This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Searchqu infection

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The problem that I'm having is that an extra search toolbar has been added to IE and Firefox, and the home page of both browsers has been set to www.searchqu.com (which also loads when you open a new tab).

My HijackThis log is below. Thanks in advance for your help!

=========================

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:00:03 PM, on 20/05/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\doubleTwist 2.0\DoubleTwist.DeviceHelper.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Whites\Desktop\uSeRiNiT.exe
C:\Documents and Settings\Whites\Desktop\rkill.com
C:\Documents and Settings\Whites\Desktop\rkill.com
C:\Documents and Settings\Whites\Desktop\rkill.com
C:\Documents and Settings\Whites\Desktop\rkill.com
C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe
C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe
C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe
C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe
C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Whites\My Documents\Downloads\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
O2 - BHO: dTPodcastBHO - {65134FDF-F8A5-4B3D-91D9-CDF273CFD578} - C:\Program Files\Common Files\doubleTwist\IEPodcastPlugin.dll
O2 - BHO: DebugBar BHO - {69FC0024-10EB-480A-BBF2-3BF4E78E17B1} - C:\Program Files\Core Services\DebugBar\DebugInfoBar.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110514101944.dll
O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\ToolBar\searchqudtx.dll
O2 - BHO: UrlHelper Class - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: DebugBar - {3E1201F4-1707-409F-BB45-A5F192381DA0} - C:\Program Files\Core Services\DebugBar\DebugToolBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\ToolBar\searchqudtx.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HTC Sync Loader] "C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Whites\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [doubleTwist] C:\Program Files\doubleTwist 2.0\DoubleTwist.DeviceHelper.exe
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} (20-20 3D Viewer) - http://kitchenplanner.ikea.com/AU/Core/Pla…yerAX_Win32.cab
O16 - DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} (FBootloaderAX) - http://static.ak.facebook.com/fbplugin/win…b?1271577864906
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://whitechimagine.com/imagine/ax/ImageUploader5.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1205222789078
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {EA1B8527-E422-4909-825A-70BE0694F18E} (PortfolioManagerWT ProfileManager Class) - https://online.westpac.com.au/wtpbs/wtBalan…iomanagerwt.cab
O20 - AppInit_DLLs: C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

–
End of file - 13663 bytes
Hello whites and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
• Please follow all instructions in the order posted
• Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
• If you don't understand something, please don't hesitate to ask for clarification before proceeding
• The fixes are specific to your problem and should only be used for this issue on this machine.
• Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I am looking at your log now and will reply with instructions shortly

Satchfan
Hello again whites

Run HijackThis

Open HijackThis and click Do a system scan only.

Place a check mark next to:

O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\ToolBar\searchqudtx.dll
O2 - BHO: UrlHelper Class - {A40DC6C5-79D0-4ca8-A185-8FF989AF1115} - C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll
O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\WI371A~1\ToolBar\searchqudtx.dll
O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~1\WI371A~1\Datamngr\DATAMN~1.EXE
O20 - AppInit_DLLs: C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll


Close all windows except for HijackThis and click Fix checked.


Run DDS

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
  • Post the contents of the DDS.txt and Attach.txt reports in your next reply

Download the GMER Rootkit Scanner

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done, click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Logs to include with next post:

DDS.txt
Attach.txt
Gmer.txt


Thanks

Satchfan
Thanks for your help. The error logs you've requested are below.

In addition to the problems I described before, I've also now had an error message appear that won't go away, so I couldn't close that while running any of these scans. I've attached a screenshot of the error message.



DDS.txt:

.
DDS (Ver_11-05-19.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_23
Run by [removed] at 20:10:07 on 2011-05-20
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2037.1349 [GMT 10:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\doubleTwist 2.0\DoubleTwist.DeviceHelper.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Whites\Desktop\uSeRiNiT.exe
C:\Documents and Settings\Whites\Desktop\rkill.com
C:\Documents and Settings\Whites\Desktop\rkill.com
C:\Documents and Settings\Whites\Desktop\rkill.com
C:\Documents and Settings\Whites\Desktop\rkill.com
C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe
C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe
C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe
C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe
C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\McAfee\MSM\McSmtFwk.exe
C:\PROGRA~1\COMMON~1\McAfee\MSC\McUICnt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
C:\Documents and Settings\Whites\Desktop\dds.pif
C:\WINDOWS\system32\WSCRIPT.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com.au/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: PodcastBHO Class: {65134fdf-f8a5-4b3d-91d9-cdf273cfd578} - c:\program files\common files\doubletwist\IEPodcastPlugin.dll
BHO: DebugBar BHO: {69fc0024-10eb-480a-bbf2-3bf4e78e17b1} - c:\program files\core services\debugbar\DebugInfoBar.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20110514101944.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: DebugBar: {3e1201f4-1707-409f-bb45-a5f192381da0} - c:\program files\core services\debugbar\DebugToolBar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Google Update] "c:\documents and settings\whites\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [doubleTwist] c:\program files\doubletwist 2.0\DoubleTwist.DeviceHelper.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: []
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [Lexmark X1100 Series] "c:\program files\lexmark x1100 series\lxbkbmgr.exe"
mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [HTC Sync Loader] "c:\program files\htc\htc sync 3.0\htcUPCTLoader.exe" -startup
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
StartupFolder: c:\docume~1\whites\startm~1\programs\startup\pictur~1.lnk - c:\program files\sony\sony picture utility\pmbcore\SPUVolumeWatcher.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} - hxxp://kitchenplanner.ikea.com/AU/Core/Player/2020PlayerAX_Win32.cab
DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} - hxxp://static.ak.facebook.com/fbplugin/win32/axfbootloader.cab?1271577864906
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://whitechimagine.com/imagine/ax/ImageUploader5.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1205222789078
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {EA1B8527-E422-4909-825A-70BE0694F18E} - hxxps://online.westpac.com.au/wtpbs/wtBalanceSheet/portfoliomanagerwt.cab
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\whites\application data\mozilla\firefox\profiles\hkvwi8ad.default\
FF - prefs.js: browser.search.selectedEngine - Google Australia
FF - prefs.js: browser.startup.homepage - hxxp://www.searchqu.com/406
FF - prefs.js: keyword.URL - hxxp://www.searchqu.com/web?src=ffb&systemid=406&q=
FF - component: c:\documents and settings\whites\application data\mozilla\firefox\profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\components\dtTransparency.dll
FF - component: c:\documents and settings\whites\application data\mozilla\firefox\profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\components\dtTransparency3.5.dll
FF - component: c:\documents and settings\whites\application data\mozilla\firefox\profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\components\dtTransparency3.6.dll
FF - component: c:\program files\windows ilivid toolbar\datamngr\firefoxextension\components\DataMngrHlp.dll
FF - plugin: c:\documents and settings\whites\application data\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\whites\local settings\application data\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\common files\doubletwist\NPPodcast.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - Ext: BugMeNot: {987311C6-B504-4aa2-90BF-60CC49808D42} - %profile%\extensions\{987311C6-B504-4aa2-90BF-60CC49808D42}
FF - Ext: Kempelton: [removed] - %profile%\extensions\[removed]
FF - Ext: Web Developer: {c45c406e-ab73-11d8-be73-000a95be3b12} - %profile%\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
FF - Ext: Site Information Tool: siteinfo@wmtips - %profile%\extensions\siteinfo@wmtips
FF - Ext: Firebug: [removed] - %profile%\extensions\[removed]
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: SearchquToolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - %profile%\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: [removed] - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2008-2-20 387480]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2010-8-3 84200]
R2 iPodDrv;iPodDrv;c:\windows\system32\drivers\iPodDrv.sys [2010-8-5 6656]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-8-3 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-8-3 271480]
R2 McProxy;McAfee Proxy Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-8-3 271480]
R2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2010-8-3 171168]
R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2010-8-3 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\common files\mcafee\systemcore\mfevtps.exe [2010-8-3 141792]
R2 PassThru Service;Internet Pass-Through Service;c:\program files\htc\internet pass-through\PassThruSvr.exe [2010-9-16 80896]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-8-3 56064]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2008-2-20 153280]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-8-3 314088]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2010-8-3 88736]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-8 135664]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-1-8 135664]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [2011-1-21 24576]
S3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\drivers\htcnprot.sys [2010-6-22 21248]
S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2008-2-20 52320]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2010-8-3 88736]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-8-3 84488]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2008-2-20 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2008-2-20 40552]
.
=============== File Associations ===============
.
.scr=AutoCADScriptFile
.
=============== Created Last 30 ================
.
2011-05-20 10:09:51 ——– d–h–w- c:\windows\PIF
2011-05-20 01:33:30 ——– d—–w- c:\documents and settings\whites\local settings\application data\Ilivid Player
2011-05-20 01:33:05 ——– d—–w- c:\documents and settings\whites\application data\searchquband
2011-05-20 01:32:02 ——– dc-h–w- c:\documents and settings\all users\application data\~0
2011-05-20 01:31:35 ——– d—–w- c:\documents and settings\whites\application data\searchqutoolbar
2011-05-20 01:31:26 ——– d—–w- c:\program files\Windows iLivid Toolbar
2011-05-20 01:31:14 ——– d—–w- c:\documents and settings\whites\local settings\application data\PackageAware
.
==================== Find3M ====================
.
2011-04-14 04:01:38 95824 —-a-w- c:\windows\system32\drivers\mfeapfk.sys
2011-04-14 04:01:38 9344 —-a-w- c:\windows\system32\drivers\mfeclnk.sys
2011-04-14 04:01:38 88736 —-a-w- c:\windows\system32\drivers\mfendisk.sys
2011-04-14 04:01:38 84488 —-a-w- c:\windows\system32\drivers\mferkdet.sys
2011-04-14 04:01:38 84200 —-a-w- c:\windows\system32\drivers\mfetdi2k.sys
2011-04-14 04:01:38 56064 —-a-w- c:\windows\system32\drivers\cfwids.sys
2011-04-14 04:01:38 52320 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2011-04-14 04:01:38 387480 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2011-04-14 04:01:38 314088 —-a-w- c:\windows\system32\drivers\mfefirek.sys
2011-04-14 04:01:38 153280 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2011-03-07 05:33:50 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37:06 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21:11 1857920 —-a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06:29 916480 —-a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06:29 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06:29 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41:59 385024 —-a-w- c:\windows\system32\html.iec
.
============= FINISH: 20:10:46.26 ===============

Attach.txt

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-05-19.01)
.
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 27/02/2008 7:03:13 PM
System Uptime: 20/05/2011 11:08:36 AM (9 hours ago)
.
Motherboard: Dell Inc. | | 0RY007
Processor: Intel® Core™2 Duo CPU E4500 @ 2.20GHz | Socket 775 | 1579/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 295 GiB total, 240.659 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP974: 20/02/2011 2:19:43 PM - System Checkpoint
RP975: 21/02/2011 2:56:56 PM - System Checkpoint
RP976: 22/02/2011 6:12:56 PM - System Checkpoint
RP977: 23/02/2011 6:29:42 PM - System Checkpoint
RP978: 24/02/2011 7:06:41 PM - System Checkpoint
RP979: 25/02/2011 7:22:01 PM - System Checkpoint
RP980: 26/02/2011 7:55:30 PM - System Checkpoint
RP981: 27/02/2011 9:50:25 PM - System Checkpoint
RP982: 1/03/2011 8:19:21 AM - System Checkpoint
RP983: 2/03/2011 6:54:35 PM - System Checkpoint
RP984: 3/03/2011 7:35:30 PM - System Checkpoint
RP985: 4/03/2011 8:56:01 PM - System Checkpoint
RP986: 5/03/2011 9:07:32 PM - System Checkpoint
RP987: 6/03/2011 9:57:34 PM - System Checkpoint
RP988: 7/03/2011 10:26:16 PM - System Checkpoint
RP989: 9/03/2011 8:06:51 AM - Software Distribution Service 3.0
RP990: 10/03/2011 6:28:36 PM - System Checkpoint
RP991: 11/03/2011 7:09:53 PM - System Checkpoint
RP992: 13/03/2011 1:46:23 PM - System Checkpoint
RP993: 15/03/2011 8:34:24 AM - System Checkpoint
RP994: 15/03/2011 9:54:54 PM - Software Distribution Service 3.0
RP995: 17/03/2011 8:24:16 PM - System Checkpoint
RP996: 19/03/2011 1:04:58 PM - System Checkpoint
RP997: 20/03/2011 1:40:59 PM - System Checkpoint
RP998: 21/03/2011 2:31:03 PM - System Checkpoint
RP999: 22/03/2011 6:33:12 PM - System Checkpoint
RP1000: 23/03/2011 7:29:54 PM - System Checkpoint
RP1001: 24/03/2011 8:09:24 AM - Software Distribution Service 3.0
RP1002: 25/03/2011 9:26:48 AM - System Checkpoint
RP1003: 26/03/2011 10:38:02 AM - System Checkpoint
RP1004: 27/03/2011 11:44:56 AM - System Checkpoint
RP1005: 28/03/2011 12:22:19 PM - System Checkpoint
RP1006: 29/03/2011 6:25:36 PM - System Checkpoint
RP1007: 30/03/2011 6:51:07 PM - System Checkpoint
RP1008: 31/03/2011 7:37:18 PM - System Checkpoint
RP1009: 1/04/2011 7:38:49 PM - System Checkpoint
RP1010: 2/04/2011 7:47:38 PM - System Checkpoint
RP1011: 3/04/2011 10:10:46 PM - System Checkpoint
RP1012: 5/04/2011 7:38:24 AM - System Checkpoint
RP1013: 6/04/2011 7:23:46 PM - System Checkpoint
RP1014: 7/04/2011 8:36:40 PM - System Checkpoint
RP1015: 9/04/2011 12:51:20 PM - System Checkpoint
RP1016: 10/04/2011 12:54:20 PM - System Checkpoint
RP1017: 11/04/2011 1:28:12 PM - System Checkpoint
RP1018: 12/04/2011 3:07:00 PM - System Checkpoint
RP1019: 13/04/2011 3:08:39 PM - System Checkpoint
RP1020: 14/04/2011 3:18:26 PM - System Checkpoint
RP1021: 14/04/2011 10:43:46 PM - Software Distribution Service 3.0
RP1022: 16/04/2011 11:04:25 AM - System Checkpoint
RP1023: 17/04/2011 12:17:33 PM - System Checkpoint
RP1024: 18/04/2011 12:52:42 PM - System Checkpoint
RP1025: 19/04/2011 1:24:40 PM - System Checkpoint
RP1026: 20/04/2011 3:09:10 PM - System Checkpoint
RP1027: 21/04/2011 3:45:47 PM - System Checkpoint
RP1028: 25/04/2011 7:05:27 PM - System Checkpoint
RP1029: 26/04/2011 4:49:37 PM - Software Distribution Service 3.0
RP1030: 27/04/2011 7:07:20 PM - System Checkpoint
RP1031: 28/04/2011 8:45:46 PM - System Checkpoint
RP1032: 28/04/2011 10:20:38 PM - Software Distribution Service 3.0
RP1033: 30/04/2011 1:02:31 PM - System Checkpoint
RP1034: 1/05/2011 8:39:44 PM - System Checkpoint
RP1035: 2/05/2011 9:40:12 PM - System Checkpoint
RP1036: 4/05/2011 10:00:03 PM - System Checkpoint
RP1037: 6/05/2011 10:09:06 AM - System Checkpoint
RP1038: 7/05/2011 10:16:36 AM - System Checkpoint
RP1039: 8/05/2011 11:41:39 AM - System Checkpoint
RP1040: 9/05/2011 12:56:11 PM - System Checkpoint
RP1041: 10/05/2011 6:52:00 PM - System Checkpoint
RP1042: 11/05/2011 8:38:49 PM - System Checkpoint
RP1043: 11/05/2011 9:41:29 PM - Software Distribution Service 3.0
RP1044: 13/05/2011 8:34:16 AM - System Checkpoint
RP1045: 15/05/2011 9:58:23 AM - System Checkpoint
RP1046: 16/05/2011 10:47:48 AM - System Checkpoint
RP1047: 17/05/2011 6:26:37 PM - System Checkpoint
RP1048: 18/05/2011 6:52:34 PM - System Checkpoint
RP1049: 19/05/2011 7:11:17 PM - System Checkpoint
.
==== Installed Programs ======================
.
7-Zip 9.12 beta
ActivePerl 5.12.2 Build 1203
Adobe AIR
Adobe Creative Suite
Adobe Digital Editions
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.2.6
Adobe Shockwave Player 11.5
Adobe SVG Viewer 3.0
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Audacity 1.2.6
AutoCAD 2004
Autodesk Express Viewer
AviSynth 2.5
Blender (remove only)
Bonjour
Canon CanoScan Toolbox 4.9
Click'N Design 3D (V5)
Compatibility Pack for the 2007 Office system
Conexant D850 56K V.9x DFVc Modem
Critical Update for Windows Media Player 11 (KB959772)
CutePDF Writer 2.7
DebugBar v5.4.1 for Internet Explorer (remove only)
Dell Support Center (Support Software)
Dell System Restore
Digital Line Detect
doubleTwist
e-tax 2008
e-tax 2009
e-tax 2010
Facebook Plug-In
ffdshow [rev 2527] [2008-12-19]
FileZilla Client 3.3.3
Google Chrome
Google Earth
Google Toolbar for Internet Explorer
Google Update Helper
Google Updater
GoToMeeting 4.1.0.366
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
HTC BMP USB Driver
HTC Driver Installer
HTC Sync
HyperXpress PDF Writer 4.1
IETester v0.4.4 (remove only)
IKEA Home Planner
Intel® Graphics Media Accelerator Driver
Intel® PRO Network Connections Drivers
iTunes
J2SE Runtime Environment 5.0 Update 6
Java Auto Updater
Java™ 6 Update 23
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7
Lexmark X1100 Series
LimeWire 5.3.6
McAfee SecurityCenter
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Works
Modem Diagnostic Tool
Mozilla Firefox (3.6.17)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB973685)
MSXML 6.0 Parser (KB933579)
MyHeritage Family Tree Builder
Nelson Maths for Victoria - Planning and Assessment software
NetManage ECCO Pro
NetWaiting
OGA Notifier 1.7.0105.35.0
Picture Package Music Transfer
PowerDVD
QuickTime
Realtek High Definition Audio Driver
Revit 3.11
Revit AccuRender 3.1
ROM CHECK FAIL 1.0
Roxio Creator Audio
Roxio Creator BDAV Plugin
Roxio Creator Copy
Roxio Creator Data
Roxio Creator DE
Roxio Creator Tools
Roxio Drag-to-Disc
Roxio Express Labeler
Roxio MyDVD DE
Roxio Update Manager
SafeCast Shared Components
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB2497640)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2491683)
Security Update for Windows XP (KB2503658)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2506223)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2508272)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2511455)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Sonic Activation Module
Sony Picture Utility
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB971180)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Vuze
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows iLivid Toolbar
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
Xvid 1.1.3 final uninstall
.
==== End Of File ===========================


gmer.txt

GMER 1.0.15.15627 - http://www.gmer.net
Rootkit scan 2011-05-21 15:59:55
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST3320620AS rev.3.ADG
Running: gmer.exe; Driver: C:\DOCUME~1\Whites\LOCALS~1\Temp\uxtdqpow.sys


—- System - GMER 1.0.15 —-

Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateKey [0xB9E0E210]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteKey [0xB9E0E224]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xB9E0E250]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xB9E0E2A6]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenKey [0xB9E0E1FC]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xB9E0E1D4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xB9E0E1E8]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwRenameKey [0xB9E0E23A]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetSecurityObject [0xB9E0E27C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetValueKey [0xB9E0E266]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0xB9E0E2D0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xB9E0E2BC]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0xB9E0E290]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetSecurityObject

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwYieldExecution 80504B08 7 Bytes JMP B9E0E294 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 805B203A 7 Bytes JMP B9E0E2AA mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805B2E48 5 Bytes JMP B9E0E2C0 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetSecurityObject 805C062E 5 Bytes JMP B9E0E280 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess 805CB440 5 Bytes JMP B9E0E1D8 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 805CB6CC 5 Bytes JMP B9E0E1EC mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805D29E2 5 Bytes JMP B9E0E2D4 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetValueKey 80622662 7 Bytes JMP B9E0E26A mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRenameKey 80623B12 7 Bytes JMP B9E0E23E mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateKey 806240F0 5 Bytes JMP B9E0E214 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteKey 8062458C 7 Bytes JMP B9E0E228 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteValueKey 8062475C 7 Bytes JMP B9E0E254 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwOpenKey 806254CE 5 Bytes JMP B9E0E200 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
? C:\DOCUME~1\Whites\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10047D70 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00150FEF
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] ntdll.dll!NtCreateKey 7C90D0EE 5 Bytes JMP 10047CF0 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00150FDE
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] ntdll.dll!NtDeleteKey 7C90D24E 5 Bytes JMP 10047D90 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] ntdll.dll!NtDeleteValueKey 7C90D26E 5 Bytes JMP 10047DB0 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10047D20 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0015000A
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] ntdll.dll!NtQueryValueKey 7C90D96E 5 Bytes JMP 10047C90 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] ntdll.dll!NtSetValueKey 7C90DDCE 5 Bytes JMP 10047CC0 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00C70780 C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll (IEHelper/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00270FEF
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00270062
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00270047
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0027002C
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00270F79
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00270FA5
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 0027009A
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00270089
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00270F26
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00270F41
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00270F15
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00270F8A
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00270000
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00270F52
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 0027001B
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00270FCA
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 002700B5
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00370FCD
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00370040
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00370FDE
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00370014
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00370F8D
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00370FEF
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00370FA8
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [57, 88]
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0037002F
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00380F9F
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] msvcrt.dll!system 77C293C7 5 Bytes JMP 00380FB0
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00380FD2
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00380FEF
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00380FC1
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0038000C
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] SHLWAPI.dll!SHCreateStreamOnFileA + 2066 77FC22BC 5 Bytes JMP 00C6C790 C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll (IEHelper/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX2\h\iexplore.exe[980] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 00C72C50 C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll (IEHelper/Discordia, LTD)
.text C:\WINDOWS\system32\services.exe[1112] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 0005000A
.text C:\WINDOWS\system32\services.exe[1112] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00050036
.text C:\WINDOWS\system32\services.exe[1112] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0005001B
.text C:\WINDOWS\system32\services.exe[1112] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00040FEF
.text C:\WINDOWS\system32\services.exe[1112] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 0004009D
.text C:\WINDOWS\system32\services.exe[1112] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 0004008C
.text C:\WINDOWS\system32\services.exe[1112] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00040065
.text C:\WINDOWS\system32\services.exe[1112] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00040FA8
.text C:\WINDOWS\system32\services.exe[1112] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0004004A
.text C:\WINDOWS\system32\services.exe[1112] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00040F72
.text C:\WINDOWS\system32\services.exe[1112] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00040F83
.text C:\WINDOWS\system32\services.exe[1112] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 000400DF
.text C:\WINDOWS\system32\services.exe[1112] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00040F46
.text C:\WINDOWS\system32\services.exe[1112] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 000400F0
.text C:\WINDOWS\system32\services.exe[1112] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00040FC3
.text C:\WINDOWS\system32\services.exe[1112] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00040000
.text C:\WINDOWS\system32\services.exe[1112] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 000400AE
.text C:\WINDOWS\system32\services.exe[1112] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00040FD4
.text C:\WINDOWS\system32\services.exe[1112] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00040025
.text C:\WINDOWS\system32\services.exe[1112] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00040F57
.text C:\WINDOWS\system32\services.exe[1112] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 006E0025
.text C:\WINDOWS\system32\services.exe[1112] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 006E0062
.text C:\WINDOWS\system32\services.exe[1112] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 006E0FCA
.text C:\WINDOWS\system32\services.exe[1112] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 006E000A
.text C:\WINDOWS\system32\services.exe[1112] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 006E0051
.text C:\WINDOWS\system32\services.exe[1112] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 006E0FEF
.text C:\WINDOWS\system32\services.exe[1112] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 006E0036
.text C:\WINDOWS\system32\services.exe[1112] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 006E0FB9
.text C:\WINDOWS\system32\services.exe[1112] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0007004C
.text C:\WINDOWS\system32\services.exe[1112] msvcrt.dll!system 77C293C7 5 Bytes JMP 00070FC1
.text C:\WINDOWS\system32\services.exe[1112] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00070FD2
.text C:\WINDOWS\system32\services.exe[1112] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0007000C
.text C:\WINDOWS\system32\services.exe[1112] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00070027
.text C:\WINDOWS\system32\services.exe[1112] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00070FE3
.text C:\WINDOWS\system32\services.exe[1112] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00060000
.text C:\WINDOWS\system32\lsass.exe[1124] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00F70000
.text C:\WINDOWS\system32\lsass.exe[1124] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00F70FDB
.text C:\WINDOWS\system32\lsass.exe[1124] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00F70011
.text C:\WINDOWS\system32\lsass.exe[1124] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BF000A
.text C:\WINDOWS\system32\lsass.exe[1124] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BF0047
.text C:\WINDOWS\system32\lsass.exe[1124] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BF0F52
.text C:\WINDOWS\system32\lsass.exe[1124] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BF0F79
.text C:\WINDOWS\system32\lsass.exe[1124] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BF0036
.text C:\WINDOWS\system32\lsass.exe[1124] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BF0FB9
.text C:\WINDOWS\system32\lsass.exe[1124] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BF0F26
.text C:\WINDOWS\system32\lsass.exe[1124] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BF0F37
.text C:\WINDOWS\system32\lsass.exe[1124] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BF0EFA
.text C:\WINDOWS\system32\lsass.exe[1124] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BF0F15
.text C:\WINDOWS\system32\lsass.exe[1124] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BF0EE9
.text C:\WINDOWS\system32\lsass.exe[1124] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BF0F94
.text C:\WINDOWS\system32\lsass.exe[1124] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BF0FEF
.text C:\WINDOWS\system32\lsass.exe[1124] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BF0062
.text C:\WINDOWS\system32\lsass.exe[1124] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BF001B
.text C:\WINDOWS\system32\lsass.exe[1124] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BF0FD4
.text C:\WINDOWS\system32\lsass.exe[1124] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BF0089
.text C:\WINDOWS\system32\lsass.exe[1124] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00FA0000
.text C:\WINDOWS\system32\lsass.exe[1124] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00FA0F54
.text C:\WINDOWS\system32\lsass.exe[1124] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00FA0FAF
.text C:\WINDOWS\system32\lsass.exe[1124] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00FA0FCA
.text C:\WINDOWS\system32\lsass.exe[1124] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00FA0011
.text C:\WINDOWS\system32\lsass.exe[1124] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00FA0FEF
.text C:\WINDOWS\system32\lsass.exe[1124] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00FA0F79
.text C:\WINDOWS\system32\lsass.exe[1124] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [1A, 89]
.text C:\WINDOWS\system32\lsass.exe[1124] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00FA0F8A
.text C:\WINDOWS\system32\lsass.exe[1124] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00F90FA6
.text C:\WINDOWS\system32\lsass.exe[1124] msvcrt.dll!system 77C293C7 5 Bytes JMP 00F90FB7
.text C:\WINDOWS\system32\lsass.exe[1124] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00F90FD2
.text C:\WINDOWS\system32\lsass.exe[1124] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00F90FE3
.text C:\WINDOWS\system32\lsass.exe[1124] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00F90031
.text C:\WINDOWS\system32\lsass.exe[1124] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00F90000
.text C:\WINDOWS\system32\lsass.exe[1124] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00F80000
.text C:\WINDOWS\system32\svchost.exe[1324] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 02490FE5
.text C:\WINDOWS\system32\svchost.exe[1324] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0249001B
.text C:\WINDOWS\system32\svchost.exe[1324] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 02490000
.text C:\WINDOWS\system32\svchost.exe[1324] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00FF0FEF
.text C:\WINDOWS\system32\svchost.exe[1324] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00FF0F52
.text C:\WINDOWS\system32\svchost.exe[1324] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00FF0047
.text C:\WINDOWS\system32\svchost.exe[1324] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00FF0F79
.text C:\WINDOWS\system32\svchost.exe[1324] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00FF0036
.text C:\WINDOWS\system32\svchost.exe[1324] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00FF000A
.text C:\WINDOWS\system32\svchost.exe[1324] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00FF009A
.text C:\WINDOWS\system32\svchost.exe[1324] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00FF0089
.text C:\WINDOWS\system32\svchost.exe[1324] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FF00C6
.text C:\WINDOWS\system32\svchost.exe[1324] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FF00B5
.text C:\WINDOWS\system32\svchost.exe[1324] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00FF0F12
.text C:\WINDOWS\system32\svchost.exe[1324] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00FF0025
.text C:\WINDOWS\system32\svchost.exe[1324] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00FF0FD4
.text C:\WINDOWS\system32\svchost.exe[1324] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00FF0062
.text C:\WINDOWS\system32\svchost.exe[1324] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00FF0F9E
.text C:\WINDOWS\system32\svchost.exe[1324] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00FF0FC3
.text C:\WINDOWS\system32\svchost.exe[1324] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00FF0F37
.text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00B20FC0
.text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00B20F68
.text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00B2001B
.text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00B20FE5
.text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00B20F79
.text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00B20000
.text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00B20F94
.text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [D2, 88]
.text C:\WINDOWS\system32\svchost.exe[1324] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00B20FAF
.text C:\WINDOWS\system32\svchost.exe[1324] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00B10055
.text C:\WINDOWS\system32\svchost.exe[1324] msvcrt.dll!system 77C293C7 5 Bytes JMP 00B10044
.text C:\WINDOWS\system32\svchost.exe[1324] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00B10029
.text C:\WINDOWS\system32\svchost.exe[1324] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00B10FEF
.text C:\WINDOWS\system32\svchost.exe[1324] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00B10FD4
.text C:\WINDOWS\system32\svchost.exe[1324] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00B10018
.text C:\WINDOWS\system32\svchost.exe[1324] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00B00000
.text C:\WINDOWS\system32\svchost.exe[1392] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00DC0000
.text C:\WINDOWS\system32\svchost.exe[1392] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00DC0FE5
.text C:\WINDOWS\system32\svchost.exe[1392] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00DC0011
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00DB0FEF
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00DB007B
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00DB0060
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00DB0F7C
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00DB0F8D
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00DB0F9E
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00DB00B3
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00DB0F6B
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00DB0F35
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00DB0F46
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00DB00F3
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00DB0025
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00DB000A
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00DB008C
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00DB0FC3
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00DB0FD4
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00DB00CE
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00DF001B
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00DF0F94
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00DF0000
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00DF0FD4
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00DF0051
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00DF0FEF
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00DF0040
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00DF0FAF
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00DE0058
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!system 77C293C7 5 Bytes JMP 00DE003D
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00DE001B
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00DE0000
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00DE002C
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00DE0FD7
.text C:\WINDOWS\system32\svchost.exe[1392] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00DD000A
.text C:\WINDOWS\System32\svchost.exe[1516] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 04700000
.text C:\WINDOWS\System32\svchost.exe[1516] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0470002C
.text C:\WINDOWS\System32\svchost.exe[1516] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 04700011
.text C:\WINDOWS\System32\svchost.exe[1516] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 046F0FEF
.text C:\WINDOWS\System32\svchost.exe[1516] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 046F0F49
.text C:\WINDOWS\System32\svchost.exe[1516] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 046F0F64
.text C:\WINDOWS\System32\svchost.exe[1516] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 046F0F75
.text C:\WINDOWS\System32\svchost.exe[1516] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 046F0028
.text C:\WINDOWS\System32\svchost.exe[1516] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 046F0F97
.text C:\WINDOWS\System32\svchost.exe[1516] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 046F0F1D
.text C:\WINDOWS\System32\svchost.exe[1516] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 046F0065
.text C:\WINDOWS\System32\svchost.exe[1516] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 046F00AF
.text C:\WINDOWS\System32\svchost.exe[1516] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 046F008A
.text C:\WINDOWS\System32\svchost.exe[1516] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 046F00CA
.text C:\WINDOWS\System32\svchost.exe[1516] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 046F0F86
.text C:\WINDOWS\System32\svchost.exe[1516] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 046F0FD4
.text C:\WINDOWS\System32\svchost.exe[1516] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 046F0F38
.text C:\WINDOWS\System32\svchost.exe[1516] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 046F0FB2
.text C:\WINDOWS\System32\svchost.exe[1516] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 046F0FC3
.text C:\WINDOWS\System32\svchost.exe[1516] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 046F0F0C
.text C:\WINDOWS\System32\svchost.exe[1516] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 047E0F9E
.text C:\WINDOWS\System32\svchost.exe[1516] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 047E0F5E
.text C:\WINDOWS\System32\svchost.exe[1516] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 047E0FAF
.text C:\WINDOWS\System32\svchost.exe[1516] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 047E0FD4
.text C:\WINDOWS\System32\svchost.exe[1516] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 047E0F79
.text C:\WINDOWS\System32\svchost.exe[1516] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 047E0FE5
.text C:\WINDOWS\System32\svchost.exe[1516] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 047E001B
.text C:\WINDOWS\System32\svchost.exe[1516] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 047E0000
.text C:\WINDOWS\System32\svchost.exe[1516] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 047D0FC3
.text C:\WINDOWS\System32\svchost.exe[1516] msvcrt.dll!system 77C293C7 5 Bytes JMP 047D0FDE
.text C:\WINDOWS\System32\svchost.exe[1516] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 047D003A
.text C:\WINDOWS\System32\svchost.exe[1516] msvcrt.dll!_open 77C2F566 5 Bytes JMP 047D0000
.text C:\WINDOWS\System32\svchost.exe[1516] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 047D0FEF
.text C:\WINDOWS\System32\svchost.exe[1516] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 047D0029
.text C:\WINDOWS\System32\svchost.exe[1516] WS2_32.dll!socket 71AB4211 5 Bytes JMP 04720FEF
.text C:\WINDOWS\System32\svchost.exe[1516] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 04710000
.text C:\WINDOWS\System32\svchost.exe[1516] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 04710011
.text C:\WINDOWS\System32\svchost.exe[1516] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 04710022
.text C:\WINDOWS\System32\svchost.exe[1516] WININET.dll!InternetOpenUrlW 3D9A6D5F 5 Bytes JMP 04710FDB
.text C:\WINDOWS\system32\svchost.exe[1620] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00C00FE5
.text C:\WINDOWS\system32\svchost.exe[1620] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00C0000A
.text C:\WINDOWS\system32\svchost.exe[1620] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00C00FD4
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BF0000
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BF009D
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BF0FA8
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BF0076
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BF0FC3
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BF0051
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BF00D5
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BF0F8D
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BF0F46
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BF0F61
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BF00FA
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BF0FD4
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BF0FE5
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BF00B8
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BF0040
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BF0025
.text C:\WINDOWS\system32\svchost.exe[1620] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BF0F72
.text C:\WINDOWS\system32\svchost.exe[1620] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00660025
.text C:\WINDOWS\system32\svchost.exe[1620] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00660054
.text C:\WINDOWS\system32\svchost.exe[1620] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00660FDE
.text C:\WINDOWS\system32\svchost.exe[1620] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00660014
.text C:\WINDOWS\system32\svchost.exe[1620] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00660F97
.text C:\WINDOWS\system32\svchost.exe[1620] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00660FEF
.text C:\WINDOWS\system32\svchost.exe[1620] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00660FA8
.text C:\WINDOWS\system32\svchost.exe[1620] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [86, 88]
.text C:\WINDOWS\system32\svchost.exe[1620] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00660FC3
.text C:\WINDOWS\system32\svchost.exe[1620] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0065007A
.text C:\WINDOWS\system32\svchost.exe[1620] msvcrt.dll!system 77C293C7 5 Bytes JMP 00650FEF
.text C:\WINDOWS\system32\svchost.exe[1620] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0065003A
.text C:\WINDOWS\system32\svchost.exe[1620] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00650000
.text C:\WINDOWS\system32\svchost.exe[1620] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00650055
.text C:\WINDOWS\system32\svchost.exe[1620] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0065001D
.text C:\WINDOWS\system32\svchost.exe[1620] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 00630000
.text C:\WINDOWS\system32\svchost.exe[1620] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 00630025
.text C:\WINDOWS\system32\svchost.exe[1620] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 00630036
.text C:\WINDOWS\system32\svchost.exe[1620] WININET.dll!InternetOpenUrlW 3D9A6D5F 5 Bytes JMP 00630051
.text C:\WINDOWS\system32\svchost.exe[1620] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00640000
.text C:\WINDOWS\system32\svchost.exe[1676] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00A3000A
.text C:\WINDOWS\system32\svchost.exe[1676] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00A3002F
.text C:\WINDOWS\system32\svchost.exe[1676] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00A30FEF
.text C:\WINDOWS\system32\svchost.exe[1676] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00A2000A
.text C:\WINDOWS\system32\svchost.exe[1676] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00A20FB0
.text C:\WINDOWS\system32\svchost.exe[1676] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00A2009B
.text C:\WINDOWS\system32\svchost.exe[1676] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00A2008A
.text C:\WINDOWS\system32\svchost.exe[1676] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00A20FCD
.text C:\WINDOWS\system32\svchost.exe[1676] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00A2005B
.text C:\WINDOWS\system32\svchost.exe[1676] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00A200C0
.text C:\WINDOWS\system32\svchost.exe[1676] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00A20F7A
.text C:\WINDOWS\system32\svchost.exe[1676] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00A200EC
.text C:\WINDOWS\system32\svchost.exe[1676] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00A20F5D
.text C:\WINDOWS\system32\svchost.exe[1676] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00A200FD
.text C:\WINDOWS\system32\svchost.exe[1676] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00A20FDE
.text C:\WINDOWS\system32\svchost.exe[1676] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00A20FEF
.text C:\WINDOWS\system32\svchost.exe[1676] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00A20F95
.text C:\WINDOWS\system32\svchost.exe[1676] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00A2004A
.text C:\WINDOWS\system32\svchost.exe[1676] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00A20025
.text C:\WINDOWS\system32\svchost.exe[1676] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00A200D1
.text C:\WINDOWS\system32\svchost.exe[1676] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00A60FCA
.text C:\WINDOWS\system32\svchost.exe[1676] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00A60047
.text C:\WINDOWS\system32\svchost.exe[1676] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00A60FE5
.text C:\WINDOWS\system32\svchost.exe[1676] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00A6001B
.text C:\WINDOWS\system32\svchost.exe[1676] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00A60036
.text C:\WINDOWS\system32\svchost.exe[1676] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00A60000
.text C:\WINDOWS\system32\svchost.exe[1676] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00A60F94
.text C:\WINDOWS\system32\svchost.exe[1676] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [C6, 88]
.text C:\WINDOWS\system32\svchost.exe[1676] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00A60FA5
.text C:\WINDOWS\system32\svchost.exe[1676] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00A50047
.text C:\WINDOWS\system32\svchost.exe[1676] msvcrt.dll!system 77C293C7 5 Bytes JMP 00A50FB2
.text C:\WINDOWS\system32\svchost.exe[1676] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00A50FDE
.text C:\WINDOWS\system32\svchost.exe[1676] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00A50FEF
.text C:\WINDOWS\system32\svchost.exe[1676] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00A50FC3
.text C:\WINDOWS\system32\svchost.exe[1676] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00A50018
.text C:\WINDOWS\system32\svchost.exe[1676] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00A40FEF
.text C:\WINDOWS\system32\svchost.exe[1764] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00FE0FEF
.text C:\WINDOWS\system32\svchost.exe[1764] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00FE0FC3
.text C:\WINDOWS\system32\svchost.exe[1764] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00FE0FDE
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00FD0FEF
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00FD0F75
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00FD0F86
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00FD0060
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00FD0F97
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00FD0FA8
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00FD0096
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00FD0085
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FD0F18
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FD0F33
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00FD00D6
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00FD002F
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00FD0014
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00FD0F5A
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00FD0FC3
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00FD0FDE
.text C:\WINDOWS\system32\svchost.exe[1764] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00FD00B1
.text C:\WINDOWS\system32\svchost.exe[1764] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01020FB2
.text C:\WINDOWS\system32\svchost.exe[1764] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01020F75
.text C:\WINDOWS\system32\svchost.exe[1764] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01020FC3
.text C:\WINDOWS\system32\svchost.exe[1764] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01020FDE
.text C:\WINDOWS\system32\svchost.exe[1764] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01020028
.text C:\WINDOWS\system32\svchost.exe[1764] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01020FEF
.text C:\WINDOWS\system32\svchost.exe[1764] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01020F90
.text C:\WINDOWS\system32\svchost.exe[1764] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [22, 89]
.text C:\WINDOWS\system32\svchost.exe[1764] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01020FA1
.text C:\WINDOWS\system32\svchost.exe[1764] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01010FB7
.text C:\WINDOWS\system32\svchost.exe[1764] msvcrt.dll!system 77C293C7 5 Bytes JMP 01010FD2
.text C:\WINDOWS\system32\svchost.exe[1764] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01010038
.text C:\WINDOWS\system32\svchost.exe[1764] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01010000
.text C:\WINDOWS\system32\svchost.exe[1764] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01010FE3
.text C:\WINDOWS\system32\svchost.exe[1764] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01010011
.text C:\WINDOWS\system32\svchost.exe[1764] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FF0000
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2240] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 62419A20 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2240] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 62419AE2 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10047D70 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00150000
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] ntdll.dll!NtCreateKey 7C90D0EE 5 Bytes JMP 10047CF0 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00150FDB
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] ntdll.dll!NtDeleteKey 7C90D24E 5 Bytes JMP 10047D90 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] ntdll.dll!NtDeleteValueKey 7C90D26E 5 Bytes JMP 10047DB0 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10047D20 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0015001B
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] ntdll.dll!NtQueryValueKey 7C90D96E 5 Bytes JMP 10047C90 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] ntdll.dll!NtSetValueKey 7C90DDCE 5 Bytes JMP 10047CC0 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00C70780 C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll (IEHelper/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00270FEF
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00270F7E
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 0027007D
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00270FAF
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00270062
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0027003D
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00270F46
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00270F63
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 002700BA
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00270F2B
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 002700D5
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00270FC0
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0027000A
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 0027008E
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 0027002C
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 0027001B
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 0027009F
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00370FCA
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00370F7C
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0037001B
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 0037000A
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00370F97
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00370FEF
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00370FA8
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [57, 88]
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00370FB9
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00380F75
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] msvcrt.dll!system 77C293C7 5 Bytes JMP 00380F86
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00380FB5
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00380FE3
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00380000
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00380FD2
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] SHLWAPI.dll!SHCreateStreamOnFileA + 2066 77FC22BC 5 Bytes JMP 00C6C790 C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll (IEHelper/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX1\h\iexplore.exe[2616] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 00C72C50 C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll (IEHelper/Discordia, LTD)
.text C:\WINDOWS\system32\svchost.exe[2752] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00D00FEF
.text C:\WINDOWS\system32\svchost.exe[2752] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00D00014
.text C:\WINDOWS\system32\svchost.exe[2752] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00D00FDE
.text C:\WINDOWS\system32\svchost.exe[2752] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00CF0FE5
.text C:\WINDOWS\system32\svchost.exe[2752] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00CF0F3E
.text C:\WINDOWS\system32\svchost.exe[2752] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00CF003D
.text C:\WINDOWS\system32\svchost.exe[2752] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00CF002C
.text C:\WINDOWS\system32\svchost.exe[2752] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00CF0F6F
.text C:\WINDOWS\system32\svchost.exe[2752] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00CF001B
.text C:\WINDOWS\system32\svchost.exe[2752] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00CF007C
.text C:\WINDOWS\system32\svchost.exe[2752] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00CF005F
.text C:\WINDOWS\system32\svchost.exe[2752] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00CF0EFE
.text C:\WINDOWS\system32\svchost.exe[2752] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00CF0F0F
.text C:\WINDOWS\system32\svchost.exe[2752] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00CF0EE3
.text C:\WINDOWS\system32\svchost.exe[2752] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00CF0F94
.text C:\WINDOWS\system32\svchost.exe[2752] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00CF0FCA
.text C:\WINDOWS\system32\svchost.exe[2752] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00CF004E
.text C:\WINDOWS\system32\svchost.exe[2752] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00CF0FAF
.text C:\WINDOWS\system32\svchost.exe[2752] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00CF0000
.text C:\WINDOWS\system32\svchost.exe[2752] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00CF008D
.text C:\WINDOWS\system32\svchost.exe[2752] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00CE0FD4
.text C:\WINDOWS\system32\svchost.exe[2752] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00CE0F97
.text C:\WINDOWS\system32\svchost.exe[2752] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00CE0025
.text C:\WINDOWS\system32\svchost.exe[2752] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00CE0FE5
.text C:\WINDOWS\system32\svchost.exe[2752] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00CE0FA8
.text C:\WINDOWS\system32\svchost.exe[2752] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00CE0000
.text C:\WINDOWS\system32\svchost.exe[2752] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00CE004A
.text C:\WINDOWS\system32\svchost.exe[2752] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00CE0FC3
.text C:\WINDOWS\system32\svchost.exe[2752] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00CD0036
.text C:\WINDOWS\system32\svchost.exe[2752] msvcrt.dll!system 77C293C7 5 Bytes JMP 00CD0FA1
.text C:\WINDOWS\system32\svchost.exe[2752] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00CD0000
.text C:\WINDOWS\system32\svchost.exe[2752] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00CD0FEF
.text C:\WINDOWS\system32\svchost.exe[2752] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00CD0011
.text C:\WINDOWS\system32\svchost.exe[2752] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00CD0FD2
.text C:\Program Files\Messenger\msmsgs.exe[2804] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00080FEF
.text C:\Program Files\Messenger\msmsgs.exe[2804] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00080FCA
.text C:\Program Files\Messenger\msmsgs.exe[2804] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0008000A
.text C:\Program Files\Messenger\msmsgs.exe[2804] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001B0FEF
.text C:\Program Files\Messenger\msmsgs.exe[2804] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001B0F86
.text C:\Program Files\Messenger\msmsgs.exe[2804] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001B0F97
.text C:\Program Files\Messenger\msmsgs.exe[2804] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001B0071
.text C:\Program Files\Messenger\msmsgs.exe[2804] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001B0054
.text C:\Program Files\Messenger\msmsgs.exe[2804] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001B0FC3
.text C:\Program Files\Messenger\msmsgs.exe[2804] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001B0F5F
.text C:\Program Files\Messenger\msmsgs.exe[2804] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001B00A7
.text C:\Program Files\Messenger\msmsgs.exe[2804] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001B00D3
.text C:\Program Files\Messenger\msmsgs.exe[2804] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001B0F44
.text C:\Program Files\Messenger\msmsgs.exe[2804] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 001B0F15
.text C:\Program Files\Messenger\msmsgs.exe[2804] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 001B0FA8
.text C:\Program Files\Messenger\msmsgs.exe[2804] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 001B0FDE
.text C:\Program Files\Messenger\msmsgs.exe[2804] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 001B0096
.text C:\Program Files\Messenger\msmsgs.exe[2804] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 001B002F
.text C:\Program Files\Messenger\msmsgs.exe[2804] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 001B0014
.text C:\Program Files\Messenger\msmsgs.exe[2804] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 001B00C2
.text C:\Program Files\Messenger\msmsgs.exe[2804] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 002A0058
.text C:\Program Files\Messenger\msmsgs.exe[2804] msvcrt.dll!system 77C293C7 5 Bytes JMP 002A0FCD
.text C:\Program Files\Messenger\msmsgs.exe[2804] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 002A0FEF
.text C:\Program Files\Messenger\msmsgs.exe[2804] msvcrt.dll!_open 77C2F566 5 Bytes JMP 002A000C
.text C:\Program Files\Messenger\msmsgs.exe[2804] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 002A0FDE
.text C:\Program Files\Messenger\msmsgs.exe[2804] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 002A0029
.text C:\Program Files\Messenger\msmsgs.exe[2804] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 002B0047
.text C:\Program Files\Messenger\msmsgs.exe[2804] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 002B007A
.text C:\Program Files\Messenger\msmsgs.exe[2804] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 002B0036
.text C:\Program Files\Messenger\msmsgs.exe[2804] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 002B0025
.text C:\Program Files\Messenger\msmsgs.exe[2804] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 002B0069
.text C:\Program Files\Messenger\msmsgs.exe[2804] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 002B0000
.text C:\Program Files\Messenger\msmsgs.exe[2804] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 002B0058
.text C:\Program Files\Messenger\msmsgs.exe[2804] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 002B0FD1
.text C:\Program Files\Messenger\msmsgs.exe[2804] WS2_32.dll!socket 71AB4211 5 Bytes JMP 002C0FEF
.text C:\Program Files\Messenger\msmsgs.exe[2804] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 002D0FEF
.text C:\Program Files\Messenger\msmsgs.exe[2804] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 002D000A
.text C:\Program Files\Messenger\msmsgs.exe[2804] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 002D001B
.text C:\Program Files\Messenger\msmsgs.exe[2804] WININET.dll!InternetOpenUrlW 3D9A6D5F 5 Bytes JMP 002D0FC0
.text C:\WINDOWS\System32\svchost.exe[2820] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00F90000
.text C:\WINDOWS\System32\svchost.exe[2820] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00F90FE5
.text C:\WINDOWS\System32\svchost.exe[2820] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00F9001B
.text C:\WINDOWS\System32\svchost.exe[2820] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F80FE5
.text C:\WINDOWS\System32\svchost.exe[2820] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F80F66
.text C:\WINDOWS\System32\svchost.exe[2820] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F80F81
.text C:\WINDOWS\System32\svchost.exe[2820] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F80F9E
.text C:\WINDOWS\System32\svchost.exe[2820] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F80FAF
.text C:\WINDOWS\System32\svchost.exe[2820] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F80036
.text C:\WINDOWS\System32\svchost.exe[2820] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F80093
.text C:\WINDOWS\System32\svchost.exe[2820] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F80F4B
.text C:\WINDOWS\System32\svchost.exe[2820] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F80F04
.text C:\WINDOWS\System32\svchost.exe[2820] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F80F1F
.text C:\WINDOWS\System32\svchost.exe[2820] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F800C2
.text C:\WINDOWS\System32\svchost.exe[2820] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F80051
.text C:\WINDOWS\System32\svchost.exe[2820] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F80000
.text C:\WINDOWS\System32\svchost.exe[2820] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F80076
.text C:\WINDOWS\System32\svchost.exe[2820] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F80FC0
.text C:\WINDOWS\System32\svchost.exe[2820] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F8001B
.text C:\WINDOWS\System32\svchost.exe[2820] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F80F30
.text C:\WINDOWS\System32\svchost.exe[2820] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00F70FD4
.text C:\WINDOWS\System32\svchost.exe[2820] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00F7005B
.text C:\WINDOWS\System32\svchost.exe[2820] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00F7001B
.text C:\WINDOWS\System32\svchost.exe[2820] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00F7000A
.text C:\WINDOWS\System32\svchost.exe[2820] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00F70F9E
.text C:\WINDOWS\System32\svchost.exe[2820] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00F70FEF
.text C:\WINDOWS\System32\svchost.exe[2820] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00F70040
.text C:\WINDOWS\System32\svchost.exe[2820] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00F70FB9
.text C:\WINDOWS\System32\svchost.exe[2820] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 006C004C
.text C:\WINDOWS\System32\svchost.exe[2820] msvcrt.dll!system 77C293C7 5 Bytes JMP 006C0031
.text C:\WINDOWS\System32\svchost.exe[2820] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 006C0016
.text C:\WINDOWS\System32\svchost.exe[2820] msvcrt.dll!_open 77C2F566 5 Bytes JMP 006C0FE3
.text C:\WINDOWS\System32\svchost.exe[2820] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 006C0FB7
.text C:\WINDOWS\System32\svchost.exe[2820] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 006C0FD2
.text C:\WINDOWS\System32\svchost.exe[2820] WS2_32.dll!socket 71AB4211 5 Bytes JMP 006B0FE5
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10047D70 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00150FEF
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] ntdll.dll!NtCreateKey 7C90D0EE 5 Bytes JMP 10047CF0 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0015001B
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] ntdll.dll!NtDeleteKey 7C90D24E 5 Bytes JMP 10047D90 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] ntdll.dll!NtDeleteValueKey 7C90D26E 5 Bytes JMP 10047DB0 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10047D20 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0015000A
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] ntdll.dll!NtQueryValueKey 7C90D96E 5 Bytes JMP 10047C90 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] ntdll.dll!NtSetValueKey 7C90DDCE 5 Bytes JMP 10047CC0 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00C70780 C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll (IEHelper/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00270000
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00270F55
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00270F66
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0027004A
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00270F8D
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00270FAF
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 0027006C
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00270F24
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00270F02
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00270091
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 002700AC
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00270F9E
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00270FDB
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 0027005B
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00270FC0
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00270011
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00270F13
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0037001B
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 0037006C
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00370FCA
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00370FE5
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00370051
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00370000
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00370040
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00370FAF
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00380FA1
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] msvcrt.dll!system 77C293C7 5 Bytes JMP 0038002C
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0038001B
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00380000
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00380FC6
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00380FE3
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] SHLWAPI.dll!SHCreateStreamOnFileA + 2066 77FC22BC 5 Bytes JMP 00C6C790 C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll (IEHelper/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX4\h\iexplore.exe[2872] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 00C72C50 C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll (IEHelper/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10047D70 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00150000
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] ntdll.dll!NtCreateKey 7C90D0EE 5 Bytes JMP 10047CF0 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00150011
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] ntdll.dll!NtDeleteKey 7C90D24E 5 Bytes JMP 10047D90 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] ntdll.dll!NtDeleteValueKey 7C90D26E 5 Bytes JMP 10047DB0 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10047D20 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00150FE5
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] ntdll.dll!NtQueryValueKey 7C90D96E 5 Bytes JMP 10047C90 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] ntdll.dll!NtSetValueKey 7C90DDCE 5 Bytes JMP 10047CC0 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00C70780 C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll (IEHelper/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00270000
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 0027008E
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 0027007D
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0027006C
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00270FAF
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00270036
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00270F63
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00270F74
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 002700DA
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00270F41
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 002700F5
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00270047
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00270FE5
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 0027009F
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00270FC0
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00270011
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00270F52
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0037002F
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 0037006C
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00370FD4
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00370FE5
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 0037005B
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00370000
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00370FAF
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [57, 88]
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00370040
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00380049
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] msvcrt.dll!system 77C293C7 5 Bytes JMP 0038002E
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0038001D
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00380000
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00380FC8
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00380FE3
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] SHLWAPI.dll!SHCreateStreamOnFileA + 2066 77FC22BC 5 Bytes JMP 00C6C790 C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll (IEHelper/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX5\h\iexplore.exe[3220] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 00C72C50 C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll (IEHelper/Discordia, LTD)
.text C:\WINDOWS\explorer.exe[4984] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00090000
.text C:\WINDOWS\explorer.exe[4984] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0009002C
.text C:\WINDOWS\explorer.exe[4984] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00090011
.text C:\WINDOWS\explorer.exe[4984] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001B0FE5
.text C:\WINDOWS\explorer.exe[4984] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001B0062
.text C:\WINDOWS\explorer.exe[4984] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001B0051
.text C:\WINDOWS\explorer.exe[4984] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001B0F83
.text C:\WINDOWS\explorer.exe[4984] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001B0036
.text C:\WINDOWS\explorer.exe[4984] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001B0014
.text C:\WINDOWS\explorer.exe[4984] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001B0090
.text C:\WINDOWS\explorer.exe[4984] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001B0F48
.text C:\WINDOWS\explorer.exe[4984] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001B00C6
.text C:\WINDOWS\explorer.exe[4984] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001B0F2D
.text C:\WINDOWS\explorer.exe[4984] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 001B00E1
.text C:\WINDOWS\explorer.exe[4984] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 001B0025
.text C:\WINDOWS\explorer.exe[4984] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 001B0FD4
.text C:\WINDOWS\explorer.exe[4984] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 001B0073
.text C:\WINDOWS\explorer.exe[4984] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 001B0F9E
.text C:\WINDOWS\explorer.exe[4984] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 001B0FAF
.text C:\WINDOWS\explorer.exe[4984] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 001B00A1
.text C:\WINDOWS\explorer.exe[4984] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 002A0FD4
.text C:\WINDOWS\explorer.exe[4984] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 002A0087
.text C:\WINDOWS\explorer.exe[4984] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 002A001B
.text C:\WINDOWS\explorer.exe[4984] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 002A0FE5
.text C:\WINDOWS\explorer.exe[4984] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 002A006C
.text C:\WINDOWS\explorer.exe[4984] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 002A0000
.text C:\WINDOWS\explorer.exe[4984] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 002A005B
.text C:\WINDOWS\explorer.exe[4984] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 002A0040
.text C:\WINDOWS\explorer.exe[4984] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 002B0025
.text C:\WINDOWS\explorer.exe[4984] msvcrt.dll!system 77C293C7 5 Bytes JMP 002B0F9A
.text C:\WINDOWS\explorer.exe[4984] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 002B0FC6
.text C:\WINDOWS\explorer.exe[4984] msvcrt.dll!_open 77C2F566 5 Bytes JMP 002B0FE3
.text C:\WINDOWS\explorer.exe[4984] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 002B0FB5
.text C:\WINDOWS\explorer.exe[4984] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 002B0000
.text C:\WINDOWS\explorer.exe[4984] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 002D0FEF
.text C:\WINDOWS\explorer.exe[4984] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 002D0FCA
.text C:\WINDOWS\explorer.exe[4984] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 002D0FB9
.text C:\WINDOWS\explorer.exe[4984] WININET.dll!InternetOpenUrlW 3D9A6D5F 5 Bytes JMP 002D000A
.text C:\WINDOWS\explorer.exe[4984] WS2_32.dll!socket 71AB4211 5 Bytes JMP 02CD0000
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 10047D70 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00150000
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] ntdll.dll!NtCreateKey 7C90D0EE 5 Bytes JMP 10047CF0 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00150011
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] ntdll.dll!NtDeleteKey 7C90D24E 5 Bytes JMP 10047D90 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] ntdll.dll!NtDeleteValueKey 7C90D26E 5 Bytes JMP 10047DB0 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10047D20 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00150FDB
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] ntdll.dll!NtQueryValueKey 7C90D96E 5 Bytes JMP 10047C90 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] ntdll.dll!NtSetValueKey 7C90DDCE 5 Bytes JMP 10047CC0 C:\PROGRA~1\WI371A~1\Datamngr\datamngr.dll (Data Manager/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00C70780 C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll (IEHelper/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00270000
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00270040
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00270F4B
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00270F5C
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00270F83
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00270FAF
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00270F30
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00270076
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00270EF3
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00270F04
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00270ED8
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00270F9E
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00270FEF
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 0027005B
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00270FD4
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 0027001B
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00270F1F
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00370040
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00370FC0
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00370025
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00370FEF
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 0037007D
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00370000
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 0037006C
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00370051
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00380FAB
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] msvcrt.dll!system 77C293C7 5 Bytes JMP 00380FBC
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00380FDE
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00380000
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00380FCD
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00380FEF
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] SHLWAPI.dll!SHCreateStreamOnFileA + 2066 77FC22BC 5 Bytes JMP 00C6C790 C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll (IEHelper/Discordia, LTD)
.text C:\DOCUME~1\Whites\LOCALS~1\Temp\RarSFX3\h\iexplore.exe[5516] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 00C72C50 C:\PROGRA~1\WI371A~1\Datamngr\IEBHO.dll (IEHelper/Discordia, LTD)
.text C:\Program Files\Mozilla Firefox\firefox.exe[5648] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)

Device \FileSystem\Fastfat \Fat A495FD20

AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (McAfee Link Driver/McAfee, Inc.)

Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Roxio)

—- Files - GMER 1.0.15 —-

File C:\Documents and Settings\Whites\Local Settings\Temporary Internet Files\Content.IE5\1VYDG0E9\0322031000[2].kmz 15461 bytes
File C:\Documents and Settings\Whites\Local Settings\Temporary Internet Files\Content.IE5\1VYDG0E9\032213[2].kmz 1758 bytes
File C:\Documents and Settings\Whites\Local Settings\Temporary Internet Files\Content.IE5\1VYDG0E9\03220132[1].kmz 2290 bytes

—- EOF - GMER 1.0.15 —-

Attachments:

  • [attachment removed: error.gif]
Hi whites

Yes, I see the problem and it shouldn’t be too bad to sort out.

I need you to run two more scans.

Run aswMBR

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
🖼Click to load external image (Posted Image)

On completion of the scan click save log, save it to your desktop and post in your next reply
🖼Click to load external image (Posted Image)

===================================================

Download and run OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

Logs to include with next post:

aswMBR log
OTL.txt
Extras.txt


Thanks

Satchfan
aswMBR.txt:

aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-05-21 19:56:20
—————————–
19:56:20.562 OS Version: Windows 5.1.2600 Service Pack 3
19:56:20.562 Number of processors: 2 586 0xF0D
19:56:20.562 ComputerName: WHITE UserName:
19:56:21.640 Initialize success
19:56:36.484 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
19:56:36.500 Disk 0 Vendor: ST3320620AS 3.ADG Size: 305245MB BusType: 3
19:56:38.562 Disk 0 MBR read successfully
19:56:38.578 Disk 0 MBR scan
19:56:38.578 Disk 0 unknown MBR code
19:56:40.609 Disk 0 scanning sectors +625137345
19:56:40.703 Disk 0 scanning C:\WINDOWS\system32\drivers
19:57:13.968 Service scanning
19:57:15.078 Disk 0 trace - called modules:
19:57:15.093
19:57:15.109 Scan finished successfully
19:57:39.515 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Whites\Desktop\MBR.dat"
19:57:39.515 The log file has been saved successfully to "C:\Documents and Settings\Whites\Desktop\aswMBR.txt"


OTL.txt:

OTL logfile created on: 21/05/2011 8:02:04 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Whites\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 57.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 294.74 Gb Total Space | 240.87 Gb Free Space | 81.72% Space Free | Partition Type: NTFS

Computer Name: WHITE | User Name: Whites | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Whites\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Whites\Desktop\aswMBR.exe (AVAST Software)
PRC - C:\Documents and Settings\Whites\Desktop\uSeRiNiT.exe ()
PRC - C:\Documents and Settings\Whites\Desktop\rkill.com ()
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - c:\Program Files\McAfee.com\Agent\mcupdate.exe (McAfee, Inc.)
PRC - C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
PRC - C:\Program Files\doubleTwist 2.0\DoubleTwist.DeviceHelper.exe (doubleTwist Corporation)
PRC - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe ()
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\McAfee\MSC\McUICnt.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MSM\McSmtFwk.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\drivers\CDAC11BA.EXE (Macrovision)
PRC - C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Documents and Settings\Whites\Local Settings\Temp\RarSFX5\h\iexplore.exe ()
PRC - C:\Documents and Settings\Whites\Local Settings\Temp\RarSFX4\h\iexplore.exe ()
PRC - C:\Documents and Settings\Whites\Local Settings\Temp\RarSFX3\h\iexplore.exe ()
PRC - C:\Documents and Settings\Whites\Local Settings\Temp\RarSFX2\h\iexplore.exe ()
PRC - C:\Documents and Settings\Whites\Local Settings\Temp\RarSFX1\h\iexplore.exe ()
PRC - C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe (Lexmark International, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Whites\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (mfevtp) – C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (PassThru Service) – C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe ()
SRV - (MSK80Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McProxy) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (C-DillaCdaC11BA) – C:\WINDOWS\system32\drivers\CDAC11BA.EXE (Macrovision)


========== Driver Services (SafeList) ==========

DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – C:\WINDOWS\system32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfendiskmp) – C:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfendisk) – C:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfetdi2k) – C:\WINDOWS\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (cfwids) – C:\WINDOWS\system32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (iPodDrv) – C:\WINDOWS\system32\drivers\iPodDrv.sys (Windows ® Codename Longhorn DDK provider)
DRV - (htcnprot) – C:\WINDOWS\system32\drivers\htcnprot.sys (Windows ® Win 7 DDK provider)
DRV - (mfesmfk) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (HTCAND32) – C:\WINDOWS\system32\drivers\ANDROIDUSB.sys (HTC, Corporation)
DRV - (CdaC15BA) – C:\WINDOWS\system32\drivers\CDAC15BA.SYS (Macrovision Europe Ltd)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (DLADResM) – C:\WINDOWS\system32\DLA\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:\WINDOWS\system32\DLA\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Roxio)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Roxio)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Roxio)
DRV - (DLARTL_M) – C:\WINDOWS\system32\drivers\DLARTL_M.SYS (Roxio)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (giveio) – C:\WINDOWS\system32\giveio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Google Australia"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
FF - prefs.js..extensions.enabledItems: {987311C6-B504-4aa2-90BF-60CC49808D42}:2.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: siteinfo@wmtips:1.2
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.9
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.6.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0
FF - prefs.js..extensions.enabledItems: {99079a25-328f-4bd4-be04-00955acaa0a7}:4.1.0.01
FF - prefs.js..extensions.enabledItems: [removed]:3.2.1
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid;=406&q;="

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/14 10:19:44 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/13 14:39:13 | 000,000,000 | —D | M]

[2011/05/20 11:31:43 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Whites\Application Data\Mozilla\Extensions
[2009/10/23 08:21:04 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Whites\Application Data\Mozilla\Extensions\[removed]
[2011/05/20 19:59:43 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions
[2010/08/13 19:26:34 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/09/16 09:21:17 | 000,000,000 | —D | M] (BugMeNot) – C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{987311C6-B504-4aa2-90BF-60CC49808D42}
[2011/05/20 11:31:36 | 000,000,000 | —D | M] (Searchqu Toolbar) – C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
[2011/01/10 18:27:51 | 000,000,000 | —D | M] (Web Developer) – C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2011/02/11 17:22:44 | 000,000,000 | —D | M] (Firebug) – C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\[removed]
[2010/04/11 15:57:47 | 000,000,000 | —D | M] (Kempelton) – C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\[removed]
[2009/04/02 11:37:49 | 000,000,000 | —D | M] (Site Information Tool) – C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\siteinfo@wmtips
[2011/05/15 19:16:02 | 000,001,698 | —- | M] () – C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\searchplugins\compact-oxford-english-dict.xml
[2011/05/15 19:16:02 | 000,002,588 | —- | M] () – C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\searchplugins\ebay-australia.xml
[2011/05/15 19:16:02 | 000,002,486 | —- | M] () – C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\searchplugins\google-australia.xml
[2008/05/09 09:34:15 | 000,001,504 | —- | M] () – C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\searchplugins\imdb.xml
[2011/03/23 22:24:21 | 000,005,529 | —- | M] () – C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\searchplugins\SearchquWebSearch.xml
[2008/03/08 12:53:46 | 000,001,058 | —- | M] () – C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\searchplugins\wikipedia-en.xml
[2008/03/01 10:40:43 | 000,002,109 | —- | M] () – C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\searchplugins\youtube-video-search.xml
[2011/05/20 19:59:43 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/06 17:26:06 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/07 06:35:45 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/12/01 10:35:58 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/25 10:45:24 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2009/03/11 06:47:00 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/05/20 11:31:43 | 000,000,000 | —D | M] (DataMngr) – C:\PROGRAM FILES\WINDOWS ILIVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION
[2011/04/14 14:01:38 | 000,024,376 | —- | M] (McAfee, Inc.) – C:\Program Files\Mozilla Firefox\components\Scriptff.dll
[2010/11/12 17:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/03/23 22:24:21 | 000,005,529 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\SearchquWebSearch.xml

O1 HOSTS File: ([2004/08/04 07:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (PodcastBHO Class) - {65134FDF-F8A5-4B3D-91D9-CDF273CFD578} - C:\Program Files\Common Files\doubleTwist\IEPodcastPlugin.dll (doubleTwist Corporation)
O2 - BHO: (DebugBar BHO) - {69FC0024-10EB-480A-BBF2-3BF4E78E17B1} - C:\Program Files\Core Services\DebugBar\DebugInfoBar.dll (Core Services)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110514101944.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (DebugBar) - {3E1201F4-1707-409F-BB45-A5F192381DA0} - C:\Program Files\Core Services\DebugBar\DebugToolBar.dll (Core Services)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [Lexmark X1100 Series] C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKCU..\Run: [doubleTwist] C:\Program Files\doubleTwist 2.0\DoubleTwist.DeviceHelper.exe (doubleTwist Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Whites\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} http://kitchenplanner.ikea.com/AU/Core/Pla…yerAX_Win32.cab (20-20 3D Viewer)
O16 - DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} http://static.ak.facebook.com/fbplugin/win…b?1271577864906 (Reg Error: Key error.)
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} http://whitechimagine.com/imagine/ax/ImageUploader5.cab (Image Uploader Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1205222789078 (MUWebControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {EA1B8527-E422-4909-825A-70BE0694F18E} https://online.westpac.com.au/wtpbs/wtBalan…iomanagerwt.cab (PortfolioManagerWT ProfileManager Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.1.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Whites\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Whites\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 15:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{13ccabd4-93c2-11de-b1fc-001d09856607}\Shell\AutoRun\command - "" = E:\WDSetup.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183584330711040)

========== Files/Folders - Created Within 30 Days ==========

[2011/05/21 19:55:29 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Whites\Desktop\OTL.exe
[2011/05/21 19:55:14 | 000,589,632 | —- | C] (AVAST Software) – C:\Documents and Settings\Whites\Desktop\aswMBR.exe
[2011/05/20 20:12:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Whites\Desktop\gmer
[2011/05/20 20:09:51 | 000,606,738 | R— | C] (Swearware) – C:\Documents and Settings\Whites\Desktop\dds.pif
[2011/05/20 20:09:51 | 000,000,000 | -H-D | C] – C:\WINDOWS\PIF
[2011/05/20 20:06:06 | 000,606,738 | —- | C] (Swearware) – C:\Documents and Settings\Whites\Desktop\dds.scr
[2011/05/20 11:33:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Whites\Local Settings\Application Data\Ilivid Player
[2011/05/20 11:33:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Whites\Application Data\searchquband
[2011/05/20 11:32:02 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\~0
[2011/05/20 11:31:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Whites\Application Data\searchqutoolbar
[2011/05/20 11:31:26 | 000,000,000 | —D | C] – C:\Program Files\Windows iLivid Toolbar
[2011/05/20 11:31:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Whites\Local Settings\Application Data\PackageAware
[2011/05/20 11:09:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/21 20:00:08 | 000,000,504 | —- | M] () – C:\WINDOWS\lexstat.ini
[2011/05/21 19:57:39 | 000,000,512 | —- | M] () – C:\Documents and Settings\Whites\Desktop\MBR.dat
[2011/05/21 19:55:38 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Whites\Desktop\OTL.exe
[2011/05/21 19:55:22 | 000,589,632 | —- | M] (AVAST Software) – C:\Documents and Settings\Whites\Desktop\aswMBR.exe
[2011/05/21 19:23:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/21 19:21:00 | 000,000,982 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2376190734-133552657-3506529271-1006UA.job
[2011/05/21 19:08:21 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/05/21 15:23:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cac72cbfea7002.job
[2011/05/21 11:17:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/05/20 20:21:00 | 000,000,930 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2376190734-133552657-3506529271-1006Core1cb13ecf33c577e.job
[2011/05/20 20:16:59 | 000,020,220 | —- | M] () – C:\Documents and Settings\Whites\Desktop\error.gif
[2011/05/20 20:11:51 | 000,293,775 | —- | M] () – C:\Documents and Settings\Whites\Desktop\gmer.zip
[2011/05/20 20:09:51 | 000,606,738 | R— | M] (Swearware) – C:\Documents and Settings\Whites\Desktop\dds.pif
[2011/05/20 20:06:11 | 000,606,738 | —- | M] (Swearware) – C:\Documents and Settings\Whites\Desktop\dds.scr
[2011/05/20 17:45:54 | 001,007,108 | —- | M] () – C:\Documents and Settings\Whites\Desktop\uSeRiNiT.exe
[2011/05/20 17:44:16 | 001,007,108 | —- | M] () – C:\Documents and Settings\Whites\Desktop\rkill.com
[2011/05/20 11:08:59 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/20 11:08:58 | 2136,129,536 | -HS- | M] () – C:\hiberfil.sys
[2011/05/15 17:32:55 | 000,002,497 | —- | M] () – C:\Documents and Settings\Whites\Desktop\Microsoft Office Word 2003.lnk
[2011/05/14 22:03:32 | 026,244,597 | —- | M] () – C:\Documents and Settings\Whites\My Documents\05-14-2011 10;03;28PM.PDF
[2011/05/11 09:52:44 | 004,990,170 | —- | M] () – C:\Documents and Settings\Whites\My Documents\05-11-2011 09;52;43AM.PDF
[2011/05/03 18:03:20 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/21 19:57:39 | 000,000,512 | —- | C] () – C:\Documents and Settings\Whites\Desktop\MBR.dat
[2011/05/20 20:16:59 | 000,020,220 | —- | C] () – C:\Documents and Settings\Whites\Desktop\error.gif
[2011/05/20 20:11:48 | 000,293,775 | —- | C] () – C:\Documents and Settings\Whites\Desktop\gmer.zip
[2011/05/20 17:45:42 | 001,007,108 | —- | C] () – C:\Documents and Settings\Whites\Desktop\uSeRiNiT.exe
[2011/05/20 17:44:10 | 001,007,108 | —- | C] () – C:\Documents and Settings\Whites\Desktop\rkill.com
[2011/05/14 22:03:31 | 026,244,597 | —- | C] () – C:\Documents and Settings\Whites\My Documents\05-14-2011 10;03;28PM.PDF
[2011/05/11 09:52:44 | 004,990,170 | —- | C] () – C:\Documents and Settings\Whites\My Documents\05-11-2011 09;52;43AM.PDF
[2011/02/16 07:29:40 | 000,034,864 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2011/02/16 07:29:39 | 000,042,166 | —- | C] () – C:\WINDOWS\System32\DATCRT.EXE
[2010/10/27 21:42:09 | 000,230,840 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/08/06 19:12:43 | 000,000,127 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.351.32.bc
[2010/08/06 19:10:56 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2010/04/12 18:02:50 | 000,087,368 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/11/24 20:23:35 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\unhyperxmon.exe
[2009/02/19 16:40:31 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2009/01/14 19:22:35 | 000,000,089 | —- | C] () – C:\WINDOWS\MyHeritage.INI
[2009/01/14 19:20:42 | 000,454,656 | —- | C] () – C:\WINDOWS\System32\PaintX.dll
[2008/12/31 16:04:42 | 000,691,560 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2008/12/31 16:04:42 | 000,528,744 | —- | C] () – C:\WINDOWS\System32\OGAVerify.exe
[2008/07/22 06:21:44 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/04/11 20:06:30 | 000,765,952 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/04/11 20:06:29 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/04/11 18:46:53 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\cdTextCtl.dll
[2008/03/10 09:04:47 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\FileOps.exe
[2008/03/01 10:57:36 | 000,023,040 | —- | C] () – C:\Documents and Settings\Whites\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/29 17:18:26 | 000,010,268 | —- | C] () – C:\Documents and Settings\Whites\Application Data\wklnhst.dat
[2008/02/27 18:31:22 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2008/02/27 18:16:34 | 000,000,504 | —- | C] () – C:\WINDOWS\lexstat.ini
[2008/02/20 00:26:12 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/02/20 00:18:51 | 000,056,056 | —- | C] () – C:\WINDOWS\System32\DLAAPI_W.DLL
[2008/02/20 00:18:51 | 000,000,120 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/02/19 23:55:34 | 000,077,824 | —- | C] () – C:\WINDOWS\setpwr32.exe
[2008/02/19 23:55:29 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4820.dll
[2008/02/19 23:54:18 | 000,001,163 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2006/11/07 06:25:58 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2006/09/17 01:36:50 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/17 01:36:50 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2004/08/10 15:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 15:07:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/10 15:02:15 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 15:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 14:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 14:57:15 | 000,509,296 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 14:51:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 14:51:20 | 000,442,796 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 14:51:20 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 14:51:20 | 000,071,936 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 14:51:20 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 14:51:18 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/10 14:51:17 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/10 14:51:16 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/10 14:51:12 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 14:51:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 14:51:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 14:50:56 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2003/08/19 00:55:48 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\LXBKIH.EXE
[2003/08/19 00:46:38 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\LXBKLCNP.DLL
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/11/14 05:40:22 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxbkvs.dll
[2002/09/14 01:40:06 | 000,000,266 | —- | C] () – C:\WINDOWS\System32\lxbkcoin.ini
[2001/01/20 05:50:20 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\INSTMON.EXE
[1996/04/04 05:33:26 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys

========== LOP Check ==========

[2008/03/10 09:41:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodesk
[2009/10/23 10:41:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2010/08/06 19:10:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\doubleTwist Corporation
[2009/01/14 19:20:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MyHeritage
[2008/02/20 00:23:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2010/04/09 21:34:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/12 11:25:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/05/14 09:36:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/05/20 11:38:37 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\~0
[2008/03/10 09:41:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Whites\Application Data\Autodesk
[2010/12/25 22:21:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Whites\Application Data\Azureus
[2010/08/07 20:34:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Whites\Application Data\Canon
[2008/05/01 19:05:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Whites\Application Data\CopyTransDoctor
[2010/04/18 18:04:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Whites\Application Data\Facebook
[2010/06/22 17:18:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Whites\Application Data\FileZilla
[2011/01/21 16:37:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Whites\Application Data\HTC
[2011/01/21 16:47:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Whites\Application Data\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2009/10/23 10:37:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Whites\Application Data\LimeWire
[2009/01/14 19:20:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Whites\Application Data\MyHeritage
[2011/05/20 11:33:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Whites\Application Data\searchquband
[2011/05/20 11:37:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Whites\Application Data\searchqutoolbar
[2008/02/29 17:18:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Whites\Application Data\Template
[2009/01/14 19:20:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Whites\Application Data\The Complete Genealogy Reporter - FTB
[2010/07/07 08:09:59 | 000,000,506 | —- | M] () – C:\WINDOWS\Tasks\Install.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2004/08/10 15:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/11/25 14:05:47 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2004/08/10 15:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/02/19 23:57:18 | 000,006,627 | RH– | M] () – C:\dell.sdr
[2011/05/20 11:08:58 | 2136,129,536 | -HS- | M] () – C:\hiberfil.sys
[2008/03/01 10:55:38 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 15:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2004/08/10 15:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/16 11:04:23 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/05/20 11:08:57 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2011/05/20 17:48:38 | 000,000,359 | —- | M] () – C:\rkill.log
[2008/03/30 20:49:34 | 000,001,304 | —- | M] () – C:\temp.log
[2008/03/10 09:08:22 | 003,335,250 | —- | M] () – C:\test.log

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/10 15:03:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 22:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2003/07/29 23:27:40 | 000,078,336 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\LXBKPP5C.DLL
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 20:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/10 14:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/08/10 14:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/08/10 14:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/09/16 11:09:41 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/02/27 18:03:53 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Whites\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/10 15:08:38 | 000,000,079 | —- | M] () – C:\Documents and Settings\Whites\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/05/21 19:55:22 | 000,589,632 | —- | M] (AVAST Software) – C:\Documents and Settings\Whites\Desktop\aswMBR.exe
[2008/03/13 20:49:53 | 001,054,616 | —- | M] () – C:\Documents and Settings\Whites\Desktop\boot622.exe
[2011/05/21 19:55:38 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Whites\Desktop\OTL.exe
[2011/05/20 17:45:54 | 001,007,108 | —- | M] () – C:\Documents and Settings\Whites\Desktop\uSeRiNiT.exe
[2008/06/22 12:32:42 | 001,445,888 | —- | M] (Option^Explicit Software Solutions) – C:\Documents and Settings\Whites\Desktop\WinsockxpFix.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-11 11:44:10

< End of report >


Extras.txt:

OTL Extras logfile created on: 21/05/2011 8:02:04 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Whites\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 57.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 294.74 Gb Total Space | 240.87 Gb Free Space | 81.72% Space Free | Partition Type: NTFS

Computer Name: WHITE | User Name: Whites | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"D:\httpd\httpd-x86-windows\apache.exe" = D:\httpd\httpd-x86-windows\apache.exe:127.0.0.1,LocalSubnet:Enabled:Apache web server
"D:\perl\win32\wperl.exe" = D:\perl\win32\wperl.exe:127.0.0.1,LocalSubnet:Enabled:Perl interpreter - part of Stunnix Web Server
"D:\extensions\engines\mysql5-x86-windows\bin\mysqld.exe" = D:\extensions\engines\mysql5-x86-windows\bin\mysqld.exe:127.0.0.1,LocalSubnet:Enabled:Mysql database server

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"D:\httpd\httpd-x86-windows\apache.exe" = D:\httpd\httpd-x86-windows\apache.exe:127.0.0.1,LocalSubnet:Enabled:Apache web server
"D:\perl\win32\wperl.exe" = D:\perl\win32\wperl.exe:127.0.0.1,LocalSubnet:Enabled:Perl interpreter - part of Stunnix Web Server
"D:\extensions\engines\mysql5-x86-windows\bin\mysqld.exe" = D:\extensions\engines\mysql5-x86-windows\bin\mysqld.exe:127.0.0.1,LocalSubnet:Enabled:Mysql database server
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – (Lime Wire, LLC)
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent
"C:\Program Files\Vuze\Azureus.exe" = C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus / Vuze – (Vuze Inc.)
"C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" = C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe:*:Enabled:McAfee Shared Service Host – (McAfee, Inc.)
"C:\Program Files\Windows iLivid Toolbar\ToolBar\dtUser.exe" = C:\Program Files\Windows iLivid Toolbar\ToolBar\dtUser.exe:*:Enabled:DTX broker – (Visicom Media Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{0A8C7880-F199-4807-ABD4-6E695B71A3D7}" = e-tax 2009
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 23
"{281ECE39-F043-492B-8337-F2E546B5604A}" = PowerDVD
"{2A697B53-0DE3-42DA-B41D-C3F804B1C538}" = iTunes
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{31A559C1-9E4D-423B-9DD3-34A6C5398752}" = HTC BMP USB Driver
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{36DC46C4-6EDD-11D4-88D5-0000863DE970}" = Revit 3.11
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5645FB61-898F-4F59-AF80-52FEF3D63A64}" = HTC Sync
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5783F2D7-0201-0409-0002-0060B0CE6BBA}" = AutoCAD 2004
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{7797FC7F-05A2-4FDB-BADD-74B3DA296935}" = ActivePerl 5.12.2 Build 1203
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8758E9AC-183B-46CC-854B-B74D7BED8441}" = Revit AccuRender 3.1
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A987FEC8-5616-49BD-BCA6-ACFFFE7403FE}" = IKEA Home Planner
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.6
"{B148AB4B-C8FA-474B-B981-F2943C5B5BCD}" = OGA Notifier 1.7.0105.35.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C252EB7B-7AE0-46DE-9BEE-DF681B885F13}" = Modem Diagnostic Tool
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CA9BCD4D-B782-4637-8F1F-F9A328D3C244}" = Canon CanoScan Toolbox 4.9
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2121C6-C94D-4A73-8EA4-6943F33EE335}" = Picture Package Music Transfer
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"{D52ECEBC-9B20-41A5-81C4-A62DE2367419}" = Adobe Creative Suite
"{D639085F-4B6E-4105-9F37-A0DBB023E2FB}" = Roxio MyDVD DE
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FBE569CA-BFEB-4E57-A674-F94D938E1AEF}" = e-tax 2010
"{FD8C6780-9515-4750-87CA-9A3CAC6FCA24}" = HyperXpress PDF Writer 4.1
"7-Zip" = 7-Zip 9.12 beta
"8461-7759-5462-8226" = Vuze
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"Audacity_is1" = Audacity 1.2.6
"Autodesk Express Viewer" = Autodesk Express Viewer
"AviSynth" = AviSynth 2.5
"Blender" = Blender (remove only)
"CdaC13Ba" = SafeCast Shared Components
"Click'N Design 3D (V5)" = Click'N Design 3D (V5)
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"CutePDF Writer Installation" = CutePDF Writer 2.7
"DebugBar" = DebugBar v5.4.1 for Internet Explorer (remove only)
"Digital Editions" = Adobe Digital Editions
"doubleTwist" = doubleTwist
"ECCO Pro" = NetManage ECCO Pro
"e-tax 2008" = e-tax 2008
"Family Tree Builder" = MyHeritage Family Tree Builder
"ffdshow_is1" = ffdshow [rev 2527] [2008-12-19]
"FileZilla Client" = FileZilla Client 3.3.3
"Google Updater" = Google Updater
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"IETester" = IETester v0.4.4 (remove only)
"Lexmark X1100 Series" = Lexmark X1100 Series
"LimeWire" = LimeWire 5.3.6
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.17)" = Mozilla Firefox (3.6.17)
"MSC" = McAfee SecurityCenter
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nelson Maths for Victoria - Planning and Assessment software" = Nelson Maths for Victoria - Planning and Assessment software
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PROSet" = Intel® PRO Network Connections Drivers
"ROM CHECK FAIL_is1" = ROM CHECK FAIL 1.0
"Searchqu 406 MediaBar" = Windows iLivid Toolbar
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xvid_is1" = Xvid 1.1.3 final uninstall

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"Google Chrome" = Google Chrome
"GoToMeeting" = GoToMeeting 4.1.0.366

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/05/2011 1:21:41 AM | Computer Name = WHITE | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 9/05/2011 1:21:41 AM | Computer Name = WHITE | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4329359

Error - 9/05/2011 1:21:41 AM | Computer Name = WHITE | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4329359

Error - 13/05/2011 8:28:28 PM | Computer Name = WHITE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 18/05/2011 4:04:36 AM | Computer Name = WHITE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 19/05/2011 9:33:34 PM | Computer Name = WHITE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 19/05/2011 9:33:34 PM | Computer Name = WHITE | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 20/05/2011 1:43:04 AM | Computer Name = WHITE | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 20/05/2011 1:43:04 AM | Computer Name = WHITE | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1556141

Error - 20/05/2011 1:43:04 AM | Computer Name = WHITE | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1556141

[ System Events ]
Error - 3/05/2011 4:03:48 AM | Computer Name = WHITE | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 3/05/2011 4:03:48 AM | Computer Name = WHITE | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.


< End of report >
Hello again whites

P2P - I see you have P2P software, (Azureus, LimeWire), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.

Should you decide to keep it, please don’t use it until we have finished up here.

===================================================

Clear all your temporary files

Download ATF Cleaner• Double-click ATF-Cleaner.exe (on your desktop) to run the program.
• Under Main choose: Select All
• Click the Empty Selected button.
If you use Firefox browser • Click Firefox at the top and choose: Select All
• Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser • Click Opera at the top and choose: Select All
• Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.

For Technical Support, double-click the e-mail address located at the bottom of each menu

===================================================

Run OTL
  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    PRC - C:\Documents and Settings\Whites\Local Settings\Temp\RarSFX5\h\iexplore.exe ()
    PRC - C:\Documents and Settings\Whites\Local Settings\Temp\RarSFX4\h\iexplore.exe ()
    PRC - C:\Documents and Settings\Whites\Local Settings\Temp\RarSFX3\h\iexplore.exe ()
    PRC - C:\Documents and Settings\Whites\Local Settings\Temp\RarSFX2\h\iexplore.exe ()
    PRC - C:\Documents and Settings\Whites\Local Settings\Temp\RarSFX1\h\iexplore.exe ()
    FF - prefs.js..browser.search.defaultenginename: "Web Search"
    FF - prefs.js..browser.search.order.1: "Web Search"
    FF - prefs.js..browser.startup.homepage: "http://www.searchqu.com/406"
    [2011/05/20 11:31:36 | 000,000,000 | —D | M] (Searchqu Toolbar) – C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}
    [2011/03/23 22:24:21 | 000,005,529 | —- | M] () – C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\searchplugins\SearchquWebSearch.xml
    [2011/05/20 11:31:43 | 000,000,000 | —D | M] (DataMngr) – C:\PROGRAM FILES\WINDOWS ILIVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O16 - DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} http://static.ak.facebook.com/fbplugin/win…b?1271577864906 (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    [2011/05/20 11:31:26 | 000,000,000 | —D | C] – C:\Program Files\Windows iLivid Toolbar
    [2011/05/20 11:31:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Whites\Application Data\searchqutoolbar
    [2011/05/20 11:33:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Whites\Local Settings\Application Data\Ilivid Player
    [2011/05/20 11:33:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Whites\Application Data\searchquband
    [2011/05/20 11:32:02 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\~0
    
    :Reg
    
    :Files
    
    :Commands
    [createrestorepoint]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
Satchfan
Things are looking better now - the toolbar and home page changes are gone. I'm still seeing searchqu.com 'Web Search' as an option in my search plugins in IE and Firefox. OTL's log file from the fix is below: All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== No active process named iexplore.exe was found! No active process named iexplore.exe was found! No active process named iexplore.exe was found! No active process named iexplore.exe was found! No active process named iexplore.exe was found! Prefs.js: "Web Search" removed from browser.search.defaultenginename Prefs.js: "Web Search" removed from browser.search.order.1 Prefs.js: "http://www.searchqu.com/406" removed from browser.startup.homepage C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\components folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\searchbar folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\options folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\weatherbutton\panels\images folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\weatherbutton\panels folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\weatherbutton\icons folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\weatherbutton folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\uwa folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\radio\images folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\radio\css folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\radio folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\panels\images folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\panels\default\scripts folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\panels\default\images folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\panels\default\css folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\panels\default folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\panels\css folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib\panels folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin\lib folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\skin folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\scripts folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\css folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.YouTube_v2\skin folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.YouTube_v2\js folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.YouTube_v2\images folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.YouTube_v2\css folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.YouTube_v2 folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Twitter\skin\scripts folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Twitter\skin\images folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Twitter\skin\css folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Twitter\skin folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Twitter\js folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Twitter\images folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Twitter\css folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Twitter folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.PPCBully folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\scripts folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\css folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.MyStartFacebook\js folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.MyStartFacebook\images folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.MyStartFacebook\css folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.MyStartFacebook folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\scripts folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\css folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Coupons_v2\skin folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Coupons_v2\js folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Coupons_v2\images folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Coupons_v2\css folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets\net.vmn.www.Coupons_v2 folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\widgets folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\modules folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\lib folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\data\search folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content\data folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome\content folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7}\chrome folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\extensions\{99079a25-328f-4bd4-be04-00955acaa0a7} folder moved successfully. C:\Documents and Settings\Whites\Application Data\Mozilla\Firefox\Profiles\hkvwi8ad.default\searchplugins\SearchquWebSearch.xml moved successfully. C:\PROGRAM FILES\WINDOWS ILIVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION\content folder moved successfully. C:\PROGRAM FILES\WINDOWS ILIVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION\components folder moved successfully. C:\PROGRAM FILES\WINDOWS ILIVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION folder moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully. Starting removal of ActiveX control {32C3FEAE-0877-4767-8C20-62A5829A0945} C:\WINDOWS\Downloaded Program Files\axfbootloader.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{32C3FEAE-0877-4767-8C20-62A5829A0945}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32C3FEAE-0877-4767-8C20-62A5829A0945}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{32C3FEAE-0877-4767-8C20-62A5829A0945}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{32C3FEAE-0877-4767-8C20-62A5829A0945}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32C3FEAE-0877-4767-8C20-62A5829A0945}\ not found. Starting removal of ActiveX control {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found. C:\Program Files\Windows iLivid Toolbar\ToolBar\components folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\searchbar folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\options folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\weatherbutton\icons folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\weatherbutton folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\uwa folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\radio\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\radio\css folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\radio folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\panels\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\panels\default\scripts folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\panels\default\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\panels\default\css folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\panels\default folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\panels\css folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib\panels folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin\lib folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\skin folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\scripts folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin\css folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\skin folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\js folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2\css folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.YouTube_v2 folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\scripts folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin\css folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\skin folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\js folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter\css folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Twitter folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.PPCBully folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\scripts folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin\css folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\skin folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\js folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook\css folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.MyStartFacebook folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\scripts folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin\css folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\skin folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\js folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\images folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2\css folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.Coupons_v2 folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\widgets folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\modules folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\lib folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\data\search folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content\data folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome\content folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar\chrome folder moved successfully. C:\Program Files\Windows iLivid Toolbar\ToolBar folder moved successfully. C:\Program Files\Windows iLivid Toolbar\Datamngr folder moved successfully. C:\Program Files\Windows iLivid Toolbar folder moved successfully. C:\Documents and Settings\Whites\Application Data\searchqutoolbar\weather folder moved successfully. C:\Documents and Settings\Whites\Application Data\searchqutoolbar\coupons folder moved successfully. C:\Documents and Settings\Whites\Application Data\searchqutoolbar folder moved successfully. C:\Documents and Settings\Whites\Local Settings\Application Data\Ilivid Player folder moved successfully. C:\Documents and Settings\Whites\Application Data\searchquband folder moved successfully. C:\Documents and Settings\All Users\Application Data\~0 folder moved successfully. ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== Restore point Set: OTL Restore Point (0) [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 56543 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 49219 bytes ->Flash cache emptied: 8012 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 49219 bytes User: Whites ->Temp folder emptied: 103238254 bytes ->Temporary Internet Files folder emptied: 75882460 bytes ->Java cache emptied: 62606802 bytes ->FireFox cache emptied: 59217032 bytes ->Google Chrome cache emptied: 6394004 bytes ->Flash cache emptied: 537656 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 19569 bytes %systemroot%\System32 .tmp files removed: 1162769 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 155176595 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 118193508 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 556.00 mb OTL by OldTimer - Version 3.2.22.3 log created on 05222011_124528 Files\Folders moved on Reboot… File\Folder C:\WINDOWS\temp\Perflib_Perfdata_ba0.dat not found! C:\WINDOWS\temp\Perflib_Perfdata_ea8.dat moved successfully. Registry entries deleted on Reboot…
Whites

Download Malwarebytes-Anti-Malware

Click here
  • double-click mbam-setup.exe and follow the prompts to install the program.
  • at the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware. and Launch Malwarebytes' Anti-Malware, then click Finish..
  • if an update is found, it will download and install the latest version.
  • once the program has loaded, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Please let me know if the plugins are still showing

Thanks

Satchfan
Hi Satchfan, The Malwarebytes log is below; the search plugins are still showing up. Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6639 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 22/05/2011 6:32:01 PM mbam-log-2011-05-22 (18-32-01).txt Scan type: Quick scan Objects scanned: 155583 Time elapsed: 5 minute(s), 2 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: c:\documents and settings\Whites\Desktop\uSeRiNiT.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
Hi whites

Open OTL
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, click the None button near the top (it may looked greyed out)
  • In the window under Custom Scans/Fixes copy and paste the following


    C:\Program Files\Mozilla Firefox\plugins\*.* /s
    C:\Program Files\Internet Explorer\plugins\*.* /s

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt. Please post this log.

Satchfan
OTL logfile created on: 22/05/2011 6:55:23 PM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Whites\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 77.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 294.74 Gb Total Space | 241.53 Gb Free Space | 81.95% Space Free | Partition Type: NTFS

Computer Name: WHITE | User Name: Whites | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Custom Scans ==========


< C:\Program Files\Mozilla Firefox\plugins\*.* /s >
[2010/11/12 17:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/05/13 14:39:10 | 000,066,520 | —- | M] (mozilla.org) – C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2007/03/22 19:23:30 | 000,017,248 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
[2011/01/22 07:11:12 | 000,095,672 | —- | M] (Adobe Systems Inc.) – C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
[2011/02/19 10:53:01 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
[2011/02/19 10:53:01 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
[2011/02/19 10:53:01 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
[2011/02/19 10:53:01 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
[2011/02/19 10:53:02 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
[2011/02/19 10:53:02 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
[2011/02/19 10:53:02 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
[2011/02/19 10:53:01 | 000,004,208 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\QuickTimePlugin.class

< C:\Program Files\Internet Explorer\plugins\*.* /s >
[2011/02/19 10:53:01 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
[2011/02/19 10:53:01 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
[2011/02/19 10:53:01 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
[2011/02/19 10:53:01 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
[2011/02/19 10:53:02 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
[2011/02/19 10:53:02 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Internet Explorer\PLUGINS\npqtplugin6.dll
[2011/02/19 10:53:02 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Internet Explorer\PLUGINS\npqtplugin7.dll
[2011/02/19 10:53:01 | 000,004,208 | —- | M] () – C:\Program Files\Internet Explorer\PLUGINS\QuickTimePlugin.class

< End of report >
Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :regfind
    *searchqu*
    *Web Search*

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Note: this may take several minutes to complete

Satchfan
SystemLook 04.09.10 by jpshortstuff Log created at 19:14 on 25/05/2011 by Whites Administrator - Elevation successful ========== regfind ========== Searching for "*searchqu*" No data found. Searching for "*Web Search*" No data found. -= EOF =-
Hi whites, was just about to find out if you were still with us.

the search plugins are still showing up

Where exactly are they showing up? It appears that the computer can't see them.

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI