This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer keeps reseting itself to 2006 and

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The computer keeps reseting itself to 2006 and everytime I reset the clock it I get the F1, F2 screen when restarting/booting up. Also- surfing the internet has recently become a nightmare, I cannot access any webpage without first getting:

There is a problem with this website's security certificate.


The security certificate presented by this website has expired or is not yet valid.

Security certificate problems may indicate an attempt to fool you or intercept any data you send to the server.
We recommend that you close this webpage and do not continue to this website.
Click here to close this webpage.
Continue to this website (not recommended).
More information


If you arrived at this page by clicking a link, check the website address in the address bar to be sure that it is the address you were expecting.
When going to a website with an address such as https://example.com, try adding the 'www' to the address, https://www.example.com.
If you choose to ignore this error and continue, do not enter private information into the website.

For more information, see Certificate Errors in Internet Explorer Help.



-Sometimes several times in a row no matter how many times I press the "Continue to this website (not recommended).
" link.

(I was pressing the link because I figured that something must have happened to IE because this started happening shortly after a microsoft update, instead of a "real" security certificate problem).

But now I think the computer is infected because it has also be acting wonky (software freezes for a few seconds even when I am not online) and slow. I have run McAfee Virus scans and Spybot Search and Destroy scans to no avail. Please help as I am disabled and depend on this computer to stay connected to people when I am physically unable to do so! As always I appreciate your time and expertise!

Here is the HiJack This log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:50:35 AM, on 1/7/2006
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\AOL\1151266064\ee\AOLSoftware.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
c:\program files\common files\aol\1151266064\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
C:\Program Files\Common Files\AOL\1151266064\EE\aolsoftware.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\AOL Desktop 9.6\waol.exe
C:\Documents and Settings\LEE BROSCIOUS\Desktop\HiJackThis.exe
C:\Program Files\AOL Desktop 9.6\shellmon.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AOL Toolbar Loader - {3ef64538-8b54-4573-b48f-4d34b0238ab2} - C:\Program Files\AOL Toolbar\aoltb.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20111027013048.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: ShopAtHomeIEHelper - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar2.dll (file missing)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: ShopAtHome Toolbar - {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar2.dll (file missing)
O3 - Toolbar: AOL Toolbar - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files\AOL Toolbar\aoltb.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1151266064\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [EPSON Stylus CX4600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE /P26 "EPSON Stylus CX4600 Series" /O6 "USB002" /M "Stylus CX4600"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL Desktop 9.6\AOL.EXE" -b
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1225142934828
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\WINDOWS\system32\mfevtps.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

–
End of file - 10876 bytes


Thank You Again for Your Time and Expertise!

Shubert
Hi schlackeye,

These two problems are not related to malware. The time reset issue has to do with your cmos battery, which is dead. And the Internet Explorer messages you receive are because of the date on your system tray's clock.

My suggestion is: Replace your cmos battery (it costs around $5), set up the right time and date and come back to tell us if that worked.

If you are planning to do it yourself, you can have a look at the following tutorial on how to replace the battery:

http://www.computerhope.com/issues/ch000239.htm

The cmos battery looks like a coin:

🖼Click to load external image (Posted Image)

Otherwise, you could take it to the technician.
Thank You Blottedisk for answering so promptly, it is much appreciated! I will do as you say as soon as I am able to get the battery and let you know the result! It may be a few days depending on the availibility of the battery . . . . . . . Thanks Again! Shubert Schlackeye
Changing the battery has solved both of the problems! Thank You! I'm glad it was such a simple solution! Blottedisk, if you want to check the computer for malware please do so . . . . is there anything you need me to do for you to do this? Just let me know. Thanks Again, Shubert Schlackeye
I'm glad to hear that :)

It would be a good idea to have a look at the machine, it never hurts.

Please follow these steps:

Step 1 | Please download OTL from one of the following mirrors:

This is THE Mirror

——————————————————————–

  • Save it to your desktop.
  • Double click on the [external image: Posted Image] icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Change the "Extra Registry" option to "SafeList"
  • Push the [external image: Posted Image] button.
  • Two reports will open, copy and paste them in your next reply:
OTListIt.txt <– Will be opened
Extras.txt <– Will be minimized


Step 2 | Please download GMER from one of the following locations and save it to your desktop:

Main Mirror - This version will download a randomly named file (Recommended)
Zipped Mirror - This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.

——————————————————————–

  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.

Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

[external image: Posted Image]

  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system…click NO.
  • Make sure all options are checked except:
  • IAT/EAT
  • Drives/Partition other than Systemdrive, which is typically C:\
  • Show All (This is important, so do not miss it.)

[external image: Posted Image]
Click the image to enlarge it

  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save… button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.
– If you encounter any problems, try running GMER in Safe Mode.
OK, HERE WE GO . . . . .!

OTL:

OTL logfile created on: 11/22/2011 3:03:11 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\LEE BROSCIOUS\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.58 Gb Available Physical Memory | 78.83% Memory free
2.60 Gb Paging File | 2.05 Gb Available in Paging File | 78.61% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 108.59 Gb Total Space | 63.50 Gb Free Space | 58.48% Space Free | Partition Type: NTFS
Drive D: | 37.24 Gb Total Space | 36.76 Gb Free Space | 98.73% Space Free | Partition Type: NTFS

Computer Name: LRBENGR | User Name: LEE BROSCIOUS | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/11/22 14:59:38 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\LEE BROSCIOUS\Desktop\OTL.exe
PRC - [2011/09/23 19:46:28 | 001,195,408 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2011/04/25 16:52:37 | 000,041,296 | —- | M] (AOL Inc.) – C:\Program Files\AOL Desktop 9.6\waol.exe
PRC - [2011/04/25 16:52:36 | 000,045,392 | —- | M] (AOL Inc.) – C:\Program Files\AOL Desktop 9.6\shellmon.exe
PRC - [2011/04/14 13:01:38 | 000,188,136 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe
PRC - [2011/04/14 13:01:38 | 000,171,168 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe
PRC - [2011/03/13 10:45:14 | 000,148,520 | —- | M] (McAfee, Inc.) – C:\WINDOWS\system32\mfevtps.exe
PRC - [2010/03/10 09:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
PRC - [2010/03/08 02:27:49 | 000,041,800 | —- | M] (AOL Inc.) – C:\Program Files\Common Files\AOL\1151266064\EE\aolsoftware.exe
PRC - [2009/05/21 10:55:32 | 000,206,064 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2008/08/13 17:32:40 | 000,201,968 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2006/10/23 14:04:42 | 000,001,536 | —- | M] () – c:\Program Files\Common Files\AOL\1151266064\EE\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
PRC - [2006/10/23 07:50:35 | 000,046,640 | R— | M] (AOL LLC) – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
PRC - [2005/12/07 16:05:12 | 000,053,248 | —- | M] (GEAR Software) – C:\WINDOWS\system32\gearsec.exe
PRC - [2005/09/08 05:20:00 | 000,122,940 | —- | M] (Sonic Solutions) – C:\WINDOWS\system32\DLA\DLACTRLW.EXE
PRC - [2004/12/13 15:30:10 | 000,165,488 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
PRC - [2004/12/13 15:30:04 | 000,198,256 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
PRC - [2004/12/13 15:30:00 | 000,058,992 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PRC - [2004/10/15 15:54:14 | 000,100,016 | —- | M] (America Online, Inc) – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
PRC - [2004/10/15 15:54:12 | 000,046,768 | —- | M] (America Online Inc) – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
PRC - [2004/03/04 03:00:00 | 000,098,304 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATI9AA.EXE
PRC - [2003/08/27 09:29:46 | 000,065,536 | —- | M] (America Online, Inc.) – C:\WINDOWS\wanmpsvc.exe


========== Modules (No Company Name) ==========

MOD - [2011/10/27 09:53:36 | 003,391,488 | —- | M] () – c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_5571e5f9\mscorlib.dll
MOD - [2011/10/27 09:53:21 | 002,088,960 | —- | M] () – c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_e274fd76\system.xml.dll
MOD - [2011/10/27 09:52:53 | 001,966,080 | —- | M] () – c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_1fa0dc53\system.dll
MOD - [2011/10/27 09:52:36 | 001,232,896 | —- | M] () – c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
MOD - [2011/04/25 16:52:37 | 000,048,640 | —- | M] () – C:\Program Files\AOL Desktop 9.6\zlib.dll
MOD - [2006/10/23 14:04:42 | 000,001,536 | —- | M] () – c:\Program Files\Common Files\AOL\1151266064\EE\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
MOD - [2004/08/10 13:11:10 | 001,339,392 | —- | M] () – c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
MOD - [2002/07/04 08:38:00 | 000,053,248 | —- | M] () – C:\Program Files\ArcSoft\Software Suite\PhotoImpression 5\Share\PIHook.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – – (MPService)
SRV - File not found [Disabled | Stopped] – – (HidServ)
SRV - File not found [On_Demand | Stopped] – – (AppMgmt)
SRV - [2011/04/14 13:01:38 | 000,188,136 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe – (mfefire)
SRV - [2011/04/14 13:01:38 | 000,171,168 | —- | M] () [Unknown | Running] – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe – (McShield)
SRV - [2011/03/13 10:45:14 | 000,148,520 | —- | M] (McAfee, Inc.) [Unknown | Running] – C:\WINDOWS\system32\mfevtps.exe – (mfevtp)
SRV - [2010/10/07 19:34:28 | 000,364,216 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\McAfee\VirusScan\mcods.exe – (McODS)
SRV - [2010/03/10 09:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McProxy)
SRV - [2010/03/10 09:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNASvc)
SRV - [2010/03/10 09:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McNaiAnn)
SRV - [2010/03/10 09:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (mcmscsvc)
SRV - [2010/03/10 09:14:44 | 000,271,480 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe – (McMPFSvc)
SRV - [2008/08/13 17:32:40 | 000,201,968 | —- | M] (SupportSoft, Inc.) [Auto | Running] – C:\Program Files\Dell Support Center\bin\sprtsvc.exe – (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
SRV - [2007/03/07 14:47:46 | 000,076,848 | —- | M] () [On_Demand | Stopped] – C:\Program Files\DellSupport\brkrsvc.exe – (DSBrokerService)
SRV - [2006/10/23 07:50:35 | 000,046,640 | R— | M] (AOL LLC) [Auto | Running] – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe – (AOL ACS)
SRV - [2006/05/08 22:29:57 | 000,822,424 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe – (Symantec Core LC)
SRV - [2005/12/07 16:05:34 | 002,066,072 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Norton Ghost\Agent\VProSvc.exe – (Norton Ghost)
SRV - [2005/12/07 16:05:12 | 000,053,248 | —- | M] (GEAR Software) [Auto | Running] – C:\WINDOWS\system32\gearsec.exe – (GEARSecurity)
SRV - [2005/07/12 18:10:18 | 000,963,072 | —- | M] (McAfee Inc.) [Disabled | Stopped] – C:\Program Files\McAfee\SpamKiller\MSKSrvr.exe – (MskService)
SRV - [2004/12/13 15:30:10 | 000,165,488 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe – (ccSetMgr)
SRV - [2004/12/13 15:30:08 | 000,079,472 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe – (ccPwdSvc)
SRV - [2004/12/13 15:30:04 | 000,198,256 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe – (ccEvtMgr)
SRV - [2004/10/15 15:54:14 | 000,100,016 | —- | M] (America Online, Inc) [Auto | Running] – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe – (AOL TopSpeedMonitor)
SRV - [2003/08/27 09:29:46 | 000,065,536 | —- | M] (America Online, Inc.) [Auto | Running] – C:\WINDOWS\wanmpsvc.exe – (WANMiniportService) WAN Miniport (ATW)


========== Driver Services (SafeList) ==========

DRV - [2011/04/14 13:01:38 | 000,314,088 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mfefirek.sys – (mfefirek)
DRV - [2011/04/14 13:01:38 | 000,153,280 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mfeavfk.sys – (mfeavfk)
DRV - [2011/04/14 13:01:38 | 000,088,736 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mfendisk.sys – (mfendiskmp)
DRV - [2011/04/14 13:01:38 | 000,088,736 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mfendisk.sys – (mfendisk)
DRV - [2011/04/14 13:01:38 | 000,084,488 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mferkdet.sys – (mferkdet)
DRV - [2011/04/14 13:01:38 | 000,084,200 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\mfetdi2k.sys – (mfetdi2k)
DRV - [2011/04/14 13:01:38 | 000,056,064 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\cfwids.sys – (cfwids)
DRV - [2011/04/14 13:01:38 | 000,052,320 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mfebopk.sys – (mfebopk)
DRV - [2011/03/13 10:20:10 | 000,459,728 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfehidk.sys – (mfehidk)
DRV - [2011/03/13 10:20:10 | 000,118,784 | —- | M] (McAfee, Inc.) [Kernel | Unknown | Running] – C:\WINDOWS\system32\drivers\mfeapfk.sys – (mfeapfk)
DRV - [2007/02/25 11:10:48 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\dsunidrv.sys – (dsunidrv)
DRV - [2006/10/05 15:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys – (DSproct)
DRV - [2006/05/08 22:29:57 | 000,004,608 | —- | M] (Symantec Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\symlcbrd.sys – (symlcbrd)
DRV - [2006/05/08 22:26:16 | 000,008,552 | —- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\asctrm.sys – (ASCTRM)
DRV - [2005/12/07 16:05:26 | 000,144,880 | —- | M] (StorageCraft) [File_System | Boot | Running] – C:\WINDOWS\System32\drivers\SymSnap.sys – (SymSnap)
DRV - [2005/12/07 16:05:24 | 000,056,240 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\V2iMount.sys – (V2IMount)
DRV - [2005/09/08 05:20:00 | 000,094,332 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS – (DLAUDFAM)
DRV - [2005/09/08 05:20:00 | 000,087,036 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS – (DLAUDF_M)
DRV - [2005/09/08 05:20:00 | 000,086,524 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS – (DLAIFS_M)
DRV - [2005/09/08 05:20:00 | 000,025,628 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLABOIOM.SYS – (DLABOIOM)
DRV - [2005/09/08 05:20:00 | 000,014,684 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS – (DLAOPIOM)
DRV - [2005/09/08 05:20:00 | 000,006,364 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAPoolM.SYS – (DLAPoolM)
DRV - [2005/09/08 05:20:00 | 000,002,496 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLADResN.SYS – (DLADResN)
DRV - [2005/08/25 12:16:52 | 000,005,628 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLACDBHM.SYS – (DLACDBHM)
DRV - [2005/08/25 12:16:16 | 000,022,684 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLARTL_N.SYS – (DLARTL_N)
DRV - [2004/09/17 14:02:54 | 000,732,928 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\senfilt.sys – (senfilt)
DRV - [2004/03/24 10:12:44 | 000,004,272 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\bvrp_pci.sys – (bvrp_pci)
DRV - [2003/11/17 21:59:20 | 000,212,224 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSFHWBS2.sys – (HSFHWBS2)
DRV - [2003/11/17 21:58:02 | 000,680,704 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_CNXT.sys – (winachsf)
DRV - [2003/11/17 21:56:26 | 001,042,432 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_DP.sys – (HSF_DP)
DRV - [2003/01/10 16:13:04 | 000,033,588 | R— | M] (America Online, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [1999/11/05 13:57:58 | 000,048,472 | —- | M] (Canon Information Systems) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\cis1284.sys – (cis1284)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1861267-2091798228-1098460282-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-1861267-2091798228-1098460282-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKU\S-1-5-21-1861267-2091798228-1098460282-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-1861267-2091798228-1098460282-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com
IE - HKU\S-1-5-21-1861267-2091798228-1098460282-1006\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-1861267-2091798228-1098460282-1006\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-1861267-2091798228-1098460282-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@ei.CouponAlert_2p.com/Plugin: C:\Program Files\CouponAlert_2pEI\Installr\2.bin\NP2pEISB.dll (CouponAlert)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()



O1 HOSTS File: ([2008/10/23 01:38:52 | 000,000,848 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AOL Toolbar Loader) - {3ef64538-8b54-4573-b48f-4d34b0238ab2} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
O2 - BHO: (McAfee AntiPhishing Filter) - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\Program Files\McAfee\SpamKiller\McApfBHO.dll (McAfee, Inc.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20111027013048.dll (McAfee, Inc.)
O2 - BHO: (ShopAtHomeIEHelper Class) - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar2.dll File not found
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (ShopAtHome Toolbar) - {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar2.dll File not found
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files\AOL Toolbar\aoltb.dll (AOL Inc.)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKU\S-1-5-21-1861267-2091798228-1098460282-1006\..\Toolbar\WebBrowser: (ShopAtHome Toolbar) - {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar2.dll File not found
O3 - HKU\S-1-5-21-1861267-2091798228-1098460282-1006\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe (America Online)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [EPSON Stylus CX4600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1151266064\EE\aolsoftware.exe (AOL Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [MSKAGENTEXE] C:\Program Files\McAfee\SpamKiller\MSKAgent.exe (McAfee Inc.)
O4 - HKU\S-1-5-21-1861267-2091798228-1098460282-1006..\Run: [AOL Fast Start] C:\Program Files\AOL Desktop 9.6\AOL.EXE (AOL Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1861267-2091798228-1098460282-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\Program Files\McAfee\SpamKiller\McApfBHO.dll (McAfee, Inc.)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O15 - HKU\S-1-5-21-1861267-2091798228-1098460282-1006\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1225142934828 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} http://offers.e-centives.com/cif/download/bin/actxcab.cab (CBSTIEPrint Class)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\LEE BROSCIOUS\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\LEE BROSCIOUS\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 12:51:28 | 000,000,032 | -H– | M] () - C:\autoexea.bat – [ NTFS ]
O32 - AutoRun File - [2004/08/10 13:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/11/22 14:59:38 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\LEE BROSCIOUS\Desktop\OTL.exe
[2011/11/22 14:00:06 | 000,000,000 | —D | C] – C:\Documents and Settings\LEE BROSCIOUS\Start Menu\Programs\Coupons
[2011/11/10 20:07:31 | 000,000,000 | —D | C] – C:\Documents and Settings\LEE BROSCIOUS\Local Settings\Application Data\Dell
[2011/11/03 15:52:49 | 000,000,000 | —D | C] – C:\Documents and Settings\LEE BROSCIOUS\My Documents\000 AOL Backups
[2011/10/27 00:30:47 | 000,009,344 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfeclnk.sys
[2011/10/27 00:30:36 | 000,314,088 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfefirek.sys
[2011/10/27 00:30:36 | 000,153,280 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfeavfk.sys
[2011/10/27 00:30:36 | 000,088,736 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfendisk.sys
[2011/10/27 00:30:36 | 000,084,488 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mferkdet.sys
[2011/10/27 00:30:36 | 000,084,200 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfetdi2k.sys
[2011/10/27 00:30:36 | 000,056,064 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\cfwids.sys
[2011/10/27 00:30:36 | 000,052,320 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\mfebopk.sys
[2011/10/27 00:30:26 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Mcafee
[2011/10/27 00:30:25 | 000,000,000 | —D | C] – C:\Program Files\McAfee.com
[2011/10/26 16:04:12 | 000,148,520 | —- | C] (McAfee, Inc.) – C:\WINDOWS\System32\mfevtps.exe
[2011/10/26 15:46:55 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\ApplicationHistory
[2011/10/26 15:14:20 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2011/10/26 14:40:24 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\AOL Toolbar
[2011/10/26 14:40:23 | 000,000,000 | —D | C] – C:\Documents and Settings\LEE BROSCIOUS\Local Settings\Application Data\AOL Toolbar
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/22 15:01:53 | 000,069,607 | —- | M] () – C:\VETlog.dmp
[2011/11/22 14:59:38 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\LEE BROSCIOUS\Desktop\OTL.exe
[2011/11/22 14:16:18 | 000,302,592 | —- | M] () – C:\Documents and Settings\LEE BROSCIOUS\Desktop\4dgnshqk.exe
[2011/11/22 13:29:50 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/11/22 13:29:02 | 000,001,595 | —- | M] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Center.lnk
[2011/11/22 13:28:51 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/11/22 13:28:50 | 2145,439,744 | -HS- | M] () – C:\hiberfil.sys
[2011/11/21 20:16:54 | 000,009,662 | —- | M] () – C:\WINDOWS\EPISME00.SWB
[2011/11/21 19:29:23 | 000,002,397 | —- | M] () – C:\Documents and Settings\LEE BROSCIOUS\Desktop\ACDSee 5.0.lnk
[2011/11/09 03:46:06 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/11/08 13:49:39 | 000,004,158 | —- | M] () – C:\Documents and Settings\LEE BROSCIOUS\My Documents\independent bible church.wpd
[2011/11/08 04:01:28 | 000,089,600 | —- | M] () – C:\Documents and Settings\LEE BROSCIOUS\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/06 16:16:10 | 000,381,692 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/11/06 16:16:10 | 000,053,436 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/11/04 14:41:44 | 000,002,409 | —- | M] () – C:\Documents and Settings\LEE BROSCIOUS\My Documents\Dell Support Center.lnk
[2011/11/02 20:55:11 | 000,224,093 | —- | M] () – C:\Documents and Settings\LEE BROSCIOUS\My Documents\DSC07545.JPG
[2011/11/01 12:14:08 | 000,030,518 | —- | M] () – C:\Documents and Settings\LEE BROSCIOUS\My Documents\File_Sunbury,_Pennsylvania.htm
[2011/10/28 15:50:12 | 000,001,907 | —- | M] () – C:\Documents and Settings\LEE BROSCIOUS\Desktop\Musicmatch Jukebox.lnk
[2011/10/26 10:33:37 | 000,000,803 | —- | M] () – C:\Documents and Settings\LEE BROSCIOUS\Desktop\Internet Explorer.lnk
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/22 14:16:17 | 000,302,592 | —- | C] () – C:\Documents and Settings\LEE BROSCIOUS\Desktop\4dgnshqk.exe
[2011/11/04 17:42:11 | 000,002,397 | —- | C] () – C:\Documents and Settings\LEE BROSCIOUS\Desktop\ACDSee 5.0.lnk
[2011/11/04 14:12:22 | 000,338,827 | —- | C] () – C:\Documents and Settings\LEE BROSCIOUS\My Documents\Copy of jake1.JPG
[2011/11/02 20:55:10 | 000,224,093 | —- | C] () – C:\Documents and Settings\LEE BROSCIOUS\My Documents\DSC07545.JPG
[2011/11/01 12:14:07 | 000,030,518 | —- | C] () – C:\Documents and Settings\LEE BROSCIOUS\My Documents\File_Sunbury,_Pennsylvania.htm
[2011/10/28 15:50:12 | 000,001,907 | —- | C] () – C:\Documents and Settings\LEE BROSCIOUS\Desktop\Musicmatch Jukebox.lnk
[2011/10/27 19:48:43 | 000,001,595 | —- | C] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Center.lnk
[2011/10/27 00:53:41 | 2145,439,744 | -HS- | C] () – C:\hiberfil.sys
[2011/10/26 15:46:59 | 000,000,135 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\fusioncache.dat
[2011/10/26 10:33:37 | 000,000,803 | —- | C] () – C:\Documents and Settings\LEE BROSCIOUS\Desktop\Internet Explorer.lnk
[2009/04/19 17:54:40 | 000,002,181 | —- | C] () – C:\WINDOWS\U3DEDIT2.INI
[2009/02/21 17:47:13 | 000,036,180 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/02/21 16:51:13 | 000,000,092 | —- | C] () – C:\WINDOWS\Retrieve9.INI
[2009/02/19 16:36:41 | 000,890,953 | —- | C] () – C:\WINDOWS\HSCasl3.ini
[2009/02/18 16:35:45 | 000,003,641 | —- | C] () – C:\WINDOWS\universe_plugin.ini
[2009/02/18 14:00:42 | 000,890,953 | —- | C] () – C:\WINDOWS\HSCafc1.ini
[2009/02/17 22:26:08 | 000,000,089 | —- | C] () – C:\WINDOWS\ULead32.ini
[2009/02/17 22:24:59 | 000,035,328 | —- | C] () – C:\WINDOWS\inetwh32.dll
[2009/02/17 22:24:59 | 000,009,136 | —- | C] () – C:\WINDOWS\inetwh16.dll
[2009/02/17 22:24:59 | 000,004,528 | —- | C] () – C:\WINDOWS\setbrows.exe
[2009/02/17 19:59:37 | 000,000,264 | —- | C] () – C:\WINDOWS\ScreenHunter.INI
[2009/02/16 17:48:40 | 000,000,011 | —- | C] () – C:\WINDOWS\System32\tscrip22.dll
[2009/02/16 17:01:27 | 000,000,011 | —- | C] () – C:\WINDOWS\3DShadow.INI
[2009/02/16 16:53:31 | 000,044,544 | —- | C] () – C:\WINDOWS\AWuninstall.exe
[2009/02/15 21:10:31 | 000,000,670 | —- | C] () – C:\WINDOWS\nvrbm.ini
[2009/02/14 15:28:45 | 000,000,695 | —- | C] () – C:\WINDOWS\nvrph.ini
[2009/02/14 00:05:50 | 000,000,805 | —- | C] () – C:\WINDOWS\PowerReg.dat
[2008/12/07 16:20:50 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2008/09/27 11:27:06 | 000,000,029 | —- | C] () – C:\WINDOWS\DEBUGSM.INI
[2008/08/28 09:53:48 | 000,000,136 | —- | C] () – C:\Documents and Settings\LEE BROSCIOUS\Local Settings\Application Data\fusioncache.dat
[2008/08/28 05:54:14 | 000,004,272 | —- | C] () – C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2007/10/23 12:39:59 | 000,000,031 | -H– | C] () – C:\WINDOWS\uccspecc.sys
[2006/10/02 10:56:07 | 000,000,021 | —- | C] () – C:\WINDOWS\PI_setup.ini
[2006/10/02 10:55:08 | 000,029,521 | —- | C] () – C:\WINDOWS\System32\EPPICPrinterDB.dat
[2006/10/02 10:55:08 | 000,020,910 | —- | C] () – C:\WINDOWS\System32\EPPICPattern2.dat
[2006/10/02 10:55:08 | 000,020,869 | —- | C] () – C:\WINDOWS\System32\EPPICPattern1.dat
[2006/10/02 10:55:08 | 000,000,022 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2006/10/02 10:51:39 | 000,000,072 | —- | C] () – C:\WINDOWS\System32\epDPE.ini
[2006/10/02 10:51:38 | 000,096,768 | —- | C] () – C:\WINDOWS\SlantAdj.dll
[2006/10/02 10:51:38 | 000,003,136 | —- | C] () – C:\WINDOWS\Ade001.bin
[2006/10/02 10:44:47 | 000,000,044 | —- | C] () – C:\WINDOWS\EPCX4600.ini
[2006/07/01 16:02:28 | 000,000,024 | —- | C] () – C:\WINDOWS\atid.ini
[2006/07/01 16:02:28 | 000,000,018 | —- | C] () – C:\WINDOWS\upst.ini
[2006/06/25 15:10:27 | 000,000,715 | —- | C] () – C:\WINDOWS\aolback.exe.lnk
[2006/05/29 19:20:03 | 000,000,088 | RHS- | C] () – C:\WINDOWS\System32\E51DD59C1E.sys
[2006/05/18 12:32:39 | 000,061,678 | —- | C] () – C:\Documents and Settings\LEE BROSCIOUS\Application Data\PFP120JPR.{PB
[2006/05/18 12:32:39 | 000,012,358 | —- | C] () – C:\Documents and Settings\LEE BROSCIOUS\Application Data\PFP120JCM.{PB
[2006/05/18 12:31:59 | 000,006,686 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/05/18 12:31:59 | 000,000,104 | RHS- | C] () – C:\WINDOWS\System32\1E9CD51DE5.sys
[2006/05/18 12:10:07 | 000,017,611 | —- | C] () – C:\WINDOWS\MPTBox.INI
[2006/05/13 12:29:29 | 000,089,600 | —- | C] () – C:\Documents and Settings\LEE BROSCIOUS\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/05/11 14:01:01 | 000,046,512 | —- | C] () – C:\WINDOWS\System32\EPSN.DLL
[2006/05/11 14:01:01 | 000,012,126 | —- | C] () – C:\WINDOWS\System32\PIXPCZ.DLL
[2006/05/11 14:01:01 | 000,011,934 | —- | C] () – C:\WINDOWS\System32\PIXPNR.DLL
[2006/05/11 13:59:50 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\Lffpx7.dll
[2006/05/11 13:59:50 | 000,141,824 | —- | C] () – C:\WINDOWS\System32\Lfcmp60n.dll
[2006/05/11 13:59:50 | 000,122,880 | —- | C] () – C:\WINDOWS\System32\Lfkodak.dll
[2006/05/11 13:59:50 | 000,043,008 | —- | C] () – C:\WINDOWS\System32\Ltfil60n.dll
[2006/05/11 13:59:50 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\Lfbmp60n.dll
[2006/05/11 13:57:34 | 000,000,028 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/05/11 13:56:11 | 000,000,049 | —- | C] () – C:\WINDOWS\SGEDIT.INI
[2006/05/11 13:55:38 | 000,000,982 | —- | C] () – C:\WINDOWS\mpass.ini
[2006/05/11 13:55:37 | 000,416,768 | —- | C] () – C:\WINDOWS\System32\FILTERS.DLL
[2006/05/11 13:55:37 | 000,308,224 | —- | C] () – C:\WINDOWS\System32\FPXLIB.DLL
[2006/05/11 13:55:37 | 000,282,624 | —- | C] () – C:\WINDOWS\System32\FPXLIBIO.DLL
[2006/05/11 13:55:37 | 000,095,232 | —- | C] () – C:\WINDOWS\System32\JPEGLIB.DLL
[2006/05/11 13:55:37 | 000,068,608 | —- | C] () – C:\WINDOWS\System32\annot.dll
[2006/05/11 13:55:37 | 000,034,816 | —- | C] () – C:\WINDOWS\System32\sgimgapi.dll
[2006/05/11 13:55:35 | 000,348,672 | —- | C] () – C:\WINDOWS\System32\dtbl32.dll
[2006/05/08 22:40:31 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/05/08 22:36:27 | 000,000,200 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/05/08 22:32:01 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2006/05/08 22:30:09 | 000,712,704 | —- | C] () – C:\WINDOWS\System32\DellSystemRestore.dll
[2006/05/08 22:25:24 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/05/08 22:00:44 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2006/05/08 22:00:24 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2006/05/08 22:00:22 | 000,000,392 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/11/10 08:56:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/08/10 13:12:05 | 000,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 13:07:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/10 13:02:15 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 13:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 12:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 12:57:15 | 000,181,832 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 12:51:28 | 000,000,032 | -H– | C] () – C:\WINDOWS\ialig.dll
[2004/08/10 12:51:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 12:51:20 | 000,381,692 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 12:51:20 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 12:51:20 | 000,053,436 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 12:51:20 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 12:51:18 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/10 12:51:17 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/10 12:51:16 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/10 12:51:12 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 12:51:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 12:51:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 12:50:56 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2002/03/21 13:51:52 | 000,503,808 | R— | C] () – C:\WINDOWS\System32\lt_xtrans.dll
[2002/03/21 13:51:52 | 000,286,720 | R— | C] () – C:\WINDOWS\System32\MrSIDD.dll
[2002/03/21 13:51:52 | 000,163,840 | R— | C] () – C:\WINDOWS\System32\lt_common.dll
[2002/03/21 13:51:52 | 000,126,976 | R— | C] () – C:\WINDOWS\System32\lt_trans.dll
[2002/03/21 13:51:52 | 000,069,632 | R— | C] () – C:\WINDOWS\System32\lt_meta.dll
[2002/03/21 13:51:52 | 000,053,248 | R— | C] () – C:\WINDOWS\System32\lt_encrypt.dll
[2002/03/21 13:51:52 | 000,020,480 | R— | C] () – C:\WINDOWS\System32\lt_messagetext.dll
[2002/03/20 22:01:06 | 000,006,688 | R— | C] () – C:\WINDOWS\System32\Digita.sys
[2002/03/20 22:00:20 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\TransportUSB.dll
[2002/03/20 22:00:20 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\TransportSerial.dll
[2002/03/20 22:00:20 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\TransportIrDA.dll
[2002/03/20 22:00:20 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\TransportIrCOMM.dll
[1998/07/12 23:32:03 | 000,115,712 | —- | C] () – C:\WINDOWS\System32\vboxp403.dll

< End of report >
OTL Extras logfile created on: 11/22/2011 3:03:11 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\LEE BROSCIOUS\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.58 Gb Available Physical Memory | 78.83% Memory free
2.60 Gb Paging File | 2.05 Gb Available in Paging File | 78.61% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 108.59 Gb Total Space | 63.50 Gb Free Space | 58.48% Space Free | Partition Type: NTFS
Drive D: | 37.24 Gb Total Space | 36.76 Gb Free Space | 98.73% Space Free | Partition Type: NTFS

Computer Name: LRBENGR | User Name: LEE BROSCIOUS | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] – "C:\Program Files\ACD Systems\ACDSee\5.0\ACDSee5.exe" "%1" (ACD Systems, Ltd.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe:*:Enabled:AOL – (AOL LLC)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – (America Online)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe:*:Enabled:AOL – (AOL LLC)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – (America Online)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader – (AOL Inc.)
"C:\Program Files\America Online 9.0a\waol.exe" = C:\Program Files\America Online 9.0a\waol.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe" = C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon – (America Online, Inc)
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe" = C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed – (America Online Inc)
"C:\Program Files\Common Files\AOL\1151266064\EE\AOLServiceHost.exe" = C:\Program Files\Common Files\AOL\1151266064\EE\AOLServiceHost.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\System Information\sinf.exe" = C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL – (AOL Inc.)
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe" = C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe" = C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:*:Enabled:AOL
"C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe" = C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL – (Gteko Ltd.)
"C:\Program Files\America Online 9.0b\waol.exe" = C:\Program Files\America Online 9.0b\waol.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\America Online 9.0c\waol.exe" = C:\Program Files\America Online 9.0c\waol.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\America Online 9.0d\waol.exe" = C:\Program Files\America Online 9.0d\waol.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\1151266064\EE\aolsoftware.exe" = C:\Program Files\Common Files\AOL\1151266064\EE\aolsoftware.exe:*:Enabled:AOL Shared Components – (AOL Inc.)
"C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe" = C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe:*:Enabled:McAfee Data Backup
"C:\Program Files\AOL Desktop 9.6\waol.exe" = C:\Program Files\AOL Desktop 9.6\waol.exe:*:Enabled:AOL – (AOL Inc.)
"C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe" = C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed – (AOL Inc.)
"C:\Program Files\AOL Desktop 9.6\AOLBrowser\aolbrowser.exe" = C:\Program Files\AOL Desktop 9.6\AOLBrowser\aolbrowser.exe:*:Enabled:AOL Browser – (AOL Inc.)
"C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" = C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe:*:Enabled:McAfee Shared Service Host – (McAfee, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio RecordNow Data
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{109D28C7-FB38-483A-9C91-001CB59E2699}" = EPSON CardMonitor
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Roxio DLA
"{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}" = Intel® PROSet for Wired Connections
"{1A15507A-8551-4626-915D-3D5FA095CC1B}" = Corel Paint Shop Pro X
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Roxio MyDVD LE
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 13
"{2C00FB6D-BF33-4EBA-BBB0-B8A8D7D43DFF}" = FocusFixer
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{32F720F5-2D0D-4245-A2B0-9EB3CECF8101}" = Norton Ghost 10.0
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{34E96A8C-2C58-490A-8D5D-3CE70E1D512E}" = NoiseFixer
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{352310C3-E46B-42D3-8F32-54721FDD72D9}" = NetZeroInstallers
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{43CAC9A1-1993-4F65-9096-7C9AFC2BBF54}" = Dell CinePlayer
"{4667B940-BB01-428B-986E-A0CC46497BF7}" = ELIcon
"{553C904F-57A2-4113-888E-BA0C3D1C69C0}" = Microsoft VC9 runtime libraries
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}" = Sonic Activation Module
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{66C8BE35-8BBB-472B-96C7-C7C9A499F988}" = ArcSoft Software Suite
"{67EDD823-135A-4D59-87BD-950616D6E857}" = EPSON Copy Utility 3
"{6C11D561-620B-47DA-A693-4C597F3CDF40}" = EPSON Smart Panel
"{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}" = Digital Content Portal
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{6EA8BBD9-84A1-4513-969D-D67C5DE7EAC7}" = Noiseware Professional Plug-in
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}" = EarthLink setup files
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7A3F0566-5E05-4919-9C98-456F6B5CF831}" = Get High Speed Internet!
"{7D50D895-C7C8-47EA-8F9C-FB77B7B9DC50}" = Kodak DIGITAL SHO Plug-In 1.1.3
"{7E5B4758-346B-4D77-BB1A-1BC878ED7498}" = Kodak DIGITAL GEM Airbrush Professional Plug-In 1.0.1
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page
"{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch® Jukebox
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8A9B8148-DDD7-448F-BD6C-358386D32354}" = Corel Photo Album 6
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{A4F65B5E-C91B-4D75-B6E9-281DA54520AB}" = TrueBlurInstaller
"{A683A2C0-821C-486F-858C-FA634DB5E864}" = EducateU
"{AA027AE9-DD20-4677-AA72-D760A358320B}" = Microsoft VC9 runtime libraries
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AE704636-ECD0-426C-952E-05B8DABD1949}" = EPSON PhotoStarter3.2
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{AF5E8D43-49AD-4BE7-A941-2BB0A8CACA62}" = ACDSee 5.0 Standard
"{B0DF58A2-40DF-4465-AA56-38623EC9938C}" = Documentation & Support Launcher
"{B0DFFD18-871A-431C-85D4-365BF1D81349}" = ShadowFixer
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio RecordNow Copy
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BDEE7660-E08C-4824-8577-6CE12F8C3492}_is1" = gPhotoShow v1.6.0
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCEB53A5-A252-4CF3-8602-429AB06BF0AE}" = Terragen
"{CDA31C03-D67C-48DF-BFE9-B0519818341E}" = Digital Element Aurora
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{D76E927F-E292-434B-9661-3858F5D7BF63}" = EPSON PhotoCenter
"{D87D6386-3C2D-4239-9780-3418FB7B0E94}" = Print Lab Series
"{DA53DF31-06F5-11D7-B1E5-0050DA6C326B}" = Extensis PhotoFrame 2.5
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E42BD75A-FC23-4E3F-9F91-2658334C644F}" = Internet Service Offers Launcher
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{EBAE381B-60A6-4863-AA9F-FCAB755BC9E5}" = ScanToWeb
"3D Maker by Lokas Software" = 3D Maker by Lokas Software
"3D Shadow by Lokas Software" = 3D Shadow by Lokas Software
"55mm for Adobe Photoshop" = 55mm for Adobe Photoshop
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Alien Skin Image Doctor" = Alien Skin Image Doctor
"AOL Toolbar" = AOL Toolbar
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"AOL YGP Screensaver" = AOL You've Got Pictures Screensaver
"AOLCoach" = AOL Coach Version 1.0(Build:20040229.1 en)
"AolCoach2_en" = AOL Coach Version 2.0(Build:20041026.5 en)
"Artistic Effects by Lokas Software" = Artistic Effects by Lokas Software
"Blow Up" = Alien Skin Blow Up
"Canon MultiPASS Desktop Manager" = Canon MultiPASS Suite 3.20
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"ColorWasher 2.02b" = ColorWasher 2.02b
"Coupon Printer for Windows2.0" = Coupon Printer for Windows
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"DCE Tools (Adobe Photoshop Plug-ins)_is1" = DCE Tools 1.0
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Dell Game Console" = Dell Game Console
"DreamSuite Bonus" = Uninstall DreamSuite Bonus
"DreamSuite Series2" = DreamSuite Series2
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"Exposure" = Alien Skin Exposure
"EyeCandy5Impact" = Alien Skin Eye Candy 5 Impact
"EyeCandy5Nature" = Alien Skin Eye Candy 5 Nature
"EyeCandy5Textures" = Alien Skin Eye Candy 5 Textures
"Filters Unlimited_is1" = Filters Unlimited 2.0
"FocalBlade" = FocalBlade
"Fractal Stepper_is1" = Fractal Stepper 1.0
"Genesis_V2_PROps_V2.00" = Genesis V2 PROps V2.01
"IcePattern v 1.22. for Adobe Photoshop_is1" = IcePattern 1.22 for Adobe Photoshop
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"KnockOut 2" = KnockOut 2
"Knoll Light Factory 2" = Knoll Light Factory 2
"KPT 6" = KPT 6
"KPT effects" = KPT® effects™
"Light v3.5 for Adobe Photoshop & Compatible Applications" = Light v3.5 for Adobe Photoshop & Compatible Applications
"LightMachine 1.0" = LightMachine 1.0
"LiveReg" = LiveReg (Symantec Corporation)
"LiveUpdate" = LiveUpdate 2.6 (Symantec Corporation)
"McAfee Uninstall Utility" = McAfee Uninstaller
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MSC" = McAfee SecurityCenter
"MSNINST" = MSN
"nik Color Efex Pro 2.0 Complete" = nik Color Efex Pro 2.0 Complete
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PAN Fire 3.1_is1" = PAN Fire 3.1
"PAN Lens Pro III 3.6_is1" = PAN Lens Pro III 3.6
"Panopticum Digitalizer 1.1_is1" = Panopticum Digitalizer 1.1
"Picasa2" = Picasa 2
"Power Retouche Pro" = Power Retouche Pro
"PROSet" = Intel® PRO Network Adapters and Drivers
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer Basic
"Silent Package Run-Time Sample" = EPSON CX4600 Reference Guide
"Snap Art" = Alien Skin Snap Art
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"StreetPlugin" = Learn2 Player (Uninstall Only)
"Trend Micro HouseCall 6.6" = HouseCall 6.6
"Ulead FX Razor 2.0" = Ulead FX Razor 2.0
"Universe" = Universe
"Universe Image Creator Plug-ins" = Universe Image Creator Plug-ins
"ViewpointMediaPlayer" = Viewpoint Media Player
"Vizros Plug-ins 4.1" = Vizros Plug-ins 4.1
"WebCyberCoach_wtrb" = WebCyberCoach 3.2 Dell
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"Wisdom-soft ScreenHunter 5.0 Free" = Wisdom-soft ScreenHunter 5.0 Free
"Xenofex2" = Alien Skin Xenofex 2.0

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1861267-2091798228-1098460282-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"AOL Toolbar" = AOL Toolbar

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/21/2011 12:34:43 AM | Computer Name = LRBENGR | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 11/21/2011 12:34:43 AM | Computer Name = LRBENGR | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 11/21/2011 12:34:43 AM | Computer Name = LRBENGR | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 11/21/2011 12:34:43 AM | Computer Name = LRBENGR | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 11/21/2011 12:34:44 AM | Computer Name = LRBENGR | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 11/21/2011 12:34:44 AM | Computer Name = LRBENGR | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 11/21/2011 12:34:44 AM | Computer Name = LRBENGR | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 11/21/2011 12:34:44 AM | Computer Name = LRBENGR | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 11/21/2011 12:34:44 AM | Computer Name = LRBENGR | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 11/21/2011 12:34:45 AM | Computer Name = LRBENGR | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

[ System Events ]
Error - 1/3/2006 1:25:12 AM | Computer Name = LRBENGR | Source = DCOM | ID = 10010
Description = The server {3A185DDE-E020-4985-A8F2-E27CDC4A0F3A} did not register
with DCOM within the required timeout.

Error - 1/3/2006 1:25:45 AM | Computer Name = LRBENGR | Source = DCOM | ID = 10010
Description = The server {209500FC-6B45-4693-8871-6296C4843751} did not register
with DCOM within the required timeout.

Error - 1/3/2006 1:03:12 AM | Computer Name = LRBENGR | Source = DCOM | ID = 10010
Description = The server {209500FC-6B45-4693-8871-6296C4843751} did not register
with DCOM within the required timeout.

Error - 1/3/2006 1:03:09 AM | Computer Name = LRBENGR | Source = DCOM | ID = 10010
Description = The server {209500FC-6B45-4693-8871-6296C4843751} did not register
with DCOM within the required timeout.

Error - 11/21/2011 1:59:29 AM | Computer Name = LRBENGR | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 1/3/2006 1:11:35 AM | Computer Name = LRBENGR | Source = DCOM | ID = 10010
Description = The server {72C2714F-4478-11D3-B537-00902771A435} did not register
with DCOM within the required timeout.

Error - 1/3/2006 1:05:40 AM | Computer Name = LRBENGR | Source = DCOM | ID = 10010
Description = The server {209500FC-6B45-4693-8871-6296C4843751} did not register
with DCOM within the required timeout.

Error - 11/21/2011 3:23:26 PM | Computer Name = LRBENGR | Source = DCOM | ID = 10010
Description = The server {209500FC-6B45-4693-8871-6296C4843751} did not register
with DCOM within the required timeout.

Error - 11/22/2011 2:31:36 PM | Computer Name = LRBENGR | Source = DCOM | ID = 10010
Description = The server {209500FC-6B45-4693-8871-6296C4843751} did not register
with DCOM within the required timeout.

Error - 11/22/2011 2:31:43 PM | Computer Name = LRBENGR | Source = DCOM | ID = 10010
Description = The server {3A185DDE-E020-4985-A8F2-E27CDC4A0F3A} did not register
with DCOM within the required timeout.


< End of report >


AND GMER:

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-11-23 00:18:11
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD1600JB-75GVC0 rev.08.02D08
Running: 4dgnshqk.exe; Driver: C:\DOCUME~1\LEEBRO~1\LOCALS~1\Temp\awrdapow.sys


—- System - GMER 1.0.15 —-

Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateKey [0xF745FD70]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteKey [0xF745FD84]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xF745FDB0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xF745FE06]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenKey [0xF745FD5C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xF745FD34]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xF745FD48]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwRenameKey [0xF745FD9A]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetSecurityObject [0xF745FDDC]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetValueKey [0xF745FDC6]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0xF745FE30]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xF745FE1C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0xF745FDF0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetSecurityObject

—- Kernel code sections - GMER 1.0.15 —-

PAGE ntoskrnl.exe!ZwUnmapViewOfSection + 3 8057A821 2 Bytes [EE, 76]
init C:\WINDOWS\system32\drivers\senfilt.sys entry point in "init" section [0xB9AA2F80]

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\svchost.exe[288] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00BA0FE5
.text C:\WINDOWS\system32\svchost.exe[288] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00BA0FC3
.text C:\WINDOWS\system32\svchost.exe[288] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00BA0FD4
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BF0FEF
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BF0F5E
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BF0053
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BF0F79
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BF0036
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BF001B
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BF009F
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BF0084
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BF00CB
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BF00BA
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BF0F17
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BF0F9E
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BF0FD4
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BF0F4D
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BF0FAF
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BF0000
.text C:\WINDOWS\system32\svchost.exe[288] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BF0F3C
.text C:\WINDOWS\system32\svchost.exe[288] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00BE002C
.text C:\WINDOWS\system32\svchost.exe[288] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00BE0076
.text C:\WINDOWS\system32\svchost.exe[288] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00BE0011
.text C:\WINDOWS\system32\svchost.exe[288] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00BE0FDB
.text C:\WINDOWS\system32\svchost.exe[288] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00BE0FAF
.text C:\WINDOWS\system32\svchost.exe[288] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00BE0000
.text C:\WINDOWS\system32\svchost.exe[288] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00BE0047
.text C:\WINDOWS\system32\svchost.exe[288] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00BE0FC0
.text C:\WINDOWS\system32\svchost.exe[288] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00BD0FB6
.text C:\WINDOWS\system32\svchost.exe[288] msvcrt.dll!system 77C293C7 5 Bytes JMP 00BD004B
.text C:\WINDOWS\system32\svchost.exe[288] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00BD0029
.text C:\WINDOWS\system32\svchost.exe[288] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00BD000C
.text C:\WINDOWS\system32\svchost.exe[288] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00BD003A
.text C:\WINDOWS\system32\svchost.exe[288] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00BD0FEF
.text C:\WINDOWS\system32\svchost.exe[288] WININET.dll!InternetOpenA 3D95D698 5 Bytes JMP 00BB0FE5
.text C:\WINDOWS\system32\svchost.exe[288] WININET.dll!InternetOpenW 3D95DB11 5 Bytes JMP 00BB000A
.text C:\WINDOWS\system32\svchost.exe[288] WININET.dll!InternetOpenUrlA 3D95F3AC 5 Bytes JMP 00BB0FCA
.text C:\WINDOWS\system32\svchost.exe[288] WININET.dll!InternetOpenUrlW 3D9A6D6F 5 Bytes JMP 00BB0FAF
.text C:\WINDOWS\system32\svchost.exe[288] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00BC0FE5
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[420] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 62419A20 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[420] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 62419AE2 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\system32\svchost.exe[572] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00BA0FEF
.text C:\WINDOWS\system32\svchost.exe[572] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00BA0FC3
.text C:\WINDOWS\system32\svchost.exe[572] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00BA0FD4
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BD000A
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BD0F3A
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BD0F55
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BD0F72
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BD0F83
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BD0F9E
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BD0F0E
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BD0F1F
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BD0EF3
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BD008C
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BD0EE2
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BD002F
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BD0FE5
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BD004A
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BD0FB9
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BD0FD4
.text C:\WINDOWS\system32\svchost.exe[572] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BD0071
.text C:\WINDOWS\system32\svchost.exe[572] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00BC0FC0
.text C:\WINDOWS\system32\svchost.exe[572] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00BC0047
.text C:\WINDOWS\system32\svchost.exe[572] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00BC0FDB
.text C:\WINDOWS\system32\svchost.exe[572] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00BC0011
.text C:\WINDOWS\system32\svchost.exe[572] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00BC0036
.text C:\WINDOWS\system32\svchost.exe[572] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00BC0000
.text C:\WINDOWS\system32\svchost.exe[572] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00BC0F94
.text C:\WINDOWS\system32\svchost.exe[572] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [DC, 88]
.text C:\WINDOWS\system32\svchost.exe[572] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00BC0FA5
.text C:\WINDOWS\system32\svchost.exe[572] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00BB005F
.text C:\WINDOWS\system32\svchost.exe[572] msvcrt.dll!system 77C293C7 5 Bytes JMP 00BB0FD4
.text C:\WINDOWS\system32\svchost.exe[572] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00BB0044
.text C:\WINDOWS\system32\svchost.exe[572] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00BB000C
.text C:\WINDOWS\system32\svchost.exe[572] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00BB0FE5
.text C:\WINDOWS\system32\svchost.exe[572] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00BB001D
.text C:\WINDOWS\system32\services.exe[1128] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 006B0FEF
.text C:\WINDOWS\system32\services.exe[1128] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 006B0FC3
.text C:\WINDOWS\system32\services.exe[1128] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 006B0FDE
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00740000
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00740075
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00740F8A
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00740064
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00740047
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00740FAF
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 007400C8
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 007400B7
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00740F54
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 007400E3
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00740F43
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0074002C
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00740011
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 0074009A
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00740FC0
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00740FD1
.text C:\WINDOWS\system32\services.exe[1128] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00740F65
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 006E0FC3
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 006E0F6B
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 006E0FD4
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 006E000A
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 006E0F7C
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 006E0FE5
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 006E0F8D
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [8E, 88]
.text C:\WINDOWS\system32\services.exe[1128] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 006E0FA8
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 006D0FA6
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!system 77C293C7 5 Bytes JMP 006D0027
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 006D0FB7
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!_open 77C2F566 5 Bytes JMP 006D0FE3
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 006D0016
.text C:\WINDOWS\system32\services.exe[1128] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 006D0FD2
.text C:\WINDOWS\system32\services.exe[1128] WS2_32.dll!socket 71AB4211 5 Bytes JMP 006C0000
.text C:\WINDOWS\system32\lsass.exe[1140] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00DB0FEF
.text C:\WINDOWS\system32\lsass.exe[1140] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00DB000A
.text C:\WINDOWS\system32\lsass.exe[1140] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00DB0FD4
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00E90000
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00E9007B
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00E90F7C
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00E90060
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00E90F97
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00E90FB9
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00E900A2
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00E90F50
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E900DF
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E900C4
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00E900FA
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00E90FA8
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00E90FE5
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00E90F6B
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00E90FCA
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00E9001B
.text C:\WINDOWS\system32\lsass.exe[1140] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00E900B3
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00DE0022
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00DE0058
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00DE0FD1
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00DE0011
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00DE0F9B
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00DE0000
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00DE0FB6
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [FE, 88]
.text C:\WINDOWS\system32\lsass.exe[1140] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00DE0033
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00DD003D
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!system 77C293C7 5 Bytes JMP 00DD0022
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00DD0FCD
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00DD0FEF
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00DD0FBC
.text C:\WINDOWS\system32\lsass.exe[1140] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00DD0FDE
.text C:\WINDOWS\system32\lsass.exe[1140] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00DC0FEF
.text C:\WINDOWS\system32\svchost.exe[1304] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00FD0000
.text C:\WINDOWS\system32\svchost.exe[1304] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00FD0FCA
.text C:\WINDOWS\system32\svchost.exe[1304] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00FD0FE5
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02420000
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02420078
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02420F83
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02420051
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02420F94
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02420FAF
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 024200AB
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 0242009A
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02420F1C
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 02420F37
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02420F0B
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02420036
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02420011
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02420089
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02420FC0
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02420FDB
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 02420F48
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 02410FDB
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 02410FA5
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0241002C
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 0241001B
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 02410FB6
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 0241000A
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 02410058
.text C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0241003D
.text C:\WINDOWS\system32\svchost.exe[1304] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00FF0FA6
.text C:\WINDOWS\system32\svchost.exe[1304] msvcrt.dll!system 77C293C7 5 Bytes JMP 00FF0FB7
.text C:\WINDOWS\system32\svchost.exe[1304] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00FF0FC8
.text C:\WINDOWS\system32\svchost.exe[1304] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00FF0FEF
.text C:\WINDOWS\system32\svchost.exe[1304] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00FF0027
.text C:\WINDOWS\system32\svchost.exe[1304] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00FF000C
.text C:\WINDOWS\system32\svchost.exe[1304] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FE0FEF
.text C:\WINDOWS\system32\svchost.exe[1368] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00AF0FEF
.text C:\WINDOWS\system32\svchost.exe[1368] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00AF0FD4
.text C:\WINDOWS\system32\svchost.exe[1368] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00AF000A
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C70FE5
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C70F46
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C70F57
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C70F72
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C70F83
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C70FA8
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C70F2B
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C70067
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C70EFF
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C70F1A
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00C700B3
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00C7002F
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00C70FD4
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00C70056
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00C70014
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00C70FC3
.text C:\WINDOWS\system32\svchost.exe[1368] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00C70098
.text C:\WINDOWS\system32\svchost.exe[1368] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00B20025
.text C:\WINDOWS\system32\svchost.exe[1368] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00B2005B
.text C:\WINDOWS\system32\svchost.exe[1368] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00B20014
.text C:\WINDOWS\system32\svchost.exe[1368] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00B20FDE
.text C:\WINDOWS\system32\svchost.exe[1368] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00B20040
.text C:\WINDOWS\system32\svchost.exe[1368] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00B20FEF
.text C:\WINDOWS\system32\svchost.exe[1368] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00B20FA8
.text C:\WINDOWS\system32\svchost.exe[1368] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [D2, 88]
.text C:\WINDOWS\system32\svchost.exe[1368] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00B20FC3
.text C:\WINDOWS\system32\svchost.exe[1368] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00B10FBE
.text C:\WINDOWS\system32\svchost.exe[1368] msvcrt.dll!system 77C293C7 5 Bytes JMP 00B10049
.text C:\WINDOWS\system32\svchost.exe[1368] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00B1002E
.text C:\WINDOWS\system32\svchost.exe[1368] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00B10000
.text C:\WINDOWS\system32\svchost.exe[1368] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00B10FD9
.text C:\WINDOWS\system32\svchost.exe[1368] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00B10011
.text C:\WINDOWS\system32\svchost.exe[1368] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00B0000A
.text C:\WINDOWS\System32\svchost.exe[1408] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 026F0FEF
.text C:\WINDOWS\System32\svchost.exe[1408] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 026F0FD4
.text C:\WINDOWS\System32\svchost.exe[1408] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 026F0014
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02F7000A
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02F700C9
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02F700AE
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02F70087
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02F70076
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02F70FDB
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02F70F94
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02F700DA
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02F70F68
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 02F700F7
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02F7011C
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02F70FCA
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02F7001B
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02F70FAF
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02F70047
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02F7002C
.text C:\WINDOWS\System32\svchost.exe[1408] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 02F70F83
.text C:\WINDOWS\System32\svchost.exe[1408] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 02F6001E
.text C:\WINDOWS\System32\svchost.exe[1408] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 02F6006F
.text C:\WINDOWS\System32\svchost.exe[1408] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 02F60FCD
.text C:\WINDOWS\System32\svchost.exe[1408] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 02F60FDE
.text C:\WINDOWS\System32\svchost.exe[1408] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 02F60054
.text C:\WINDOWS\System32\svchost.exe[1408] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 02F60FEF
.text C:\WINDOWS\System32\svchost.exe[1408] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 02F6002F
.text C:\WINDOWS\System32\svchost.exe[1408] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 02F60FB2
.text C:\WINDOWS\System32\svchost.exe[1408] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 02F50FB2
.text C:\WINDOWS\System32\svchost.exe[1408] msvcrt.dll!system 77C293C7 5 Bytes JMP 02F5003D
.text C:\WINDOWS\System32\svchost.exe[1408] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 02F50FDE
.text C:\WINDOWS\System32\svchost.exe[1408] msvcrt.dll!_open 77C2F566 5 Bytes JMP 02F50FEF
.text C:\WINDOWS\System32\svchost.exe[1408] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 02F50FCD
.text C:\WINDOWS\System32\svchost.exe[1408] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 02F50018
.text C:\WINDOWS\System32\svchost.exe[1408] WS2_32.dll!socket 71AB4211 5 Bytes JMP 02F40FEF
.text C:\WINDOWS\System32\svchost.exe[1408] WININET.dll!InternetOpenA 3D95D698 5 Bytes JMP 02740FEF
.text C:\WINDOWS\System32\svchost.exe[1408] WININET.dll!InternetOpenW 3D95DB11 5 Bytes JMP 0274000A
.text C:\WINDOWS\System32\svchost.exe[1408] WININET.dll!InternetOpenUrlA 3D95F3AC 5 Bytes JMP 02740025
.text C:\WINDOWS\System32\svchost.exe[1408] WININET.dll!InternetOpenUrlW 3D9A6D6F 5 Bytes JMP 02740036
.text C:\WINDOWS\system32\svchost.exe[1456] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00740FE5
.text C:\WINDOWS\system32\svchost.exe[1456] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00740FCA
.text C:\WINDOWS\system32\svchost.exe[1456] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00740000
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00780FEF
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00780075
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00780064
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00780F8A
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00780047
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00780025
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 007800BE
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 007800A1
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 007800FB
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 007800E0
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00780F3D
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00780036
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00780FD4
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00780090
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00780014
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00780FB9
.text C:\WINDOWS\system32\svchost.exe[1456] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 007800CF
.text C:\WINDOWS\system32\svchost.exe[1456] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00770025
.text C:\WINDOWS\system32\svchost.exe[1456] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00770F8D
.text C:\WINDOWS\system32\svchost.exe[1456] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00770FD4
.text C:\WINDOWS\system32\svchost.exe[1456] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00770FE5
.text C:\WINDOWS\system32\svchost.exe[1456] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 0077004A
.text C:\WINDOWS\system32\svchost.exe[1456] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00770000
.text C:\WINDOWS\system32\svchost.exe[1456] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00770F9E
.text C:\WINDOWS\system32\svchost.exe[1456] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [97, 88]
.text C:\WINDOWS\system32\svchost.exe[1456] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00770FAF
.text C:\WINDOWS\system32\svchost.exe[1456] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0076003D
.text C:\WINDOWS\system32\svchost.exe[1456] msvcrt.dll!system 77C293C7 5 Bytes JMP 00760FB2
.text C:\WINDOWS\system32\svchost.exe[1456] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00760FCD
.text C:\WINDOWS\system32\svchost.exe[1456] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00760000
.text C:\WINDOWS\system32\svchost.exe[1456] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0076002C
.text C:\WINDOWS\system32\svchost.exe[1456] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00760011
.text C:\WINDOWS\system32\svchost.exe[1456] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00750000
.text C:\WINDOWS\system32\svchost.exe[1520] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00B20FE5
.text C:\WINDOWS\system32\svchost.exe[1520] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00B20000
.text C:\WINDOWS\system32\svchost.exe[1520] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B20FD4
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00B60000
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00B6007D
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00B60F92
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00B6006C
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00B60051
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00B6002F
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00B600B5
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00B60F6D
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00B600F2
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00B600E1
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00B6010D
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00B60040
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00B60FE5
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00B6008E
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00B60FC3
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00B60FD4
.text C:\WINDOWS\system32\svchost.exe[1520] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00B600C6
.text C:\WINDOWS\system32\svchost.exe[1520] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00B5001B
.text C:\WINDOWS\system32\svchost.exe[1520] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00B50040
.text C:\WINDOWS\system32\svchost.exe[1520] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00B5000A
.text C:\WINDOWS\system32\svchost.exe[1520] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00B50FD4
.text C:\WINDOWS\system32\svchost.exe[1520] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00B50F79
.text C:\WINDOWS\system32\svchost.exe[1520] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00B50FEF
.text C:\WINDOWS\system32\svchost.exe[1520] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00B50F94
.text C:\WINDOWS\system32\svchost.exe[1520] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [D5, 88] {AAD 0x88}
.text C:\WINDOWS\system32\svchost.exe[1520] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00B50FAF
.text C:\WINDOWS\system32\svchost.exe[1520] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00B40F8B
.text C:\WINDOWS\system32\svchost.exe[1520] msvcrt.dll!system 77C293C7 5 Bytes JMP 00B40F9C
.text C:\WINDOWS\system32\svchost.exe[1520] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00B40FC8
.text C:\WINDOWS\system32\svchost.exe[1520] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00B40FE3
.text C:\WINDOWS\system32\svchost.exe[1520] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00B40FAD
.text C:\WINDOWS\system32\svchost.exe[1520] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00B40000
.text C:\WINDOWS\system32\svchost.exe[1520] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00B30000
.text C:\WINDOWS\Explorer.EXE[1796] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00D30FE5
.text C:\WINDOWS\Explorer.EXE[1796] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00D30FC3
.text C:\WINDOWS\Explorer.EXE[1796] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00D30FD4
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00D90000
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00D90F92
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00D90091
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00D90080
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00D9006F
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00D90FD4
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00D900B3
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00D900A2
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D900FA
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D900E9
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00D9011F
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00D90FC3
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00D9001B
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00D90F81
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00D90FE5
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00D90036
.text C:\WINDOWS\Explorer.EXE[1796] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00D900C4
.text C:\WINDOWS\Explorer.EXE[1796] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00D80FC3
.text C:\WINDOWS\Explorer.EXE[1796] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00D8006F
.text C:\WINDOWS\Explorer.EXE[1796] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00D80FDE
.text C:\WINDOWS\Explorer.EXE[1796] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00D80FEF
.text C:\WINDOWS\Explorer.EXE[1796] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00D8004A
.text C:\WINDOWS\Explorer.EXE[1796] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00D80000
.text C:\WINDOWS\Explorer.EXE[1796] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00D80FA8
.text C:\WINDOWS\Explorer.EXE[1796] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [F8, 88]
.text C:\WINDOWS\Explorer.EXE[1796] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00D8002F
.text C:\WINDOWS\Explorer.EXE[1796] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00D60055
.text C:\WINDOWS\Explorer.EXE[1796] msvcrt.dll!system 77C293C7 5 Bytes JMP 00D60FCA
.text C:\WINDOWS\Explorer.EXE[1796] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00D6003A
.text C:\WINDOWS\Explorer.EXE[1796] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00D60000
.text C:\WINDOWS\Explorer.EXE[1796] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00D60FE5
.text C:\WINDOWS\Explorer.EXE[1796] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00D6001D
.text C:\WINDOWS\Explorer.EXE[1796] WININET.dll!InternetOpenA 3D95D698 5 Bytes JMP 00D4000A
.text C:\WINDOWS\Explorer.EXE[1796] WININET.dll!InternetOpenW 3D95DB11 5 Bytes JMP 00D4001B
.text C:\WINDOWS\Explorer.EXE[1796] WININET.dll!InternetOpenUrlA 3D95F3AC 5 Bytes JMP 00D4002C
.text C:\WINDOWS\Explorer.EXE[1796] WININET.dll!InternetOpenUrlW 3D9A6D6F 5 Bytes JMP 00D40FDB
.text C:\WINDOWS\Explorer.EXE[1796] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00D5000A

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Ntfs \Ntfs SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \Driver\Tcpip \Device\Ip mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)
AttachedDevice \Driver\Tcpip \Device\Udp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat SymSnap.sys (StorageCraft Volume Snap-Shot/StorageCraft)

Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

—- EOF - GMER 1.0.15 —-


Thank You Blottedisk!
Thanks for the logs.

You don't seem to be infected, but we have some work to do. Please follow these steps:

Step 1 | Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    [2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [2007/10/23 12:39:59 | 000,000,031 | -H– | C] () – C:\WINDOWS\uccspecc.sys
    
    :Commands
    [purity]
    [EmptyFlash]
    [emptytemp]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered, reboot when it is done.
  • It will produce a log for you on reboot, please post that log in your next reply.

Step 2 | Please go to the following site to scan a file: Virus Total

  • Click on Browse, and upload the following file for analysis:

    • C:\Program Files\CouponAlert_2pEI\Installr\2.bin\NP2pEISB.dll
      C:\WINDOWS\System32\E51DD59C1E.sys
      C:\WINDOWS\System32\1E9CD51DE5.sys
      C:\WINDOWS\System32\mlfcache.dat
  • Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
  • If it says already scanned – click "reanalyze now"
  • Please post the results in your next reply.
Sorry Blottedisk, I won't have an internet connection fort a little while (visiting with relatives for awhile, came up suddenly). Can you elaborate on why I have to do these fixes? How bad is the problem (can it be ignored for a little while or is it extreme)? I am away from the computer with the problem for quite some time . . . . . you might not hear back from me for another week or more! Let me know if you are able to stick with this or if I neeed to start over when I get back to the problem computer!
Hi schlackeye, thanks for the update :)

The fix is related to coupons.com adware - more info: here

It's not an important infection (in fact some believe it's not an infection at all). You have Symantec antivirus, which is doing a great job. I don't think you are infected with any other malware.

If you want us to take a look at the machine in a later time, I would suggest you to start over, as fresh logs are needed to work with. So, whenever you are back, you can open a new thread.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI