OK, HERE WE GO . . . . .!
OTL:
OTL logfile created on: 11/22/2011 3:03:11 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\LEE BROSCIOUS\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.58 Gb Available Physical Memory | 78.83% Memory free
2.60 Gb Paging File | 2.05 Gb Available in Paging File | 78.61% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 108.59 Gb Total Space | 63.50 Gb Free Space | 58.48% Space Free | Partition Type: NTFS
Drive D: | 37.24 Gb Total Space | 36.76 Gb Free Space | 98.73% Space Free | Partition Type: NTFS
Computer Name: LRBENGR | User Name: LEE BROSCIOUS | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/11/22 14:59:38 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\LEE BROSCIOUS\Desktop\OTL.exe
PRC - [2011/09/23 19:46:28 | 001,195,408 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2011/04/25 16:52:37 | 000,041,296 | —- | M] (AOL Inc.) – C:\Program Files\AOL Desktop 9.6\waol.exe
PRC - [2011/04/25 16:52:36 | 000,045,392 | —- | M] (AOL Inc.) – C:\Program Files\AOL Desktop 9.6\shellmon.exe
PRC - [2011/04/14 13:01:38 | 000,188,136 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe
PRC - [2011/04/14 13:01:38 | 000,171,168 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe
PRC - [2011/03/13 10:45:14 | 000,148,520 | —- | M] (McAfee, Inc.) – C:\WINDOWS\system32\mfevtps.exe
PRC - [2010/03/10 09:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
PRC - [2010/03/08 02:27:49 | 000,041,800 | —- | M] (AOL Inc.) – C:\Program Files\Common Files\AOL\1151266064\EE\aolsoftware.exe
PRC - [2009/05/21 10:55:32 | 000,206,064 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2008/08/13 17:32:40 | 000,201,968 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2006/10/23 14:04:42 | 000,001,536 | —- | M] () – c:\Program Files\Common Files\AOL\1151266064\EE\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
PRC - [2006/10/23 07:50:35 | 000,046,640 | R— | M] (AOL LLC) – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
PRC - [2005/12/07 16:05:12 | 000,053,248 | —- | M] (GEAR Software) – C:\WINDOWS\system32\gearsec.exe
PRC - [2005/09/08 05:20:00 | 000,122,940 | —- | M] (Sonic Solutions) – C:\WINDOWS\system32\DLA\DLACTRLW.EXE
PRC - [2004/12/13 15:30:10 | 000,165,488 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
PRC - [2004/12/13 15:30:04 | 000,198,256 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
PRC - [2004/12/13 15:30:00 | 000,058,992 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC - [2004/10/15 15:54:14 | 000,100,016 | —- | M] (America Online, Inc) – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
PRC - [2004/10/15 15:54:12 | 000,046,768 | —- | M] (America Online Inc) – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
PRC - [2004/03/04 03:00:00 | 000,098,304 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATI9AA.EXE
PRC - [2003/08/27 09:29:46 | 000,065,536 | —- | M] (America Online, Inc.) – C:\WINDOWS\wanmpsvc.exe
========== Modules (No Company Name) ==========
MOD - [2011/10/27 09:53:36 | 003,391,488 | —- | M] () – c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_5571e5f9\mscorlib.dll
MOD - [2011/10/27 09:53:21 | 002,088,960 | —- | M] () – c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_e274fd76\system.xml.dll
MOD - [2011/10/27 09:52:53 | 001,966,080 | —- | M] () – c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_1fa0dc53\system.dll
MOD - [2011/10/27 09:52:36 | 001,232,896 | —- | M] () – c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
MOD - [2011/04/25 16:52:37 | 000,048,640 | —- | M] () – C:\Program Files\AOL Desktop 9.6\zlib.dll
MOD - [2006/10/23 14:04:42 | 000,001,536 | —- | M] () – c:\Program Files\Common Files\AOL\1151266064\EE\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
MOD - [2004/08/10 13:11:10 | 001,339,392 | —- | M] () – c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
MOD - [2002/07/04 08:38:00 | 000,053,248 | —- | M] () – C:\Program Files\ArcSoft\Software Suite\PhotoImpression 5\Share\PIHook.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] – – (MPService)
SRV - File not found [Disabled | Stopped] – – (HidServ)
SRV - File not found [On_Demand | Stopped] – – (AppMgmt)
SRV - [2011/04/14 13:01:38 | 000,188,136 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe – (mfefire)
SRV - [2011/04/14 13:01:38 | 000,171,168 | —- | M] () [Unknown | Running] – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe – (McShield)
SRV - [2011/03/13 10:45:14 | 000,148,520 | —- | M] (McAfee, Inc.) [Unknown | Running] – C:\WINDOWS\system32\mfevtps.exe – (mfevtp)
SRV - [2010/10/07 19:34:28 | 000,364,216 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\McAfee\VirusScan\mcods.exe – (McODS)
SRV - [2010/03/10 09:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McProxy)
SRV - [2010/03/10 09:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNASvc)
SRV - [2010/03/10 09:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNaiAnn)
SRV - [2010/03/10 09:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (mcmscsvc)
SRV - [2010/03/10 09:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McMPFSvc)
SRV - [2008/08/13 17:32:40 | 000,201,968 | —- | M] (SupportSoft, Inc.) [Auto | Running] – C:\Program Files\Dell Support Center\bin\sprtsvc.exe – (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
SRV - [2007/03/07 14:47:46 | 000,076,848 | —- | M] () [On_Demand | Stopped] – C:\Program Files\DellSupport\brkrsvc.exe – (DSBrokerService)
SRV - [2006/10/23 07:50:35 | 000,046,640 | R— | M] (AOL LLC) [Auto | Running] – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe – (AOL ACS)
SRV - [2006/05/08 22:29:57 | 000,822,424 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe – (Symantec Core LC)
SRV - [2005/12/07 16:05:34 | 002,066,072 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Norton Ghost\Agent\VProSvc.exe – (Norton Ghost)
SRV - [2005/12/07 16:05:12 | 000,053,248 | —- | M] (GEAR Software) [Auto | Running] – C:\WINDOWS\system32\gearsec.exe – (GEARSecurity)
SRV - [2005/07/12 18:10:18 | 000,963,072 | —- | M] (McAfee Inc.) [Disabled | Stopped] – C:\Program Files\McAfee\SpamKiller\MSKSrvr.exe – (MskService)
SRV - [2004/12/13 15:30:10 | 000,165,488 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe – (ccSetMgr)
SRV - [2004/12/13 15:30:08 | 000,079,472 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe – (ccPwdSvc)
SRV - [2004/12/13 15:30:04 | 000,198,256 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe – (ccEvtMgr)
SRV - [2004/10/15 15:54:14 | 000,100,016 | —- | M] (America Online, Inc) [Auto | Running] – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe – (AOL TopSpeedMonitor)
SRV - [2003/08/27 09:29:46 | 000,065,536 | —- | M] (America Online, Inc.) [Auto | Running] – C:\WINDOWS\wanmpsvc.exe – (WANMiniportService) WAN Miniport (ATW)
========== Driver Services (SafeList) ==========
DRV - [2011/04/14 13:01:38 | 000,314,088 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mfefirek.sys – (mfefirek)
DRV - [2011/04/14 13:01:38 | 000,153,280 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mfeavfk.sys – (mfeavfk)
DRV - [2011/04/14 13:01:38 | 000,088,736 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mfendisk.sys – (mfendiskmp)
DRV - [2011/04/14 13:01:38 | 000,088,736 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfendisk.sys – (mfendisk)
DRV - [2011/04/14 13:01:38 | 000,084,488 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mferkdet.sys – (mferkdet)
DRV - [2011/04/14 13:01:38 | 000,084,200 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\mfetdi2k.sys – (mfetdi2k)
DRV - [2011/04/14 13:01:38 | 000,056,064 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\cfwids.sys – (cfwids)
DRV - [2011/04/14 13:01:38 | 000,052,320 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mfebopk.sys – (mfebopk)
DRV - [2011/03/13 10:20:10 | 000,459,728 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfehidk.sys – (mfehidk)
DRV - [2011/03/13 10:20:10 | 000,118,784 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfeapfk.sys – (mfeapfk)
DRV - [2007/02/25 11:10:48 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\dsunidrv.sys – (dsunidrv)
DRV - [2006/10/05 15:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys – (DSproct)
DRV - [2006/05/08 22:29:57 | 000,004,608 | —- | M] (Symantec Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\symlcbrd.sys – (symlcbrd)
DRV - [2006/05/08 22:26:16 | 000,008,552 | —- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\asctrm.sys – (ASCTRM)
DRV - [2005/12/07 16:05:26 | 000,144,880 | —- | M] (StorageCraft) [File_System | Boot | Running] – C:\WINDOWS\System32\drivers\SymSnap.sys – (SymSnap)
DRV - [2005/12/07 16:05:24 | 000,056,240 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\V2iMount.sys – (V2IMount)
DRV - [2005/09/08 05:20:00 | 000,094,332 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS – (DLAUDFAM)
DRV - [2005/09/08 05:20:00 | 000,087,036 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS – (DLAUDF_M)
DRV - [2005/09/08 05:20:00 | 000,086,524 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS – (DLAIFS_M)
DRV - [2005/09/08 05:20:00 | 000,025,628 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLABOIOM.SYS – (DLABOIOM)
DRV - [2005/09/08 05:20:00 | 000,014,684 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS – (DLAOPIOM)
DRV - [2005/09/08 05:20:00 | 000,006,364 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAPoolM.SYS – (DLAPoolM)
DRV - [2005/09/08 05:20:00 | 000,002,496 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLADResN.SYS – (DLADResN)
DRV - [2005/08/25 12:16:52 | 000,005,628 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLACDBHM.SYS – (DLACDBHM)
DRV - [2005/08/25 12:16:16 | 000,022,684 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLARTL_N.SYS – (DLARTL_N)
DRV - [2004/09/17 14:02:54 | 000,732,928 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\senfilt.sys – (senfilt)
DRV - [2004/03/24 10:12:44 | 000,004,272 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\bvrp_pci.sys – (bvrp_pci)
DRV - [2003/11/17 21:59:20 | 000,212,224 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSFHWBS2.sys – (HSFHWBS2)
DRV - [2003/11/17 21:58:02 | 000,680,704 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_CNXT.sys – (winachsf)
DRV - [2003/11/17 21:56:26 | 001,042,432 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_DP.sys – (HSF_DP)
DRV - [2003/01/10 16:13:04 | 000,033,588 | R— | M] (America Online, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [1999/11/05 13:57:58 | 000,048,472 | —- | M] (Canon Information Systems) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\cis1284.sys – (cis1284)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1861267-2091798228-1098460282-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-1861267-2091798228-1098460282-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKU\S-1-5-21-1861267-2091798228-1098460282-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKU\S-1-5-21-1861267-2091798228-1098460282-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com
IE - HKU\S-1-5-21-1861267-2091798228-1098460282-1006\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-1861267-2091798228-1098460282-1006\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-1861267-2091798228-1098460282-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@ei.CouponAlert_2p.com/Plugin: C:\Program Files\CouponAlert_2pEI\Installr\2.bin\NP2pEISB.dll (CouponAlert)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
O1 HOSTS File: ([2008/10/23 01:38:52 | 000,000,848 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AOL Toolbar Loader) - {3ef64538-8b54-4573-b48f-4d34b0238ab2} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
O2 - BHO: (McAfee AntiPhishing Filter) - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\Program Files\McAfee\SpamKiller\McApfBHO.dll (McAfee, Inc.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20111027013048.dll (McAfee, Inc.)
O2 - BHO: (ShopAtHomeIEHelper Class) - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar2.dll File not found
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (ShopAtHome Toolbar) - {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar2.dll File not found
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKU\S-1-5-21-1861267-2091798228-1098460282-1006\..\Toolbar\WebBrowser: (ShopAtHome Toolbar) - {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar2.dll File not found
O3 - HKU\S-1-5-21-1861267-2091798228-1098460282-1006\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe (America Online)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [EPSON Stylus CX4600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1151266064\EE\aolsoftware.exe (AOL Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MSKAGENTEXE] C:\Program Files\McAfee\SpamKiller\MSKAgent.exe (McAfee Inc.)
O4 - HKU\S-1-5-21-1861267-2091798228-1098460282-1006..\Run: [AOL Fast Start] C:\Program Files\AOL Desktop 9.6\AOL.EXE (AOL Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1861267-2091798228-1098460282-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\Program Files\McAfee\SpamKiller\McApfBHO.dll (McAfee, Inc.)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O15 - HKU\S-1-5-21-1861267-2091798228-1098460282-1006\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdat…b?1225142934828 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} http://offers.e-centives.com/cif/download/bin/actxcab.cab (CBSTIEPrint Class)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\LEE BROSCIOUS\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\LEE BROSCIOUS\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 12:51:28 | 000,000,032 | -H– | M] () - C:\autoexea.bat – [ NTFS ]
O32 - AutoRun File - [2004/08/10 13:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/11/22 14:59:38 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\LEE BROSCIOUS\Desktop\OTL.exe
[2011/11/22 14:00:06 | 000,000,000 | —D | C] – C:\Documents and Settings\LEE BROSCIOUS\Start Menu\Programs\Coupons
[2011/11/10 20:07:31 | 000,000,000 | —D | C] – C:\Documents and Settings\LEE BROSCIOUS\Local Settings\Application Data\Dell
[2011/11/03 15:52:49 | 000,000,000 | —D | C] – C:\Documents and Settings\LEE BROSCIOUS\My Documents\000 AOL Backups
[2011/10/27 00:30:47 | 000,009,344 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfeclnk.sys
[2011/10/27 00:30:36 | 000,314,088 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfefirek.sys
[2011/10/27 00:30:36 | 000,153,280 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfeavfk.sys
[2011/10/27 00:30:36 | 000,088,736 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfendisk.sys
[2011/10/27 00:30:36 | 000,084,488 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mferkdet.sys
[2011/10/27 00:30:36 | 000,084,200 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfetdi2k.sys
[2011/10/27 00:30:36 | 000,056,064 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\cfwids.sys
[2011/10/27 00:30:36 | 000,052,320 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfebopk.sys
[2011/10/27 00:30:26 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Mcafee
[2011/10/27 00:30:25 | 000,000,000 | —D | C] – C:\Program Files\McAfee.com
[2011/10/26 16:04:12 | 000,148,520 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\mfevtps.exe
[2011/10/26 15:46:55 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\ApplicationHistory
[2011/10/26 15:14:20 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2011/10/26 14:40:24 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\AOL Toolbar
[2011/10/26 14:40:23 | 000,000,000 | —D | C] – C:\Documents and Settings\LEE BROSCIOUS\Local Settings\Application Data\AOL Toolbar
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/22 15:01:53 | 000,069,607 | —- | M] () – C:\VETlog.dmp
[2011/11/22 14:59:38 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\LEE BROSCIOUS\Desktop\OTL.exe
[2011/11/22 14:16:18 | 000,302,592 | —- | M] () – C:\Documents and Settings\LEE BROSCIOUS\Desktop\4dgnshqk.exe
[2011/11/22 13:29:50 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/11/22 13:29:02 | 000,001,595 | —- | M] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Center.lnk
[2011/11/22 13:28:51 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/11/22 13:28:50 | 2145,439,744 | -HS- | M] () – C:\hiberfil.sys
[2011/11/21 20:16:54 | 000,009,662 | —- | M] () – C:\WINDOWS\EPISME00.SWB
[2011/11/21 19:29:23 | 000,002,397 | —- | M] () – C:\Documents and Settings\LEE BROSCIOUS\Desktop\ACDSee 5.0.lnk
[2011/11/09 03:46:06 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/11/08 13:49:39 | 000,004,158 | —- | M] () – C:\Documents and Settings\LEE BROSCIOUS\My Documents\independent bible church.wpd
[2011/11/08 04:01:28 | 000,089,600 | —- | M] () – C:\Documents and Settings\LEE BROSCIOUS\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/06 16:16:10 | 000,381,692 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/11/06 16:16:10 | 000,053,436 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/11/04 14:41:44 | 000,002,409 | —- | M] () – C:\Documents and Settings\LEE BROSCIOUS\My Documents\Dell Support Center.lnk
[2011/11/02 20:55:11 | 000,224,093 | —- | M] () – C:\Documents and Settings\LEE BROSCIOUS\My Documents\DSC07545.JPG
[2011/11/01 12:14:08 | 000,030,518 | —- | M] () – C:\Documents and Settings\LEE BROSCIOUS\My Documents\File_Sunbury,_Pennsylvania.htm
[2011/10/28 15:50:12 | 000,001,907 | —- | M] () – C:\Documents and Settings\LEE BROSCIOUS\Desktop\Musicmatch Jukebox.lnk
[2011/10/26 10:33:37 | 000,000,803 | —- | M] () – C:\Documents and Settings\LEE BROSCIOUS\Desktop\Internet Explorer.lnk
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/22 14:16:17 | 000,302,592 | —- | C] () – C:\Documents and Settings\LEE BROSCIOUS\Desktop\4dgnshqk.exe
[2011/11/04 17:42:11 | 000,002,397 | —- | C] () – C:\Documents and Settings\LEE BROSCIOUS\Desktop\ACDSee 5.0.lnk
[2011/11/04 14:12:22 | 000,338,827 | —- | C] () – C:\Documents and Settings\LEE BROSCIOUS\My Documents\Copy of jake1.JPG
[2011/11/02 20:55:10 | 000,224,093 | —- | C] () – C:\Documents and Settings\LEE BROSCIOUS\My Documents\DSC07545.JPG
[2011/11/01 12:14:07 | 000,030,518 | —- | C] () – C:\Documents and Settings\LEE BROSCIOUS\My Documents\File_Sunbury,_Pennsylvania.htm
[2011/10/28 15:50:12 | 000,001,907 | —- | C] () – C:\Documents and Settings\LEE BROSCIOUS\Desktop\Musicmatch Jukebox.lnk
[2011/10/27 19:48:43 | 000,001,595 | —- | C] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Center.lnk
[2011/10/27 00:53:41 | 2145,439,744 | -HS- | C] () – C:\hiberfil.sys
[2011/10/26 15:46:59 | 000,000,135 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\fusioncache.dat
[2011/10/26 10:33:37 | 000,000,803 | —- | C] () – C:\Documents and Settings\LEE BROSCIOUS\Desktop\Internet Explorer.lnk
[2009/04/19 17:54:40 | 000,002,181 | —- | C] () – C:\WINDOWS\U3DEDIT2.INI
[2009/02/21 17:47:13 | 000,036,180 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/02/21 16:51:13 | 000,000,092 | —- | C] () – C:\WINDOWS\Retrieve9.INI
[2009/02/19 16:36:41 | 000,890,953 | —- | C] () – C:\WINDOWS\HSCasl3.ini
[2009/02/18 16:35:45 | 000,003,641 | —- | C] () – C:\WINDOWS\universe_plugin.ini
[2009/02/18 14:00:42 | 000,890,953 | —- | C] () – C:\WINDOWS\HSCafc1.ini
[2009/02/17 22:26:08 | 000,000,089 | —- | C] () – C:\WINDOWS\ULead32.ini
[2009/02/17 22:24:59 | 000,035,328 | —- | C] () – C:\WINDOWS\inetwh32.dll
[2009/02/17 22:24:59 | 000,009,136 | —- | C] () – C:\WINDOWS\inetwh16.dll
[2009/02/17 22:24:59 | 000,004,528 | —- | C] () – C:\WINDOWS\setbrows.exe
[2009/02/17 19:59:37 | 000,000,264 | —- | C] () – C:\WINDOWS\ScreenHunter.INI
[2009/02/16 17:48:40 | 000,000,011 | —- | C] () – C:\WINDOWS\System32\tscrip22.dll
[2009/02/16 17:01:27 | 000,000,011 | —- | C] () – C:\WINDOWS\3DShadow.INI
[2009/02/16 16:53:31 | 000,044,544 | —- | C] () – C:\WINDOWS\AWuninstall.exe
[2009/02/15 21:10:31 | 000,000,670 | —- | C] () – C:\WINDOWS\nvrbm.ini
[2009/02/14 15:28:45 | 000,000,695 | —- | C] () – C:\WINDOWS\nvrph.ini
[2009/02/14 00:05:50 | 000,000,805 | —- | C] () – C:\WINDOWS\PowerReg.dat
[2008/12/07 16:20:50 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2008/09/27 11:27:06 | 000,000,029 | —- | C] () – C:\WINDOWS\DEBUGSM.INI
[2008/08/28 09:53:48 | 000,000,136 | —- | C] () – C:\Documents and Settings\LEE BROSCIOUS\Local Settings\Application Data\fusioncache.dat
[2008/08/28 05:54:14 | 000,004,272 | —- | C] () – C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2007/10/23 12:39:59 | 000,000,031 | -H– | C] () – C:\WINDOWS\uccspecc.sys
[2006/10/02 10:56:07 | 000,000,021 | —- | C] () – C:\WINDOWS\PI_setup.ini
[2006/10/02 10:55:08 | 000,029,521 | —- | C] () – C:\WINDOWS\System32\EPPICPrinterDB.dat
[2006/10/02 10:55:08 | 000,020,910 | —- | C] () – C:\WINDOWS\System32\EPPICPattern2.dat
[2006/10/02 10:55:08 | 000,020,869 | —- | C] () – C:\WINDOWS\System32\EPPICPattern1.dat
[2006/10/02 10:55:08 | 000,000,022 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2006/10/02 10:51:39 | 000,000,072 | —- | C] () – C:\WINDOWS\System32\epDPE.ini
[2006/10/02 10:51:38 | 000,096,768 | —- | C] () – C:\WINDOWS\SlantAdj.dll
[2006/10/02 10:51:38 | 000,003,136 | —- | C] () – C:\WINDOWS\Ade001.bin
[2006/10/02 10:44:47 | 000,000,044 | —- | C] () – C:\WINDOWS\EPCX4600.ini
[2006/07/01 16:02:28 | 000,000,024 | —- | C] () – C:\WINDOWS\atid.ini
[2006/07/01 16:02:28 | 000,000,018 | —- | C] () – C:\WINDOWS\upst.ini
[2006/06/25 15:10:27 | 000,000,715 | —- | C] () – C:\WINDOWS\aolback.exe.lnk
[2006/05/29 19:20:03 | 000,000,088 | RHS- | C] () – C:\WINDOWS\System32\E51DD59C1E.sys
[2006/05/18 12:32:39 | 000,061,678 | —- | C] () – C:\Documents and Settings\LEE BROSCIOUS\Application Data\PFP120JPR.{PB
[2006/05/18 12:32:39 | 000,012,358 | —- | C] () – C:\Documents and Settings\LEE BROSCIOUS\Application Data\PFP120JCM.{PB
[2006/05/18 12:31:59 | 000,006,686 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/05/18 12:31:59 | 000,000,104 | RHS- | C] () – C:\WINDOWS\System32\1E9CD51DE5.sys
[2006/05/18 12:10:07 | 000,017,611 | —- | C] () – C:\WINDOWS\MPTBox.INI
[2006/05/13 12:29:29 | 000,089,600 | —- | C] () – C:\Documents and Settings\LEE BROSCIOUS\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/05/11 14:01:01 | 000,046,512 | —- | C] () – C:\WINDOWS\System32\EPSN.DLL
[2006/05/11 14:01:01 | 000,012,126 | —- | C] () – C:\WINDOWS\System32\PIXPCZ.DLL
[2006/05/11 14:01:01 | 000,011,934 | —- | C] () – C:\WINDOWS\System32\PIXPNR.DLL
[2006/05/11 13:59:50 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\Lffpx7.dll
[2006/05/11 13:59:50 | 000,141,824 | —- | C] () – C:\WINDOWS\System32\Lfcmp60n.dll
[2006/05/11 13:59:50 | 000,122,880 | —- | C] () – C:\WINDOWS\System32\Lfkodak.dll
[2006/05/11 13:59:50 | 000,043,008 | —- | C] () – C:\WINDOWS\System32\Ltfil60n.dll
[2006/05/11 13:59:50 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\Lfbmp60n.dll
[2006/05/11 13:57:34 | 000,000,028 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/05/11 13:56:11 | 000,000,049 | —- | C] () – C:\WINDOWS\SGEDIT.INI
[2006/05/11 13:55:38 | 000,000,982 | —- | C] () – C:\WINDOWS\mpass.ini
[2006/05/11 13:55:37 | 000,416,768 | —- | C] () – C:\WINDOWS\System32\FILTERS.DLL
[2006/05/11 13:55:37 | 000,308,224 | —- | C] () – C:\WINDOWS\System32\FPXLIB.DLL
[2006/05/11 13:55:37 | 000,282,624 | —- | C] () – C:\WINDOWS\System32\FPXLIBIO.DLL
[2006/05/11 13:55:37 | 000,095,232 | —- | C] () – C:\WINDOWS\System32\JPEGLIB.DLL
[2006/05/11 13:55:37 | 000,068,608 | —- | C] () – C:\WINDOWS\System32\annot.dll
[2006/05/11 13:55:37 | 000,034,816 | —- | C] () – C:\WINDOWS\System32\sgimgapi.dll
[2006/05/11 13:55:35 | 000,348,672 | —- | C] () – C:\WINDOWS\System32\dtbl32.dll
[2006/05/08 22:40:31 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/05/08 22:36:27 | 000,000,200 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/05/08 22:32:01 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2006/05/08 22:30:09 | 000,712,704 | —- | C] () – C:\WINDOWS\System32\DellSystemRestore.dll
[2006/05/08 22:25:24 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/05/08 22:00:44 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2006/05/08 22:00:24 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2006/05/08 22:00:22 | 000,000,392 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/11/10 08:56:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/10 13:12:05 | 000,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 13:07:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/10 13:02:15 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 13:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 12:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 12:57:15 | 000,181,832 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 12:51:28 | 000,000,032 | -H– | C] () – C:\WINDOWS\ialig.dll
[2004/08/10 12:51:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 12:51:20 | 000,381,692 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 12:51:20 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 12:51:20 | 000,053,436 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 12:51:20 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 12:51:18 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/10 12:51:17 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/10 12:51:16 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/10 12:51:12 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 12:51:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 12:51:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 12:50:56 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2002/03/21 13:51:52 | 000,503,808 | R— | C] () – C:\WINDOWS\System32\lt_xtrans.dll
[2002/03/21 13:51:52 | 000,286,720 | R— | C] () – C:\WINDOWS\System32\MrSIDD.dll
[2002/03/21 13:51:52 | 000,163,840 | R— | C] () – C:\WINDOWS\System32\lt_common.dll
[2002/03/21 13:51:52 | 000,126,976 | R— | C] () – C:\WINDOWS\System32\lt_trans.dll
[2002/03/21 13:51:52 | 000,069,632 | R— | C] () – C:\WINDOWS\System32\lt_meta.dll
[2002/03/21 13:51:52 | 000,053,248 | R— | C] () – C:\WINDOWS\System32\lt_encrypt.dll
[2002/03/21 13:51:52 | 000,020,480 | R— | C] () – C:\WINDOWS\System32\lt_messagetext.dll
[2002/03/20 22:01:06 | 000,006,688 | R— | C] () – C:\WINDOWS\System32\Digita.sys
[2002/03/20 22:00:20 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\TransportUSB.dll
[2002/03/20 22:00:20 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\TransportSerial.dll
[2002/03/20 22:00:20 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\TransportIrDA.dll
[2002/03/20 22:00:20 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\TransportIrCOMM.dll
[1998/07/12 23:32:03 | 000,115,712 | —- | C] () – C:\WINDOWS\System32\vboxp403.dll
< End of report >
OTL Extras logfile created on: 11/22/2011 3:03:11 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\LEE BROSCIOUS\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.58 Gb Available Physical Memory | 78.83% Memory free
2.60 Gb Paging File | 2.05 Gb Available in Paging File | 78.61% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 108.59 Gb Total Space | 63.50 Gb Free Space | 58.48% Space Free | Partition Type: NTFS
Drive D: | 37.24 Gb Total Space | 36.76 Gb Free Space | 98.73% Space Free | Partition Type: NTFS
Computer Name: LRBENGR | User Name: LEE BROSCIOUS | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] – "C:\Program Files\ACD Systems\ACDSee\5.0\ACDSee5.exe" "%1" (ACD Systems, Ltd.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe:*:Enabled:AOL – (AOL LLC)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – (America Online)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe:*:Enabled:AOL – (AOL LLC)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – (America Online)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader – (AOL Inc.)
"C:\Program Files\America Online 9.0a\waol.exe" = C:\Program Files\America Online 9.0a\waol.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe" = C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon – (America Online, Inc)
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe" = C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed – (America Online Inc)
"C:\Program Files\Common Files\AOL\1151266064\EE\AOLServiceHost.exe" = C:\Program Files\Common Files\AOL\1151266064\EE\AOLServiceHost.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\System Information\sinf.exe" = C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL – (AOL Inc.)
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe" = C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe" = C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe" = C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL – (Gteko Ltd.)
"C:\Program Files\America Online 9.0b\waol.exe" = C:\Program Files\America Online 9.0b\waol.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\America Online 9.0c\waol.exe" = C:\Program Files\America Online 9.0c\waol.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\America Online 9.0d\waol.exe" = C:\Program Files\America Online 9.0d\waol.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\1151266064\EE\aolsoftware.exe" = C:\Program Files\Common Files\AOL\1151266064\EE\aolsoftware.exe:*:Enabled:AOL Shared Components – (AOL Inc.)
"C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe" = C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe:*:Enabled:McAfee Data Backup
"C:\Program Files\AOL Desktop 9.6\waol.exe" = C:\Program Files\AOL Desktop 9.6\waol.exe:*:Enabled:AOL – (AOL Inc.)
"C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe" = C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed – (AOL Inc.)
"C:\Program Files\AOL Desktop 9.6\AOLBrowser\aolbrowser.exe" = C:\Program Files\AOL Desktop 9.6\AOLBrowser\aolbrowser.exe:*:Enabled:AOL Browser – (AOL Inc.)
"C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" = C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe:*:Enabled:McAfee Shared Service Host – (McAfee, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio RecordNow Data
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{109D28C7-FB38-483A-9C91-001CB59E2699}" = EPSON CardMonitor
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Roxio DLA
"{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}" = Intel® PROSet for Wired Connections
"{1A15507A-8551-4626-915D-3D5FA095CC1B}" = Corel Paint Shop Pro X
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Roxio MyDVD LE
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 13
"{2C00FB6D-BF33-4EBA-BBB0-B8A8D7D43DFF}" = FocusFixer
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{32F720F5-2D0D-4245-A2B0-9EB3CECF8101}" = Norton Ghost 10.0
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{34E96A8C-2C58-490A-8D5D-3CE70E1D512E}" = NoiseFixer
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{352310C3-E46B-42D3-8F32-54721FDD72D9}" = NetZeroInstallers
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{43CAC9A1-1993-4F65-9096-7C9AFC2BBF54}" = Dell CinePlayer
"{4667B940-BB01-428B-986E-A0CC46497BF7}" = ELIcon
"{553C904F-57A2-4113-888E-BA0C3D1C69C0}" = Microsoft VC9 runtime libraries
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}" = Sonic Activation Module
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{66C8BE35-8BBB-472B-96C7-C7C9A499F988}" = ArcSoft Software Suite
"{67EDD823-135A-4D59-87BD-950616D6E857}" = EPSON Copy Utility 3
"{6C11D561-620B-47DA-A693-4C597F3CDF40}" = EPSON Smart Panel
"{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}" = Digital Content Portal
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{6EA8BBD9-84A1-4513-969D-D67C5DE7EAC7}" = Noiseware Professional Plug-in
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}" = EarthLink setup files
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7A3F0566-5E05-4919-9C98-456F6B5CF831}" = Get High Speed Internet!
"{7D50D895-C7C8-47EA-8F9C-FB77B7B9DC50}" = Kodak DIGITAL SHO Plug-In 1.1.3
"{7E5B4758-346B-4D77-BB1A-1BC878ED7498}" = Kodak DIGITAL GEM Airbrush Professional Plug-In 1.0.1
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page
"{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch® Jukebox
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8A9B8148-DDD7-448F-BD6C-358386D32354}" = Corel Photo Album 6
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{A4F65B5E-C91B-4D75-B6E9-281DA54520AB}" = TrueBlurInstaller
"{A683A2C0-821C-486F-858C-FA634DB5E864}" = EducateU
"{AA027AE9-DD20-4677-AA72-D760A358320B}" = Microsoft VC9 runtime libraries
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AE704636-ECD0-426C-952E-05B8DABD1949}" = EPSON PhotoStarter3.2
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{AF5E8D43-49AD-4BE7-A941-2BB0A8CACA62}" = ACDSee 5.0 Standard
"{B0DF58A2-40DF-4465-AA56-38623EC9938C}" = Documentation & Support Launcher
"{B0DFFD18-871A-431C-85D4-365BF1D81349}" = ShadowFixer
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio RecordNow Copy
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BDEE7660-E08C-4824-8577-6CE12F8C3492}_is1" = gPhotoShow v1.6.0
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCEB53A5-A252-4CF3-8602-429AB06BF0AE}" = Terragen
"{CDA31C03-D67C-48DF-BFE9-B0519818341E}" = Digital Element Aurora
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{D76E927F-E292-434B-9661-3858F5D7BF63}" = EPSON PhotoCenter
"{D87D6386-3C2D-4239-9780-3418FB7B0E94}" = Print Lab Series
"{DA53DF31-06F5-11D7-B1E5-0050DA6C326B}" = Extensis PhotoFrame 2.5
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E42BD75A-FC23-4E3F-9F91-2658334C644F}" = Internet Service Offers Launcher
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{EBAE381B-60A6-4863-AA9F-FCAB755BC9E5}" = ScanToWeb
"3D Maker by Lokas Software" = 3D Maker by Lokas Software
"3D Shadow by Lokas Software" = 3D Shadow by Lokas Software
"55mm for Adobe Photoshop" = 55mm for Adobe Photoshop
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Alien Skin Image Doctor" = Alien Skin Image Doctor
"AOL Toolbar" = AOL Toolbar
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"AOL YGP Screensaver" = AOL You've Got Pictures Screensaver
"AOLCoach" = AOL Coach Version 1.0(Build:20040229.1 en)
"AolCoach2_en" = AOL Coach Version 2.0(Build:20041026.5 en)
"Artistic Effects by Lokas Software" = Artistic Effects by Lokas Software
"Blow Up" = Alien Skin Blow Up
"Canon MultiPASS Desktop Manager" = Canon MultiPASS Suite 3.20
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"ColorWasher 2.02b" = ColorWasher 2.02b
"Coupon Printer for Windows2.0" = Coupon Printer for Windows
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"DCE Tools (Adobe Photoshop Plug-ins)_is1" = DCE Tools 1.0
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Dell Game Console" = Dell Game Console
"DreamSuite Bonus" = Uninstall DreamSuite Bonus
"DreamSuite Series2" = DreamSuite Series2
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"Exposure" = Alien Skin Exposure
"EyeCandy5Impact" = Alien Skin Eye Candy 5 Impact
"EyeCandy5Nature" = Alien Skin Eye Candy 5 Nature
"EyeCandy5Textures" = Alien Skin Eye Candy 5 Textures
"Filters Unlimited_is1" = Filters Unlimited 2.0
"FocalBlade" = FocalBlade
"Fractal Stepper_is1" = Fractal Stepper 1.0
"Genesis_V2_PROps_V2.00" = Genesis V2 PROps V2.01
"IcePattern v 1.22. for Adobe Photoshop_is1" = IcePattern 1.22 for Adobe Photoshop
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"KnockOut 2" = KnockOut 2
"Knoll Light Factory 2" = Knoll Light Factory 2
"KPT 6" = KPT 6
"KPT effects" = KPT® effects™
"Light v3.5 for Adobe Photoshop & Compatible Applications" = Light v3.5 for Adobe Photoshop & Compatible Applications
"LightMachine 1.0" = LightMachine 1.0
"LiveReg" = LiveReg (Symantec Corporation)
"LiveUpdate" = LiveUpdate 2.6 (Symantec Corporation)
"McAfee Uninstall Utility" = McAfee Uninstaller
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MSC" = McAfee SecurityCenter
"MSNINST" = MSN
"nik Color Efex Pro 2.0 Complete" = nik Color Efex Pro 2.0 Complete
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PAN Fire 3.1_is1" = PAN Fire 3.1
"PAN Lens Pro III 3.6_is1" = PAN Lens Pro III 3.6
"Panopticum Digitalizer 1.1_is1" = Panopticum Digitalizer 1.1
"Picasa2" = Picasa 2
"Power Retouche Pro" = Power Retouche Pro
"PROSet" = Intel® PRO Network Adapters and Drivers
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer Basic
"Silent Package Run-Time Sample" = EPSON CX4600 Reference Guide
"Snap Art" = Alien Skin Snap Art
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"StreetPlugin" = Learn2 Player (Uninstall Only)
"Trend Micro HouseCall 6.6" = HouseCall 6.6
"Ulead FX Razor 2.0" = Ulead FX Razor 2.0
"Universe" = Universe
"Universe Image Creator Plug-ins" = Universe Image Creator Plug-ins
"ViewpointMediaPlayer" = Viewpoint Media Player
"Vizros Plug-ins 4.1" = Vizros Plug-ins 4.1
"WebCyberCoach_wtrb" = WebCyberCoach 3.2 Dell
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"Wisdom-soft ScreenHunter 5.0 Free" = Wisdom-soft ScreenHunter 5.0 Free
"Xenofex2" = Alien Skin Xenofex 2.0
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-1861267-2091798228-1098460282-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"AOL Toolbar" = AOL Toolbar
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 11/21/2011 12:34:43 AM | Computer Name = LRBENGR | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 11/21/2011 12:34:43 AM | Computer Name = LRBENGR | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 11/21/2011 12:34:43 AM | Computer Name = LRBENGR | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 11/21/2011 12:34:43 AM | Computer Name = LRBENGR | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 11/21/2011 12:34:44 AM | Computer Name = LRBENGR | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 11/21/2011 12:34:44 AM | Computer Name = LRBENGR | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 11/21/2011 12:34:44 AM | Computer Name = LRBENGR | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 11/21/2011 12:34:44 AM | Computer Name = LRBENGR | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 11/21/2011 12:34:44 AM | Computer Name = LRBENGR | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
Error - 11/21/2011 12:34:45 AM | Computer Name = LRBENGR | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.
[ System Events ]
Error - 1/3/2006 1:25:12 AM | Computer Name = LRBENGR | Source = DCOM | ID = 10010
Description = The server {3A185DDE-E020-4985-A8F2-E27CDC4A0F3A} did not register
with DCOM within the required timeout.
Error - 1/3/2006 1:25:45 AM | Computer Name = LRBENGR | Source = DCOM | ID = 10010
Description = The server {209500FC-6B45-4693-8871-6296C4843751} did not register
with DCOM within the required timeout.
Error - 1/3/2006 1:03:12 AM | Computer Name = LRBENGR | Source = DCOM | ID = 10010
Description = The server {209500FC-6B45-4693-8871-6296C4843751} did not register
with DCOM within the required timeout.
Error - 1/3/2006 1:03:09 AM | Computer Name = LRBENGR | Source = DCOM | ID = 10010
Description = The server {209500FC-6B45-4693-8871-6296C4843751} did not register
with DCOM within the required timeout.
Error - 11/21/2011 1:59:29 AM | Computer Name = LRBENGR | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.
Error - 1/3/2006 1:11:35 AM | Computer Name = LRBENGR | Source = DCOM | ID = 10010
Description = The server {72C2714F-4478-11D3-B537-00902771A435} did not register
with DCOM within the required timeout.
Error - 1/3/2006 1:05:40 AM | Computer Name = LRBENGR | Source = DCOM | ID = 10010
Description = The server {209500FC-6B45-4693-8871-6296C4843751} did not register
with DCOM within the required timeout.
Error - 11/21/2011 3:23:26 PM | Computer Name = LRBENGR | Source = DCOM | ID = 10010
Description = The server {209500FC-6B45-4693-8871-6296C4843751} did not register
with DCOM within the required timeout.
Error - 11/22/2011 2:31:36 PM | Computer Name = LRBENGR | Source = DCOM | ID = 10010
Description = The server {209500FC-6B45-4693-8871-6296C4843751} did not register
with DCOM within the required timeout.
Error - 11/22/2011 2:31:43 PM | Computer Name = LRBENGR | Source = DCOM | ID = 10010
Description = The server {3A185DDE-E020-4985-A8F2-E27CDC4A0F3A} did not register
with DCOM within the required timeout.
< End of report >
AND GMER:
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2011-11-23 00:18:11
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD1600JB-75GVC0 rev.08.02D08
Running: 4dgnshqk.exe; Driver: C:\DOCUME~1\LEEBRO~1\LOCALS~1\Temp\awrdapow.sys
—- System - GMER 1.0.15 —-
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateKey [0xF745FD70]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteKey [0xF745FD84]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xF745FDB0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xF745FE06]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenKey [0xF745FD5C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xF745FD34]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xF745FD48]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwRenameKey [0xF745FD9A]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetSecurityObject [0xF745FDDC]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetValueKey [0xF745FDC6]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0xF745FE30]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xF745FE1C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0xF745FDF0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetSecurityObject
—- Kernel code sections - GMER 1.0.15 —-
PAGE ntoskrnl.exe!ZwUnmapViewOfSection + 3 8057A821 2 Bytes [EE, 76]
init C:\WINDOWS\system32\drivers\senfilt.sys entry point in "init" section [0xB9AA2F80]
—- User code sections - GMER 1.0.15 —-
.text C:\WINDOWS\system32\svchost.exe[288] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00BA0FE5
.text C:\WINDOWS\system32\svchost.exe[288] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00BA0FC3
.text C:\WINDOWS\system32\svchost.exe[288] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00BA0FD4
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BF0FEF
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BF0F5E
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BF0053
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BF0F79
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BF0036
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BF001B
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BF009F
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BF0084
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BF00CB
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BF00BA
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BF0F17
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BF0F9E
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BF0FD4
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BF0F4D
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BF0FAF
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BF0000
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BF0F3C
.text C:\WINDOWS\system32\svchost.exe[288] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00BE002C
.text C:\WINDOWS\system32\svchost.exe[288] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00BE0076
.text C:\WINDOWS\system32\svchost.exe[288] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00BE0011
.text C:\WINDOWS\system32\svchost.exe[288] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00BE0FDB
.text C:\WINDOWS\system32\svchost.exe[288] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00BE0FAF
.text C:\WINDOWS\system32\svchost.exe[288] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00BE0000
.text C:\WINDOWS\system32\svchost.exe[288] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00BE0047
.text C:\WINDOWS\system32\svchost.exe[288] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00BE0FC0
.text C:\WINDOWS\system32\svchost.exe[288] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00BD0FB6
.text C:\WINDOWS\system32\svchost.exe[288] msvcrt.dll!system 77C293C7 5 Bytes JMP 00BD004B
.text C:\WINDOWS\system32\svchost.exe[288] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00BD0029
.text C:\WINDOWS\system32\svchost.exe[288] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00BD000C
.text C:\WINDOWS\system32\svchost.exe[288] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00BD003A
.text C:\WINDOWS\system32\svchost.exe[288] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00BD0FEF
.text C:\WINDOWS\system32\svchost.exe[288] WININET.dll!InternetOpenA 3D95D698 5 Bytes JMP 00BB0FE5
.text C:\WINDOWS\system32\svchost.exe[288] WININET.dll!InternetOpenW 3D95DB11 5 Bytes JMP 00BB000A
.text C:\WINDOWS\system32\svchost.exe[288] WININET.dll!InternetOpenUrlA 3D95F3AC 5 Bytes JMP 00BB0FCA
.text C:\WINDOWS\system32\svchost.exe[288] WININET.dll!InternetOpenUrlW 3D9A6D6F 5 Bytes JMP 00BB0FAF
.text C:\WINDOWS\system32\svchost.exe[288] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00BC0FE5
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[420] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 62419A20 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[420] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 62419AE2 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\system32\svchost.exe[572] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00BA0FEF
.text C:\WINDOWS\system32\svchost.exe[572] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00BA0FC3
.text C:\WINDOWS\system32\svchost.exe[572] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00BA0FD4
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BD000A
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BD0F3A
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BD0F55
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BD0F72
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BD0F83
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BD0F9E
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BD0F0E
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BD0F1F
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BD0EF3
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BD008C
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BD0EE2
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BD002F
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BD0FE5
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BD004A
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BD0FB9
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BD0FD4
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BD0071
.text C:\WINDOWS\system32\svchost.exe[572] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00BC0FC0
.text C:\WINDOWS\system32\svchost.exe[572] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00BC0047
.text C:\WINDOWS\system32\svchost.exe[572] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00BC0FDB
.text C:\WINDOWS\system32\svchost.exe[572] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00BC0011
.text C:\WINDOWS\system32\svchost.exe[572] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00BC0036
.text C:\WINDOWS\system32\svchost.exe[572] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00BC0000
.text C:\WINDOWS\system32\svchost.exe[572] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00BC0F94
.text C:\WINDOWS\system32\svchost.exe[572] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [DC, 88]
.text C:\WINDOWS\system32\svchost.exe[572] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00BC0FA5
.text C:\WINDOWS\system32\svchost.exe[572] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00BB005F
.text C:\WINDOWS\system32\svchost.exe[572] msvcrt.dll!system 77C293C7 5 Bytes JMP 00BB0FD4
.text C:\WINDOWS\system32\svchost.exe[572] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00BB0044
.text C:\WINDOWS\system32\svchost.exe[572] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00BB000C
.text C:\WINDOWS\system32\svchost.exe[572] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00BB0FE5
.text C:\WINDOWS\system32\svchost.exe[572] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00BB001D
.text C:\WINDOWS\system32\services.exe[1128] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 006B0FEF
.text C:\WINDOWS\system32\services.exe[1128] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 006B0FC3
.text C:\WINDOWS\system32\services.exe[1128] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 006B0FDE
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00740000
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00740075
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00740F8A
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00740064
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00740047
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00740FAF
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 007400C8
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 007400B7
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00740F54
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 007400E3
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00740F43
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0074002C
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00740011
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 0074009A
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00740FC0
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00740FD1
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00740F65
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 006E0FC3
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 006E0F6B
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 006E0FD4
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 006E000A
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 006E0F7C
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 006E0FE5
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 006E0F8D
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [8E, 88]
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 006E0FA8
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 006D0FA6
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!system 77C293C7 5 Bytes JMP 006D0027
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 006D0FB7
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!_open 77C2F566 5 Bytes JMP 006D0FE3
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 006D0016
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 006D0FD2
.text C:\WINDOWS\system32\services.exe[1128] WS2_32.dll!socket 71AB4211 5 Bytes JMP 006C0000
.text C:\WINDOWS\system32\lsass.exe[1140] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00DB0FEF
.text C:\WINDOWS\system32\lsass.exe[1140] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00DB000A
.text C:\WINDOWS\system32\lsass.exe[1140] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00DB0FD4
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00E90000
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00E9007B
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00E90F7C
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00E90060
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00E90F97
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00E90FB9
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00E900A2
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00E90F50
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E900DF
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E900C4
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00E900FA
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00E90FA8
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00E90FE5
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00E90F6B
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00E90FCA
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00E9001B
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00E900B3
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00DE0022
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00DE0058
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00DE0FD1
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00DE0011
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00DE0F9B
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00DE0000
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00DE0FB6
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [FE, 88]
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00DE0033
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00DD003D
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!system 77C293C7 5 Bytes JMP 00DD0022
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00DD0FCD
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00DD0FEF
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00DD0FBC
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00DD0FDE
.text C:\WINDOWS\system32\lsass.exe[1140] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00DC0FEF
.text C:\WINDOWS\system32\svchost.exe[1304] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00FD0000
.text C:\WINDOWS\system32\svchost.exe[1304] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00FD0FCA
.text C:\WINDOWS\system32\svchost.exe[1304] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00FD0FE5
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02420000
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02420078
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02420F83
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02420051
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02420F94
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02420FAF
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 024200AB
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 0242009A
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02420F1C
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 02420F37
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02420F0B
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02420036
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02420011
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02420089
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02420FC0
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02420FDB
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 02420F48
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 02410FDB
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 02410FA5
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0241002C
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 0241001B
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 02410FB6
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 0241000A
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 02410058
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0241003D
.text C:\WINDOWS\system32\svchost.exe[1304] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00FF0FA6
.text C:\WINDOWS\system32\svchost.exe[1304] msvcrt.dll!system 77C293C7 5 Bytes JMP 00FF0FB7
.text C:\WINDOWS\system32\svchost.exe[1304] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00FF0FC8
.text C:\WINDOWS\system32\svchost.exe[1304] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00FF0FEF
.text C:\WINDOWS\system32\svchost.exe[1304] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00FF0027
.text C:\WINDOWS\system32\svchost.exe[1304] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00FF000C
.text C:\WINDOWS\system32\svchost.exe[1304] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FE0FEF
.text C:\WINDOWS\system32\svchost.exe[1368] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00AF0FEF
.text C:\WINDOWS\system32\svchost.exe[1368] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00AF0FD4
.text C:\WINDOWS\system32\svchost.exe[1368] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00AF000A
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C70FE5
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C70F46
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C70F57
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C70F72
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C70F83
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C70FA8
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C70F2B
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C70067
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C70EFF
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C70F1A
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00C700B3
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00C7002F
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00C70FD4
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00C70056
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00C70014
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00C70FC3
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00C70098
.text C:\WINDOWS\system32\svchost.exe[1368] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00B20025
.text C:\WINDOWS\system32\svchost.exe[1368] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00B2005B
.text C:\WINDOWS\system32\svchost.exe[1368] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00B20014
.text C:\WINDOWS\system32\svchost.exe[1368] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00B20FDE
.text C:\WINDOWS\system32\svchost.exe[1368] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00B20040
.text C:\WINDOWS\system32\svchost.exe[1368] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00B20FEF
.text C:\WINDOWS\system32\svchost.exe[1368] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00B20FA8
.text C:\WINDOWS\system32\svchost.exe[1368] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [D2, 88]
.text C:\WINDOWS\system32\svchost.exe[1368] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00B20FC3
.text C:\WINDOWS\system32\svchost.exe[1368] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00B10FBE
.text C:\WINDOWS\system32\svchost.exe[1368] msvcrt.dll!system 77C293C7 5 Bytes JMP 00B10049
.text C:\WINDOWS\system32\svchost.exe[1368] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00B1002E
.text C:\WINDOWS\system32\svchost.exe[1368] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00B10000
.text C:\WINDOWS\system32\svchost.exe[1368] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00B10FD9
.text C:\WINDOWS\system32\svchost.exe[1368] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00B10011
.text C:\WINDOWS\system32\svchost.exe[1368] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00B0000A
.text C:\WINDOWS\System32\svchost.exe[1408] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 026F0FEF
.text C:\WINDOWS\System32\svchost.exe[1408] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 026F0FD4
.text C:\WINDOWS\System32\svchost.exe[1408] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 026F0014
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02F7000A
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02F700C9
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02F700AE
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02F70087
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02F70076
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02F70FDB
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02F70F94
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02F700DA
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02F70F68
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 02F700F7
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02F7011C
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02F70FCA
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02F7001B
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02F70FAF
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02F70047
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02F7002C
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 02F70F83
.text C:\WINDOWS\System32\svchost.exe[1408] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 02F6001E
.text C:\WINDOWS\System32\svchost.exe[1408] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 02F6006F
.text C:\WINDOWS\System32\svchost.exe[1408] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 02F60FCD
.text C:\WINDOWS\System32\svchost.exe[1408] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 02F60FDE
.text C:\WINDOWS\System32\svchost.exe[1408] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 02F60054
.text C:\WINDOWS\System32\svchost.exe[1408] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 02F60FEF
.text C:\WINDOWS\System32\svchost.exe[1408] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 02F6002F
.text C:\WINDOWS\System32\svchost.exe[1408] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 02F60FB2
.text C:\WINDOWS\System32\svchost.exe[1408] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 02F50FB2
.text C:\WINDOWS\System32\svchost.exe[1408] msvcrt.dll!system 77C293C7 5 Bytes JMP 02F5003D
.text C:\WINDOWS\System32\svchost.exe[1408] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 02F50FDE
.text C:\WINDOWS\System32\svchost.exe[1408] msvcrt.dll!_open 77C2F566 5 Bytes JMP 02F50FEF
.text C:\WINDOWS\System32\svchost.exe[1408] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 02F50FCD
.text C:\WINDOWS\System32\svchost.exe[1408] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 02F50018
.text C:\WINDOWS\System32\svchost.exe[1408] WS2_32.dll!socket 71AB4211 5 Bytes JMP 02F40FEF
.text C:\WINDOWS\System32\svchost.exe[1408] WININET.dll!InternetOpenA 3D95D698 5 Bytes JMP 02740FEF
.text C:\WINDOWS\System32\svchost.exe[1408] WININET.dll!InternetOpenW 3D95DB11 5 Bytes JMP 0274000A
.text C:\WINDOWS\System32\svchost.exe[1408] WININET.dll!InternetOpenUrlA 3D95F3AC 5 Bytes JMP 02740025
.text C:\WINDOWS\System32\svchost.exe[1408] WININET.dll!InternetOpenUrlW 3D9A6D6F 5 Bytes JMP 02740036
.text C:\WINDOWS\system32\svchost.exe[1456] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00740FE5
.text C:\WINDOWS\system32\svchost.exe[1456] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00740FCA
.text C:\WINDOWS\system32\svchost.exe[1456] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00740000
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00780FEF
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00780075
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00780064
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00780F8A
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00780047
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00780025
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 007800BE
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 007800A1
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 007800FB
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 007800E0
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00780F3D
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00780036
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00780FD4
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00780090
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00780014
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00780FB9
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 007800CF
.text C:\WINDOWS\system32\svchost.exe[1456] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00770025
.text C:\WINDOWS\system32\svchost.exe[1456] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00770F8D
.text C:\WINDOWS\system32\svchost.exe[1456] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00770FD4
.text C:\WINDOWS\system32\svchost.exe[1456] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00770FE5
.text C:\WINDOWS\system32\svchost.exe[1456] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 0077004A
.text C:\WINDOWS\system32\svchost.exe[1456] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00770000
.text C:\WINDOWS\system32\svchost.exe[1456] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00770F9E
.text C:\WINDOWS\system32\svchost.exe[1456] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [97, 88]
.text C:\WINDOWS\system32\svchost.exe[1456] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00770FAF
.text C:\WINDOWS\system32\svchost.exe[1456] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0076003D
.text C:\WINDOWS\system32\svchost.exe[1456] msvcrt.dll!system 77C293C7 5 Bytes JMP 00760FB2
.text C:\WINDOWS\system32\svchost.exe[1456] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00760FCD
.text C:\WINDOWS\system32\svchost.exe[1456] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00760000
.text C:\WINDOWS\system32\svchost.exe[1456] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0076002C
.text C:\WINDOWS\system32\svchost.exe[1456] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00760011
.text C:\WINDOWS\system32\svchost.exe[1456] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00750000
.text C:\WINDOWS\system32\svchost.exe[1520] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00B20FE5
.text C:\WINDOWS\system32\svchost.exe[1520] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00B20000
.text C:\WINDOWS\system32\svchost.exe[1520] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B20FD4
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00B60000
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00B6007D
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00B60F92
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00B6006C
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00B60051
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00B6002F
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00B600B5
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00B60F6D
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00B600F2
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00B600E1
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00B6010D
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00B60040
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00B60FE5
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00B6008E
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00B60FC3
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00B60FD4
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00B600C6
.text C:\WINDOWS\system32\svchost.exe[1520] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00B5001B
.text C:\WINDOWS\system32\svchost.exe[1520] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00B50040
.text C:\WINDOWS\system32\svchost.exe[1520] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00B5000A
.text C:\WINDOWS\system32\svchost.exe[1520] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00B50FD4
.text C:\WINDOWS\system32\svchost.exe[1520] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00B50F79
.text C:\WINDOWS\system32\svchost.exe[1520] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00B50FEF
.text C:\WINDOWS\system32\svchost.exe[1520] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00B50F94
.text C:\WINDOWS\system32\svchost.exe[1520] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [D5, 88] {AAD 0x88}
.text C:\WINDOWS\system32\svchost.exe[1520] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00B50FAF
.text C:\WINDOWS\system32\svchost.exe[1520] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00B40F8B
.text C:\WINDOWS\system32\svchost.exe[1520] msvcrt.dll!system 77C293C7 5 Bytes JMP 00B40F9C
.text C:\WINDOWS\system32\svchost.exe[1520] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00B40FC8
.text C:\WINDOWS\system32\svchost.exe[1520] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00B40FE3
.text C:\WINDOWS\system32\svchost.exe[1520] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00B40FAD
.text C:\WINDOWS\system32\svchost.exe[1520] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00B40000
.text C:\WINDOWS\system32\svchost.exe[1520] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00B30000
.text C:\WINDOWS\Explorer.EXE[1796] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00D30FE5
.text C:\WINDOWS\Explorer.EXE[1796] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00D30FC3
.text C:\WINDOWS\Explorer.EXE[1796] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00D30FD4
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00D90000
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00D90F92
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00D90091
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00D90080
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00D9006F
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00D90FD4
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00D900B3
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00D900A2
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D900FA
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D900E9
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00D9011F
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00D90FC3
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00D9001B
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00D90F81
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00D90FE5
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00D90036
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00D900C4
.text C:\WINDOWS\Explorer.EXE[1796] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00D80FC3
.text C:\WINDOWS\Explorer.EXE[1796] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00D8006F
.text C:\WINDOWS\Explorer.EXE[1796] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00D80FDE
.text C:\WINDOWS\Explorer.EXE[1796] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00D80FEF
.text C:\WINDOWS\Explorer.EXE[1796] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00D8004A
.text C:\WINDOWS\Explorer.EXE[1796] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00D80000
.text C:\WINDOWS\Explorer.EXE[1796] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00D80FA8
.text C:\WINDOWS\Explorer.EXE[1796] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [F8, 88]
.text C:\WINDOWS\Explorer.EXE[1796] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00D8002F
.text C:\WINDOWS\Explorer.EXE[1796] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00D60055
.text C:\WINDOWS\Explorer.EXE[1796] msvcrt.dll!system 77C293C7 5 Bytes JMP 00D60FCA
.text C:\WINDOWS\Explorer.EXE[1796] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00D6003A
.text C:\WINDOWS\Explorer.EXE[1796] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00D60000
.text C:\WINDOWS\Explorer.EXE[1796] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00D60FE5
.text C:\WINDOWS\Explorer.EXE[1796] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00D6001D
.text C:\WINDOWS\Explorer.EXE[1796] WININET.dll!InternetOpenA 3D95D698 5 Bytes JMP 00D4000A
.text C:\WINDOWS\Explorer.EXE[1796] WININET.dll!InternetOpenW 3D95DB11 5 Bytes JMP 00D4001B
.text C:\WINDOWS\Explorer.EXE[1796] WININET.dll!InternetOpenUrlA 3D95F3AC 5 Bytes JMP 00D4002C
.text C:\WINDOWS\Explorer.EXE[1796] WININET.dll!InternetOpenUrlW 3D9A6D6F 5 Bytes JMP 00D40FDB
.text C:\WINDOWS\Explorer.EXE[1796] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00D5000A
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Ntfs \Ntfs SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \Driver\Tcpip \Device\Ip mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \Driver\Tcpip \Device\Udp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)
—- EOF - GMER 1.0.15 —-
Thank You Blottedisk!