetOpenA, Type: Inline - RelativeJump 0x3D953081–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>wininet.dll–>InternetOpenUrlA, Type: Inline - RelativeJump 0x3D956F5A–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>wininet.dll–>InternetQueryDataAvailable, Type: Inline - RelativeJump 0x3D951615–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>wininet.dll–>InternetReadFile, Type: Inline - RelativeJump 0x3D9513D4–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>ws2_32.dll–>accept, Type: Inline - RelativeJump 0x71AC1040–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>ws2_32.dll–>bind, Type: Inline - RelativeJump 0x71AB4480–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>ws2_32.dll–>connect, Type: Inline - RelativeJump 0x71AB4A07–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>ws2_32.dll–>getpeername, Type: Inline - RelativeJump 0x71AC0B68–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>ws2_32.dll–>listen, Type: Inline - RelativeJump 0x71AB8CD3–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>ws2_32.dll–>WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>ws2_32.dll–>WSAStartup, Type: Inline - RelativeJump 0x71AB6A55–>00000000 [sophos_detoured.dll] [4008]OUTLOOK.EXE–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5A [unknown_code_page] [4008]OUTLOOK.EXE–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5B [unknown_code_page] [452]svchost.exe–>kernel32.dll–>CreateFileA, Type: Inline - RelativeJump 0x7C801A28–>00000000 [sophos_detoured.dll] [452]svchost.exe–>kernel32.dll–>CreateProcessA, Type: Inline - RelativeJump 0x7C80236B–>00000000 [sophos_detoured.dll] [452]svchost.exe–>kernel32.dll–>CreateProcessInternalA, Type: Inline - RelativeJump 0x7C81D54E–>00000000 [sophos_detoured.dll] [452]svchost.exe–>kernel32.dll–>ExitProcess, Type: Inline - RelativeJump 0x7C81CB12–>00000000 [sophos_detoured.dll] [452]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - RelativeJump 0x7C80C0F8–>00000000 [sophos_detoured.dll] [452]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FD [unknown_code_page] [452]svchost.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FE [unknown_code_page] [452]svchost.exe–>kernel32.dll–>FreeLibrary, Type: Inline - RelativeJump 0x7C80AC7E–>00000000 [sophos_detoured.dll] [452]svchost.exe–>kernel32.dll–>GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40–>00000000 [sophos_detoured.dll] [452]svchost.exe–>kernel32.dll–>GetThreadContext, Type: Inline - RelativeJump 0x7C83973D–>00000000 [sophos_detoured.dll] [452]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - RelativeJump 0x7C80FDCD–>00000000 [sophos_detoured.dll] [452]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD2 [unknown_code_page] [452]svchost.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD3 [unknown_code_page] [452]svchost.exe–>kernel32.dll–>LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B–>00000000 [sophos_detoured.dll] [452]svchost.exe–>kernel32.dll–>LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53–>00000000 [sophos_detoured.dll] [452]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5–>00000000 [sophos_detoured.dll] [452]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page] [452]svchost.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page] [452]svchost.exe–>kernel32.dll–>LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB–>00000000 [sophos_detoured.dll] [452]svchost.exe–>kernel32.dll–>ResumeThread, Type: Inline - RelativeJump 0x7C832927–>00000000 [sophos_detoured.dll] [452]svchost.exe–>kernel32.dll–>SetThreadContext, Type: Inline - RelativeJump 0x7C863C09–>00000000 [sophos_detoured.dll] [452]svchost.exe–>kernel32.dll–>VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4–>00000000 [sophos_detoured.dll] [452]svchost.exe–>kernel32.dll–>VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A61–>00000000 [sophos_detoured.dll] [452]svchost.exe–>kernel32.dll–>WinExec, Type: Inline - RelativeJump 0x7C86250D–>00000000 [sophos_detoured.dll] [452]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - RelativeJump 0x7C810E27–>00000000 [sophos_detoured.dll] [452]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2C [unknown_code_page] [452]svchost.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2D [unknown_code_page] [452]svchost.exe–>kernel32.dll–>WriteFileEx, Type: Inline - RelativeJump 0x7C85D6D9–>00000000 [sophos_detoured.dll] [452]svchost.exe–>kernel32.dll–>WriteProcessMemory, Type: Inline - RelativeJump 0x7C802213–>00000000 [sophos_detoured.dll] [452]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x7C90E47C–>00000000 [sophos_detoured.dll] [452]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E481 [unknown_code_page] [452]svchost.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E482 [unknown_code_page] [452]svchost.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [sophos_detoured.dll] [452]svchost.exe–>ws2_32.dll–>accept, Type: Inline - RelativeJump 0x71AC1040–>00000000 [sophos_detoured.dll] [452]svchost.exe–>ws2_32.dll–>bind, Type: Inline - RelativeJump 0x71AB4480–>00000000 [sophos_detoured.dll] [452]svchost.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [sophos_detoured.dll] [452]svchost.exe–>ws2_32.dll–>connect, Type: Inline - RelativeJump 0x71AB4A07–>00000000 [sophos_detoured.dll] [452]svchost.exe–>ws2_32.dll–>getpeername, Type: Inline - RelativeJump 0x71AC0B68–>00000000 [sophos_detoured.dll] [452]svchost.exe–>ws2_32.dll–>listen, Type: Inline - RelativeJump 0x71AB8CD3–>00000000 [sophos_detoured.dll] [452]svchost.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [sophos_detoured.dll] [452]svchost.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [sophos_detoured.dll] [452]svchost.exe–>ws2_32.dll–>WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A–>00000000 [sophos_detoured.dll] [452]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - RelativeJump 0x71AB6A55–>00000000 [sophos_detoured.dll] [452]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5A [unknown_code_page] [452]svchost.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5B [unknown_code_page] [528]p4sshLink.exe–>advapi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77DD1218–>00000000 [shimeng.dll] [528]p4sshLink.exe–>advapi32.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x77DD1214–>00000000 [aclayers.dll] [528]p4sshLink.exe–>advapi32.dll–>kernel32.dll–>LoadLibraryExW, Type: IAT modification 0x77DD105C–>00000000 [aclayers.dll] [528]p4sshLink.exe–>advapi32.dll–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x77DD11E0–>00000000 [aclayers.dll] [528]p4sshLink.exe–>gdi32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x77F110B4–>00000000 [shimeng.dll] [528]p4sshLink.exe–>gdi32.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x77F11084–>00000000 [aclayers.dll] [528]p4sshLink.exe–>gdi32.dll–>kernel32.dll–>LoadLibraryExW, Type: IAT modification 0x77F11078–>00000000 [aclayers.dll] [528]p4sshLink.exe–>gdi32.dll–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x77F110B8–>00000000 [aclayers.dll] [528]p4sshLink.exe–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x0043C0A8–>00000000 [shimeng.dll] [528]p4sshLink.exe–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x0043C064–>00000000 [aclayers.dll] [528]p4sshLink.exe–>mswsock.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x71A51178–>00000000 [shimeng.dll] [528]p4sshLink.exe–>mswsock.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x71A51184–>00000000 [aclayers.dll] [528]p4sshLink.exe–>mswsock.dll–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x71A511A0–>00000000 [aclayers.dll] [528]p4sshLink.exe–>shell32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x7C9C15A4–>00000000 [shimeng.dll] [528]p4sshLink.exe–>shell32.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x7C9C13E8–>00000000 [aclayers.dll] [528]p4sshLink.exe–>shell32.dll–>kernel32.dll–>LoadLibraryExA, Type: IAT modification 0x7C9C163C–>00000000 [aclayers.dll] [528]p4sshLink.exe–>shell32.dll–>kernel32.dll–>LoadLibraryExW, Type: IAT modification 0x7C9C161C–>00000000 [aclayers.dll] [528]p4sshLink.exe–>shell32.dll–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x7C9C15A0–>00000000 [aclayers.dll] [528]p4sshLink.exe–>user32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x7E41133C–>00000000 [shimeng.dll] [528]p4sshLink.exe–>user32.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x7E4112F4–>00000000 [aclayers.dll] [528]p4sshLink.exe–>user32.dll–>kernel32.dll–>LoadLibraryExW, Type: IAT modification 0x7E411208–>00000000 [aclayers.dll] [528]p4sshLink.exe–>user32.dll–>kernel32.dll–>LoadLibraryW, Type: IAT modification 0x7E411340–>00000000 [aclayers.dll] [528]p4sshLink.exe–>ws2_32.dll–>kernel32.dll–>GetProcAddress, Type: IAT modification 0x71AB109C–>00000000 [shimeng.dll] [528]p4sshLink.exe–>ws2_32.dll–>kernel32.dll–>LoadLibraryA, Type: IAT modification 0x71AB10A8–>00000000 [aclayers.dll] [792]lsass.exe–>kernel32.dll–>CreateFileA, Type: Inline - RelativeJump 0x7C801A28–>00000000 [sophos_detoured.dll] [792]lsass.exe–>kernel32.dll–>CreateProcessA, Type: Inline - RelativeJump 0x7C80236B–>00000000 [sophos_detoured.dll] [792]lsass.exe–>kernel32.dll–>CreateProcessInternalA, Type: Inline - RelativeJump 0x7C81D54E–>00000000 [sophos_detoured.dll] [792]lsass.exe–>kernel32.dll–>ExitProcess, Type: Inline - RelativeJump 0x7C81CB12–>00000000 [sophos_detoured.dll] [792]lsass.exe–>kernel32.dll–>ExitThread, Type: Inline - RelativeJump 0x7C80C0F8–>00000000 [sophos_detoured.dll] [792]lsass.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FD [unknown_code_page] [792]lsass.exe–>kernel32.dll–>ExitThread, Type: Inline - SEH 0x7C80C0FE [unknown_code_page] [792]lsass.exe–>kernel32.dll–>FreeLibrary, Type: Inline - RelativeJump 0x7C80AC7E–>00000000 [sophos_detoured.dll] [792]lsass.exe–>kernel32.dll–>GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40–>00000000 [sophos_detoured.dll] [792]lsass.exe–>kernel32.dll–>GetThreadContext, Type: Inline - RelativeJump 0x7C83973D–>00000000 [sophos_detoured.dll] [792]lsass.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - RelativeJump 0x7C80FDCD–>00000000 [sophos_detoured.dll] [792]lsass.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD2 [unknown_code_page] [792]lsass.exe–>kernel32.dll–>GlobalAlloc, Type: Inline - SEH 0x7C80FDD3 [unknown_code_page] [792]lsass.exe–>kernel32.dll–>LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B–>00000000 [sophos_detoured.dll] [792]lsass.exe–>kernel32.dll–>LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53–>00000000 [sophos_detoured.dll] [792]lsass.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5–>00000000 [sophos_detoured.dll] [792]lsass.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page] [792]lsass.exe–>kernel32.dll–>LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page] [792]lsass.exe–>kernel32.dll–>LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB–>00000000 [sophos_detoured.dll] [792]lsass.exe–>kernel32.dll–>ResumeThread, Type: Inline - RelativeJump 0x7C832927–>00000000 [sophos_detoured.dll] [792]lsass.exe–>kernel32.dll–>SetThreadContext, Type: Inline - RelativeJump 0x7C863C09–>00000000 [sophos_detoured.dll] [792]lsass.exe–>kernel32.dll–>VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4–>00000000 [sophos_detoured.dll] [792]lsass.exe–>kernel32.dll–>VirtualProtectEx, Type: Inline - RelativeJump 0x7C801A61–>00000000 [sophos_detoured.dll] [792]lsass.exe–>kernel32.dll–>WinExec, Type: Inline - RelativeJump 0x7C86250D–>00000000 [sophos_detoured.dll] [792]lsass.exe–>kernel32.dll–>WriteFile, Type: Inline - RelativeJump 0x7C810E27–>00000000 [sophos_detoured.dll] [792]lsass.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2C [unknown_code_page] [792]lsass.exe–>kernel32.dll–>WriteFile, Type: Inline - SEH 0x7C810E2D [unknown_code_page] [792]lsass.exe–>kernel32.dll–>WriteFileEx, Type: Inline - RelativeJump 0x7C85D6D9–>00000000 [sophos_detoured.dll] [792]lsass.exe–>kernel32.dll–>WriteProcessMemory, Type: Inline - RelativeJump 0x7C802213–>00000000 [sophos_detoured.dll] [792]lsass.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x7C90E47C–>00000000 [sophos_detoured.dll] [792]lsass.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E481 [unknown_code_page] [792]lsass.exe–>ntdll.dll–>KiUserExceptionDispatcher, Type: Inline - SEH 0x7C90E482 [unknown_code_page] [792]lsass.exe–>ntdll.dll–>LdrLoadDll, Type: Inline - RelativeJump 0x7C91632D–>00000000 [sophos_detoured.dll] [792]lsass.exe–>ws2_32.dll–>accept, Type: Inline - RelativeJump 0x71AC1040–>00000000 [sophos_detoured.dll] [792]lsass.exe–>ws2_32.dll–>bind, Type: Inline - RelativeJump 0x71AB4480–>00000000 [sophos_detoured.dll] [792]lsass.exe–>ws2_32.dll–>closesocket, Type: Inline - RelativeJump 0x71AB3E2B–>00000000 [sophos_detoured.dll] [792]lsass.exe–>ws2_32.dll–>connect, Type: Inline - RelativeJump 0x71AB4A07–>00000000 [sophos_detoured.dll] [792]lsass.exe–>ws2_32.dll–>getpeername, Type: Inline - RelativeJump 0x71AC0B68–>00000000 [sophos_detoured.dll] [792]lsass.exe–>ws2_32.dll–>listen, Type: Inline - RelativeJump 0x71AB8CD3–>00000000 [sophos_detoured.dll] [792]lsass.exe–>ws2_32.dll–>recv, Type: Inline - RelativeJump 0x71AB676F–>00000000 [sophos_detoured.dll] [792]lsass.exe–>ws2_32.dll–>send, Type: Inline - RelativeJump 0x71AB4C27–>00000000 [sophos_detoured.dll] [792]lsass.exe–>ws2_32.dll–>WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A–>00000000 [sophos_detoured.dll] [792]lsass.exe–>ws2_32.dll–>WSAStartup, Type: Inline - RelativeJump 0x71AB6A55–>00000000 [sophos_detoured.dll] [792]lsass.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5A [unknown_code_page] [792]lsass.exe–>ws2_32.dll–>WSAStartup, Type: Inline - SEH 0x71AB6A5B [unknown_code_page]
Hi gtbear,

How's your computer running now? Did you have to change your homepage again?

I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start.  The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button.  The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.
Morning Noodle Tech, Computers running OK and the Home Page hijack seems to have cleared so Thank you for that. Here's the ESET file D:\_OTL\MovedFiles\03082011_085533\D_Documents and Settings\ucyzdun\Local Settings\Application Data\gersai.exe IRC/SdBot trojan D:\_OTL\MovedFiles\03082011_085533\D_Documents and Settings\ucyzdun\Start Menu\Programs\Startup\frilm.exe IRC/SdBot trojan D:\_OTL\MovedFiles\03082011_085533\D_Documents and Settings\ucyzdun\Start Menu\Programs\Startup\peyci.exe IRC/SdBot trojan Regards David
Hi gtbear,

Great! Your system appears to be clean.

Now time for some cleanup.

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
===================================================

I noticed you are not running a firewall. Firewalls help protect you on the internet by making your PC invisible to hackers and stops malicious software from sending your data out on the Internet.

Try Zone Alarm Free Firewall

===================================================

Now Set a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.  

The easiest and safest way to do this is:
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then go to Start > Run and type: Cleanmgr
  • Click "OK".
  • Click the "More Options" Tab.
  • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.
Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer More Secure
  • Click Start > Run
  • Type Inetcpl.cpl and click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected and Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to Prompt, and ("Initialize and Script ActiveX controls not marked as safe") to Disable.
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
2. Update your Anti-Virus Software - I can not overemphasize the need for you to update your Anti-virus application on a regular basis.  With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. Make sure you keep your Windows OS current by visiting Windows update   regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

4. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

5. Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI