This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

XP Malware Issues

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I have been having many problems with my computer running XP Professional and im pretty sure its a malware issue. I have ran many anti-virus scans and found and removed some viruses, but the problems are still happening.
When I start-up xp, the desktop loads without desk-top icons and without the task-bar. The temporary fix is to end explorer.exe in task manager and start it again in a new task. After this the desktop icons and task bar will load but I still have to wait about 10- 15 minutes before i can open a program such as firefox or itunes. Even after the computer is running ok, its still much slower and laggier than it used to be.
Ive research and looked online to try find a fix for corrupted explorer.exe as these symptoms sound similar to common xp issues, but im convinced that its a much bigger issue as these fixes didnt work for me.

Also ive noticed that as soon as I start my computer up, the avast icon in the system tray comes up with a red cross, then a yellow triangle with an explanation mark, and then it goes normal. Im pretty sure something is affecting the whole system.

Here is my HiJackThis log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:23:11, on 05/04/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.21073)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\lxedcoms.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NeoSmart Technologies\ToolTipFixer\ToolTipFixer.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Administrator\My Documents\Downloads\HiJackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/broadband
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = IE
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favorites
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common

Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Lexmark Printable Web - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable

Web\bho.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark

Toolbar\toolband.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [DriveSpace] C:\Program Files\Drive Space Indicator\DrvSpace.exe /NOTRAY
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [lxedmon.exe] "C:\Program Files\Lexmark S600 Series\lxedmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark S600 Series\ezprint.exe"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [True Transparency] "C:\Program Files\Utilities\True Transparency\TrueTransparency.exe" (User

'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK

SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O8 - Extra context menu item: Download with USDownloader - C:\Program Files\Universal Share

Downloader\Ext\downloadie.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Administrator\Application

Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google

Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -

C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) -

http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O20 - AppInit_DLLs: prio.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} -

C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} -

C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device

Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision

Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxedCATSCustConnectService - Lexmark International, Inc. -

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxedserv.exe
O23 - Service: lxed_device - - C:\WINDOWS\system32\lxedcoms.exe
O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol

120\StarWind\StarWindServiceAE.exe
O23 - Service: NST ToolTipFixer (TTFixerService) - NeoSmart Technologies - C:\Program Files\NeoSmart

Technologies\ToolTipFixer\ToolTipFixer.exe

–
End of file - 7840 bytes

Thank you, your help is much appreciated.

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, wallbanger

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
Hello there,

Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • If it needs to, DeFogger may ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.

===================================================

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click OK to load a custom scan from a file or Cancel to cancel"
  • Click the OK button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic
===================================================

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
===================================================

On your next reply please post :
OTL log
GMER log
Checkup log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
— OTL Log —-

OTL logfile created on: 06/04/2011 14:37:26 - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 75.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 16.39 Gb Free Space | 44.02% Space Free | Partition Type: NTFS
Drive D: | 697.06 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 465.65 Gb Total Space | 341.58 Gb Free Space | 73.36% Space Free | Partition Type: FAT32
Drive F: | 564.73 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: FAMILY | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Lexmark S600 Series\ezprint.exe ()
PRC - C:\Program Files\Lexmark S600 Series\lxedmon.exe ()
PRC - C:\WINDOWS\system32\lxedcoms.exe ( )
PRC - C:\Program Files\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
PRC - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe (Raxco Software, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Drive Space Indicator\DrvSpace.exe ()
PRC - C:\Program Files\NeoSmart Technologies\ToolTipFixer\ToolTipFixer.exe (NeoSmart Technologies)
PRC - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)


========== Modules (SafeList) ==========

MOD - C:\Users\Administrator\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Alwil Software\Avast5\snxhk.dll (AVAST Software)
MOD - C:\Program Files\Alwil Software\Avast5\ashShell.dll (AVAST Software)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\GdiPlus.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5508_x-ww_35d3ce4a\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\sti.dll (Microsoft Corporation)
MOD - C:\Program Files\Prio\prio.dll (O&K; Software)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (lxed_device) – C:\WINDOWS\System32\lxedcoms.exe ( )
SRV - (lxedCATSCustConnectService) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxedserv.exe ()
SRV - (PD91Engine) – C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe (Raxco Software, Inc.)
SRV - (PD91Agent) – C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe (Raxco Software, Inc.)
SRV - (TTFixerService) – C:\Program Files\NeoSmart Technologies\ToolTipFixer\ToolTipFixer.exe (NeoSmart Technologies)
SRV - (StarWindServiceAE) – C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
SRV - (dlbt_device) – C:\WINDOWS\System32\dlbtcoms.exe (Dell)


========== Driver Services (SafeList) ==========

DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (mcdbus) – C:\WINDOWS\system32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (DefragFS) – C:\WINDOWS\System32\drivers\DefragFS.sys (Raxco Software, Inc.)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (Prio) – C:\WINDOWS\System32\drivers\prio.sys (Xeno)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (L8042Kbd) – C:\WINDOWS\system32\drivers\L8042Kbd.sys (Logitech Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/broadband
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\AV, = http://www.altavista.com/sites/search/web?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\FM, = http://www.filemirrors.com/search.src?file=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\GGL, = http://www.google.com/search?q=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\MSKB, = http://support.microsoft.com/?kbid=%s
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\MSN, = http://search.msn.com/results.asp?q=%s
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 48
FF - prefs.js..extensions.enabledItems: {0FED7D55-65D4-47b6-A6DE-9A4ADB55355F}:1.0.1
FF - prefs.js..extensions.enabledItems: {987311C6-B504-4aa2-90BF-60CC49808D42}:2.2
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.7.2
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: [removed]:1.2.2
FF - prefs.js..extensions.enabledItems: {6e84150a-d526-41f1-a480-a67d3fed910d}:[removed]
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.6.1
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.4
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: [removed]:2.1
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&q;="

FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/03 12:06:38 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/06 14:24:14 | 000,000,000 | —D | M]

[2009/10/05 15:32:33 | 000,000,000 | —D | M] (No name found) – C:\Users\Administrator\Application Data\Mozilla\Extensions
[2011/04/03 12:20:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Administrator\Application Data\Mozilla\Firefox\Profiles\2kdcrdfm.default\extensions
[2010/08/02 21:43:58 | 000,000,000 | —D | M] (Auto Copy) – C:\Users\Administrator\Application Data\Mozilla\Firefox\Profiles\2kdcrdfm.default\extensions\{0FED7D55-65D4-47b6-A6DE-9A4ADB55355F}
[2011/02/05 19:01:42 | 000,000,000 | —D | M] (PDF Download) – C:\Users\Administrator\Application Data\Mozilla\Firefox\Profiles\2kdcrdfm.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2010/02/21 21:48:50 | 000,000,000 | —D | M] (IE View) – C:\Users\Administrator\Application Data\Mozilla\Firefox\Profiles\2kdcrdfm.default\extensions\{6e84150a-d526-41f1-a480-a67d3fed910d}
[2009/11/30 19:01:24 | 000,000,000 | —D | M] (BugMeNot) – C:\Users\Administrator\Application Data\Mozilla\Firefox\Profiles\2kdcrdfm.default\extensions\{987311C6-B504-4aa2-90BF-60CC49808D42}
[2011/01/05 15:00:42 | 000,000,000 | —D | M] ("DVDVideoSoft Menu") – C:\Users\Administrator\Application Data\Mozilla\Firefox\Profiles\2kdcrdfm.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011/04/03 12:20:47 | 000,000,000 | —D | M] (No name found) – C:\Users\Administrator\Application Data\Mozilla\Firefox\Profiles\2kdcrdfm.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2009/10/06 03:18:14 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Users\Administrator\Application Data\Mozilla\Firefox\Profiles\2kdcrdfm.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/08/02 21:44:02 | 000,000,000 | —D | M] (Fast Youtube Downloader) – C:\Users\Administrator\Application Data\Mozilla\Firefox\Profiles\2kdcrdfm.default\extensions\[removed]
[2010/12/28 20:00:11 | 000,000,000 | —D | M] ("YouTube Auto Replay") – C:\Users\Administrator\Application Data\Mozilla\Firefox\Profiles\2kdcrdfm.default\extensions\[removed]
[2011/04/03 12:20:46 | 000,000,000 | —D | M] (No name found) – C:\Users\Administrator\Application Data\Mozilla\Firefox\Profiles\2kdcrdfm.default\extensions\{dc572301-7619-498c-a57d-39143191b318}\modules\extensions
[2011/04/03 12:06:38 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) –
() (No name found) – C:\USERS\ADMINISTRATOR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\2KDCRDFM.DEFAULT\EXTENSIONS\{A0D7CCB3-214D-498B-B4AA-0E8FDA9A7BF7}.XPI
() (No name found) – C:\USERS\ADMINISTRATOR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\2KDCRDFM.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\ADMINISTRATOR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\2KDCRDFM.DEFAULT\EXTENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI
() (No name found) – C:\USERS\ADMINISTRATOR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\2KDCRDFM.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
() (No name found) – C:\USERS\ADMINISTRATOR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\2KDCRDFM.DEFAULT\EXTENSIONS\[removed]
[2009/10/11 11:59:13 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/03/18 18:53:24 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 09:00:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/04/04 01:44:03 | 000,431,524 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14855 more lines…
O2 - BHO: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Lexmark Printable Web) - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll ()
O3 - HKLM\..\Toolbar: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Lexmark Toolbar) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll ()
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DriveSpace] C:\Program Files\Drive Space Indicator\DrvSpace.exe ()
O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark S600 Series\ezprint.exe ()
O4 - HKLM..\Run: [lxedmon.exe] C:\Program Files\Lexmark S600 Series\lxedmon.exe ()
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Users\Administrator\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuFavorites = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MemCheckBoxInRunDlg = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LockTaskbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O8 - Extra context menu item: Download with USDownloader - C:\Program Files\Universal Share Downloader\Ext\downloadie.html ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Administrator\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - AppInit_DLLs: (prio.dll) - C:\Program Files\Prio\prio.dll (O&K; Software)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Users\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/04 09:39:57 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [1999/01/19 12:37:14 | 002,119,160 | R— | M] () - D:\AUTOPLAY.WAV – [ CDFS ]
O32 - AutoRun File - [1999/07/16 16:54:52 | 000,532,480 | R— | M] () - D:\AUTORUN.EXE – [ CDFS ]
O32 - AutoRun File - [2003/01/28 12:10:26 | 000,000,050 | R— | M] () - D:\Autorun.inf – [ CDFS ]
O32 - AutoRun File - [2007/08/21 22:18:24 | 000,000,000 | —D | M] - E:\autorun – [ FAT32 ]
O32 - AutoRun File - [2005/11/15 11:08:04 | 000,000,036 | -H– | M] () - E:\autorun.inf – [ FAT32 ]
O32 - AutoRun File - [1998/10/29 12:34:42 | 001,641,984 | R— | M] () - F:\AUTORUN.EXE – [ CDFS ]
O32 - AutoRun File - [1996/06/04 20:07:26 | 000,000,051 | R— | M] () - F:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\{b547b438-b4eb-11df-9251-000f1f57021a}\Shell\AutoRun\command - "" = H:\PMBP_Win.exe
O34 - HKLM BootExecute: (PDBoot.exe) - C:\WINDOWS\System32\PDBoot.exe (Raxco Software, Inc.)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.I420 - C:\WINDOWS\System32\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56027131116781568)

========== Files/Folders - Created Within 30 Days ==========

[2011/04/06 14:25:25 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Administrator\Desktop\OTL.exe
[2011/04/05 18:10:33 | 000,000,000 | —D | C] – C:\Users\Administrator\Start Menu\Programs\Westwood
[2011/04/05 18:08:01 | 000,299,520 | —- | C] (InstallShield Corporation, Inc.) – C:\WINDOWS\uninst.exe
[2011/04/05 18:07:58 | 000,000,000 | —D | C] – C:\Users\Administrator\WINDOWS
[2011/04/05 17:44:56 | 000,000,000 | —D | C] – C:\Users\Administrator\Start Menu\Programs\MagicDisc
[2011/04/05 17:44:44 | 000,116,736 | —- | C] (MagicISO, Inc.) – C:\WINDOWS\System32\drivers\mcdbus.sys
[2011/04/05 17:44:42 | 000,000,000 | —D | C] – C:\Program Files\MagicDisc
[2011/04/04 23:05:36 | 000,000,000 | —D | C] – C:\Users\All Users\Application Data\SUPERAntiSpyware.com
[2011/04/04 23:05:36 | 000,000,000 | —D | C] – C:\Users\Administrator\Application Data\SUPERAntiSpyware.com
[2011/04/04 23:05:11 | 000,000,000 | —D | C] – C:\Users\All Users\Start Menu\Programs\SUPERAntiSpyware
[2011/04/04 23:05:06 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2011/04/04 17:20:07 | 000,000,000 | —D | C] – C:\Users\Administrator\Application Data\Malwarebytes
[2011/04/04 17:19:38 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/04/04 17:19:38 | 000,000,000 | —D | C] – C:\Users\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/04/04 17:19:37 | 000,000,000 | —D | C] – C:\Users\All Users\Application Data\Malwarebytes
[2011/04/04 17:19:25 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/04/04 17:19:24 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/04/04 00:11:51 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2011/04/03 22:54:42 | 000,000,000 | RH-D | C] – C:\Users\Administrator\Recent
[2011/04/03 22:40:55 | 000,000,000 | —D | C] – C:\Users\All Users\Start Menu\Programs\CCleaner
[2011/04/03 12:14:05 | 000,371,544 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSnx.sys
[2010/06/29 13:47:57 | 000,425,984 | —- | C] ( ) – C:\WINDOWS\System32\lxedcoin.dll
[2010/06/29 13:39:28 | 000,364,544 | —- | C] ( ) – C:\WINDOWS\System32\lxedinpa.dll
[2010/06/29 13:39:28 | 000,356,352 | —- | C] ( ) – C:\WINDOWS\System32\LXEDhcp.dll
[2010/06/29 13:39:27 | 000,847,872 | —- | C] ( ) – C:\WINDOWS\System32\lxedusb1.dll
[2010/06/29 13:39:27 | 000,344,064 | —- | C] ( ) – C:\WINDOWS\System32\lxediesc.dll
[2010/06/29 13:39:26 | 001,044,480 | —- | C] ( ) – C:\WINDOWS\System32\lxedserv.dll
[2010/06/29 13:39:25 | 000,643,072 | —- | C] ( ) – C:\WINDOWS\System32\lxedpmui.dll
[2010/06/29 13:39:25 | 000,569,344 | —- | C] ( ) – C:\WINDOWS\System32\lxedlmpm.dll
[2010/06/29 13:39:23 | 000,324,264 | —- | C] ( ) – C:\WINDOWS\System32\lxedih.exe
[2010/06/29 13:39:22 | 000,679,936 | —- | C] ( ) – C:\WINDOWS\System32\lxedhbn3.dll
[2010/06/29 13:39:20 | 000,598,696 | —- | C] ( ) – C:\WINDOWS\System32\lxedcoms.exe
[2010/06/29 13:39:20 | 000,372,736 | —- | C] ( ) – C:\WINDOWS\System32\lxedcomm.dll
[2010/06/29 13:39:19 | 000,802,816 | —- | C] ( ) – C:\WINDOWS\System32\lxedcomc.dll
[2010/06/29 13:39:19 | 000,369,320 | —- | C] ( ) – C:\WINDOWS\System32\lxedcfg.exe
[2008/04/01 00:31:03 | 000,180,224 | —- | C] ( ) – C:\WINDOWS\System32\driverbackup.exe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Users\All Users\*.tmp files -> C:\Users\All Users\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/04/06 14:25:29 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Administrator\Desktop\OTL.exe
[2011/04/06 14:24:15 | 000,001,729 | —- | M] () – C:\Users\All Users\Desktop\Adobe Reader 9.lnk
[2011/04/06 10:29:17 | 000,000,428 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.ics
[2011/04/06 10:11:24 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/04/05 19:33:59 | 000,000,803 | —- | M] () – C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Explorer (2).lnk
[2011/04/05 19:07:03 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/04/05 17:44:56 | 000,000,652 | —- | M] () – C:\Users\Administrator\Start Menu\Programs\Startup\MagicDisc.lnk
[2011/04/05 17:16:22 | 000,002,155 | —- | M] () – C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2011/04/05 14:40:16 | 000,002,137 | —- | M] () – C:\Users\All Users\Desktop\iTunes.lnk
[2011/04/04 12:51:57 | 006,099,072 | —- | M] () – C:\Users\Administrator\Desktop\Zeds Dead ft. Omar Linx - Out For Blood.mp3
[2011/04/04 12:50:27 | 006,916,224 | —- | M] () – C:\Users\Administrator\Desktop\Skream - Guitar Hero.mp3
[2011/04/04 12:43:19 | 003,072,128 | —- | M] () – C:\Users\Administrator\Desktop\Doctor P - Watch Out (New 2011).mp3
[2011/04/04 12:40:42 | 002,097,280 | —- | M] () – C:\Users\Administrator\Desktop\Wiley - Gangsters.mp3
[2011/04/04 12:37:49 | 002,601,088 | —- | M] () – C:\Users\Administrator\Desktop\Emalkay 'Fabrication' Official Video - OUT NOW on Dub Police..mp3
[2011/04/04 12:35:59 | 004,489,344 | —- | M] () – C:\Users\Administrator\Desktop\Zeds Dead - Dark Side Dub.mp3
[2011/04/04 12:32:25 | 004,886,656 | —- | M] () – C:\Users\Administrator\Desktop\Numbernin6- Beneath The Boards [HQ].mp3
[2011/04/04 12:27:22 | 007,403,648 | —- | M] () – C:\Users\Administrator\Desktop\Numbernin6 - Nebulous (HQ).mp3
[2011/04/04 12:19:44 | 004,409,472 | —- | M] () – C:\Users\Administrator\Desktop\Skrillex - 'Kill Everybody (Bare Noize Remix)'.mp3
[2011/04/04 12:17:55 | 005,097,600 | —- | M] () – C:\Users\Administrator\Desktop\Skrillex - Scatta (Ft. Foreign Beggars And Bare Noize).mp3
[2011/04/04 12:10:21 | 006,582,400 | —- | M] () – C:\Users\Administrator\Desktop\SKRILLEX - Scary Monsters And Nice Sprites.mp3
[2011/04/04 12:05:03 | 000,000,892 | —- | M] () – C:\Users\Administrator\Desktop\DVDVideoSoft Free Studio.lnk
[2011/04/04 12:04:01 | 000,001,051 | —- | M] () – C:\Users\Administrator\Desktop\Free YouTube to MP3 Converter.lnk
[2011/04/04 01:44:03 | 000,431,524 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/04/04 00:29:29 | 000,000,231 | -HS- | M] () – C:\boot.ini
[2011/04/03 12:14:05 | 000,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2011/04/03 12:06:43 | 000,000,742 | —- | M] () – C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/04/03 12:06:43 | 000,000,724 | —- | M] () – C:\Users\All Users\Desktop\Mozilla Firefox.lnk
[2011/04/03 11:16:16 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/03/27 20:15:32 | 000,441,432 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/03/27 20:15:31 | 000,071,176 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Users\All Users\*.tmp files -> C:\Users\All Users\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/05 19:33:59 | 000,000,803 | —- | C] () – C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Explorer (2).lnk
[2011/04/05 18:10:09 | 000,069,632 | —- | C] () – C:\WINDOWS\UNINSTCC.EXE
[2011/04/05 17:44:56 | 000,000,652 | —- | C] () – C:\Users\Administrator\Start Menu\Programs\Startup\MagicDisc.lnk
[2011/04/05 17:16:17 | 000,002,155 | —- | C] () – C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2011/04/04 12:51:03 | 006,099,072 | —- | C] () – C:\Users\Administrator\Desktop\Zeds Dead ft. Omar Linx - Out For Blood.mp3
[2011/04/04 12:49:33 | 006,916,224 | —- | C] () – C:\Users\Administrator\Desktop\Skream - Guitar Hero.mp3
[2011/04/04 12:42:35 | 003,072,128 | —- | C] () – C:\Users\Administrator\Desktop\Doctor P - Watch Out (New 2011).mp3
[2011/04/04 12:40:10 | 002,097,280 | —- | C] () – C:\Users\Administrator\Desktop\Wiley - Gangsters.mp3
[2011/04/04 12:37:13 | 002,601,088 | —- | C] () – C:\Users\Administrator\Desktop\Emalkay 'Fabrication' Official Video - OUT NOW on Dub Police..mp3
[2011/04/04 12:35:20 | 004,489,344 | —- | C] () – C:\Users\Administrator\Desktop\Zeds Dead - Dark Side Dub.mp3
[2011/04/04 12:30:10 | 004,886,656 | —- | C] () – C:\Users\Administrator\Desktop\Numbernin6- Beneath The Boards [HQ].mp3
[2011/04/04 12:24:25 | 007,403,648 | —- | C] () – C:\Users\Administrator\Desktop\Numbernin6 - Nebulous (HQ).mp3
[2011/04/04 12:19:02 | 004,409,472 | —- | C] () – C:\Users\Administrator\Desktop\Skrillex - 'Kill Everybody (Bare Noize Remix)'.mp3
[2011/04/04 12:16:32 | 005,097,600 | —- | C] () – C:\Users\Administrator\Desktop\Skrillex - Scatta (Ft. Foreign Beggars And Bare Noize).mp3
[2011/04/04 12:09:23 | 006,582,400 | —- | C] () – C:\Users\Administrator\Desktop\SKRILLEX - Scary Monsters And Nice Sprites.mp3
[2011/04/03 12:06:42 | 000,000,730 | —- | C] () – C:\Users\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2010/11/22 17:02:54 | 000,166,696 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/06/29 13:48:05 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxedvs.dll
[2010/06/29 13:47:40 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\lxedgcfg.dll
[2010/06/29 13:47:38 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\lxedcuir.dll
[2010/06/29 13:47:37 | 000,294,912 | —- | C] () – C:\WINDOWS\System32\lxedcui.dll
[2010/06/29 13:39:48 | 000,000,044 | -H– | C] () – C:\WINDOWS\System32\lxedrwrd.ini
[2010/06/29 13:39:28 | 000,327,680 | —- | C] () – C:\WINDOWS\System32\LXEDinst.dll
[2010/06/29 13:39:24 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\lxedinsb.dll
[2010/06/29 13:39:24 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\lxedinsr.dll
[2010/06/29 13:39:24 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\lxedjswr.dll
[2010/06/29 13:39:23 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\lxedins.dll
[2010/06/29 13:39:22 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\lxedgrd.dll
[2010/06/29 13:39:21 | 000,253,952 | —- | C] () – C:\WINDOWS\System32\lxedcu.dll
[2010/06/29 13:39:21 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\lxedcub.dll
[2010/06/29 13:39:21 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\lxedcur.dll
[2010/06/29 13:37:42 | 000,023,552 | —- | C] () – C:\WINDOWS\System32\LXEDsmr.dll
[2010/06/29 13:37:41 | 000,299,008 | —- | C] () – C:\WINDOWS\System32\LXEDsm.dll
[2009/12/23 20:41:29 | 000,003,584 | —- | C] () – C:\Users\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/22 13:33:46 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2009/10/11 08:58:57 | 000,034,308 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2009/10/11 03:28:31 | 000,000,648 | —- | C] () – C:\WINDOWS\dellstat.ini
[2009/10/11 03:24:07 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dlbtinsb.dll
[2009/10/11 03:24:07 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\dlbtins.dll
[2009/10/11 03:24:07 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\dlbtinsr.dll
[2009/10/11 03:24:07 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\dlbtcub.dll
[2009/10/11 03:24:07 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlbtvs.dll
[2009/10/11 03:24:05 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\dlbtcu.dll
[2009/10/11 03:24:05 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\dlbtcur.dll
[2009/10/11 03:24:04 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\dlbtcoin.dll
[2009/10/11 03:24:04 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\dlbtjswr.dll
[2009/10/11 03:24:04 | 000,126,976 | —- | C] () – C:\WINDOWS\System32\dlbtsnls.dll
[2009/10/11 03:24:00 | 000,397,312 | —- | C] () – C:\WINDOWS\System32\dlbtutil.dll
[2009/10/04 19:19:57 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/10/04 19:05:30 | 001,913,168 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/10/04 15:48:53 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/10/04 10:21:15 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/10/04 09:55:22 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/10/04 09:35:14 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/10/04 09:31:28 | 000,708,272 | —- | C] () – C:\WINDOWS\System32\Universal Silent Switch Finder.exe
[2009/10/04 09:31:20 | 000,394,752 | —- | C] () – C:\WINDOWS\System32\cygwinb19.dll
[2009/10/04 09:31:10 | 004,542,464 | —- | C] () – C:\WINDOWS\System32\Prime95.exe
[2008/04/01 00:31:03 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2008/04/01 00:31:03 | 000,888,320 | —- | C] () – C:\WINDOWS\System32\mjplayer.exe
[2008/04/01 00:31:03 | 000,693,792 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2008/04/01 00:31:03 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/01 00:31:03 | 000,441,432 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2008/04/01 00:31:03 | 000,345,600 | —- | C] () – C:\WINDOWS\System32\SAFEXP.EXE
[2008/04/01 00:31:03 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/01 00:31:03 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/01 00:31:03 | 000,185,516 | —- | C] () – C:\WINDOWS\System32\cmdhide.exe
[2008/04/01 00:31:03 | 000,155,720 | —- | C] () – C:\WINDOWS\System32\CDR.exe
[2008/04/01 00:31:03 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\CABARC.EXE
[2008/04/01 00:31:03 | 000,071,176 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2008/04/01 00:31:03 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\XXMKLINK.EXE
[2008/04/01 00:31:03 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\SetRes.exe
[2008/04/01 00:31:03 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/01 00:31:03 | 000,031,232 | —- | C] () – C:\WINDOWS\System32\cmdow.exe
[2008/04/01 00:31:03 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\renuser.exe
[2008/04/01 00:31:03 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/01 00:31:03 | 000,026,013 | —- | C] () – C:\WINDOWS\System32\sleep.exe
[2008/04/01 00:31:03 | 000,022,528 | —- | C] () – C:\WINDOWS\System32\MonOff.exe
[2008/04/01 00:31:03 | 000,019,083 | —- | C] () – C:\WINDOWS\System32\DELTREE.EXE
[2008/04/01 00:31:03 | 000,013,339 | —- | C] () – C:\WINDOWS\System32\WAIT.EXE
[2008/04/01 00:31:03 | 000,008,636 | —- | C] () – C:\WINDOWS\System32\MODIFYPE.EXE
[2008/04/01 00:31:03 | 000,006,656 | —- | C] () – C:\WINDOWS\System32\taskill.exe
[2008/04/01 00:31:03 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/01 00:31:03 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2008/04/01 00:31:03 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/04/01 00:31:03 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2008/04/01 00:31:03 | 000,000,367 | —- | C] () – C:\WINDOWS\System32\Oeminfo.ini
[1997/06/14 02:56:08 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\iyvu9_32.dll

========== Custom Scans ==========


< >

< %SYSTEMDRIVE%\*.* >
[2009/10/04 09:39:57 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/04/04 00:29:29 | 000,000,231 | -HS- | M] () – C:\boot.ini
[2009/10/04 09:39:57 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/10/04 09:39:57 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/10/04 09:39:57 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/01 00:31:03 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/01 00:31:03 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/04/06 10:11:17 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2009/10/05 03:12:29 | 000,000,184 | —- | M] () – C:\setuplog.exe
[2009/10/04 10:27:14 | 000,013,873 | —- | M] () – C:\WPI_Log.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 05:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 04:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 05:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 04:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/10/04 09:39:10 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/02/28 05:57:40 | 000,075,264 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\DLBTPP5C.DLL
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/06/19 09:58:00 | 000,157,696 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\lxeddrpp.dll
[2008/07/06 11:50:04 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/02/23 15:04:21 | 000,040,648 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/10/04 19:05:06 | 000,098,304 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/10/04 19:05:06 | 001,089,536 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/10/04 19:05:06 | 000,897,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/10/04 09:40:04 | 000,000,231 | -HS- | M] () – C:\Users\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >
[2009/10/04 09:53:24 | 000,000,356 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\MSIc0c00.LOG
[1 C:\WINDOWS\system32\config\systemprofile\*.tmp files -> C:\WINDOWS\system32\config\systemprofile\*.tmp -> ]

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/10/04 10:33:43 | 000,000,060 | -HS- | M] () – C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/10/04 10:33:43 | 000,000,079 | —- | M] () – C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/04/06 14:25:29 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Administrator\Desktop\OTL.exe
[2010/08/04 15:15:08 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Users\Administrator\Desktop\setup-spybotsd162.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2009-10-11 10:59:30

< End of report >



—- Extras.txt —–



OTL Extras logfile created on: 06/04/2011 14:30:00 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 75.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 16.39 Gb Free Space | 44.02% Space Free | Partition Type: NTFS
Drive D: | 697.06 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 465.65 Gb Total Space | 341.58 Gb Free Space | 73.36% Space Free | Partition Type: FAT32
Drive F: | 564.73 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: FAMILY | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [CmdHere] – C:\WINDOWS\system32\cmd.exe /k cd "%1" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\FlashGet\flashget.exe" = C:\Program Files\FlashGet\flashget.exe:*:Enabled:Flashget
"C:\Program Files\uTorrent\utorrent.exe" = C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent
"C:\Program Files\Microsoft Games\Age of Empires II\empires2.EXE" = C:\Program Files\Microsoft Games\Age of Empires II\empires2.EXE:*:Enabled:Age of Empires II – (Microsoft Corporation)
"C:\WINDOWS\system32\dplaysvr.exe" = C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper – (Microsoft Corporation)
"C:\WINDOWS\system32\lxedcoms.exe" = C:\WINDOWS\system32\lxedcoms.exe:*:Enabled:S600 Series Server – ( )
"C:\Program Files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe" = C:\Program Files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:*:Enabled:ABBYY FineReader – (ABBYY (BIT Software))
"C:\Westwood\SUN\PATCHGET.DAT" = C:\Westwood\SUN\PATCHGET.DAT:*:Enabled:patchgrabber – (Westwood Studios)
"C:\Westwood\SUN\GAME.ICD" = C:\Westwood\SUN\GAME.ICD:*:Enabled:Main executable for Tiberian Sun – (Westwood Studios)
"C:\Westwood\SUN\Game.exe" = C:\Westwood\SUN\Game.exe:*:Enabled:Main executable for Tiberian Sun – (Westwood Studios)
"C:\Program Files\EA Games\Command & Conquer The First Decade\Command & Conquer™ Tiberian Sun™\SUN\Game.exe" = C:\Program Files\EA Games\Command & Conquer The First Decade\Command & Conquer™ Tiberian Sun™\SUN\Game.exe:*:Enabled:Main executable for Tiberian Sun – (Westwood Studios)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{1017A80C-6F09-4548-A84D-EDD6AC9525F0}" = Lexmark Toolbar
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2180B909-6C34-4777-AC7F-9D3F5480C4B6}" = Adobe Shockwave Player
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2B6EC03E-6FA0-4D7C-9CCE-1B03819AB613}" = PerfectDisk 2008 Professional
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4AE3A0CB-87B0-4F51-BECD-3D1F8DFDD62F}" = SAGEM F@st 800-840
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.3
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D1BB4446-AE9C-4256-9A7F-4D46604D2462}" = Adobe Setup
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D2C5E510-BE6D-42CC-9F61-E4F939078474}" = Lexmark Printable Web
"{DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}" = iTunes
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_2ac78060bc5856b0c1cf873bb919b58" = Adobe Photoshop CS3
"Age of Empires 2.0" = Microsoft Age of Empires II
"avast" = avast! Free Antivirus
"CCleaner" = CCleaner
"ClipName" = ClipName
"Command & Conquer 95" = Command & Conquer Windows 95
"CPLBonus" = Kel's CPL 24-in-One Bonus Pack!
"Dell Photo AIO Printer 922" = Dell Photo AIO Printer 922
"DriveSpace" = Drive Space Indicator
"FoxIt PDF Reader_is1" = FoxIt PDF Reader 2.2.2129
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4.7
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.9.35.324
"IrfanView" = IrfanView (remove only)
"Lexmark S600 Series" = Lexmark S600 Series
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 4.0 (x86 en-US)" = Mozilla Firefox 4.0 (x86 en-US)
"Notepad++" = Notepad++
"Piky Basket_is1" = Piky Basket 2.0
"Prio" = Prio v1.9.8
"SUPER ©" = SUPER © Version 2009.bld.36 (June 10, 2009)
"Switch" = Switch Sound File Converter
"ThumbView_Lite 1.0" = ThumbView_Lite 1.0
"Tiberian Sun" = Command & Conquer Tiberian Sun
"ToolTipFixer" = ToolTipFixer 1.0.1
"Uninstall_is1" = Uninstall 1.0.0.1
"USDownloader" = Universal Share Downloader
"USSF" = Universal Silent Switch Finder
"VLC media player" = VideoLAN VLC media player 0.8.6f
"WavePad" = WavePad Sound Editor
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WinSnap" = WinSnap
"WOLAPI" = Westwood Shared Internet Components
"Xilisoft Video Converter Ultimate" = Xilisoft Video Converter Ultimate
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 04/08/2010 06:41:12 | Computer Name = FAMILY | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 04/08/2010 06:41:12 | Computer Name = FAMILY | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 04/08/2010 06:41:27 | Computer Name = FAMILY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 04/08/2010 06:55:07 | Computer Name = FAMILY | Source = Google Update | ID = 20
Description =

Error - 04/08/2010 07:55:20 | Computer Name = FAMILY | Source = Google Update | ID = 20
Description =

Error - 04/08/2010 08:55:07 | Computer Name = FAMILY | Source = Google Update | ID = 20
Description =

Error - 07/08/2010 14:07:23 | Computer Name = FAMILY | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 08/08/2010 17:00:06 | Computer Name = FAMILY | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 08/08/2010 17:00:06 | Computer Name = FAMILY | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 08/08/2010 17:42:19 | Computer Name = FAMILY | Source = EventSystem | ID = 4614
Description = The COM+ Event System detected an inconsistency in its internal state.
The assertion "GetLastError() == 122L" failed at line 162 of d:\comxp_sp3\com\com1x\src\events\shared\sectools.cpp.
Please contact Microsoft Product Support Services to report this erro

[ System Events ]
Error - 15/01/2010 13:15:58 | Computer Name = FAMILY | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
ASH-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{8C9F737A-3E08-42C8-B5.
The
master browser is stopping or an election is being forced.

Error - 15/01/2010 14:28:04 | Computer Name = FAMILY | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
ASH-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{8C9F737A-3E08-42C8-B5.
The
master browser is stopping or an election is being forced.

Error - 17/01/2010 08:33:57 | Computer Name = FAMILY | Source = ipnathlp | ID = 30013
Description = The DHCP allocator has disabled itself on IP address 192.168.1.4, since
the IP address is outside the 192.168.0.0/255.255.255.0 scope from which addresses
are being allocated to DHCP clients. To enable the DHCP allocator on this IP address,
please
change the scope to include the IP address, or change the IP address to fall within
the scope.

Error - 18/01/2010 17:46:49 | Computer Name = FAMILY | Source = ipnathlp | ID = 30013
Description = The DHCP allocator has disabled itself on IP address 192.168.1.4, since
the IP address is outside the 192.168.0.0/255.255.255.0 scope from which addresses
are being allocated to DHCP clients. To enable the DHCP allocator on this IP address,
please
change the scope to include the IP address, or change the IP address to fall within
the scope.

Error - 19/01/2010 16:11:12 | Computer Name = FAMILY | Source = ipnathlp | ID = 30013
Description = The DHCP allocator has disabled itself on IP address 192.168.1.4, since
the IP address is outside the 192.168.0.0/255.255.255.0 scope from which addresses
are being allocated to DHCP clients. To enable the DHCP allocator on this IP address,
please
change the scope to include the IP address, or change the IP address to fall within
the scope.

Error - 20/01/2010 12:35:47 | Computer Name = FAMILY | Source = ipnathlp | ID = 30013
Description = The DHCP allocator has disabled itself on IP address 192.168.1.4, since
the IP address is outside the 192.168.0.0/255.255.255.0 scope from which addresses
are being allocated to DHCP clients. To enable the DHCP allocator on this IP address,
please
change the scope to include the IP address, or change the IP address to fall within
the scope.

Error - 20/01/2010 12:42:56 | Computer Name = FAMILY | Source = ipnathlp | ID = 30013
Description = The DHCP allocator has disabled itself on IP address 192.168.1.4, since
the IP address is outside the 192.168.0.0/255.255.255.0 scope from which addresses
are being allocated to DHCP clients. To enable the DHCP allocator on this IP address,
please
change the scope to include the IP address, or change the IP address to fall within
the scope.

Error - 20/01/2010 19:15:46 | Computer Name = FAMILY | Source = ipnathlp | ID = 30013
Description = The DHCP allocator has disabled itself on IP address 192.168.1.4, since
the IP address is outside the 192.168.0.0/255.255.255.0 scope from which addresses
are being allocated to DHCP clients. To enable the DHCP allocator on this IP address,
please
change the scope to include the IP address, or change the IP address to fall within
the scope.

Error - 26/01/2010 18:06:20 | Computer Name = FAMILY | Source = ipnathlp | ID = 30013
Description = The DHCP allocator has disabled itself on IP address 192.168.1.4, since
the IP address is outside the 192.168.0.0/255.255.255.0 scope from which addresses
are being allocated to DHCP clients. To enable the DHCP allocator on this IP address,
please
change the scope to include the IP address, or change the IP address to fall within
the scope.

Error - 27/01/2010 11:41:34 | Computer Name = FAMILY | Source = ipnathlp | ID = 30013
Description = The DHCP allocator has disabled itself on IP address 192.168.1.4, since
the IP address is outside the 192.168.0.0/255.255.255.0 scope from which addresses
are being allocated to DHCP clients. To enable the DHCP allocator on this IP address,
please
change the scope to include the IP address, or change the IP address to fall within
the scope.


< End of report >



—- Check-up Log ——



Results of screen317's Security Check version 0.99.10
Windows XP Service Pack 3
Internet Explorer 7 Out of date!
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
avast! Free Antivirus
Antivirus up to date!
```````````````````````````````
Anti-malware/Other Utilities Check:

MVPS Hosts File
Malwarebytes' Anti-Malware
CCleaner
Java™ 6 Update 5
Out of date Java installed!
Adobe Flash Player 10.2.153.1
Adobe Reader 9.4.3
Out of date Adobe Reader installed!
Mozilla Firefox (x86 en-US..)
````````````````````````````````
Process Check:
objlist.exe by Laurent

Alwil Software Avast5 AvastSvc.exe
ALWILS~1 Avast5 avastUI.exe
``````````End of Log````````````


Thanks!
I tried to upload and attach it but didnt work. Heres the gmer log:

GMER 1.0.15.15570 - http://www.gmer.net
Rootkit scan 2011-04-06 15:00:43
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST340014A rev.8.16
Running: goeikn5s.exe; Driver: C:\Users\ADMINI~1\LOCALS~1\Temp\pxtdypod.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0xB14419CA]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0xB1496A68]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwClose [0xB1461AF5]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0xB1443EAC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0xB1443F04]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0xB144401A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateKey [0xB14614A9]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0xB1443E02]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0xB1443F54]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0xB1443E56]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0xB1443FC8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0xB14419EE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteKey [0xB14621BB]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteValueKey [0xB1462471]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDuplicateObject [0xB144429E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateKey [0xB1462026]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateValueKey [0xB1461E91]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0xB1496B18]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0xB14417B8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0xB1441A12]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0xB1444412]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0xB14424AA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0xB1443EDC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0xB1443F2C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0xB1444044]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenKey [0xB1461805]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0xB1443E2E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenProcess [0xB14440D6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0xB1443F94]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0xB1443E84]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenThread [0xB14441BA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0xB1443FF2]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0xB1496BB0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryKey [0xB1461D0C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0xB1442370]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryValueKey [0xB1461B5E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwRenameKey [0xB149EE26]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwRestoreKey [0xB1460B1C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0xB1441A36]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0xB1441A5A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0xB1441812]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0xB144194E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetValueKey [0xB14622C2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0xB144192A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0xB1441972]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xB1640620]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0xB1441A7E]

INT 0x62 ? 8A6E5BF8
INT 0x63 ? 8A54EBF8
INT 0x82 ? 8A6E5BF8
INT 0xA4 ? 8A54EBF8
INT 0xB4 ? 8A54EBF8

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0xB14AB8DE]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject

—- Kernel code sections - GMER 1.0.15 —-

PAGE ntoskrnl.exe!ObInsertObject 8056503A 5 Bytes JMP B14A8D38 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntoskrnl.exe!ZwReplyWaitReceivePortEx + 3CC 8056B712 4 Bytes CALL B1442E25 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntoskrnl.exe!ZwCreateProcessEx 8057FC6C 7 Bytes JMP B14AB8E2 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntoskrnl.exe!ObMakeTemporaryObject 8059F85D 5 Bytes JMP B14A729E \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
? spbq.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload B9D118AC 5 Bytes JMP 8A54E1D8
init C:\WINDOWS\system32\drivers\senfilt.sys entry point in "init" section [0xB9A5BF80]
.text aad131z5.SYS B9971384 1 Byte [20]
.text aad131z5.SYS B9971384 37 Bytes [20, 00, 00, 68, 00, 00, 00, …]
.text aad131z5.SYS B99713AA 24 Bytes [00, 00, 20, 00, 00, E0, 00, …]
.text aad131z5.SYS B99713C4 3 Bytes [00, 00, 00]
.text aad131z5.SYS B99713C9 1 Byte [00]
.text …

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\ctfmon.exe[160] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 000A0030
.text C:\WINDOWS\system32\ctfmon.exe[160] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 000A006C
.text C:\WINDOWS\system32\ctfmon.exe[160] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002C01D4
.text C:\WINDOWS\system32\ctfmon.exe[160] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002C00E4
.text C:\WINDOWS\system32\ctfmon.exe[160] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002C0120
.text C:\WINDOWS\system32\ctfmon.exe[160] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002C015C
.text C:\WINDOWS\system32\ctfmon.exe[160] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002C0198
.text C:\WINDOWS\system32\ctfmon.exe[160] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002C0030
.text C:\WINDOWS\system32\ctfmon.exe[160] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002C006C
.text C:\WINDOWS\system32\ctfmon.exe[160] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002C00A8
.text C:\WINDOWS\system32\ctfmon.exe[160] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002D00E4
.text C:\WINDOWS\system32\ctfmon.exe[160] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002D0120
.text C:\WINDOWS\system32\ctfmon.exe[160] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002D00A8
.text C:\WINDOWS\system32\ctfmon.exe[160] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002D0030
.text C:\WINDOWS\system32\ctfmon.exe[160] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002D006C
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[184] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00050030
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[184] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0005006C
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[184] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002A00E4
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[184] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002A0120
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[184] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002A00A8
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[184] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002A0030
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[184] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002A006C
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[184] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[184] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[184] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[184] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[184] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[184] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[184] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[184] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\explorer.exe[200] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00090030
.text C:\WINDOWS\explorer.exe[200] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0009006C
.text C:\WINDOWS\explorer.exe[200] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 004A01D4
.text C:\WINDOWS\explorer.exe[200] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 004A00E4
.text C:\WINDOWS\explorer.exe[200] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 004A0120
.text C:\WINDOWS\explorer.exe[200] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 004A015C
.text C:\WINDOWS\explorer.exe[200] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 004A0198
.text C:\WINDOWS\explorer.exe[200] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 004A0030
.text C:\WINDOWS\explorer.exe[200] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 004A006C
.text C:\WINDOWS\explorer.exe[200] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 004A00A8
.text C:\WINDOWS\explorer.exe[200] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 004B00E4
.text C:\WINDOWS\explorer.exe[200] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 004B0120
.text C:\WINDOWS\explorer.exe[200] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 004B00A8
.text C:\WINDOWS\explorer.exe[200] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 004B0030
.text C:\WINDOWS\explorer.exe[200] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 004B006C
.text C:\Program Files\MagicDisc\MagicDisc.exe[324] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00140030
.text C:\Program Files\MagicDisc\MagicDisc.exe[324] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0014006C
.text C:\Program Files\MagicDisc\MagicDisc.exe[324] ADVAPI32.DLL!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003801D4
.text C:\Program Files\MagicDisc\MagicDisc.exe[324] ADVAPI32.DLL!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003800E4
.text C:\Program Files\MagicDisc\MagicDisc.exe[324] ADVAPI32.DLL!ChangeServiceConfigW 77E37001 5 Bytes JMP 00380120
.text C:\Program Files\MagicDisc\MagicDisc.exe[324] ADVAPI32.DLL!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0038015C
.text C:\Program Files\MagicDisc\MagicDisc.exe[324] ADVAPI32.DLL!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00380198
.text C:\Program Files\MagicDisc\MagicDisc.exe[324] ADVAPI32.DLL!CreateServiceA 77E37211 5 Bytes JMP 00380030
.text C:\Program Files\MagicDisc\MagicDisc.exe[324] ADVAPI32.DLL!CreateServiceW 77E373A9 5 Bytes JMP 0038006C
.text C:\Program Files\MagicDisc\MagicDisc.exe[324] ADVAPI32.DLL!DeleteService 77E374B1 5 Bytes JMP 003800A8
.text C:\Program Files\MagicDisc\MagicDisc.exe[324] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003900E4
.text C:\Program Files\MagicDisc\MagicDisc.exe[324] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390120
.text C:\Program Files\MagicDisc\MagicDisc.exe[324] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003900A8
.text C:\Program Files\MagicDisc\MagicDisc.exe[324] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00390030
.text C:\Program Files\MagicDisc\MagicDisc.exe[324] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0039006C
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe[348] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00140030
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe[348] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0014006C
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe[348] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003801D4
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe[348] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003800E4
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe[348] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00380120
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe[348] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0038015C
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe[348] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00380198
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe[348] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00380030
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe[348] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0038006C
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe[348] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003800A8
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe[348] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003900E4
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe[348] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390120
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe[348] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003900A8
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe[348] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00390030
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe[348] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0039006C
.text C:\WINDOWS\system32\winlogon.exe[688] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00070030
.text C:\WINDOWS\system32\winlogon.exe[688] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0007006C
.text C:\WINDOWS\system32\winlogon.exe[688] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 005301D4
.text C:\WINDOWS\system32\winlogon.exe[688] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 005300E4
.text C:\WINDOWS\system32\winlogon.exe[688] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00530120
.text C:\WINDOWS\system32\winlogon.exe[688] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0053015C
.text C:\WINDOWS\system32\winlogon.exe[688] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00530198
.text C:\WINDOWS\system32\winlogon.exe[688] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00530030
.text C:\WINDOWS\system32\winlogon.exe[688] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0053006C
.text C:\WINDOWS\system32\winlogon.exe[688] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 005300A8
.text C:\WINDOWS\system32\winlogon.exe[688] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 005400E4
.text C:\WINDOWS\system32\winlogon.exe[688] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00540120
.text C:\WINDOWS\system32\winlogon.exe[688] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 005400A8
.text C:\WINDOWS\system32\winlogon.exe[688] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00540030
.text C:\WINDOWS\system32\winlogon.exe[688] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0054006C
.text C:\WINDOWS\system32\services.exe[732] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00090030
.text C:\WINDOWS\system32\services.exe[732] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0009006C
.text C:\WINDOWS\system32\services.exe[732] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\system32\services.exe[732] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\system32\services.exe[732] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\system32\services.exe[732] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\system32\services.exe[732] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\system32\services.exe[732] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\system32\services.exe[732] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\system32\services.exe[732] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\system32\services.exe[732] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\system32\services.exe[732] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\system32\services.exe[732] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\system32\services.exe[732] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\system32\services.exe[732] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\WINDOWS\system32\lsass.exe[744] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00090030
.text C:\WINDOWS\system32\lsass.exe[744] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0009006C
.text C:\WINDOWS\system32\lsass.exe[744] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\system32\lsass.exe[744] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\system32\lsass.exe[744] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\system32\lsass.exe[744] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\system32\lsass.exe[744] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\system32\lsass.exe[744] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\system32\lsass.exe[744] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\system32\lsass.exe[744] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\system32\lsass.exe[744] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\system32\lsass.exe[744] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\system32\lsass.exe[744] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\system32\lsass.exe[744] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\system32\lsass.exe[744] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\WINDOWS\system32\svchost.exe[908] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00090030
.text C:\WINDOWS\system32\svchost.exe[908] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0009006C
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\system32\svchost.exe[908] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\system32\svchost.exe[908] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\system32\svchost.exe[908] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\system32\svchost.exe[908] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\system32\svchost.exe[908] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\system32\svchost.exe[908] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\WINDOWS\system32\svchost.exe[1012] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00090030
.text C:\WINDOWS\system32\svchost.exe[1012] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0009006C
.text C:\WINDOWS\system32\svchost.exe[1012] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\system32\svchost.exe[1012] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\system32\svchost.exe[1012] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\system32\svchost.exe[1012] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\system32\svchost.exe[1012] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\system32\svchost.exe[1012] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\system32\svchost.exe[1012] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\system32\svchost.exe[1012] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\system32\svchost.exe[1012] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\system32\svchost.exe[1012] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\system32\svchost.exe[1012] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\system32\svchost.exe[1012] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\system32\svchost.exe[1012] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\WINDOWS\System32\svchost.exe[1108] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00090030
.text C:\WINDOWS\System32\svchost.exe[1108] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0009006C
.text C:\WINDOWS\System32\svchost.exe[1108] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\System32\svchost.exe[1108] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\System32\svchost.exe[1108] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\System32\svchost.exe[1108] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\System32\svchost.exe[1108] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\System32\svchost.exe[1108] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\System32\svchost.exe[1108] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\System32\svchost.exe[1108] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\System32\svchost.exe[1108] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\System32\svchost.exe[1108] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\System32\svchost.exe[1108] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\System32\svchost.exe[1108] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\System32\svchost.exe[1108] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\WINDOWS\System32\alg.exe[1124] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00090030
.text C:\WINDOWS\System32\alg.exe[1124] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0009006C
.text C:\WINDOWS\System32\alg.exe[1124] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002B00E4
.text C:\WINDOWS\System32\alg.exe[1124] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002B0120
.text C:\WINDOWS\System32\alg.exe[1124] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002B00A8
.text C:\WINDOWS\System32\alg.exe[1124] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002B0030
.text C:\WINDOWS\System32\alg.exe[1124] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002B006C
.text C:\WINDOWS\System32\alg.exe[1124] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002C01D4
.text C:\WINDOWS\System32\alg.exe[1124] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002C00E4
.text C:\WINDOWS\System32\alg.exe[1124] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002C0120
.text C:\WINDOWS\System32\alg.exe[1124] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002C015C
.text C:\WINDOWS\System32\alg.exe[1124] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002C0198
.text C:\WINDOWS\System32\alg.exe[1124] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002C0030
.text C:\WINDOWS\System32\alg.exe[1124] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002C006C
.text C:\WINDOWS\System32\alg.exe[1124] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002C00A8
.text C:\WINDOWS\system32\svchost.exe[1148] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00090030
.text C:\WINDOWS\system32\svchost.exe[1148] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0009006C
.text C:\WINDOWS\system32\svchost.exe[1148] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\system32\svchost.exe[1148] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\system32\svchost.exe[1148] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\system32\svchost.exe[1148] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\system32\svchost.exe[1148] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\system32\svchost.exe[1148] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\system32\svchost.exe[1148] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\system32\svchost.exe[1148] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\system32\svchost.exe[1148] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\system32\svchost.exe[1148] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\system32\svchost.exe[1148] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\system32\svchost.exe[1148] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\system32\svchost.exe[1148] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\WINDOWS\system32\spoolsv.exe[1252] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00090030
.text C:\WINDOWS\system32\spoolsv.exe[1252] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0009006C
.text C:\WINDOWS\system32\spoolsv.exe[1252] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\system32\spoolsv.exe[1252] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\system32\spoolsv.exe[1252] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\system32\spoolsv.exe[1252] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\system32\spoolsv.exe[1252] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\system32\spoolsv.exe[1252] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\system32\spoolsv.exe[1252] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\system32\spoolsv.exe[1252] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\system32\spoolsv.exe[1252] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\system32\spoolsv.exe[1252] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\system32\spoolsv.exe[1252] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\system32\spoolsv.exe[1252] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\system32\spoolsv.exe[1252] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\WINDOWS\system32\svchost.exe[1416] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00090030
.text C:\WINDOWS\system32\svchost.exe[1416] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0009006C
.text C:\WINDOWS\system32\svchost.exe[1416] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\system32\svchost.exe[1416] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\system32\svchost.exe[1416] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\system32\svchost.exe[1416] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\system32\svchost.exe[1416] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\system32\svchost.exe[1416] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\system32\svchost.exe[1416] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\system32\svchost.exe[1416] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\system32\svchost.exe[1416] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\system32\svchost.exe[1416] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\system32\svchost.exe[1416] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\system32\svchost.exe[1416] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\system32\svchost.exe[1416] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\WINDOWS\system32\svchost.exe[1516] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00090030
.text C:\WINDOWS\system32\svchost.exe[1516] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0009006C
.text C:\WINDOWS\system32\svchost.exe[1516] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\system32\svchost.exe[1516] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\system32\svchost.exe[1516] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\system32\svchost.exe[1516] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\system32\svchost.exe[1516] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\system32\svchost.exe[1516] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\system32\svchost.exe[1516] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\system32\svchost.exe[1516] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\system32\svchost.exe[1516] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\system32\svchost.exe[1516] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\system32\svchost.exe[1516] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\system32\svchost.exe[1516] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\system32\svchost.exe[1516] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\WINDOWS\System32\svchost.exe[1644] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00090030
.text C:\WINDOWS\System32\svchost.exe[1644] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0009006C
.text C:\WINDOWS\System32\svchost.exe[1644] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\System32\svchost.exe[1644] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\System32\svchost.exe[1644] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\System32\svchost.exe[1644] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\System32\svchost.exe[1644] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\System32\svchost.exe[1644] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\System32\svchost.exe[1644] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\System32\svchost.exe[1644] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\System32\svchost.exe[1644] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\System32\svchost.exe[1644] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\System32\svchost.exe[1644] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\System32\svchost.exe[1644] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\System32\svchost.exe[1644] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1704] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP }
.text C:\WINDOWS\system32\svchost.exe[1716] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00090030
.text C:\WINDOWS\system32\svchost.exe[1716] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0009006C
.text C:\WINDOWS\system32\svchost.exe[1716] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\system32\svchost.exe[1716] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\system32\svchost.exe[1716] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\system32\svchost.exe[1716] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\system32\svchost.exe[1716] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\system32\svchost.exe[1716] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\system32\svchost.exe[1716] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\system32\svchost.exe[1716] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\system32\svchost.exe[1716] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\system32\svchost.exe[1716] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\system32\svchost.exe[1716] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\system32\svchost.exe[1716] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\system32\svchost.exe[1716] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00150030
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0015006C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003901D4
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003900E4
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390120
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0039015C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390198
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00390030
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0039006C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003900A8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A00E4
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0120
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A00A8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A0030
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A006C
.text C:\Program Files\Bonjour\mDNSResponder.exe[1780] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00150030
.text C:\Program Files\Bonjour\mDNSResponder.exe[1780] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0015006C
.text C:\Program Files\Bonjour\mDNSResponder.exe[1780] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003901D4
.text C:\Program Files\Bonjour\mDNSResponder.exe[1780] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003900E4
.text C:\Program Files\Bonjour\mDNSResponder.exe[1780] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390120
.text C:\Program Files\Bonjour\mDNSResponder.exe[1780] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0039015C
.text C:\Program Files\Bonjour\mDNSResponder.exe[1780] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390198
.text C:\Program Files\Bonjour\mDNSResponder.exe[1780] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00390030
.text C:\Program Files\Bonjour\mDNSResponder.exe[1780] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0039006C
.text C:\Program Files\Bonjour\mDNSResponder.exe[1780] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003900A8
.text C:\Program Files\Bonjour\mDNSResponder.exe[1780] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A00E4
.text C:\Program Files\Bonjour\mDNSResponder.exe[1780] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0120
.text C:\Program Files\Bonjour\mDNSResponder.exe[1780] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A00A8
.text C:\Program Files\Bonjour\mDNSResponder.exe[1780] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A0030
.text C:\Program Files\Bonjour\mDNSResponder.exe[1780] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A006C
.text C:\WINDOWS\system32\igfxtray.exe[1936] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00140030
.text C:\WINDOWS\system32\igfxtray.exe[1936] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0014006C
.text C:\WINDOWS\system32\igfxtray.exe[1936] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003800E4
.text C:\WINDOWS\system32\igfxtray.exe[1936] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00380120
.text C:\WINDOWS\system32\igfxtray.exe[1936] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003800A8
.text C:\WINDOWS\system32\igfxtray.exe[1936] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00380030
.text C:\WINDOWS\system32\igfxtray.exe[1936] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0038006C
.text C:\WINDOWS\system32\igfxtray.exe[1936] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003901D4
.text C:\WINDOWS\system32\igfxtray.exe[1936] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003900E4
.text C:\WINDOWS\system32\igfxtray.exe[1936] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390120
.text C:\WINDOWS\system32\igfxtray.exe[1936] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0039015C
.text C:\WINDOWS\system32\igfxtray.exe[1936] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390198
.text C:\WINDOWS\system32\igfxtray.exe[1936] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00390030
.text C:\WINDOWS\system32\igfxtray.exe[1936] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0039006C
.text C:\WINDOWS\system32\igfxtray.exe[1936] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003900A8
.text C:\WINDOWS\system32\hkcmd.exe[1952] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00140030
.text C:\WINDOWS\system32\hkcmd.exe[1952] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0014006C
.text C:\WINDOWS\system32\hkcmd.exe[1952] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003801D4
.text C:\WINDOWS\system32\hkcmd.exe[1952] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003800E4
.text C:\WINDOWS\system32\hkcmd.exe[1952] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00380120
.text C:\WINDOWS\system32\hkcmd.exe[1952] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0038015C
.text C:\WINDOWS\system32\hkcmd.exe[1952] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00380198
.text C:\WINDOWS\system32\hkcmd.exe[1952] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00380030
.text C:\WINDOWS\system32\hkcmd.exe[1952] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0038006C
.text C:\WINDOWS\system32\hkcmd.exe[1952] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003800A8
.text C:\WINDOWS\system32\hkcmd.exe[1952] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003900E4
.text C:\WINDOWS\system32\hkcmd.exe[1952] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390120
.text C:\WINDOWS\system32\hkcmd.exe[1952] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003900A8
.text C:\WINDOWS\system32\hkcmd.exe[1952] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00390030
.text C:\WINDOWS\system32\hkcmd.exe[1952] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0039006C
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1960] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00150030
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1960] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0015006C
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1960] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003E01D4
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1960] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003E00E4
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1960] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003E0120
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1960] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003E015C
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1960] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003E0198
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1960] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003E0030
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1960] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003E006C
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1960] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003E00A8
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1960] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003F00E4
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1960] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003F0120
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1960] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003F00A8
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1960] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003F0030
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1960] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003F006C
.text C:\Program Files\Drive Space Indicator\DrvSpace.exe[1968] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00050030
.text C:\Program Files\Drive Space Indicator\DrvSpace.exe[1968] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0005006C
.text C:\Program Files\Drive Space Indicator\DrvSpace.exe[1968] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002901D4
.text C:\Program Files\Drive Space Indicator\DrvSpace.exe[1968] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002900E4
.text C:\Program Files\Drive Space Indicator\DrvSpace.exe[1968] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00290120
.text C:\Program Files\Drive Space Indicator\DrvSpace.exe[1968] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0029015C
.text C:\Program Files\Drive Space Indicator\DrvSpace.exe[1968] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00290198
.text C:\Program Files\Drive Space Indicator\DrvSpace.exe[1968] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00290030
.text C:\Program Files\Drive Space Indicator\DrvSpace.exe[1968] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0029006C
.text C:\Program Files\Drive Space Indicator\DrvSpace.exe[1968] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002900A8
.text C:\Program Files\Drive Space Indicator\DrvSpace.exe[1968] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002A00E4
.text C:\Program Files\Drive Space Indicator\DrvSpace.exe[1968] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002A0120
.text C:\Program Files\Drive Space Indicator\DrvSpace.exe[1968] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002A00A8
.text C:\Program Files\Drive Space Indicator\DrvSpace.exe[1968] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002A0030
.text C:\Program Files\Drive Space Indicator\DrvSpace.exe[1968] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002A006C
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe[1976] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00140030
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe[1976] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0014006C
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe[1976] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003800E4
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe[1976] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00380120
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe[1976] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003800A8
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe[1976] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00380030
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe[1976] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0038006C
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe[1976] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003901D4
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe[1976] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003900E4
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe[1976] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390120
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe[1976] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0039015C
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe[1976] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390198
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe[1976] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00390030
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe[1976] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0039006C
.text C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe[1976] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003900A8
.text C:\Program Files\iTunes\iTunesHelper.exe[1992] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00150030
.text C:\Program Files\iTunes\iTunesHelper.exe[1992] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0015006C
.text C:\Program Files\iTunes\iTunesHelper.exe[1992] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A00E4
.text C:\Program Files\iTunes\iTunesHelper.exe[1992] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0120
.text C:\Program Files\iTunes\iTunesHelper.exe[1992] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A00A8
.text C:\Program Files\iTunes\iTunesHelper.exe[1992] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A0030
.text C:\Program Files\iTunes\iTunesHelper.exe[1992] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A006C
.text C:\Program Files\iTunes\iTunesHelper.exe[1992] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003B01D4
.text C:\Program Files\iTunes\iTunesHelper.exe[1992] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003B00E4
.text C:\Program Files\iTunes\iTunesHelper.exe[1992] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003B0120
.text C:\Program Files\iTunes\iTunesHelper.exe[1992] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003B015C
.text C:\Program Files\iTunes\iTunesHelper.exe[1992] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003B0198
.text C:\Program Files\iTunes\iTunesHelper.exe[1992] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003B0030
.text C:\Program Files\iTunes\iTunesHelper.exe[1992] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003B006C
.text C:\Program Files\iTunes\iTunesHelper.exe[1992] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003B00A8
.text C:\Program Files\Lexmark S600 Series\lxedmon.exe[2000] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00150030
.text C:\Program Files\Lexmark S600 Series\lxedmon.exe[2000] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0015006C
.text C:\Program Files\Lexmark S600 Series\lxedmon.exe[2000] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003901D4
.text C:\Program Files\Lexmark S600 Series\lxedmon.exe[2000] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003900E4
.text C:\Program Files\Lexmark S600 Series\lxedmon.exe[2000] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390120
.text C:\Program Files\Lexmark S600 Series\lxedmon.exe[2000] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0039015C
.text C:\Program Files\Lexmark S600 Series\lxedmon.exe[2000] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390198
.text C:\Program Files\Lexmark S600 Series\lxedmon.exe[2000] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00390030
.text C:\Program Files\Lexmark S600 Series\lxedmon.exe[2000] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0039006C
.text C:\Program Files\Lexmark S600 Series\lxedmon.exe[2000] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003900A8
.text C:\Program Files\Lexmark S600 Series\lxedmon.exe[2000] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A00E4
.text C:\Program Files\Lexmark S600 Series\lxedmon.exe[2000] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0120
.text C:\Program Files\Lexmark S600 Series\lxedmon.exe[2000] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A00A8
.text C:\Program Files\Lexmark S600 Series\lxedmon.exe[2000] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A0030
.text C:\Program Files\Lexmark S600 Series\lxedmon.exe[2000] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A006C
.text C:\Program Files\Lexmark S600 Series\ezprint.exe[2008] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00150030
.text C:\Program Files\Lexmark S600 Series\ezprint.exe[2008] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0015006C
.text C:\Program Files\Lexmark S600 Series\ezprint.exe[2008] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 008301D4
.text C:\Program Files\Lexmark S600 Series\ezprint.exe[2008] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 008300E4
.text C:\Program Files\Lexmark S600 Series\ezprint.exe[2008] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00830120
.text C:\Program Files\Lexmark S600 Series\ezprint.exe[2008] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0083015C
.text C:\Program Files\Lexmark S600 Series\ezprint.exe[2008] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00830198
.text C:\Program Files\Lexmark S600 Series\ezprint.exe[2008] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00830030
.text C:\Program Files\Lexmark S600 Series\ezprint.exe[2008] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0083006C
.text C:\Program Files\Lexmark S600 Series\ezprint.exe[2008] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 008300A8
.text C:\Program Files\Lexmark S600 Series\ezprint.exe[2008] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 008400E4
.text C:\Program Files\Lexmark S600 Series\ezprint.exe[2008] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00840120
.text C:\Program Files\Lexmark S600 Series\ezprint.exe[2008] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 008400A8
.text C:\Program Files\Lexmark S600 Series\ezprint.exe[2008] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00840030
.text C:\Program Files\Lexmark S600 Series\ezprint.exe[2008] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0084006C
.text C:\WINDOWS\system32\lxedcoms.exe[2152] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00150030
.text C:\WINDOWS\system32\lxedcoms.exe[2152] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0015006C
.text C:\WINDOWS\system32\lxedcoms.exe[2152] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003900E4
.text C:\WINDOWS\system32\lxedcoms.exe[2152] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390120
.text C:\WINDOWS\system32\lxedcoms.exe[2152] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003900A8
.text C:\WINDOWS\system32\lxedcoms.exe[2152] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00390030
.text C:\WINDOWS\system32\lxedcoms.exe[2152] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 0039006C
.text C:\WINDOWS\system32\lxedcoms.exe[2152] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A01D4
.text C:\WINDOWS\system32\lxedcoms.exe[2152] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A00E4
.text C:\WINDOWS\system32\lxedcoms.exe[2152] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0120
.text C:\WINDOWS\system32\lxedcoms.exe[2152] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A015C
.text C:\WINDOWS\system32\lxedcoms.exe[2152] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0198
.text C:\WINDOWS\system32\lxedcoms.exe[2152] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A0030
.text C:\WINDOWS\system32\lxedcoms.exe[2152] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A006C
.text C:\WINDOWS\system32\lxedcoms.exe[2152] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003A00A8
.text C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe[2272] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00150030
.text C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe[2272] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0015006C
.text C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe[2272] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 004D01D4
.text C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe[2272] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 004D00E4
.text C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe[2272] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 004D0120
.text C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe[2272] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 004D015C
.text C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe[2272] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 004D0198
.text C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe[2272] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 004D0030
.text C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe[2272] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 004D006C
.text C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe[2272] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 004D00A8
.text C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe[2272] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 004E00E4
.text C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe[2272] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 004E0120
.text C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe[2272] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 004E00A8
.text C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe[2272] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 004E0030
.text C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe[2272] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 004E006C
.text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[2328] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00080030
.text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[2328] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0008006C
.text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[2328] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002C01D4
.text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[2328] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002C00E4
.text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[2328] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002C0120
.text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[2328] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002C015C
.text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[2328] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002C0198
.text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[2328] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002C0030
.text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[2328] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002C006C
.text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[2328] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002C00A8
.text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[2328] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002D00E4
.text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[2328] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002D0120
.text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[2328] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002D00A8
.text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[2328] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002D0030
.text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[2328] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002D006C
.text C:\WINDOWS\system32\svchost.exe[2372] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00090030
.text C:\WINDOWS\system32\svchost.exe[2372] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0009006C
.text C:\WINDOWS\system32\svchost.exe[2372] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B01D4
.text C:\WINDOWS\system32\svchost.exe[2372] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B00E4
.text C:\WINDOWS\system32\svchost.exe[2372] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0120
.text C:\WINDOWS\system32\svchost.exe[2372] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B015C
.text C:\WINDOWS\system32\svchost.exe[2372] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0198
.text C:\WINDOWS\system32\svchost.exe[2372] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B0030
.text C:\WINDOWS\system32\svchost.exe[2372] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B006C
.text C:\WINDOWS\system32\svchost.exe[2372] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B00A8
.text C:\WINDOWS\system32\svchost.exe[2372] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C00E4
.text C:\WINDOWS\system32\svchost.exe[2372] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0120
.text C:\WINDOWS\system32\svchost.exe[2372] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C00A8
.text C:\WINDOWS\system32\svchost.exe[2372] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C0030
.text C:\WINDOWS\system32\svchost.exe[2372] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C006C
.text C:\WINDOWS\explorer.exe[2912] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00090030
.text C:\WINDOWS\explorer.exe[2912] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0009006C
.text C:\WINDOWS\explorer.exe[2912] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 004A01D4
.text C:\WINDOWS\explorer.exe[2912] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 004A00E4
.text C:\WINDOWS\explorer.exe[2912] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 004A0120
.text C:\WINDOWS\explorer.exe[2912] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 004A015C
.text C:\WINDOWS\explorer.exe[2912] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 004A0198
.text C:\WINDOWS\explorer.exe[2912] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 004A0030
.text C:\WINDOWS\explorer.exe[2912] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 004A006C
.text C:\WINDOWS\explorer.exe[2912] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 004A00A8
.text C:\WINDOWS\explorer.exe[2912] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 004B00E4
.text C:\WINDOWS\explorer.exe[2912] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 004B0120
.text C:\WINDOWS\explorer.exe[2912] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 004B00A8
.text C:\WINDOWS\explorer.exe[2912] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 004B0030
.text C:\WINDOWS\explorer.exe[2912] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 004B006C
.text C:\Program Files\Mozilla Firefox\firefox.exe[3056] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00150030
.text C:\Program Files\Mozilla Firefox\firefox.exe[3056] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0015006C
.text C:\Program Files\Mozilla Firefox\firefox.exe[3056] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 007D01D4
.text C:\Program Files\Mozilla Firefox\firefox.exe[3056] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 007D00E4
.text C:\Program Files\Mozilla Firefox\firefox.exe[3056] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 007D0120
.text C:\Program Files\Mozilla Firefox\firefox.exe[3056] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 007D015C
.text C:\Program Files\Mozilla Firefox\firefox.exe[3056] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 007D0198
.text C:\Program Files\Mozilla Firefox\firefox.exe[3056] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 007D0030
.text C:\Program Files\Mozilla Firefox\firefox.exe[3056] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 007D006C
.text C:\Program Files\Mozilla Firefox\firefox.exe[3056] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 007D00A8
.text C:\Program Files\Mozilla Firefox\firefox.exe[3056] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 007E00E4
.text C:\Program Files\Mozilla Firefox\firefox.exe[3056] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 007E0120
.text C:\Program Files\Mozilla Firefox\firefox.exe[3056] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 007E00A8
.text C:\Program Files\Mozilla Firefox\firefox.exe[3056] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 007E0030
.text C:\Program Files\Mozilla Firefox\firefox.exe[3056] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 007E006C
.text C:\Program Files\iPod\bin\iPodService.exe[3380] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00150030
.text C:\Program Files\iPod\bin\iPodService.exe[3380] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0015006C
.text C:\Program Files\iPod\bin\iPodService.exe[3380] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003901D4
.text C:\Program Files\iPod\bin\iPodService.exe[3380] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003900E4
.text C:\Program Files\iPod\bin\iPodService.exe[3380] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390120
.text C:\Program Files\iPod\bin\iPodService.exe[3380] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 0039015C
.text C:\Program Files\iPod\bin\iPodService.exe[3380] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390198
.text C:\Program Files\iPod\bin\iPodService.exe[3380] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 00390030
.text C:\Program Files\iPod\bin\iPodService.exe[3380] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 0039006C
.text C:\Program Files\iPod\bin\iPodService.exe[3380] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003900A8
.text C:\Program Files\iPod\bin\iPodService.exe[3380] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A00E4
.text C:\Program Files\iPod\bin\iPodService.exe[3380] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0120
.text C:\Program Files\iPod\bin\iPodService.exe[3380] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A00A8
.text C:\Program Files\iPod\bin\iPodService.exe[3380] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A0030
.text C:\Program Files\iPod\bin\iPodService.exe[3380] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A006C
.text C:\Users\Administrator\Desktop\goeikn5s.exe[3668] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00150030
.text C:\Users\Administrator\Desktop\goeikn5s.exe[3668] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0015006C

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/AVAST Software)
Device \FileSystem\Ntfs \Ntfs 8A6E41F8

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software)

Device \FileSystem\Fastfat \FatCdrom aswSP.SYS (avast! self protection module/AVAST Software)
Device \FileSystem\Fastfat \FatCdrom 8A1583D8

AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\Ip prio.sys (Prio Network Activity Driver/Xeno)
AttachedDevice \Driver\Tcpip \Device\Ip ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)

Device \Driver\sptd \Device\2219684634 spbq.sys
Device \Driver\usbuhci \Device\USBPDO-0 8A54D1F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8A7521F8
Device \Driver\dmio \Device\DmControl\DmConfig 8A7521F8
Device \Driver\dmio \Device\DmControl\DmPnP 8A7521F8
Device \Driver\dmio \Device\DmControl\DmInfo 8A7521F8
Device \Driver\usbuhci \Device\USBPDO-1 8A54D1F8
Device \Driver\usbuhci \Device\USBPDO-2 8A54D1F8
Device \Driver\usbehci \Device\USBPDO-3 8A5271F8
Device \Driver\PCI_PNP9634 \Device\00000047 spbq.sys
Device \Driver\PCI_PNP9634 \Device\00000047 spbq.sys

AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\Tcp prio.sys (Prio Network Activity Driver/Xeno)
AttachedDevice \Driver\Tcpip \Device\Tcp ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)

Device \Driver\USBSTOR \Device\00000062 8A5E8460
Device \Driver\NetBT \Device\NetBT_Tcpip_{8C9F737A-3E08-42C8-B5F1-AEA36F9589B7} 8A5CB500
Device \Driver\USBSTOR \Device\00000063 8A5E8460
Device \Driver\Ftdisk \Device\HarddiskVolume1 8A6E61F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 8A6E61F8
Device \Driver\Cdrom \Device\CdRom0 8A3E31F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F7833B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort0 [F7833B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [F7833B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e [F7833B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Cdrom \Device\CdRom1 8A3E31F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 8A5CB500
Device \Driver\NetBT \Device\NetbiosSmb 8A5CB500

AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\Udp prio.sys (Prio Network Activity Driver/Xeno)
AttachedDevice \Driver\Tcpip \Device\Udp ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\RawIp prio.sys (Prio Network Activity Driver/Xeno)
AttachedDevice \Driver\Tcpip \Device\RawIp ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)

Device \Driver\usbuhci \Device\USBFDO-0 8A54D1F8
Device \Driver\usbuhci \Device\USBFDO-1 8A54D1F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8A54F1F8
Device \Driver\usbuhci \Device\USBFDO-2 8A54D1F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8A54F1F8
Device \Driver\usbehci \Device\USBFDO-3 8A5271F8
Device \Driver\Ftdisk \Device\FtControl 8A6E61F8
Device \Driver\aad131z5 \Device\Scsi\aad131z51 8A2281F8
Device \FileSystem\Fastfat \Fat aswSP.SYS (avast! self protection module/AVAST Software)
Device \FileSystem\Fastfat \Fat 8A1583D8

AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software)

Device \FileSystem\Cdfs \Cdfs 8A40A500

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xCF 0x8C 0x0F 0x4E …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xCF 0x8C 0x0F 0x4E …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xCF 0x8C 0x0F 0x4E …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …

—- EOF - GMER 1.0.15 —-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI