I did the scans that you asked me to do but when I redid the OTL scan I did not see a log for OTL extras.txt. The only log that shows up is the one that I am posting. I looked on the program and didn't see anywhere that I could get the log from either.
OTL logfile created on: 11/5/2011 12:55:18 AM - Run 5
OTL by OldTimer - Version 3.1.26.0 Folder = C:\Users\cliff\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 42.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 56.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 110.32 Gb Total Space | 52.96 Gb Free Space | 48.01% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HOME
Current User Name: cliff
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ========== PRC - [2011/10/18 09:40:25 | 00,140,952 | ---- | M] (Google Inc.) -- C:\Users\cliff\AppData\Local\Google\Update\1.3.21.79\GoogleCrashHandler.exe
PRC - [2011/10/06 16:41:16 | 00,166,024 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
PRC - [2011/09/16 18:38:10 | 01,318,552 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2011/08/22 10:01:00 | 00,593,920 | ---- | M] () -- C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
PRC - [2011/08/19 15:59:30 | 00,148,520 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\mfevtps.exe
PRC - [2011/08/19 15:55:34 | 00,160,344 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
PRC - [2011/08/12 17:13:26 | 00,087,040 | ---- | M] () -- C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
PRC - [2011/06/16 07:55:12 | 00,079,160 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
PRC - [2011/06/06 12:55:28 | 00,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/04/08 12:59:52 | 00,254,696 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe
PRC - [2011/03/28 20:31:16 | 00,193,920 | ---- | M] (Microsoft Corp.) -- C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2011/03/28 20:31:14 | 01,713,536 | ---- | M] (Microsoft Corp.) -- C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2011/02/24 21:08:34 | 00,566,688 | ---- | M] (Affinegy, Inc.) -- C:\Program Files\Belkin\Router Setup and Monitor\BelkinService.exe
PRC - [2011/02/24 21:08:32 | 07,034,272 | ---- | M] (Affinegy, Inc.) -- C:\Program Files\Belkin\Router Setup and Monitor\BelkinSetup.exe
PRC - [2011/02/24 21:08:32 | 01,770,400 | ---- | M] (Affinegy, Inc.) -- C:\Program Files\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
PRC - [2011/01/27 18:28:14 | 00,214,904 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
PRC - [2010/12/15 23:46:06 | 00,151,056 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\Core\mchost.exe
PRC - [2010/10/27 20:17:52 | 00,207,424 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2010/09/22 12:03:38 | 00,249,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2010/08/25 11:27:44 | 00,309,824 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
PRC - [2010/04/13 21:11:16 | 03,045,176 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Online Backup\MOBKstat.exe
PRC - [2010/04/13 21:11:14 | 00,229,688 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Online Backup\MOBKbackup.exe
PRC - [2010/03/18 11:19:26 | 00,113,152 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2010/03/17 14:31:58 | 00,106,496 | R--- | M] (SweetIM Technologies Ltd.) -- C:\Program Files\SweetIM\Messenger\SweetIM.exe
PRC - [2010/01/25 21:29:04 | 00,547,328 | ---- | M] (OldTimer Tools) -- C:\Users\cliff\Downloads\OTL.exe
PRC - [2010/01/15 07:49:20 | 00,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2009/12/07 19:29:44 | 00,055,016 | ---- | M] (Xobni Corporation) -- C:\Program Files\Xobni\XobniService.exe
PRC - [2009/04/11 01:27:36 | 02,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/03/20 07:36:58 | 00,210,216 | ---- | M] (Synaptics Incorporated) -- C:\Program Files\Synaptics\SynTP\SynToshiba.exe
PRC - [2009/03/20 07:36:38 | 01,451,304 | ---- | M] (Synaptics Incorporated) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2009/03/20 07:36:38 | 00,103,720 | ---- | M] (Synaptics Incorporated) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
PRC - [2008/11/09 15:48:14 | 00,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/10/25 11:44:34 | 00,031,072 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
PRC - [2008/02/21 17:02:53 | 00,238,968 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PRC - [2008/01/29 21:51:52 | 04,911,104 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2008/01/22 16:25:26 | 00,712,704 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
PRC - [2008/01/21 18:54:46 | 00,083,312 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
PRC - [2008/01/20 21:25:33 | 00,202,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnscfg.exe
PRC - [2008/01/20 21:23:32 | 01,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2008/01/17 18:27:52 | 00,431,456 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
PRC - [2008/01/17 18:27:34 | 00,431,456 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
PRC - [2008/01/09 17:02:08 | 01,056,768 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
PRC - [2007/12/25 16:07:14 | 00,040,960 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
PRC - [2007/12/25 16:06:52 | 00,405,504 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
PRC - [2007/12/03 19:03:52 | 00,126,976 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\SMARTLogService\TosIPCSrv.exe
PRC - [2007/11/21 20:23:32 | 00,129,632 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\TODDSrv.exe
PRC - [2007/10/23 19:27:16 | 00,066,928 | ---- | M] () -- c:\Toshiba\IVP\swupdate\swupdtmr.exe
PRC - [2007/09/28 19:05:16 | 00,128,360 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
PRC - [2007/09/20 12:58:48 | 00,252,440 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxsrvc.exe
PRC - [2007/09/20 12:58:44 | 00,129,560 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxpers.exe
PRC - [2007/09/20 12:58:34 | 00,154,136 | ---- | M] (Intel Corporation) -- C:\Windows\System32\hkcmd.exe
PRC - [2007/06/15 23:01:58 | 00,448,080 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\SmoothView\SmoothView.exe
PRC - [2007/01/25 21:47:50 | 00,136,816 | ---- | M] () -- C:\Toshiba\IVP\ISM\pinger.exe
PRC - [2006/11/06 20:14:44 | 00,034,352 | ---- | M] () -- C:\Program Files\Toshiba\Utilities\KeNotify.exe
PRC - [2006/10/05 15:10:12 | 00,009,216 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe
PRC - [2006/08/23 19:39:48 | 00,049,152 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
========== Modules (SafeList) ========== MOD - [2011/08/11 16:37:26 | 00,018,176 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\sahook.dll
MOD - [2010/08/31 10:43:52 | 01,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
MOD - [2010/01/25 21:29:04 | 00,547,328 | ---- | M] (OldTimer Tools) -- C:\Users\cliff\Downloads\OTL.exe
========== Win32 Services (SafeList) ========== SRV - [2011/10/06 16:41:16 | 00,166,024 | ---- | M] () [Unknown | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
SRV - [2011/08/31 17:00:48 | 00,366,152 | ---- | M] (Malwarebytes Corporation) [Disabled | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/08/19 15:59:30 | 00,148,520 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Windows\System32\mfevtps.exe -- (mfevtp)
SRV - [2011/08/19 15:55:34 | 00,160,344 | ---- | M] () [Unknown | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire)
SRV - [2011/08/12 17:13:26 | 00,087,040 | ---- | M] () [Auto | Running] -- C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe -- (PassThru Service)
SRV - [2011/06/06 12:55:28 | 00,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/05/13 15:27:02 | 01,492,840 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2011/03/28 20:31:14 | 01,713,536 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2011/03/17 16:38:42 | 00,361,712 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV - [2011/02/24 21:08:34 | 00,566,688 | ---- | M] (Affinegy, Inc.) [Auto | Running] -- C:\Program Files\Belkin\Router Setup and Monitor\BelkinService.exe -- (AffinegyService)
SRV - [2011/02/22 08:33:09 | 00,797,696 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2011/01/27 18:28:14 | 00,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (MSK80Service)
SRV - [2011/01/27 18:28:14 | 00,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McProxy)
SRV - [2011/01/27 18:28:14 | 00,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNASvc)
SRV - [2011/01/27 18:28:14 | 00,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McNaiAnn)
SRV - [2011/01/27 18:28:14 | 00,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (mcmscsvc)
SRV - [2011/01/27 18:28:14 | 00,214,904 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McMPFSvc)
SRV - [2011/01/27 18:28:14 | 00,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McAfee SiteAdvisor Service)
SRV - [2010/09/22 16:33:04 | 00,051,040 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2010/09/22 12:03:38 | 00,249,136 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
SRV - [2010/04/13 21:11:14 | 00,229,688 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee Online Backup\MOBKbackup.exe -- (MOBKbackup)
SRV - [2010/03/18 13:16:28 | 00,753,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
SRV - [2010/03/18 13:16:28 | 00,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/03/18 11:19:26 | 00,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2010/02/04 19:24:14 | 00,135,664 | ---- | M] (Google Inc.) [On_Demand | Stopped] -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdatem) Google Update Service (gupdatem)
SRV - [2010/02/04 19:24:14 | 00,135,664 | ---- | M] (Google Inc.) [Auto | Stopped] -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate) Google Update Service (gupdate)
SRV - [2010/01/15 07:49:20 | 00,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2009/12/07 19:29:44 | 00,055,016 | ---- | M] (Xobni Corporation) [Auto | Running] -- C:\Program Files\Xobni\XobniService.exe -- (XobniService)
SRV - [2009/04/15 22:20:30 | 00,182,768 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc)
SRV - [2008/11/15 00:25:54 | 00,029,744 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe -- (GoogleDesktopManager-061008-081103)
SRV - [2008/11/09 15:48:14 | 00,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/11/04 01:06:28 | 00,441,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2008/10/25 11:44:08 | 00,065,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service)
SRV - [2008/09/05 11:52:32 | 03,220,856 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE -- (LiveUpdate)
SRV - [2008/05/05 17:25:46 | 00,165,416 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2008/02/21 17:02:53 | 00,238,968 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe -- (Automatic LiveUpdate Scheduler)
SRV - [2008/01/21 18:54:46 | 00,083,312 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe -- (TNaviSrv)
SRV - [2008/01/20 21:23:32 | 00,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008/01/17 18:27:34 | 00,431,456 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2007/12/25 16:07:14 | 00,040,960 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
SRV - [2007/12/03 19:03:52 | 00,126,976 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe -- (TOSHIBA SMART Log Service)
SRV - [2007/11/21 20:23:32 | 00,129,632 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\System32\TODDSrv.exe -- (TODDSrv)
SRV - [2007/10/30 02:35:40 | 00,937,984 | ---- | M] (Atheros Communications, Inc.) [On_Demand | Stopped] -- C:\Program Files\Jumpstart\jswpsapi.exe -- (jswpsapi)
SRV - [2007/10/23 19:27:16 | 00,066,928 | ---- | M] () [Auto | Running] -- c:\Toshiba\IVP\swupdate\swupdtmr.exe -- (Swupdtmr)
SRV - [2007/09/28 19:05:16 | 00,128,360 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service)
SRV - [2007/01/25 21:47:50 | 00,136,816 | ---- | M] () [Auto | Running] -- C:\Toshiba\IVP\ISM\pinger.exe -- (pinger)
SRV - [2006/11/02 07:35:29 | 00,013,312 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\ehome\ehstart.dll -- (ehstart)
SRV - [2006/10/26 17:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2006/10/05 15:10:12 | 00,009,216 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
SRV - [2006/08/23 19:39:48 | 00,049,152 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)
SRV - [2004/10/22 04:24:18 | 00,073,728 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com/IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://home.sweetim.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
http://us.rd.yahoo.c...rch/search.htmlIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com/?fr=fp-yie8IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {b843a48a-b70f-45cd-a15a-6c2b30c2c11e} - C:\Program Files\Gamers Unite! Snag Bar\Helper.dll ()
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn9\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.defaultthis.engineName: "Mafia Mofo Tools Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "
http://search.condui...={searchTerms}"FF - prefs.js..browser.search.selectedEngine: "Secure Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.yahoo.com"
FF - prefs.js..keyword.URL: "
http://ws.infospace...._id=62781&qkw="FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\eMusic Download Manager\Extensions\\Components: C:\Program Files\eMusic Download Manager\xulrunner\components [2010/02/15 20:19:33 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\eMusic Download Manager\Extensions\\Plugins: C:\Program Files\eMusic Download Manager\xulrunner\plugins [2011/09/15 10:40:03 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B728AB94-9BC7-49b7-B76A-422BB31B2FD0}: C:\Program Files\ArcSoft\Media Converter for Philips\Internet Video Downloader\Plugin_FireFox [2009/11/27 16:32:14 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2011/10/31 19:09:15 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2011/11/04 23:33:43 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/10 12:17:09 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/15 10:40:04 | 00,000,000 | ---D | M]
[2011/04/19 09:13:10 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\mozilla\Extensions
[2009/10/06 18:24:08 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\mozilla\Extensions\
[email protected][2009/03/22 18:59:20 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\mozilla\Extensions\
[email protected][2008/12/24 20:24:42 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\mozilla\Firefox\extensions
[2008/12/24 20:24:42 | 00,000,000 | ---D | M] (No name found) -- C:\Users\cliff\AppData\Roaming\mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2011/11/04 00:50:29 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\mozilla\Firefox\Profiles\hrl7wxku.default\extensions
[2011/11/03 08:26:32 | 00,000,000 | ---D | M] (Mafia Mofo Tools Community Toolbar) -- C:\Users\cliff\AppData\Roaming\mozilla\Firefox\Profiles\hrl7wxku.default\extensions\{60e2adb1-527c-4b38-becd-70dc757b57ca}
[2011/11/03 08:26:37 | 00,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\cliff\AppData\Roaming\mozilla\Firefox\Profiles\hrl7wxku.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/04/19 10:44:08 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\mozilla\Firefox\Profiles\hrl7wxku.default\extensions\
[email protected][2011/11/04 00:50:29 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\mozilla\Firefox\Profiles\hrl7wxku.default\extensions\staged
[2011/06/19 13:04:44 | 00,000,935 | ---- | M] () -- C:\Users\cliff\AppData\Roaming\Mozilla\FireFox\Profiles\hrl7wxku.default\searchplugins\conduit.xml
[2011/05/11 12:16:12 | 00,001,742 | ---- | M] () -- C:\Users\cliff\AppData\Roaming\Mozilla\FireFox\Profiles\hrl7wxku.default\searchplugins\search-the-web.xml
[2011/06/14 18:24:21 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2011/04/19 09:13:26 | 00,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/05/20 18:02:25 | 00,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/06 17:31:44 | 00,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/22 01:35:00 | 00,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/23 19:45:56 | 00,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/02 11:25:47 | 00,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/06/14 18:24:22 | 00,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/04/30 12:55:41 | 00,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/04/14 14:01:38 | 00,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Mozilla Firefox\components\Scriptff.dll
[2011/05/04 04:52:23 | 00,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/01 03:00:00 | 00,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2011/11/03 08:27:11 | 00,002,024 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\McSiteAdvisor.xml
O1 HOSTS File: ([2006/09/18 16:41:30 | 00,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn9\yt.dll (Yahoo! Inc.)
O2 - BHO: (IEPlugin Class) - {11222041-111B-46E3-BD29-EFB2449479B1} - C:\Program Files\ArcSoft\Media Converter for Philips\Internet Video Downloader\ArcURLRecord.dll (ArcSoft, Inc.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (Gamers Unite! Snag Bar BHO) - {26A7CA19-7D58-411D-B2DA-F1B0324CBFFC} - C:\Program Files\Gamers Unite! Snag Bar\Toolbar.dll ()
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll File not found
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20111010183406.dll (McAfee, Inc.)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn9\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Gamers Unite! Snag Bar) - {25515A79-C1C7-4B97-97F8-31A711694487} - C:\Program Files\Gamers Unite! Snag Bar\Toolbar.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn9\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Gamers Unite! Snag Bar) - {25515A79-C1C7-4B97-97F8-31A711694487} - C:\Program Files\Gamers Unite! Snag Bar\Toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Zynga Toolbar) - {7B13EC3E-999A-4B70-B9CB-2617B8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
O4 - HKLM..\Run: [HWSetup] File not found
O4 - HKLM..\Run: [IgfxTray] C:\Windows\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [InstaLAN] C:\Program Files\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe (Affinegy, Inc.)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe ( TOSHIBA CORPORATION)
O4 - HKLM..\Run: [KeNotify] C:\Program Files\Toshiba\Utilities\KeNotify.exe ()
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [Persistence] C:\Windows\System32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Skytel] C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA)
O4 - HKLM..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DW6] C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe File not found
O4 - HKCU..\Run: [Google Update] C:\Users\cliff\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc.)
O4 - HKCU..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe File not found
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Spotify] C:\Users\cliff\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - Startup: C:\Users\cliff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Advanced Registry Optimizer.lnk = C:\Program Files\Advanced Registry Optimizer\ARO.exe File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089}
http://office.micros...n/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\cliff\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\cliff\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{b1e83d98-9545-11dd-934b-001eec3a14ac}\Shell - "" = AutoRun
O33 - MountPoints2\{b1e83d98-9545-11dd-934b-001eec3a14ac}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk /p \??\C:) - File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
========== Files/Folders - Created Within 14 Days ========== [2011/11/04 23:31:43 | 00,100,864 | ---- | C] (GMER) -- C:\fgtdipow.sys
[2011/11/04 23:25:53 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{2B0C3DA1-57EB-4ADE-B39B-5D707333EC3A}
[2011/11/04 03:50:07 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{62620A39-3EB0-443E-921E-3F35D0CD4DB7}
[2011/11/04 03:49:54 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{4B86D02A-7760-4F66-A617-A2ADCB849B67}
[2011/11/03 14:30:35 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\Spotify
[2011/11/03 14:30:19 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Roaming\Spotify
[2011/11/03 07:02:34 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{52A67EB2-5010-4FE9-93B5-D766C64FC392}
[2011/11/03 07:02:10 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{B0D8F4CE-B807-41AC-AA63-3FB205BC4561}
[2011/11/02 18:39:30 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{A5342B85-5637-44D2-A043-6B89A78F34FC}
[2011/11/02 09:27:35 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{CF392AB0-F462-4460-A69B-42E613E982D4}
[2011/11/01 09:23:34 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{67069923-6A2D-436A-BDE7-8DA846A7F68F}
[2011/11/01 09:23:00 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{2B0DC11F-6C94-4E88-B5DF-7683C226911A}
[2011/10/31 18:56:35 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{8408C5CF-0A3A-493E-82D0-3DC2B0252B08}
[2011/10/30 04:54:04 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{3AF8CC55-3DCD-4877-98AF-8D65694C8CCB}
[2011/10/30 04:53:40 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{2CFB834B-9896-47DC-84E6-A96500905940}
[2011/10/29 09:28:04 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{A89FBDE9-211E-48BA-8658-705A2961D784}
[2011/10/29 09:27:42 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{7BA5AC1E-C1BD-4D7C-B4B8-794E11FFD5F3}
[2011/10/28 18:28:16 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{11D129B6-7BDA-446E-A2F0-BE105DC048A4}
[2011/10/28 18:27:42 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{A5CE609A-2C72-40E0-8B43-F1E11F163E9E}
[2011/10/28 08:31:55 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{DC148965-B01B-4530-BD15-233E6E7EE067}
[2011/10/27 21:29:57 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{5DEADAE7-1752-438C-956B-AD932BD54093}
[2011/10/27 09:27:32 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{136665D5-3438-4FE3-A392-673D1FB2B55D}
[2011/10/27 09:27:03 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{3EA9B427-5534-4E39-82BA-3F20495B2AEE}
[2011/10/26 09:56:22 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{1B8DE92F-72BB-4C40-8A8F-BC7FE057468D}
[2011/10/26 09:55:39 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{CCF2A741-EBBD-4EE0-8380-28471A39A375}
[2011/10/25 18:19:38 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{F03CB791-F3BC-4734-8C67-A6C771405282}
[2011/10/25 18:19:03 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{BBE6B90E-C13E-43F8-957D-47EEDE3E5F8F}
[2011/10/25 09:49:14 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{0BC65151-E65A-4BE6-AE93-B47C2A80BA01}
[2011/10/25 09:49:02 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{6AE80744-83DD-40F8-A3BF-9083FAA11BA5}
[2011/10/24 19:37:24 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{B5EA4D88-0678-4197-860D-5C7B68D3B43F}
[2011/10/23 15:28:14 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{69A3DBA5-A4A3-42FD-BAB8-E7EA54D6CD4E}
[2011/10/22 09:41:47 | 00,000,000 | ---D | C] -- C:\Users\cliff\AppData\Local\{985BA710-D0E6-4FC8-97D1-DB74319B9CDB}
[2011/10/18 15:12:04 | 00,000,000 | ---D | C] -- C:\Users\cliff\FrostWire
[2011/10/18 15:11:57 | 00,000,000 | ---D | C] -- C:\Users\cliff\.frostwire5
[2011/10/13 11:54:04 | 00,000,000 | ---D | C] -- C:\ProgramData\Affinegy
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\Users\cliff\AppData\Local\*.tmp files -> C:\Users\cliff\AppData\Local\*.tmp -> ]
========== Files - Modified Within 14 Days ========== [2011/11/05 00:55:17 | 06,553,600 | -HS- | M] () -- C:\Users\cliff\ntuser.dat
[2011/11/05 00:45:00 | 00,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2883493492-1982095606-3702794389-1000UA.job
[2011/11/05 00:04:31 | 00,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/04 23:55:06 | 00,044,544 | ---- | M] (Absolute Software Corp.) -- C:\Windows\System32\agremove.exe
[2011/11/04 23:31:44 | 00,001,702 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Internet Security.lnk
[2011/11/04 23:31:43 | 00,100,864 | ---- | M] (GMER) -- C:\fgtdipow.sys
[2011/11/04 23:24:33 | 00,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/04 23:24:27 | 00,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/04 23:23:54 | 00,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/04 23:22:55 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2011/11/04 23:22:50 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/11/04 23:22:46 | 21,374,48448 | -HS- | M] () -- C:\hiberfil.sys
[2011/11/04 23:22:05 | 00,524,288 | -HS- | M] () -- C:\Users\cliff\ntuser.dat{98f93032-5b56-11de-92b1-da968f19cc63}.TMContainer00000000000000000002.regtrans-ms
[2011/11/04 23:22:05 | 00,065,536 | -HS- | M] () -- C:\Users\cliff\ntuser.dat{98f93032-5b56-11de-92b1-da968f19cc63}.TM.blf
[2011/11/03 14:30:24 | 00,000,832 | ---- | M] () -- C:\Users\cliff\Desktop\Spotify.lnk
[2011/11/03 09:45:01 | 00,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2883493492-1982095606-3702794389-1000Core1cc0223f69c98ab.job
[2011/11/02 12:05:53 | 00,002,024 | ---- | M] () -- C:\Windows\MOBK.blk
[2011/11/02 12:05:53 | 00,000,802 | ---- | M] () -- C:\Windows\MOBK.flt
[2011/10/22 10:15:00 | 00,711,302 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2011/10/22 10:15:00 | 00,610,022 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/10/22 10:15:00 | 00,106,228 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/10/20 00:00:17 | 00,010,604 | ---- | M] () -- C:\Users\cliff\Documents\GeeksToGo.docx
[2011/10/19 23:50:20 | 00,000,847 | ---- | M] () -- C:\Users\cliff\Desktop\OTL (1).exe - Shortcut.lnk
[2011/10/18 15:11:47 | 00,001,037 | ---- | M] () -- C:\Users\cliff\Desktop\FrostWire 5.1.5.lnk
[2011/10/14 03:26:06 | 00,418,544 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/10/13 11:54:31 | 00,000,051 | ---- | M] () -- C:\Windows\System32\drivers\etc\lmhosts
[2011/10/12 11:02:56 | 00,000,958 | ---- | M] () -- C:\Users\Public\Desktop\HTC Sync.lnk
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\Users\cliff\AppData\Local\*.tmp files -> C:\Users\cliff\AppData\Local\*.tmp -> ]
========== Files Created - No Company Name ========== [2011/11/04 23:22:46 | 21,374,48448 | -HS- | C] () -- C:\hiberfil.sys
[2011/11/03 14:30:24 | 00,000,832 | ---- | C] () -- C:\Users\cliff\Desktop\Spotify.lnk
[2011/10/20 00:00:15 | 00,010,604 | ---- | C] () -- C:\Users\cliff\Documents\GeeksToGo.docx
[2011/10/19 23:50:20 | 00,000,847 | ---- | C] () -- C:\Users\cliff\Desktop\OTL (1).exe - Shortcut.lnk
[2011/10/18 15:11:47 | 00,001,037 | ---- | C] () -- C:\Users\cliff\Desktop\FrostWire 5.1.5.lnk
[2011/10/12 11:02:56 | 00,000,958 | ---- | C] () -- C:\Users\Public\Desktop\HTC Sync.lnk
[2011/09/16 04:28:58 | 00,000,000 | ---- | C] () -- C:\Users\cliff\AppData\Local\{F1157D44-08CC-4725-AA0E-705D97D4602A}
[2011/09/16 04:26:58 | 00,000,000 | ---- | C] () -- C:\Users\cliff\AppData\Local\{2EEDD777-7511-4A3A-93B5-11B5BFA5C416}
[2011/09/16 04:22:45 | 00,000,000 | ---- | C] () -- C:\Users\cliff\AppData\Local\{0CC20129-1078-45AD-91EA-BFA396AFE21E}
[2011/06/14 11:48:03 | 00,000,000 | ---- | C] () -- C:\Windows\DbgOut.INI
[2010/09/18 06:56:27 | 00,002,578 | ---- | C] () -- C:\Users\cliff\AppData\Roaming\Rim.Desktop.Exception.log
[2010/09/16 16:50:54 | 00,001,602 | ---- | C] () -- C:\Users\cliff\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
[2010/03/01 21:51:12 | 00,000,032 | ---- | C] () -- C:\Users\cliff\AppData\Local\xobni_installer_updater.log
[2010/03/01 15:13:21 | 00,005,864 | ---- | C] () -- C:\Users\cliff\AppData\Local\d3d9caps.dat
[2009/12/05 22:35:12 | 00,974,848 | ---- | C] () -- C:\Windows\System32\LtDlgRes14n.dll
[2009/12/03 15:07:42 | 00,000,110 | ---- | C] () -- C:\Windows\ULEAD32.INI
[2009/09/23 18:44:39 | 00,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/08/03 15:07:42 | 00,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/03/05 07:54:58 | 00,073,728 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2009/02/09 20:49:31 | 00,004,096 | -H-- | C] () -- C:\Users\cliff\AppData\Local\keyfile3.drm
[2009/01/17 19:33:36 | 00,007,250 | ---- | C] () -- C:\ProgramData\N360BUOptions.ini
[2009/01/17 19:30:37 | 00,000,067 | ---- | C] () -- C:\Windows\wininit.ini
[2008/11/08 21:01:03 | 00,029,184 | ---- | C] () -- C:\Users\cliff\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/10/07 13:51:29 | 00,119,314 | ---- | C] () -- C:\ProgramData\LUUnInstall.LiveUpdate
[2008/09/13 15:04:30 | 00,000,067 | ---- | C] () -- C:\Windows\swupdate.INI
[2008/08/07 09:59:37 | 00,000,013 | RHS- | C] () -- C:\Windows\System32\drivers\fbd.sys
[2008/08/07 09:59:35 | 00,000,004 | RHS- | C] () -- C:\Windows\System32\drivers\taishop.sys
[2008/02/20 14:16:48 | 00,204,800 | ---- | C] () -- C:\Windows\System32\IVIresizeW7.dll
[2008/02/20 14:16:48 | 00,200,704 | ---- | C] () -- C:\Windows\System32\IVIresizeA6.dll
[2008/02/20 14:16:48 | 00,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeP6.dll
[2008/02/20 14:16:48 | 00,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeM6.dll
[2008/02/20 14:16:48 | 00,188,416 | ---- | C] () -- C:\Windows\System32\IVIresizePX.dll
[2008/02/20 14:16:48 | 00,020,480 | ---- | C] () -- C:\Windows\System32\IVIresize.dll
[2008/02/18 21:43:23 | 00,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI
[2008/02/18 21:36:45 | 00,036,864 | ---- | C] () -- C:\Windows\System32\HWS_Ctrl.dll
[2008/02/18 21:33:34 | 00,128,113 | ---- | C] () -- C:\Windows\System32\csellang.ini
[2008/02/18 21:33:34 | 00,045,056 | ---- | C] () -- C:\Windows\System32\csellang.dll
[2008/02/18 21:33:34 | 00,010,150 | ---- | C] () -- C:\Windows\System32\tosmreg.ini
[2008/02/18 21:33:34 | 00,007,671 | ---- | C] () -- C:\Windows\System32\cseltbl.ini
[2007/12/21 19:46:32 | 00,118,784 | ---- | C] () -- C:\Windows\System32\TosBtAcc.dll
[2007/09/13 17:31:06 | 00,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1329.dll
[2007/09/13 17:22:46 | 01,238,832 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll
[2007/09/13 17:22:46 | 00,104,636 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.dll
[2007/09/13 17:11:18 | 00,249,856 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll
[2006/11/02 07:35:32 | 00,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 02:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2005/11/23 17:55:42 | 00,024,576 | ---- | C] () -- C:\Windows\System32\SPCtl.dll
[2005/07/23 00:30:18 | 00,065,536 | ---- | C] () -- C:\Windows\System32\TosCommAPI.dll
========== LOP Check ========== [2010/02/15 20:26:02 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\eMusic
[2009/12/20 01:30:08 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\F-Secure
[2011/10/18 15:10:29 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\FrostWire
[2008/10/06 10:18:47 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\GetRightToGo
[2009/04/27 18:43:10 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\gtk-2.0
[2011/10/12 11:04:30 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\HTC
[2011/04/17 22:48:09 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2009/04/28 23:52:48 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\Jasc
[2009/12/16 01:31:21 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\Opera
[2011/04/21 12:26:02 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\Outlook
[2009/06/10 14:05:22 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\Pogo Games
[2010/09/18 06:56:14 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\Research In Motion
[2010/12/19 16:51:08 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\Sammsoft
[2010/11/30 00:18:20 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\Skip-Bo
[2011/11/04 23:25:23 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\Spotify
[2011/04/21 12:18:02 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\Teleca
[2008/10/12 12:28:03 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\TOSHIBA
[2010/03/01 22:03:13 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\Trillian
[2011/03/07 01:33:08 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\Ulead Systems
[2008/08/07 12:51:00 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\WildTangent
[2008/11/03 16:39:17 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\WinBatch
[2011/08/27 16:31:19 | 00,000,000 | ---D | M] -- C:\Users\cliff\AppData\Roaming\Windows Live Writer
[2011/11/04 20:36:08 | 00,032,570 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 76 bytes -> C:\Users\cliff\Documents\BFT MASS ADDS FAST AND FLAWLESS.txt:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\cliff\Documents\base flasher.gif:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\cliff\Documents\2008_Federal_Return.pdf:Roxio EMC Stream
@Alternate Data Stream - 203 bytes -> C:\ProgramData\TEMP:A73EAFFB
< End of report >
GMER 1.0.15.15641 -
http://www.gmer.netRootkit scan 2011-11-05 00:54:13
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-4 Hitachi_HTS542512K9SA00 rev.BB2OC33P
Running: 9lepvu8x.exe; Driver: C:\Users\cliff\AppData\Local\Temp\fgtdipow.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0x82E83268]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0x82E83292]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0x82E8327E]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0x82E83254]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwYieldExecution 82834982 5 Bytes JMP 82E83258 \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 829FA143 5 Bytes JMP 82E83296 \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 82A1989A 7 Bytes JMP 82E8326C \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 82A19B5D 5 Bytes JMP 82E83282 \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
.text C:\Windows\system32\DRIVERS\tos_sps32.sys section is writeable [0x83759000, 0x4036D, 0xE8000020]
.dsrt C:\Windows\system32\DRIVERS\tos_sps32.sys unknown last section [0x837A2000, 0x510, 0x40000040]
? C:\Users\cliff\AppData\Local\Temp\aswMBR.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[180] kernel32.dll!LoadLibraryW 75E99400 5 Bytes JMP 6D619A63 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[180] kernel32.dll!LoadLibraryA 75E9957C 5 Bytes JMP 6D6199A1 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateFile 77604224 5 Bytes JMP 000D0000
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcess 776042E4 5 Bytes JMP 000D0FD4
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtProtectVirtualMemory 77604B84 5 Bytes JMP 000D0FE5
.text C:\Windows\system32\services.exe[700] kernel32.dll!GetStartupInfoW 75E71929 5 Bytes JMP 000E008C
.text C:\Windows\system32\services.exe[700] kernel32.dll!GetStartupInfoA 75E719C9 5 Bytes JMP 000E0F50
.text C:\Windows\system32\services.exe[700] kernel32.dll!CreateProcessW 75E71BF3 5 Bytes JMP 000E0F1A
.text C:\Windows\system32\services.exe[700] kernel32.dll!CreateProcessA 75E71C28 5 Bytes JMP 000E0F2B
.text C:\Windows\system32\services.exe[700] kernel32.dll!VirtualProtect 75E71DC3 5 Bytes JMP 000E0F72
.text C:\Windows\system32\services.exe[700] kernel32.dll!CreateNamedPipeA 75E72EF5 5 Bytes JMP 000E000A
.text C:\Windows\system32\services.exe[700] kernel32.dll!CreateNamedPipeW 75E75C0C 5 Bytes JMP 000E0025
.text C:\Windows\system32\services.exe[700] kernel32.dll!CreatePipe 75E98F06 5 Bytes JMP 000E007B
.text C:\Windows\system32\services.exe[700] kernel32.dll!LoadLibraryExW 75E9927C 5 Bytes JMP 000E0F8D
.text C:\Windows\system32\services.exe[700] kernel32.dll!LoadLibraryW 75E99400 5 Bytes JMP 000E0036
.text C:\Windows\system32\services.exe[700] kernel32.dll!LoadLibraryExA 75E99554 5 Bytes JMP 000E0F9E
.text C:\Windows\system32\services.exe[700] kernel32.dll!LoadLibraryA 75E9957C 5 Bytes JMP 000E0FAF
.text C:\Windows\system32\services.exe[700] kernel32.dll!VirtualProtectEx 75E9DC52 5 Bytes JMP 000E0F61
.text C:\Windows\system32\services.exe[700] kernel32.dll!GetProcAddress 75EB925B 5 Bytes JMP 000E0F09
.text C:\Windows\system32\services.exe[700] kernel32.dll!CreateFileW 75EBB0EB 5 Bytes JMP 000E0FD4
.text C:\Windows\system32\services.exe[700] kernel32.dll!CreateFileA 75EBD07F 5 Bytes JMP 000E0FEF
.text C:\Windows\system32\services.exe[700] kernel32.dll!WinExec 75F060CF 5 Bytes JMP 000E00B1
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegCreateKeyExA 772D39AB 5 Bytes JMP 00100F86
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegCreateKeyA 772D3BA9 5 Bytes JMP 00100FA8
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegOpenKeyA 772D89C7 5 Bytes JMP 00100FEF
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegCreateKeyW 772E391E 5 Bytes JMP 00100F97
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegCreateKeyExW 772E41F1 5 Bytes JMP 00100F6B
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegOpenKeyExA 772E7C42 5 Bytes JMP 00100FD4
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegOpenKeyW 772EE2B5 5 Bytes JMP 00100000
.text C:\Windows\system32\services.exe[700] ADVAPI32.dll!RegOpenKeyExW 772F7BA1 5 Bytes JMP 00100FB9
.text C:\Windows\system32\services.exe[700] msvcrt.dll!_wsystem 76047F2F 5 Bytes JMP 000F0027
.text C:\Windows\system32\services.exe[700] msvcrt.dll!system 7604804B 5 Bytes JMP 000F0F9C
.text C:\Windows\system32\services.exe[700] msvcrt.dll!_creat 7604BBE1 5 Bytes JMP 000F0FC8
.text C:\Windows\system32\services.exe[700] msvcrt.dll!_open 7604D106 5 Bytes JMP 000F0FEF
.text C:\Windows\system32\services.exe[700] msvcrt.dll!_wcreat 7604D326 5 Bytes JMP 000F0FB7
.text C:\Windows\system32\services.exe[700] msvcrt.dll!_wopen 7604D501 5 Bytes JMP 000F000C
.text C:\Windows\system32\services.exe[700] WS2_32.dll!socket 776D36D1 5 Bytes JMP 00310FE5
.text C:\Windows\system32\lsass.exe[716] ntdll.dll!NtCreateFile 77604224 5 Bytes JMP 00130FEF
.text C:\Windows\system32\lsass.exe[716] ntdll.dll!NtCreateProcess 776042E4 5 Bytes JMP 00130FD4
.text C:\Windows\system32\lsass.exe[716] ntdll.dll!NtProtectVirtualMemory 77604B84 5 Bytes JMP 0013000A
.text C:\Windows\system32\lsass.exe[716] kernel32.dll!GetStartupInfoW 75E71929 5 Bytes JMP 0014009D
.text C:\Windows\system32\lsass.exe[716] kernel32.dll!GetStartupInfoA 75E719C9 5 Bytes JMP 00140F57
.text C:\Windows\system32\lsass.exe[716] kernel32.dll!CreateProcessW 75E71BF3 5 Bytes JMP 001400D3
.text C:\Windows\system32\lsass.exe[716] kernel32.dll!CreateProcessA 75E71C28 5 Bytes JMP 00140F3C
.text C:\Windows\system32\lsass.exe[716] kernel32.dll!VirtualProtect 75E71DC3 5 Bytes JMP 00140F83
.text C:\Windows\system32\lsass.exe[716] kernel32.dll!CreateNamedPipeA 75E72EF5 5 Bytes JMP 0014001B
.text C:\Windows\system32\lsass.exe[716] kernel32.dll!CreateNamedPipeW 75E75C0C 5 Bytes JMP 00140FCA
.text C:\Windows\system32\lsass.exe[716] kernel32.dll!CreatePipe 75E98F06 5 Bytes JMP 00140082
.text C:\Windows\system32\lsass.exe[716] kernel32.dll!LoadLibraryExW 75E9927C 5 Bytes JMP 0014005B
.text C:\Windows\system32\lsass.exe[716] kernel32.dll!LoadLibraryW 75E99400 5 Bytes JMP 00140FAF
.text C:\Windows\system32\lsass.exe[716] kernel32.dll!LoadLibraryExA 75E99554 5 Bytes JMP 00140F9E
.text C:\Windows\system32\lsass.exe[716] kernel32.dll!LoadLibraryA 75E9957C 5 Bytes JMP 00140036
.text C:\Windows\system32\lsass.exe[716] kernel32.dll!VirtualProtectEx 75E9DC52 5 Bytes JMP 00140F72
.text C:\Windows\system32\lsass.exe[716] kernel32.dll!GetProcAddress 75EB925B 5 Bytes JMP 00140F21
.text C:\Windows\system32\lsass.exe[716] kernel32.dll!CreateFileW 75EBB0EB 5 Bytes JMP 0014000A
.text C:\Windows\system32\lsass.exe[716] kernel32.dll!CreateFileA 75EBD07F 5 Bytes JMP 00140FEF
.text C:\Windows\system32\lsass.exe[716] kernel32.dll!WinExec 75F060CF 5 Bytes JMP 001400B8
.text C:\Windows\system32\lsass.exe[716] ADVAPI32.dll!RegCreateKeyExA 772D39AB 1 Byte [E9]
.text C:\Windows\system32\lsass.exe[716] ADVAPI32.dll!RegCreateKeyExA 772D39AB 5 Bytes JMP 00520FAF
.text C:\Windows\system32\lsass.exe[716] ADVAPI32.dll!RegCreateKeyA 772D3BA9 5 Bytes JMP 00520051
.text C:\Windows\system32\lsass.exe[716] ADVAPI32.dll!RegOpenKeyA 772D89C7 5 Bytes JMP 00520000
.text C:\Windows\system32\lsass.exe[716] ADVAPI32.dll!RegCreateKeyW 772E391E 5 Bytes JMP 00520FC0
.text C:\Windows\system32\lsass.exe[716] ADVAPI32.dll!RegCreateKeyExW 772E41F1 5 Bytes JMP 00520F9E
.text C:\Windows\system32\lsass.exe[716] ADVAPI32.dll!RegOpenKeyExA 772E7C42 5 Bytes JMP 00520036
.text C:\Windows\system32\lsass.exe[716] ADVAPI32.dll!RegOpenKeyW 772EE2B5 5 Bytes JMP 0052001B
.text C:\Windows\system32\lsass.exe[716] ADVAPI32.dll!RegOpenKeyExW 772F7BA1 5 Bytes JMP 00520FE5
.text C:\Windows\system32\lsass.exe[716] msvcrt.dll!_wsystem 76047F2F 1 Byte [E9]
.text C:\Windows\system32\lsass.exe[716] msvcrt.dll!_wsystem 76047F2F 5 Bytes JMP 00150033
.text C:\Windows\system32\lsass.exe[716] msvcrt.dll!system 7604804B 5 Bytes JMP 00150022
.text C:\Windows\system32\lsass.exe[716] msvcrt.dll!_creat 7604BBE1 5 Bytes JMP 00150000
.text C:\Windows\system32\lsass.exe[716] msvcrt.dll!_open 7604D106 5 Bytes JMP 00150FEF
.text C:\Windows\system32\lsass.exe[716] msvcrt.dll!_wcreat 7604D326 5 Bytes JMP 00150011
.text C:\Windows\system32\lsass.exe[716] msvcrt.dll!_wopen 7604D501 5 Bytes JMP 00150FD2
.text C:\Windows\system32\lsass.exe[716] WS2_32.dll!socket 776D36D1 5 Bytes JMP 00530FEF
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateFile 77604224 5 Bytes JMP 00140000
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtCreateProcess 776042E4 5 Bytes JMP 0014001B
.text C:\Windows\system32\svchost.exe[916] ntdll.dll!NtProtectVirtualMemory 77604B84 5 Bytes JMP 00140FE5
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!GetStartupInfoW 75E71929 5 Bytes JMP 00190F4B
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!GetStartupInfoA 75E719C9 5 Bytes JMP 00190091
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateProcessW 75E71BF3 5 Bytes JMP 001900BD
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateProcessA 75E71C28 5 Bytes JMP 001900AC
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!VirtualProtect 75E71DC3 5 Bytes JMP 00190F88
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateNamedPipeA 75E72EF5 5 Bytes JMP 00190025
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateNamedPipeW 75E75C0C 5 Bytes JMP 00190FD4
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreatePipe 75E98F06 5 Bytes JMP 00190F66
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!LoadLibraryExW 75E9927C 5 Bytes JMP 00190062
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!LoadLibraryW 75E99400 5 Bytes JMP 00190051
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!LoadLibraryExA 75E99554 5 Bytes JMP 00190FAF
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!LoadLibraryA 75E9957C 5 Bytes JMP 00190040
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!VirtualProtectEx 75E9DC52 5 Bytes JMP 00190F77
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!GetProcAddress 75EB925B 5 Bytes JMP 00190F0B
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateFileW 75EBB0EB 5 Bytes JMP 00190FE5
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateFileA 75EBD07F 5 Bytes JMP 0019000A
.text C:\Windows\system32\svchost.exe[916] kernel32.dll!WinExec 75F060CF 5 Bytes JMP 00190F30
.text C:\Windows\system32\svchost.exe[916] msvcrt.dll!_wsystem 76047F2F 5 Bytes JMP 001A0FC8
.text C:\Windows\system32\svchost.exe[916] msvcrt.dll!system 7604804B 5 Bytes JMP 001A0053
.text C:\Windows\system32\svchost.exe[916] msvcrt.dll!_creat 7604BBE1 5 Bytes JMP 001A002E
.text C:\Windows\system32\svchost.exe[916] msvcrt.dll!_open 7604D106 5 Bytes JMP 001A000C
.text C:\Windows\system32\svchost.exe[916] msvcrt.dll!_wcreat 7604D326 5 Bytes JMP 001A0FE3
.text C:\Windows\system32\svchost.exe[916] msvcrt.dll!_wopen 7604D501 5 Bytes JMP 001A001D
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegCreateKeyExA 772D39AB 5 Bytes JMP 001F0F5E
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegCreateKeyA 772D3BA9 5 Bytes JMP 001F0F9E
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegOpenKeyA 772D89C7 5 Bytes JMP 001F0FEF
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegCreateKeyW 772E391E 5 Bytes JMP 001F0F79
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegCreateKeyExW 772E41F1 5 Bytes JMP 001F001B
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegOpenKeyExA 772E7C42 5 Bytes JMP 001F000A
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegOpenKeyW 772EE2B5 5 Bytes JMP 001F0FD4
.text C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegOpenKeyExW 772F7BA1 5 Bytes JMP 001F0FAF
.text C:\Windows\system32\svchost.exe[916] WS2_32.dll!socket 776D36D1 5 Bytes JMP 00200FEF
.text C:\Windows\system32\svchost.exe[1008] ntdll.dll!NtCreateFile 77604224 5 Bytes JMP 00750000
.text C:\Windows\system32\svchost.exe[1008] ntdll.dll!NtCreateProcess 776042E4 5 Bytes JMP 00750FDE
.text C:\Windows\system32\svchost.exe[1008] ntdll.dll!NtProtectVirtualMemory 77604B84 5 Bytes JMP 00750FEF
.text C:\Windows\system32\svchost.exe[1008] kernel32.dll!GetStartupInfoW 75E71929 5 Bytes JMP 00760F50
.text C:\Windows\system32\svchost.exe[1008] kernel32.dll!GetStartupInfoA 75E719C9 5 Bytes JMP 00760F61
.text C:\Windows\system32\svchost.exe[1008] kernel32.dll!CreateProcessW 75E71BF3 5 Bytes JMP 00760F06
.text C:\Windows\system32\svchost.exe[1008] kernel32.dll!CreateProcessA 75E71C28 5 Bytes JMP 00760F2B
.text C:\Windows\system32\svchost.exe[1008] kernel32.dll!VirtualProtect 75E71DC3 5 Bytes JMP 00760F97
.text C:\Windows\system32\svchost.exe[1008] kernel32.dll!CreateNamedPipeA 75E72EF5 5 Bytes JMP 00760025
.text C:\Windows\system32\svchost.exe[1008] kernel32.dll!CreateNamedPipeW 75E75C0C 5 Bytes JMP 00760040
.text C:\Windows\system32\svchost.exe[1008] kernel32.dll!CreatePipe 75E98F06 5 Bytes JMP 00760F72
.text C:\Windows\system32\svchost.exe[1008] kernel32.dll!LoadLibraryExW 75E9927C 5 Bytes JMP 00760FA8
.text C:\Windows\system32\svchost.exe[1008] kernel32.dll!LoadLibraryW 75E99400 5 Bytes JMP 00760FD4
.text C:\Windows\system32\svchost.exe[1008] kernel32.dll!LoadLibraryExA 75E99554 5 Bytes JMP 00760FC3
.text C:\Windows\system32\svchost.exe[1008] kernel32.dll!LoadLibraryA 75E9957C 5 Bytes JMP 0076005B
.text C:\Windows\system32\svchost.exe[1008] kernel32.dll!VirtualProtectEx 75E9DC52 5 Bytes JMP 0076008C
.text C:\Windows\system32\svchost.exe[1008] kernel32.dll!GetProcAddress 75EB925B 5 Bytes JMP 00760EF5
.text C:\Windows\system32\svchost.exe[1008] kernel32.dll!CreateFileW 75EBB0EB 5 Bytes JMP 0076000A
.text C:\Windows\system32\svchost.exe[1008] kernel32.dll!CreateFileA 75EBD07F 5 Bytes JMP 00760FEF
.text C:\Windows\system32\svchost.exe[1008] kernel32.dll!WinExec 75F060CF 5 Bytes JMP 007600A7
.text C:\Windows\system32\svchost.exe[1008] msvcrt.dll!_wsystem 76047F2F 5 Bytes JMP 00770067
.text C:\Windows\system32\svchost.exe[1008] msvcrt.dll!system 7604804B 5 Bytes JMP 00770042
.text C:\Windows\system32\svchost.exe[1008] msvcrt.dll!_creat 7604BBE1 5 Bytes JMP 00770FD2
.text C:\Windows\system32\svchost.exe[1008] msvcrt.dll!_open 7604D106 5 Bytes JMP 00770FEF
.text C:\Windows\system32\svchost.exe[1008] msvcrt.dll!_wcreat 7604D326 5 Bytes JMP 00770031
.text C:\Windows\system32\svchost.exe[1008] msvcrt.dll!_wopen 7604D501 5 Bytes JMP 0077000C
.text C:\Windows\system32\svchost.exe[1008] ADVAPI32.dll!RegCreateKeyExA 772D39AB 5 Bytes JMP 0078006F
.text C:\Windows\system32\svchost.exe[1008] ADVAPI32.dll!RegCreateKeyA 772D3BA9 5 Bytes JMP 00780FCD
.text C:\Windows\system32\svchost.exe[1008] ADVAPI32.dll!RegOpenKeyA 772D89C7 5 Bytes JMP 0078000A
.text C:\Windows\system32\svchost.exe[1008] ADVAPI32.dll!RegCreateKeyW 772E391E 5 Bytes JMP 0078005E
.text C:\Windows\system32\svchost.exe[1008] ADVAPI32.dll!RegCreateKeyExW 772E41F1 5 Bytes JMP 00780080
.text C:\Windows\system32\svchost.exe[1008] ADVAPI32.dll!RegOpenKeyExA 772E7C42 5 Bytes JMP 00780FEF
.text C:\Windows\system32\svchost.exe[1008] ADVAPI32.dll!RegOpenKeyW 772EE2B5 5 Bytes JMP 00780025
.text C:\Windows\system32\svchost.exe[1008] ADVAPI32.dll!RegOpenKeyExW 772F7BA1 5 Bytes JMP 00780FDE
.text C:\Windows\system32\svchost.exe[1008] WS2_32.dll!socket 776D36D1 5 Bytes JMP 00790000
.text C:\Windows\System32\svchost.exe[1040] ntdll.dll!NtCreateFile 77604224 5 Bytes JMP 00830000
.text C:\Windows\System32\svchost.exe[1040] ntdll.dll!NtCreateProcess 776042E4 5 Bytes JMP 0083001B
.text C:\Windows\System32\svchost.exe[1040] ntdll.dll!NtProtectVirtualMemory 77604B84 5 Bytes JMP 00830FEF
.text C:\Windows\System32\svchost.exe[1040] kernel32.dll!GetStartupInfoW 75E71929 5 Bytes JMP 008A0F77
.text C:\Windows\System32\svchost.exe[1040] kernel32.dll!GetStartupInfoA 75E719C9 5 Bytes JMP 008A0F88
.text C:\Windows\System32\svchost.exe[1040] kernel32.dll!CreateProcessW 75E71BF3 5 Bytes JMP 008A0F55
.text C:\Windows\System32\svchost.exe[1040] kernel32.dll!CreateProcessA 75E71C28 5 Bytes JMP 008A00EC
.text C:\Windows\System32\svchost.exe[1040] kernel32.dll!VirtualProtect 75E71DC3 5 Bytes JMP 008A0087
.text C:\Windows\System32\svchost.exe[1040] kernel32.dll!CreateNamedPipeA 75E72EF5 5 Bytes JMP 008A001B
.text C:\Windows\System32\svchost.exe[1040] kernel32.dll!CreateNamedPipeW 75E75C0C 5 Bytes JMP 008A0FCA
.text C:\Windows\System32\svchost.exe[1040] kernel32.dll!CreatePipe 75E98F06 5 Bytes JMP 008A00A9
.text C:\Windows\System32\svchost.exe[1040] kernel32.dll!LoadLibraryExW 75E9927C 5 Bytes JMP 008A0FB9
.text C:\Windows\System32\svchost.exe[1040] kernel32.dll!LoadLibraryW 75E99400 5 Bytes JMP 008A005B
.text C:\Windows\System32\svchost.exe[1040] kernel32.dll!LoadLibraryExA 75E99554 5 Bytes JMP 008A0076
.text C:\Windows\System32\svchost.exe[1040] kernel32.dll!LoadLibraryA 75E9957C 5 Bytes JMP 008A0036
.text C:\Windows\System32\svchost.exe[1040] kernel32.dll!VirtualProtectEx 75E9DC52 5 Bytes JMP 008A0098
.text C:\Windows\System32\svchost.exe[1040] kernel32.dll!GetProcAddress 75EB925B 5 Bytes JMP 008A0107
.text C:\Windows\System32\svchost.exe[1040] kernel32.dll!CreateFileW 75EBB0EB 5 Bytes JMP 008A0FE5
.text C:\Windows\System32\svchost.exe[1040] kernel32.dll!CreateFileA 75EBD07F 5 Bytes JMP 008A0000
.text C:\Windows\System32\svchost.exe[1040] kernel32.dll!WinExec 75F060CF 5 Bytes JMP 008A0F66
.text C:\Windows\System32\svchost.exe[1040] msvcrt.dll!_wsystem 76047F2F 5 Bytes JMP 008B004E
.text C:\Windows\System32\svchost.exe[1040] msvcrt.dll!system 7604804B 5 Bytes JMP 008B003D
.text C:\Windows\System32\svchost.exe[1040] msvcrt.dll!_creat 7604BBE1 5 Bytes JMP 008B0022
.text C:\Windows\System32\svchost.exe[1040] msvcrt.dll!_open 7604D106 5 Bytes JMP 008B0000
.text C:\Windows\System32\svchost.exe[1040] msvcrt.dll!_wcreat 7604D326 5 Bytes JMP 008B0FCD
.text C:\Windows\System32\svchost.exe[1040] msvcrt.dll!_wopen 7604D501 5 Bytes JMP 008B0011
.text C:\Windows\System32\svchost.exe[1040] ADVAPI32.dll!RegCreateKeyExA 772D39AB 5 Bytes JMP 00910F94
.text C:\Windows\System32\svchost.exe[1040] ADVAPI32.dll!RegCreateKeyA 772D3BA9 5 Bytes JMP 00910FC0
.text C:\Windows\System32\svchost.exe[1040] ADVAPI32.dll!RegOpenKeyA 772D89C7 5 Bytes JMP 00910FEF
.text C:\Windows\System32\svchost.exe[1040] ADVAPI32.dll!RegCreateKeyW 772E391E 5 Bytes JMP 00910FAF
.text C:\Windows\System32\svchost.exe[1040] ADVAPI32.dll!RegCreateKeyExW 772E41F1 5 Bytes JMP 00910F83
.text C:\Windows\System32\svchost.exe[1040] ADVAPI32.dll!RegOpenKeyExA 772E7C42 5 Bytes JMP 00910025
.text C:\Windows\System32\svchost.exe[1040] ADVAPI32.dll!RegOpenKeyW 772EE2B5 5 Bytes JMP 0091000A
.text C:\Windows\System32\svchost.exe[1040] ADVAPI32.dll!RegOpenKeyExW 772F7BA1 5 Bytes JMP 00910036
.text C:\Windows\System32\svchost.exe[1040] WS2_32.dll!socket 776D36D1 5 Bytes JMP 00DF0000
.text C:\Windows\System32\svchost.exe[1040] WININET.dll!InternetOpenA 76F14E33 5 Bytes JMP 008C0FEF
.text C:\Windows\System32\svchost.exe[1040] WININET.dll!InternetOpenUrlA 76F1BFCE 5 Bytes JMP 008C0025
.text C:\Windows\System32\svchost.exe[1040] WININET.dll!InternetOpenW 76F4C02E 5 Bytes JMP 008C000A
.text C:\Windows\System32\svchost.exe[1040] WININET.dll!InternetOpenUrlW 76F7D70A 5 Bytes JMP 008C0040
.text C:\Windows\System32\svchost.exe[1108] ntdll.dll!NtCreateFile 77604224 5 Bytes JMP 0091000A
.text C:\Windows\System32\svchost.exe[1108] ntdll.dll!NtCreateProcess 776042E4 5 Bytes JMP 00910FE5
.text C:\Windows\System32\svchost.exe[1108] ntdll.dll!NtProtectVirtualMemory 77604B84 5 Bytes JMP 0091001B
.text C:\Windows\System32\svchost.exe[1108] kernel32.dll!GetStartupInfoW 75E71929 5 Bytes JMP 00A300A4
.text C:\Windows\System32\svchost.exe[1108] kernel32.dll!GetStartupInfoA 75E719C9 5 Bytes JMP 00A30093
.text C:\Windows\System32\svchost.exe[1108] kernel32.dll!CreateProcessW 75E71BF3 5 Bytes JMP 00A30F28
.text C:\Windows\System32\svchost.exe[1108] kernel32.dll!CreateProcessA 75E71C28 5 Bytes JMP 00A300B5
.text C:\Windows\System32\svchost.exe[1108] kernel32.dll!VirtualProtect 75E71DC3 5 Bytes JMP 00A30F83
.text C:\Windows\System32\svchost.exe[1108] kernel32.dll!CreateNamedPipeA 75E72EF5 5 Bytes JMP 00A3000A
.text C:\Windows\System32\svchost.exe[1108] kernel32.dll!CreateNamedPipeW 75E75C0C 5 Bytes JMP 00A30025
.text C:\Windows\System32\svchost.exe[1108] kernel32.dll!CreatePipe 75E98F06 5 Bytes JMP 00A30078
.text C:\Windows\System32\svchost.exe[1108] kernel32.dll!LoadLibraryExW 75E9927C 5 Bytes JMP 00A30F94
.text C:\Windows\System32\svchost.exe[1108] kernel32.dll!LoadLibraryW 75E99400 5 Bytes JMP 00A30040
.text C:\Windows\System32\svchost.exe[1108] kernel32.dll!LoadLibraryExA 75E99554 5 Bytes JMP 00A30051
.text C:\Windows\System32\svchost.exe[1108] kernel32.dll!LoadLibraryA 75E9957C 5 Bytes JMP 00A30FB9
.text C:\Windows\System32\svchost.exe[1108] kernel32.dll!VirtualProtectEx 75E9DC52 5 Bytes JMP 00A30F72
.text C:\Windows\System32\svchost.exe[1108] kernel32.dll!GetProcAddress 75EB925B 5 Bytes JMP 00A30F17
.text C:\Windows\System32\svchost.exe[1108] kernel32.dll!CreateFileW 75EBB0EB 5 Bytes JMP 00A30FD4
.text C:\Windows\System32\svchost.exe[1108] kernel32.dll!CreateFileA 75EBD07F 5 Bytes JMP 00A30FEF
.text C:\Windows\System32\svchost.exe[1108] kernel32.dll!WinExec 75F060CF 5 Bytes JMP 00A30F43
.text C:\Windows\System32\svchost.exe[1108] msvcrt.dll!_wsystem 76047F2F 5 Bytes JMP 00F10F92
.text C:\Windows\System32\svchost.exe[1108] msvcrt.dll!system 7604804B 5 Bytes JMP 00F1001D
.text C:\Windows\System32\svchost.exe[1108] msvcrt.dll!_creat 7604BBE1 5 Bytes JMP 00F10FC1
.text C:\Windows\System32\svchost.exe[1108] msvcrt.dll!_open 7604D106 5 Bytes JMP 00F10FE3
.text C:\Windows\System32\svchost.exe[1108] msvcrt.dll!_wcreat 7604D326 5 Bytes JMP 00F1000C
.text C:\Windows\System32\svchost.exe[1108] msvcrt.dll!_wopen 7604D501 5 Bytes JMP 00F10FD2
.text C:\Windows\System32\svchost.exe[1108] ADVAPI32.dll!RegCreateKeyExA 772D39AB 5 Bytes JMP 00F20040
.text C:\Windows\System32\svchost.exe[1108] ADVAPI32.dll!RegCreateKeyA 772D3BA9 5 Bytes JMP 00F20FB9
.text C:\Windows\System32\svchost.exe[1108] ADVAPI32.dll!RegOpenKeyA 772D89C7 5 Bytes JMP 00F20FEF
.text C:\Windows\System32\svchost.exe[1108] ADVAPI32.dll!RegCreateKeyW 772E391E 5 Bytes JMP 00F20FA8
.text C:\Windows\System32\svchost.exe[1108] ADVAPI32.dll!RegCreateKeyExW 772E41F1 5 Bytes JMP 00F20F8D
.text C:\Windows\System32\svchost.exe[1108] ADVAPI32.dll!RegOpenKeyExA 772E7C42 5 Bytes JMP 00F20025
.text C:\Windows\System32\svchost.exe[1108] ADVAPI32.dll!RegOpenKeyW 772EE2B5 5 Bytes JMP 00F2000A
.text C:\Windows\System32\svchost.exe[1108] ADVAPI32.dll!RegOpenKeyExW 772F7BA1 5 Bytes JMP 00F20FD4
.text C:\Windows\System32\svchost.exe[1108] WS2_32.dll!socket 776D36D1 5 Bytes JMP 00F30FEF
.text C:\Windows\System32\svchost.exe[1200] ntdll.dll!NtCreateFile 77604224 5 Bytes JMP 01710000
.text C:\Windows\System32\svchost.exe[1200] ntdll.dll!NtCreateProcess 776042E4 5 Bytes JMP 0171002C
.text C:\Windows\System32\svchost.exe[1200] ntdll.dll!NtProtectVirtualMemory 77604B84 5 Bytes JMP 01710011
.text C:\Windows\System32\svchost.exe[1200] kernel32.dll!GetStartupInfoW 75E71929 5 Bytes JMP 01720091
.text C:\Windows\System32\svchost.exe[1200] kernel32.dll!GetStartupInfoA 75E719C9 5 Bytes JMP 01720F4B
.text C:\Windows\System32\svchost.exe[1200] kernel32.dll!CreateProcessW 75E71BF3 5 Bytes JMP 01720F04
.text C:\Windows\System32\svchost.exe[1200] kernel32.dll!CreateProcessA 75E71C28 5 Bytes JMP 01720F15
.text C:\Windows\System32\svchost.exe[1200] kernel32.dll!VirtualProtect 75E71DC3 5 Bytes JMP 0172005B
.text C:\Windows\System32\svchost.exe[1200] kernel32.dll!CreateNamedPipeA 75E72EF5 5 Bytes JMP 01720FCA
.text C:\Windows\System32\svchost.exe[1200] kernel32.dll!CreateNamedPipeW 75E75C0C 5 Bytes JMP 0172001B
.text C:\Windows\System32\svchost.exe[1200] kernel32.dll!CreatePipe 75E98F06 5 Bytes JMP 01720076
.text C:\Windows\System32\svchost.exe[1200] kernel32.dll!LoadLibraryExW 75E9927C 5 Bytes JMP 01720F77
.text C:\Windows\System32\svchost.exe[1200] kernel32.dll!LoadLibraryW 75E99400 5 Bytes JMP 01720040
.text C:\Windows\System32\svchost.exe[1200] kernel32.dll!LoadLibraryExA 75E99554 5 Bytes JMP 01720F9E
.text C:\Windows\System32\svchost.exe[1200] kernel32.dll!LoadLibraryA 75E9957C 5 Bytes JMP 01720FB9
.text C:\Windows\System32\svchost.exe[1200] kernel32.dll!VirtualProtectEx 75E9DC52 5 Bytes JMP 01720F66
.text C:\Windows\System32\svchost.exe[1200] kernel32.dll!GetProcAddress 75EB925B 5 Bytes JMP 017200AC
.text C:\Windows\System32\svchost.exe[1200] kernel32.dll!CreateFileW 75EBB0EB 5 Bytes JMP 01720000
.text C:\Windows\System32\svchost.exe[1200] kernel32.dll!CreateFileA 75EBD07F 5 Bytes JMP 01720FE5
.text C:\Windows\System32\svchost.exe[1200] kernel32.dll!WinExec 75F060CF 5 Bytes JMP 01720F30
.text C:\Windows\System32\svchost.exe[1200] msvcrt.dll!_wsystem 76047F2F 5 Bytes JMP 017C0F9C
.text C:\Windows\System32\svchost.exe[1200] msvcrt.dll!system 7604804B 5 Bytes JMP 017C0FB7
.text C:\Windows\System32\svchost.exe[1200] msvcrt.dll!_creat 7604BBE1 5 Bytes JMP 017C0FD9
.text C:\Windows\System32\svchost.exe[1200] msvcrt.dll!_open 7604D106 5 Bytes JMP 017C0000
.text C:\Windows\System32\svchost.exe[1200] msvcrt.dll!_wcreat 7604D326 5 Bytes JMP 017C0FC8
.text C:\Windows\System32\svchost.exe[1200] msvcrt.dll!_wopen 7604D501 5 Bytes JMP 017C001D
.text C:\Windows\System32\svchost.exe[1200] ADVAPI32.dll!RegCreateKeyExA 772D39AB 5 Bytes JMP 017D0FDE
.text C:\Windows\System32\svchost.exe[1200] ADVAPI32.dll!RegCreateKeyA 772D3BA9 5 Bytes JMP 017D0FEF
.text C:\Windows\System32\svchost.exe[1200] ADVAPI32.dll!RegOpenKeyA 772D89C7 5 Bytes JMP 017D0000
.text C:\Windows\System32\svchost.exe[1200] ADVAPI32.dll!RegCreateKeyW 772E391E 5 Bytes JMP 017D0076
.text C:\Windows\System32\svchost.exe[1200] ADVAPI32.dll!RegCreateKeyExW 772E41F1 5 Bytes JMP 017D0FC3
.text C:\Windows\System32\svchost.exe[1200] ADVAPI32.dll!RegOpenKeyExA 772E7C42 5 Bytes JMP 017D0040
.text C:\Windows\System32\svchost.exe[1200] ADVAPI32.dll!RegOpenKeyW 772EE2B5 5 Bytes JMP 017D001B
.text C:\Windows\System32\svchost.exe[1200] ADVAPI32.dll!RegOpenKeyExW 772F7BA1 5 Bytes JMP 017D0051
.text C:\Windows\System32\svchost.exe[1200] WS2_32.dll!socket 776D36D1 5 Bytes JMP 0182000A
.text C:\Windows\system32\svchost.exe[1216] ntdll.dll!NtCreateFile 77604224 5 Bytes JMP 01270FEF
.text C:\Windows\system32\svchost.exe[1216] ntdll.dll!NtCreateProcess 776042E4 5 Bytes JMP 01270FCA
.text C:\Windows\system32\svchost.exe[1216] ntdll.dll!NtProtectVirtualMemory 77604B84 5 Bytes JMP 0127000A
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!GetStartupInfoW 75E71929 5 Bytes JMP 020800AF
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!GetStartupInfoA 75E719C9 5 Bytes JMP 0208009E
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!CreateProcessW 75E71BF3 5 Bytes JMP 020800DB
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!CreateProcessA 75E71C28 5 Bytes JMP 020800C0
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!VirtualProtect 75E71DC3 5 Bytes JMP 02080072
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!CreateNamedPipeA 75E72EF5 5 Bytes JMP 02080FD1
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!CreateNamedPipeW 75E75C0C 5 Bytes JMP 02080022
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!CreatePipe 75E98F06 5 Bytes JMP 0208008D
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!LoadLibraryExW 75E9927C 5 Bytes JMP 02080055
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!LoadLibraryW 75E99400 5 Bytes JMP 02080044
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!LoadLibraryExA 75E99554 5 Bytes JMP 02080F98
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!LoadLibraryA 75E9957C 5 Bytes JMP 02080033
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!VirtualProtectEx 75E9DC52 5 Bytes JMP 02080F87
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!GetProcAddress 75EB925B 5 Bytes JMP 020800F6
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!CreateFileW 75EBB0EB 5 Bytes JMP 02080011
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!CreateFileA 75EBD07F 5 Bytes JMP 02080000
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!WinExec 75F060CF 5 Bytes JMP 02080F4E
.text C:\Windows\system32\svchost.exe[1216] msvcrt.dll!_wsystem 76047F2F 5 Bytes JMP 02090042
.text C:\Windows\system32\svchost.exe[1216] msvcrt.dll!system 7604804B 5 Bytes JMP 02090FC1
.text C:\Windows\system32\svchost.exe[1216] msvcrt.dll!_creat 7604BBE1 5 Bytes JMP 0209000C
.text C:\Windows\system32\svchost.exe[1216] msvcrt.dll!_open 7604D106 5 Bytes JMP 02090FEF
.text C:\Windows\system32\svchost.exe[1216] msvcrt.dll!_wcreat 7604D326 5 Bytes JMP 02090027
.text C:\Windows\system32\svchost.exe[1216] msvcrt.dll!_wopen 7604D501 5 Bytes JMP 02090FD2
.text C:\Windows\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyExA 772D39AB 5 Bytes JMP 020E005B
.text C:\Windows\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyA 772D3BA9 5 Bytes JMP 020E002F
.text C:\Windows\system32\svchost.exe[1216] ADVAPI32.dll!RegOpenKeyA 772D89C7 5 Bytes JMP 020E0FEF
.text C:\Windows\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyW 772E391E 5 Bytes JMP 020E004A
.text C:\Windows\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyExW 772E41F1 5 Bytes JMP 020E0076
.text C:\Windows\system32\svchost.exe[1216] ADVAPI32.dll!RegOpenKeyExA 772E7C42 5 Bytes JMP 020E0FB9
.text C:\Windows\system32\svchost.exe[1216] ADVAPI32.dll!RegOpenKeyW 772EE2B5 5 Bytes JMP 020E0FD4
.text C:\Windows\system32\svchost.exe[1216] ADVAPI32.dll!RegOpenKeyExW 772F7BA1 5 Bytes JMP 020E000A
.text C:\Windows\system32\svchost.exe[1216] WS2_32.dll!socket 776D36D1 5 Bytes JMP 020F0FEF
.text C:\Windows\system32\svchost.exe[1216] WININET.dll!InternetOpenA 76F14E33 5 Bytes JMP 02260FEF
.text C:\Windows\system32\svchost.exe[1216] WININET.dll!InternetOpenUrlA 76F1BFCE 5 Bytes JMP 02260025
.text C:\Windows\system32\svchost.exe[1216] WININET.dll!InternetOpenW 76F4C02E 5 Bytes JMP 0226000A
.text C:\Windows\system32\svchost.exe[1216] WININET.dll!InternetOpenUrlW 76F7D70A 5 Bytes JMP 02260040
.text C:\Windows\system32\svchost.exe[1308] ntdll.dll!NtCreateFile 77604224 5 Bytes JMP 00150000
.text C:\Windows\system32\svchost.exe[1308] ntdll.dll!NtCreateProcess 776042E4 5 Bytes JMP 00150FCA
.text C:\Windows\system32\svchost.exe[1308] ntdll.dll!NtProtectVirtualMemory 77604B84 5 Bytes JMP 00150FE5
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!GetStartupInfoW 75E71929 5 Bytes JMP 00160F81
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!GetStartupInfoA 75E719C9 5 Bytes JMP 001600C7
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!CreateProcessW 75E71BF3 5 Bytes JMP 00160F55
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!CreateProcessA 75E71C28 5 Bytes JMP 001600E2
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!VirtualProtect 75E71DC3 5 Bytes JMP 00160FAD
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!CreateNamedPipeA 75E72EF5 5 Bytes JMP 0016001B
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!CreateNamedPipeW 75E75C0C 5 Bytes JMP 00160036
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!CreatePipe 75E98F06 5 Bytes JMP 001600B6
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!LoadLibraryExW 75E9927C 5 Bytes JMP 00160091
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!LoadLibraryW 75E99400 5 Bytes JMP 00160076
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!LoadLibraryExA 75E99554 5 Bytes JMP 00160FD4
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!LoadLibraryA 75E9957C 5 Bytes JMP 0016005B
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!VirtualProtectEx 75E9DC52 5 Bytes JMP 00160F9C
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!GetProcAddress 75EB925B 5 Bytes JMP 00160111
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!CreateFileW 75EBB0EB 1 Byte [E9]
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!CreateFileW 75EBB0EB 5 Bytes JMP 00160FEF
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!CreateFileA 75EBD07F 5 Bytes JMP 00160000
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!WinExec 75F060CF 5 Bytes JMP 00160F66
.text C:\Windows\system32\svchost.exe[1308] msvcrt.dll!_wsystem 76047F2F 5 Bytes JMP 00390FA1
.text C:\Windows\system32\svchost.exe[1308] msvcrt.dll!system 7604804B 5 Bytes JMP 00390FB2
.text C:\Windows\system32\svchost.exe[1308] msvcrt.dll!_creat 7604BBE1 5 Bytes JMP 00390FCD
.text C:\Windows\system32\svchost.exe[1308] msvcrt.dll!_open 7604D106 5 Bytes JMP 00390FEF
.text C:\Windows\system32\svchost.exe[1308] msvcrt.dll!_wcreat 7604D326 5 Bytes JMP 00390018
.text C:\Windows\system32\svchost.exe[1308] msvcrt.dll!_wopen 7604D501 5 Bytes JMP 00390FDE
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!RegCreateKeyExA 772D39AB 5 Bytes JMP 00820F83
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!RegCreateKeyA 772D3BA9 5 Bytes JMP 00820FA8
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!RegOpenKeyA 772D89C7 5 Bytes JMP 00820FEF
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!RegCreateKeyW 772E391E 5 Bytes JMP 00820025
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!RegCreateKeyExW 772E41F1 5 Bytes JMP 00820F72
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!RegOpenKeyExA 772E7C42 5 Bytes JMP 00820014
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!RegOpenKeyW 772EE2B5 5 Bytes JMP 00820FDE
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!RegOpenKeyExW 772F7BA1 5 Bytes JMP 00820FC3
.text C:\Windows\system32\svchost.exe[1308] WS2_32.dll!socket 776D36D1 5 Bytes JMP 00830FEF
.text C:\Windows\system32\svchost.exe[1364] ntdll.dll!NtCreateFile 77604224 5 Bytes JMP 00080000
.text C:\Windows\system32\svchost.exe[1364] ntdll.dll!NtCreateProcess 776042E4 5 Bytes JMP 0008002C
.text C:\Windows\system32\svchost.exe[1364] ntdll.dll!NtProtectVirtualMemory 77604B84 5 Bytes JMP 00080011
.text C:\Windows\system32\svchost.exe[1364] kernel32.dll!GetStartupInfoW 75E71929 5 Bytes JMP 00D30073
.text C:\Windows\system32\svchost.exe[1364] kernel32.dll!GetStartupInfoA 75E719C9 5 Bytes JMP 00D30062
.text C:\Windows\system32\svchost.exe[1364] kernel32.dll!CreateProcessW 75E71BF3 5 Bytes JMP 00D30095
.text C:\Windows\system32\svchost.exe[1364] kernel32.dll!CreateProcessA 75E71C28 5 Bytes JMP 00D30084
.text C:\Windows\system32\svchost.exe[1364] kernel32.dll!VirtualProtect 75E71DC3 5 Bytes JMP 00D30F6D
.text C:\Windows\system32\svchost.exe[1364] kernel32.dll!CreateNamedPipeA 75E72EF5 5 Bytes JMP 00D30FD4
.text C:\Windows\system32\svchost.exe[1364] kernel32.dll!CreateNamedPipeW 75E75C0C 5 Bytes JMP 00D30025
.text C:\Windows\system32\svchost.exe[1364] kernel32.dll!CreatePipe 75E98F06 5 Bytes JMP 00D30F37
.text C:\Windows\system32\svchost.exe[1364] kernel32.dll!LoadLibraryExW 75E9927C 5 Bytes JMP 00D30047
.text C:\Windows\system32\svchost.exe[1364] kernel32.dll!LoadLibraryW 75E99400 5 Bytes JMP 00D30F9E
.text C:\Windows\system32\svchost.exe[1364] kernel32.dll!LoadLibraryExA 75E99554 5 Bytes JMP 00D30036
.text C:\Windows\system32\svchost.exe[1364] kernel32.dll!LoadLibraryA 75E9957C 5 Bytes JMP 00D30FB9
.text C:\Windows\system32\svchost.exe[1364] kernel32.dll!VirtualProtectEx 75E9DC52 5 Bytes JMP 00D30F52
.text C:\Windows\system32\svchost.exe[1364] kernel32.dll!GetProcAddress 75EB925B 5 Bytes JMP 00D300A6
.text C:\Windows\system32\svchost.exe[1364] kernel32.dll!CreateFileW 75EBB0EB 5 Bytes JMP 00D3000A
.text C:\Windows\system32\svchost.exe[1364] kernel32.dll!CreateFileA 75EBD07F 5 Bytes JMP 00D30FEF
.text C:\Windows\system32\svchost.exe[1364] kernel32.dll!WinExec 75F060CF 5 Bytes JMP 00D30F12
.text C:\Windows\system32\svchost.exe[1364] msvcrt.dll!_wsystem 76047F2F 5 Bytes JMP 00D40FAD
.text C:\Windows\system32\svchost.exe[1364] msvcrt.dll!system 7604804B 5 Bytes JMP 00D40FBE
.text C:\Windows\system32\svchost.exe[1364] msvcrt.dll!_creat 7604BBE1 5 Bytes JMP 00D40FE3
.text C:\Windows\system32\svchost.exe[1364] msvcrt.dll!_open 7604D106 5 Bytes JMP 00D40000
.text C:\Windows\system32\svchost.exe[1364] msvcrt.dll!_wcreat 7604D326 5 Bytes JMP 00D40038
.text C:\Windows\system32\svchost.exe[1364] msvcrt.dll!_wopen 7604D501 5 Bytes JMP 00D4001D
.text C:\Windows\system32\svchost.exe[1364] ADVAPI32.dll!RegCreateKeyExA 772D39AB 5 Bytes JMP 00DE0F87
.text C:\Windows\system32\svchost.exe[1364] ADVAPI32.dll!RegCreateKeyA 772D3BA9 5 Bytes JMP 00DE0033
.text C:\Windows\system32\svchost.exe[1364] ADVAPI32.dll!RegOpenKeyA 772D89C7 5 Bytes JMP 00DE0000
.text C:\Windows\system32\svchost.exe[1364] ADVAPI32.dll!RegCreateKeyW 772E391E 5 Bytes JMP 00DE0FA2
.text C:\Windows\system32\svchost.exe[1364] ADVAPI32.dll!RegCreateKeyExW 772E41F1 5 Bytes JMP 00DE0F76
.text C:\Windows\system32\svchost.exe[1364] ADVAPI32.dll!RegOpenKeyExA 772E7C42 5 Bytes JMP 00DE0FD1
.text C:\Windows\system32\svchost.exe[1364] ADVAPI32.dll!RegOpenKeyW 772EE2B5 5 Bytes JMP 00DE0011
.text C:\Windows\system32\svchost.exe[1364] ADVAPI32.dll!RegOpenKeyExW 772F7BA1 5 Bytes JMP 00DE0022
.text C:\Windows\system32\svchost.exe[1364] WS2_32.dll!socket 776D36D1 5 Bytes JMP 00DF000A
.text C:\Windows\system32\svchost.exe[1364] WININET.dll!InternetOpenA 76F14E33 5 Bytes JMP 00D90000
.text C:\Windows\system32\svchost.exe[1364] WININET.dll!InternetOpenUrlA 76F1BFCE 5 Bytes JMP 00D90FC0
.text C:\Windows\system32\svchost.exe[1364] WININET.dll!InternetOpenW 76F4C02E 5 Bytes JMP 00D90FE5
.text C:\Windows\system32\svchost.exe[1364] WININET.dll!InternetOpenUrlW 76F7D70A 5 Bytes JMP 00D90011
.text C:\Windows\system32\svchost.exe[1504] ntdll.dll!NtCreateFile 77604224 5 Bytes JMP 00160000
.text C:\Windows\system32\svchost.exe[1504] ntdll.dll!NtCreateProcess 776042E4 5 Bytes JMP 00160FC0
.text C:\Windows\system32\svchost.exe[1504] ntdll.dll!NtProtectVirtualMemory 77604B84 5 Bytes JMP 00160FDB
.text C:\Windows\system32\svchost.exe[1504] kernel32.dll!GetStartupInfoW 75E71929 5 Bytes JMP 001800DA
.text C:\Windows\system32\svchost.exe[1504] kernel32.dll!GetStartupInfoA 75E719C9 5 Bytes JMP 001800BF
.text C:\Windows\system32\svchost.exe[1504] kernel32.dll!CreateProcessW 75E71BF3 5 Bytes JMP 00180F6F
.text C:\Windows\system32\svchost.exe[1504] kernel32.dll!CreateProcessA 75E71C28 5 Bytes JMP 001800FC
.text C:\Windows\system32\svchost.exe[1504] kernel32.dll!VirtualProtect 75E71DC3 5 Bytes JMP 00180F9E
.text C:\Windows\system32\svchost.exe[1504] kernel32.dll!CreateNamedPipeA 75E72EF5 5 Bytes JMP 0018001B
.text C:\Windows\system32\svchost.exe[1504] kernel32.dll!CreateNamedPipeW 75E75C0C 5 Bytes JMP 00180036
.text C:\Windows\system32\svchost.exe[1504] kernel32.dll!CreatePipe 75E98F06 5 Bytes JMP 001800AE
.text C:\Windows\system32\svchost.exe[1504] kernel32.dll!LoadLibraryExW 75E9927C 5 Bytes JMP 00180FAF
.text C:\Windows\system32\svchost.exe[1504] kernel32.dll!LoadLibraryW 75E99400 5 Bytes JMP 0018005B
.text C:\Windows\system32\svchost.exe[1504] kernel32.dll!LoadLibraryExA 75E99554 5 Bytes JMP 0018006C
.text C:\Windows\system32\svchost.exe[1504] kernel32.dll!LoadLibraryA 75E9957C 5 Bytes JMP 00180FCA
.text C:\Windows\system32\svchost.exe[1504] kernel32.dll!VirtualProtectEx 75E9DC52 5 Bytes JMP 00180093
.text C:\Windows\system32\svchost.exe[1504] kernel32.dll!GetProcAddress 75EB925B 5 Bytes JMP 00180F5E
.text C:\Windows\system32\svchost.exe[1504] kernel32.dll!CreateFileW 75EBB0EB 5 Bytes JMP 0018000A
.text C:\Windows\system32\svchost.exe[1504] kernel32.dll!CreateFileA 75EBD07F 5 Bytes JMP 00180FE5
.text C:\Windows\system32\svchost.exe[1504] kernel32.dll!WinExec 75F060CF 5 Bytes JMP 001800EB
.text C:\Windows\system32\svchost.exe[1504] msvcrt.dll!_wsystem 76047F2F 5 Bytes JMP 00190FB9
.text C:\Windows\system32\svchost.exe[1504] msvcrt.dll!system 7604804B 5 Bytes JMP 00190044
.text C:\Windows\system32\svchost.exe[1504] msvcrt.dll!_creat 7604BBE1 5 Bytes JMP 00190029
.text C:\Windows\system32\svchost.exe[1504] msvcrt.dll!_open 7604D106 5 Bytes JMP 00190FEF
.text C:\Windows\system32\svchost.exe[1504] msvcrt.dll!_wcreat 7604D326 5 Bytes JMP 00190FDE
.text C:\Windows\system32\svchost.exe[1504] msvcrt.dll!_wopen 7604D501 5 Bytes JMP 00190018
.text C:\Windows\system32\svchost.exe[1504] ADVAPI32.dll!RegCreateKeyExA 772D39AB 5 Bytes JMP 00DD0047
.text C:\Windows\system32\svchost.exe[1504] ADVAPI32.dll!RegCreateKeyA 772D3BA9 5 Bytes JMP 00DD001B
.text C:\Windows\system32\svchost.exe[1504] ADVAPI32.dll!RegOpenKeyA 772D89C7 5 Bytes JMP 00DD0FE5
.text C:\Windows\system32\svchost.exe[1504] ADVAPI32.dll!RegCreateKeyW 772E391E 5 Bytes JMP 00DD0036
.text C:\Windows\system32\svchost.exe[1504] ADVAPI32.dll!RegCreateKeyExW 772E41F1 5 Bytes JMP 00DD0058
.text C:\Windows\system32\svchost.exe[1504] ADVAPI32.dll!RegOpenKeyExA 772E7C42 5 Bytes JMP 00DD0FB9
.text C:\Windows\system32\svchost.exe[1504] ADVAPI32.dll!RegOpenKeyW 772EE2B5 5 Bytes JMP 00DD0FCA
.text C:\Windows\system32\svchost.exe[1504] ADVAPI32.dll!RegOpenKeyExW 772F7BA1 5 Bytes JMP 00DD0000
.text C:\Windows\system32\svchost.exe[1504] WS2_32.dll!socket 776D36D1 5 Bytes JMP 00DE0000
.text C:\Windows\system32\svchost.exe[1732] ntdll.dll!NtCreateFile 77604224 5 Bytes JMP 00280FEF
.text C:\Windows\system32\svchost.exe[1732] ntdll.dll!NtCreateProcess 776042E4 5 Bytes JMP 00280FD4
.text C:\Windows\system32\svchost.exe[1732] ntdll.dll!NtProtectVirtualMemory 77604B84 5 Bytes JMP 0028000A
.text C:\Windows\system32\svchost.exe[1732] kernel32.dll!GetStartupInfoW 75E71929 5 Bytes JMP 0029006E
.text C:\Windows\system32\svchost.exe[1732] kernel32.dll!GetStartupInfoA 75E719C9 5 Bytes JMP 00290053
.text C:\Windows\system32\svchost.exe[1732] kernel32.dll!CreateProcessW 75E71BF3 5 Bytes JMP 0029009A
.text C:\Windows\system32\svchost.exe[1732] kernel32.dll!CreateProcessA 75E71C28 5 Bytes JMP 00290F03
.text C:\Windows\system32\svchost.exe[1732] kernel32.dll!VirtualProtect 75E71DC3 5 Bytes JMP 00290F4D
.text C:\Windows\system32\svchost.exe[1732] kernel32.dll!CreateNamedPipeA 75E72EF5 5 Bytes JMP 00290FD4
.text C:\Windows\system32\svchost.exe[1732] kernel32.dll!CreateNamedPipeW 75E75C0C 5 Bytes JMP 00290FB9
.text C:\Windows\system32\svchost.exe[1732] kernel32.dll!CreatePipe 75E98F06 5 Bytes JMP 00290F28
.text C:\Windows\system32\svchost.exe[1732] kernel32.dll!LoadLibraryExW 75E9927C 5 Bytes JMP 00290F5E
.text C:\Windows\system32\svchost.exe[1732] kernel32.dll!LoadLibraryW 75E99400 5 Bytes JMP 00290F8A
.text C:\Windows\system32\svchost.exe[1732] kernel32.dll!LoadLibraryExA 75E99554 5 Bytes JMP 00290F79
.text C:\Windows\system32\svchost.exe[1732] kernel32.dll!LoadLibraryA 75E9957C 5 Bytes JMP 0029001B
.text C:\Windows\system32\svchost.exe[1732] kernel32.dll!VirtualProtectEx 75E9DC52 5 Bytes JMP 00290042
.text C:\Windows\system32\svchost.exe[1732] kernel32.dll!GetProcAddress 75EB925B 5 Bytes JMP 002900B5
.text C:\Windows\system32\svchost.exe[1732] kernel32.dll!CreateFileW 75EBB0EB 1 Byte [E9]
.text C:\Windows\system32\svchost.exe[1732] kernel32.dll!CreateFileW 75EBB0EB 5 Bytes JMP 00290FEF
.text C:\Windows\system32\svchost.exe[1732] kernel32.dll!CreateFileA 75EBD07F 5 Bytes JMP 0029000A
.text C:\Windows\system32\svchost.exe[1732] kernel32.dll!WinExec 75F060CF 5 Bytes JMP 0029007F
.text C:\Windows\system32\svchost.exe[1732] msvcrt.dll!_wsystem 76047F2F 5 Bytes JMP 00820F89
.text C:\Windows\system32\svchost.exe[1732] msvcrt.dll!system 7604804B 5 Bytes JMP 00820F9A
.text C:\Windows\system32\svchost.exe[1732] msvcrt.dll!_creat 7604BBE1 5 Bytes JMP 00820000
.text C:\Windows\system32\svchost.exe[1732] msvcrt.dll!_open 7604D106 5 Bytes JMP 00820FE3
.text C:\Windows\system32\svchost.exe[1732] msvcrt.dll!_wcreat 7604D326 5 Bytes JMP 00820FAB
.text C:\Windows\system32\svchost.exe[1732] msvcrt.dll!_wopen 7604D501 5 Bytes JMP 00820FC6
.text C:\Windows\system32\svchost.exe[1732] ADVAPI32.dll!RegCreateKeyExA 772D39AB 1 Byte [E9]
.text C:\Windows\system32\svchost.exe[1732] ADVAPI32.dll!RegCreateKeyExA 772D39AB 5 Bytes JMP 00830FAF
.text C:\Windows\system32\svchost.exe[1732] ADVAPI32.dll!RegCreateKeyA 772D3BA9 5 Bytes JMP 00830051
.text C:\Windows\system32\svchost.exe[1732] ADVAPI32.dll!RegOpenKeyA 772D89C7 5 Bytes JMP 00830FE5
.text C:\Windows\system32\svchost.exe[1732] ADVAPI32.dll!RegCreateKeyW 772E391E 5 Bytes JMP 00830FC0
.text C:\Windows\system32\svchost.exe[1732] ADVAPI32.dll!RegCreateKeyExW 772E41F1 5 Bytes JMP 0083006C
.text C:\Windows\system32\svchost.exe[1732] ADVAPI32.dll!RegOpenKeyExA 772E7C42 5 Bytes JMP 0083001B
.text C:\Windows\system32\svchost.exe[1732] ADVAPI32.dll!RegOpenKeyW 772EE2B5 5 Bytes JMP 0083000A
.text C:\Windows\system32\svchost.exe[1732] ADVAPI32.dll!RegOpenKeyExW 772F7BA1 5 Bytes JMP 00830036
.text C:\Windows\system32\svchost.exe[1732] WS2_32.dll!socket 776D36D1 5 Bytes JMP 0089000A
.text C:\Windows\system32\svchost.exe[1912] ntdll.dll!NtCreateFile 77604224 5 Bytes JMP 000B000A
.text C:\Windows\system32\svchost.exe[1912] ntdll.dll!NtCreateProcess 776042E4 5 Bytes JMP 000B0036
.text C:\Windows\system32\svchost.exe[1912] ntdll.dll!NtProtectVirtualMemory 77604B84 5 Bytes JMP 000B001B
.text C:\Windows\system32\svchost.exe[1912] kernel32.dll!GetStartupInfoW 75E71929 5 Bytes JMP 005E0F4B
.text C:\Windows\system32\svchost.exe[1912] kernel32.dll!GetStartupInfoA 75E719C9 5 Bytes JMP 005E009B
.text C:\Windows\system32\svchost.exe[1912] kernel32.dll!CreateProcessW 75E71BF3 5 Bytes JMP 005E00B6
.text C:\Windows\system32\svchost.exe[1912] kernel32.dll!CreateProcessA 75E71C28 5 Bytes JMP 005E0F1F
.text C:\Windows\system32\svchost.exe[1912] kernel32.dll!VirtualProtect 75E71DC3 5 Bytes JMP 005E0F77
.text C:\Windows\system32\svchost.exe[1912] kernel32.dll!CreateNamedPipeA 75E72EF5 5 Bytes JMP 005E0000
.text C:\Windows\system32\svchost.exe[1912] kernel32.dll!CreateNamedPipeW 75E75C0C 5 Bytes JMP 005E0011
.text C:\Windows\system32\svchost.exe[1912] kernel32.dll!CreatePipe 75E98F06 5 Bytes JMP 005E0076
.text C:\Windows\system32\svchost.exe[1912] kernel32.dll!LoadLibraryExW 75E9927C 5 Bytes JMP 005E0051
.text C:\Windows\system32\svchost.exe[1912] kernel32.dll!LoadLibraryW 75E99400 5 Bytes JMP 005E0F9E
.text C:\Windows\system32\svchost.exe[1912] kernel32.dll!LoadLibraryExA 75E99554 5 Bytes JMP 005E0040
.text C:\Windows\system32\svchost.exe[1912] kernel32.dll!LoadLibraryA 75E9957C 5 Bytes JMP 005E0FAF
.text C:\Windows\system32\svchost.exe[1912] kernel32.dll!VirtualProtectEx 75E9DC52 5 Bytes JMP 005E0F66
.text C:\Windows\system32\svchost.exe[1912] kernel32.dll!GetProcAddress 75EB925B 5 Bytes JMP 005E0EFA
.text C:\Windows\system32\svchost.exe[1912] kernel32.dll!CreateFileW 75EBB0EB 5 Bytes JMP 005E0FD4
.text C:\Windows\system32\svchost.exe[1912] kernel32.dll!CreateFileA 75EBD07F 5 Bytes JMP 005E0FE5
.text C:\Windows\system32\svchost.exe[1912] kernel32.dll!WinExec 75F060CF 5 Bytes JMP 005E0F3A
.text C:\Windows\system32\svchost.exe[1912] msvcrt.dll!_wsystem 76047F2F 5 Bytes JMP 00640042
.text C:\Windows\system32\svchost.exe[1912] msvcrt.dll!system 7604804B 5 Bytes JMP 00640031
.text C:\Windows\system32\svchost.exe[1912] msvcrt.dll!_creat 7604BBE1 5 Bytes JMP 00640FD2
.text C:\Windows\system32\svchost.exe[1912] msvcrt.dll!_open 7604D106 5 Bytes JMP 0064000C
.text C:\Windows\system32\svchost.exe[1912] msvcrt.dll!_wcreat 7604D326 5 Bytes JMP 00640FC1
.text C:\Windows\system32\svchost.exe[1912] msvcrt.dll!_wopen 7604D501 5 Bytes JMP 00640FEF
.text C:\Windows\system32\svchost.exe[1912] ADVAPI32.dll!RegCreateKeyExA 772D39AB 5 Bytes JMP 00650F9E
.text C:\Windows\system32\svchost.exe[1912] ADVAPI32.dll!RegCreateKeyA 772D3BA9 5 Bytes JMP 00650025
.text C:\Windows\system32\svchost.exe[1912] ADVAPI32.dll!RegOpenKeyA 772D89C7 5 Bytes JMP 00650FEF
.text C:\Windows\system32\svchost.exe[1912] ADVAPI32.dll!RegCreateKeyW 772E391E 5 Bytes JMP 00650036
.text C:\Windows\system32\svchost.exe[1912] ADVAPI32.dll!RegCreateKeyExW 772E41F1 5 Bytes JMP 00650F8D
.text C:\Windows\system32\svchost.exe[1912] ADVAPI32.dll!RegOpenKeyExA 772E7C42 5 Bytes JMP 00650FC3
.text C:\Windows\system32\svchost.exe[1912] ADVAPI32.dll!RegOpenKeyW 772EE2B5 5 Bytes JMP 00650FD4
.text C:\Windows\system32\svchost.exe[1912] ADVAPI32.dll!RegOpenKeyExW 772F7BA1 5 Bytes JMP 00650014
.text C:\Windows\system32\svchost.exe[1912] WS2_32.dll!socket 776D36D1 5 Bytes JMP 0066000A
.text C:\Windows\system32\svchost.exe[2052] ntdll.dll!NtCreateFile 77604224 5 Bytes JMP 008D0FEF
.text C:\Windows\system32\svchost.exe[2052] ntdll.dll!NtCreateProcess 776042E4 5 Bytes JMP 008D000A
.text C:\Windows\system32\svchost.exe[2052] ntdll.dll!NtProtectVirtualMemory 77604B84 5 Bytes JMP 008D0FD4
.text C:\Windows\system32\svchost.exe[2052] kernel32.dll!GetStartupInfoW 75E71929 5 Bytes JMP 008E0F50
.text C:\Windows\system32\svchost.exe[2052] kernel32.dll!GetStartupInfoA 75E719C9 5 Bytes JMP 008E0F61
.text C:\Windows\system32\svchost.exe[2052] kernel32.dll!CreateProcessW 75E71BF3 5 Bytes JMP 008E0F10
.text C:\Windows\system32\svchost.exe[2052] kernel32.dll!CreateProcessA 75E71C28 5 Bytes JMP 008E00B1
.text C:\Windows\system32\svchost.exe[2052] kernel32.dll!VirtualProtect 75E71DC3 5 Bytes JMP 008E0FA8
.text C:\Windows\system32\svchost.exe[2052] kernel32.dll!CreateNamedPipeA 75E72EF5 5 Bytes JMP 008E0FD4
.text C:\Windows\system32\svchost.exe[2052] kernel32.dll!CreateNamedPipeW 75E75C0C 5 Bytes JMP 008E0025
.text C:\Windows\system32\svchost.exe[2052] kernel32.dll!CreatePipe 75E98F06 5 Bytes JMP 008E0F72
.text C:\Windows\system32\svchost.exe[2052] kernel32.dll!LoadLibraryExW 75E9927C 5 Bytes JMP 008E0082
.text C:\Windows\system32\svchost.exe[2052] kernel32.dll!LoadLibraryW 75E99400 5 Bytes JMP 008E005B
.text C:\Windows\system32\svchost.exe[2052] kernel32.dll!LoadLibraryExA 75E99554 5 Bytes JMP 008E0FB9
.text C:\Windows\system32\svchost.exe[2052] kernel32.dll!LoadLibraryA 75E9957C 5 Bytes JMP 008E0040
.text C:\Windows\system32\svchost.exe[2052] kernel32.dll!VirtualProtectEx 75E9DC52 5 Bytes JMP 008E0F83
.text C:\Windows\system32\svchost.exe[2052] kernel32.dll!GetProcAddress 75EB925B 5 Bytes JMP 008E0EFF
.text C:\Windows\system32\svchost.exe[2052] kernel32.dll!CreateFileW 75EBB0EB 1 Byte [E9]
.text C:\Windows\system32\svchost.exe[2052] kernel32.dll!CreateFileW 75EBB0EB 5 Bytes JMP 008E0FEF
.text C:\Windows\system32\svchost.exe[2052] kernel32.dll!CreateFileA 75EBD07F 5 Bytes JMP 008E0000
.text C:\Windows\system32\svchost.exe[2052] kernel32.dll!WinExec 75F060CF 5 Bytes JMP 008E0F35
.text C:\Windows\system32\svchost.exe[2052] msvcrt.dll!_wsystem 76047F2F 5 Bytes JMP 008F0022
.text C:\Windows\system32\svchost.exe[2052] msvcrt.dll!system 7604804B 5 Bytes JMP 008F0F97
.text C:\Windows\system32\svchost.exe[2052] msvcrt.dll!_creat 7604BBE1 5 Bytes JMP 008F0011
.text C:\Windows\system32\svchost.exe[2052] msvcrt.dll!_open 7604D106 5 Bytes JMP 008F0000
.text C:\Windows\system32\svchost.exe[2052] msvcrt.dll!_wcreat 7604D326 5 Bytes JMP 008F0FB2
.text C:\Windows\system32\svchost.exe[2052] msvcrt.dll!_wopen 7604D501 5 Bytes JMP 008F0FE3
.text C:\Windows\system32\svchost.exe[2052] ADVAPI32.dll!RegCreateKeyExA 772D39AB 5 Bytes JMP 00900040
.text C:\Windows\system32\svchost.exe[2052] ADVAPI32.dll!RegCreateKeyA 772D3BA9 5 Bytes JMP 00900FAF
.text C:\Windows\system32\svchost.exe[2052] ADVAPI32.dll!RegOpenKeyA 772D89C7 5 Bytes JMP 00900FEF
.text C:\Windows\system32\svchost.exe[2052] ADVAPI32.dll!RegCreateKeyW 772E391E 5 Bytes JMP 00900F9E
.text C:\Windows\system32\svchost.exe[2052] ADVAPI32.dll!RegCreateKeyExW 772E41F1 5 Bytes JMP 00900051
.text C:\Windows\system32\svchost.exe[2052] ADVAPI32.dll!RegOpenKeyExA 772E7C42 5 Bytes JMP 0090001B
.text C:\Windows\system32\svchost.exe[2052] ADVAPI32.dll!RegOpenKeyW 772EE2B5 5 Bytes JMP 0090000A
.text C:\Windows\system32\svchost.exe[2052] ADVAPI32.dll!RegOpenKeyExW 772F7BA1 5 Bytes JMP 00900FC0
.text C:\Windows\system32\svchost.exe[2052] WS2_32.dll!socket 776D36D1 5 Bytes JMP 00910FEF
.text C:\Windows\System32\svchost.exe[2324] ntdll.dll!NtCreateFile 77604224 5 Bytes JMP 00050FE5
.text C:\Windows\System32\svchost.exe[2324] ntdll.dll!NtCreateProcess 776042E4 5 Bytes JMP 00050011
.text C:\Windows\System32\svchost.exe[2324] ntdll.dll!NtProtectVirtualMemory 77604B84 5 Bytes JMP 00050000
.text C:\Windows\System32\svchost.exe[2324] kernel32.dll!GetStartupInfoW 75E71929 5 Bytes JMP 00070F8B
.text C:\Windows\System32\svchost.exe[2324] kernel32.dll!GetStartupInfoA 75E719C9 5 Bytes JMP 000700C7
.text C:\Windows\System32\svchost.exe[2324] kernel32.dll!CreateProcessW 75E71BF3 5 Bytes JMP 00070F55
.text C:\Windows\System32\svchost.exe[2324] kernel32.dll!CreateProcessA 75E71C28 5 Bytes JMP 000700F6
.text C:\Windows\System32\svchost.exe[2324] kernel32.dll!VirtualProtect 75E71DC3 5 Bytes JMP 00070FB7
.text C:\Windows\System32\svchost.exe[2324] kernel32.dll!CreateNamedPipeA 75E72EF5 5 Bytes JMP 00070FEF
.text C:\Windows\System32\svchost.exe[2324] kernel32.dll!CreateNamedPipeW 75E75C0C 5 Bytes JMP 0007004A
.text C:\Windows\System32\svchost.exe[2324] kernel32.dll!CreatePipe 75E98F06 5 Bytes JMP 00070F9C
.text C:\Windows\System32\svchost.exe[2324] kernel32.dll!LoadLibraryExW 75E9927C 5 Bytes JMP 00070091
.text C:\Windows\System32\svchost.exe[2324] kernel32.dll!LoadLibraryW 75E99400 5 Bytes JMP 00070065
.text C:\Windows\System32\svchost.exe[2324] kernel32.dll!LoadLibraryExA 75E99554 5 Bytes JMP 00070080
.text C:\Windows\System32\svchost.exe[2324] kernel32.dll!LoadLibraryA 75E9957C 5 Bytes JMP 00070FDE
.text C:\Windows\System32\svchost.exe[2324] kernel32.dll!VirtualProtectEx 75E9DC52 5 Bytes JMP 000700AC
.text C:\Windows\System32\svchost.exe[2324] kernel32.dll!GetProcAddress 75EB925B 5 Bytes JMP 00070107
.text C:\Windows\System32\svchost.exe[2324] kernel32.dll!CreateFileW 75EBB0EB 5 Bytes JMP 00070025
.text C:\Windows\System32\svchost.exe[2324] kernel32.dll!CreateFileA 75EBD07F 5 Bytes JMP 0007000A
.text C:\Windows\System32\svchost.exe[2324] kernel32.dll!WinExec 75F060CF 5 Bytes JMP 00070F7A
.text C:\Windows\System32\svchost.exe[2324] msvcrt.dll!_wsystem 76047F2F 5 Bytes JMP 00080F9E
.text C:\Windows\System32\svchost.exe[2324] msvcrt.dll!system 7604804B 5 Bytes JMP 00080FB9
.text C:\Windows\System32\svchost.exe[2324] msvcrt.dll!_creat 7604BBE1 5 Bytes JMP 00080FDE
.text C:\Windows\System32\svchost.exe[2324] msvcrt.dll!_open 7604D106 5 Bytes JMP 00080FEF
.text C:\Windows\System32\svchost.exe[2324] msvcrt.dll!_wcreat 7604D326 5 Bytes JMP 00080029
.text C:\Windows\System32\svchost.exe[2324] msvcrt.dll!_wopen 7604D501 5 Bytes JMP 0008000C
.text C:\Windows\System32\svchost.exe[2324] ADVAPI32.dll!RegCreateKeyExA 772D39AB 5 Bytes JMP 00090FA8
.text C:\Windows\System32\svchost.exe[2324] ADVAPI32.dll!RegCreateKeyA 772D3BA9 5 Bytes JMP 00090FB9
.text C:\Windows\System32\svchost.exe[2324] ADVAPI32.dll!RegOpenKeyA 772D89C7 5 Bytes JMP 00090FE5
.text C:\Windows\System32\svchost.exe[2324] ADVAPI32.dll!RegCreateKeyW 772E391E 5 Bytes JMP 00090040
.text C:\Windows\System32\svchost.exe[2324] ADVAPI32.dll!RegCreateKeyExW 772E41F1 5 Bytes JMP 00090F8D
.text C:\Windows\System32\svchost.exe[2324] ADVAPI32.dll!RegOpenKeyExA 772E7C42 5 Bytes JMP 00090FD4
.text C:\Windows\System32\svchost.exe[2324] ADVAPI32.dll!RegOpenKeyW 772EE2B5 5 Bytes JMP 0009000A
.text C:\Windows\System32\svchost.exe[2324] ADVAPI32.dll!RegOpenKeyExW 772F7BA1 5 Bytes JMP 00090025
.text C:\Windows\System32\svchost.exe[2324] WS2_32.dll!socket 776D36D1 5 Bytes JMP 00200000
.text C:\Windows\Explorer.EXE[3224] ntdll.dll!NtCreateFile 77604224 5 Bytes JMP 00C40FE5
.text C:\Windows\Explorer.EXE[3224] ntdll.dll!NtCreateProcess 776042E4 5 Bytes JMP 00C4001B
.text C:\Windows\Explorer.EXE[3224] ntdll.dll!NtProtectVirtualMemory 77604B84 5 Bytes JMP 00C4000A
.text C:\Windows\Explorer.EXE[3224] kernel32.dll!GetStartupInfoW 75E71929 5 Bytes JMP 063E00E1
.text C:\Windows\Explorer.EXE[3224] kernel32.dll!GetStartupInfoA 75E719C9 5 Bytes JMP 063E00D0
.text C:\Windows\Explorer.EXE[3224] kernel32.dll!CreateProcessW 75E71BF3 5 Bytes JMP 063E0117
.text C:\Windows\Explorer.EXE[3224] kernel32.dll!CreateProcessA 75E71C28 5 Bytes JMP 063E00F2
.text C:\Windows\Explorer.EXE[3224] kernel32.dll!VirtualProtect 75E71DC3 5 Bytes JMP 063E009A
.text C:\Windows\Explorer.EXE[3224] kernel32.dll!CreateNamedPipeA 75E72EF5 5 Bytes JMP 063E001B
.text C:\Windows\Explorer.EXE[3224] kernel32.dll!CreateNamedPipeW 75E75C0C 5 Bytes JMP 063E002C
.text C:\Windows\Explorer.EXE[3224] kernel32.dll!CreatePipe 75E98F06 5 Bytes JMP 063E0F9B
.text C:\Windows\Explorer.EXE[3224] kernel32.dll!LoadLibraryExW 75E9927C 5 Bytes JMP 063E0FC0
.text C:\Windows\Explorer.EXE[3224] kernel32.dll!LoadLibraryW 75E99400 5 Bytes JMP 063E0058
.text C:\Windows\Explorer.EXE[3224] kernel32.dll!LoadLibraryExA 75E99554 5 Bytes JMP 063E0073
.text C:\Windows\Explorer.EXE[3224] kernel32.dll!LoadLibraryA 75E9957C 5 Bytes JMP 063E0047
.text C:\Windows\Explorer.EXE[3224] kernel32.dll!VirtualProtectEx 75E9DC52 5 Bytes JMP 063E00B5
.text C:\Windows\Explorer.EXE[3224] kernel32.dll!GetProcAddress 75EB925B 5 Bytes JMP 063E0132
.text C:\Windows\Explorer.EXE[3224] kernel32.dll!CreateFileW 75EBB0EB 5 Bytes JMP 063E0000
.text C:\Windows\Explorer.EXE[3224] kernel32.dll!CreateFileA 75EBD07F 5 Bytes JMP 063E0FE5
.text C:\Windows\Explorer.EXE[3224] kernel32.dll!WinExec 75F060CF 5 Bytes JMP 063E0F80
.text C:\Windows\Explorer.EXE[3224] ADVAPI32.dll!RegCreateKeyExA 772D39AB 5 Bytes JMP 0641005B
.text C:\Windows\Explorer.EXE[3224] ADVAPI32.dll!RegCreateKeyA 772D3BA9 5 Bytes JMP 06410FCD
.text C:\Windows\Explorer.EXE[3224] ADVAPI32.dll!RegOpenKeyA 772D89C7 5 Bytes JMP 06410FEF
.text C:\Windows\Explorer.EXE[3224] ADVAPI32.dll!RegCreateKeyW 772E391E 5 Bytes JMP 0641004A
.text C:\Windows\Explorer.EXE[3224] ADVAPI32.dll!RegCreateKeyExW 772E41F1 5 Bytes JMP 06410F94
.text C:\Windows\Explorer.EXE[3224] ADVAPI32.dll!RegOpenKeyExA 772E7C42 5 Bytes JMP 06410FDE
.text C:\Windows\Explorer.EXE[3224] ADVAPI32.dll!RegOpenKeyW 772EE2B5 5 Bytes JMP 0641000A
.text C:\Windows\Explorer.EXE[3224] ADVAPI32.dll!RegOpenKeyExW 772F7BA1 5 Bytes JMP 06410039
.text C:\Windows\Explorer.EXE[3224] msvcrt.dll!_wsystem 76047F2F 5 Bytes JMP 063F0042
.text C:\Windows\Explorer.EXE[3224] msvcrt.dll!system 7604804B 5 Bytes JMP 063F0031
.text C:\Windows\Explorer.EXE[3224] msvcrt.dll!_creat 7604BBE1 5 Bytes JMP 063F0016
.text C:\Windows\Explorer.EXE[3224] msvcrt.dll!_open 7604D106 5 Bytes JMP 063F0FEF
.text C:\Windows\Explorer.EXE[3224] msvcrt.dll!_wcreat 7604D326 5 Bytes JMP 063F0FC1
.text C:\Windows\Explorer.EXE[3224] msvcrt.dll!_wopen 7604D501 5 Bytes JMP 063F0FD2
.text C:\Windows\Explorer.EXE[3224] WS2_32.dll!socket 776D36D1 5 Bytes JMP 06420FEF
.text C:\Windows\Explorer.EXE[3224] WININET.dll!InternetOpenA 76F14E33 5 Bytes JMP 06400000
.text C:\Windows\Explorer.EXE[3224] WININET.dll!InternetOpenUrlA 76F1BFCE 5 Bytes JMP 06400FCA
.text C:\Windows\Explorer.EXE[3224] WININET.dll!InternetOpenW 76F4C02E 5 Bytes JMP 06400FE5
.text C:\Windows\Explorer.EXE[3224] WININET.dll!InternetOpenUrlW 76F7D70A 5 Bytes JMP 06400FAF
.text C:\Windows\system32\svchost.exe[5676] ntdll.dll!NtCreateFile 77604224 5 Bytes JMP 00170FEF
.text C:\Windows\system32\svchost.exe[5676] ntdll.dll!NtCreateProcess 776042E4 5 Bytes JMP 00170FCA
.text C:\Windows\system32\svchost.exe[5676] ntdll.dll!NtProtectVirtualMemory 77604B84 5 Bytes JMP 00170000
.text C:\Windows\system32\svchost.exe[5676] kernel32.dll!GetStartupInfoW 75E71929 5 Bytes JMP 00180F0D
.text C:\Windows\system32\svchost.exe[5676] kernel32.dll!GetStartupInfoA 75E719C9 5 Bytes JMP 00180F28
.text C:\Windows\system32\svchost.exe[5676] kernel32.dll!CreateProcessW 75E71BF3 5 Bytes JMP 00180EDE
.text C:\Windows\system32\svchost.exe[5676] kernel32.dll!CreateProcessA 75E71C28 5 Bytes JMP 00180075
.text C:\Windows\system32\svchost.exe[5676] kernel32.dll!VirtualProtect 75E71DC3 5 Bytes JMP 00180F54
.text C:\Windows\system32\svchost.exe[5676] kernel32.dll!CreateNamedPipeA 75E72EF5 5 Bytes JMP 00180011
.text C:\Windows\system32\svchost.exe[5676] kernel32.dll!CreateNamedPipeW 75E75C0C 5 Bytes JMP 00180022
.text C:\Windows\system32\svchost.exe[5676] kernel32.dll!CreatePipe 75E98F06 5 Bytes JMP 00180053
.text C:\Windows\system32\svchost.exe[5676] kernel32.dll!LoadLibraryExW 75E9927C 5 Bytes JMP 00180F65
.text C:\Windows\system32\svchost.exe[5676] kernel32.dll!LoadLibraryW 75E99400 5 Bytes JMP 00180F91
.text C:\Windows\system32\svchost.exe[5676] kernel32.dll!LoadLibraryExA 75E99554 5 Bytes JMP 00180F80
.text C:\Windows\system32\svchost.exe[5676] kernel32.dll!LoadLibraryA 75E9957C 5 Bytes JMP 00180FB6
.text C:\Windows\system32\svchost.exe[5676] kernel32.dll!VirtualProtectEx 75E9DC52 5 Bytes JMP 00180F43
.text C:\Windows\system32\svchost.exe[5676] kernel32.dll!GetProcAddress 75EB925B 5 Bytes JMP 00180086
.text C:\Windows\system32\svchost.exe[5676] kernel32.dll!CreateFileW 75EBB0EB 5 Bytes JMP 00180FDB
.text C:\Windows\system32\svchost.exe[5676] kernel32.dll!CreateFileA 75EBD07F 5 Bytes JMP 00180000
.text C:\Windows\system32\svchost.exe[5676] kernel32.dll!WinExec 75F060CF 5 Bytes JMP 00180064
.text C:\Windows\system32\svchost.exe[5676] msvcrt.dll!_wsystem 76047F2F 5 Bytes JMP 006A0070
.text C:\Windows\system32\svchost.exe[5676] msvcrt.dll!system 7604804B 5 Bytes JMP 006A0055
.text C:\Windows\system32\svchost.exe[5676] msvcrt.dll!_creat 7604BBE1 5 Bytes JMP 006A0FEF
.text C:\Windows\system32\svchost.exe[5676] msvcrt.dll!_open 7604D106 5 Bytes JMP 006A0000
.text C:\Windows\system32\svchost.exe[5676] msvcrt.dll!_wcreat 7604D326 5 Bytes JMP 006A0044
.text C:\Windows\system32\svchost.exe[5676] msvcrt.dll!_wopen 7604D501 5 Bytes JMP 006A0029
.text C:\Windows\system32\svchost.exe[5676] ADVAPI32.dll!RegCreateKeyExA 772D39AB 5 Bytes JMP 007D0F86
.text C:\Windows\system32\svchost.exe[5676] ADVAPI32.dll!RegCreateKeyA 772D3BA9 5 Bytes JMP 007D0FB2
.text C:\Windows\system32\svchost.exe[5676] ADVAPI32.dll!RegOpenKeyA 772D89C7 5 Bytes JMP 007D0FEF
.text C:\Windows\system32\svchost.exe[5676] ADVAPI32.dll!RegCreateKeyW 772E391E 5 Bytes JMP 007D0F97
.text C:\Windows\system32\svchost.exe[5676] ADVAPI32.dll!RegCreateKeyExW 772E41F1 5 Bytes JMP 007D0F6B
.text C:\Windows\system32\svchost.exe[5676] ADVAPI32.dll!RegOpenKeyExA 772E7C42 5 Bytes JMP 007D0FC3
.text C:\Windows\system32\svchost.exe[5676] ADVAPI32.dll!RegOpenKeyW 772EE2B5 5 Bytes JMP 007D0FDE
.text C:\Windows\system32\svchost.exe[5676] ADVAPI32.dll!RegOpenKeyExW 772F7BA1 5 Bytes JMP 007D001E
.text C:\Windows\system32\svchost.exe[5676] WS2_32.dll!socket 776D36D1 5 Bytes JMP 007E000A
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\system32\mfevtps.exe[604] @ C:\Windows\system32\CRYPT32.dll [ADVAPI32.dll!RegQueryValueExW] [0100A4B0] C:\Windows\system32\mfevtps.exe (McAfee Process Validation Service/McAfee, Inc.)
IAT C:\Windows\system32\mfevtps.exe[604] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [0100A510] C:\Windows\system32\mfevtps.exe (McAfee Process Validation Service/McAfee, Inc.)
IAT C:\Windows\Explorer.EXE[3224] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [73877817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3224] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [738CA86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3224] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7387BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3224] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [7386F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3224] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [738775E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3224] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [7386E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3224] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [738A8395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3224] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [7387DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3224] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [7386FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3224] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [7386FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3224] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [738671CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3224] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [738FCAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3224] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [7389C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3224] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [7386D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3224] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [73866853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3224] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [7386687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3224] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [73872AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [613473FB] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6134732D] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [61346BCD] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6134736D] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [613473FB] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6134732D] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6134736D] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [61346BCD] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\USER32.dll [GDI32.dll!GetStockObject] [61345FBC] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6134736D] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [613473FB] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6134732D] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [61346BCD] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\SHLWAPI.dll [GDI32.dll!GetStockObject] [61345FBC] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [61345EF7] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [613467E4] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [613467E4] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [613473FB] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [61346BCD] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6134736D] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6134732D] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!GetStockObject] [61345FBC] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [61345E64] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [61345E26] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColorBrush] [61345FC2] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColor] [61345EF7] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\SHELL32.dll [USER32.dll!DefWindowProcW] [613467E4] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\SHELL32.dll [USER32.dll!AnimateWindow] [61346057] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!CreateFileA] [61346142] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!CreateFileW] [6134609C] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\SAMLIB.dll [KERNEL32.dll!LoadLibraryA] [6134732D] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
IAT C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe[4824] @ C:\Windows\system32\SAMLIB.dll [KERNEL32.dll!GetProcAddress] [61346BCD] C:\PROGRA~1\Yahoo!\MESSEN~1\yui.dll
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs MOBK.sys (Mozy Change Monitor Filter Driver/Mozy, Inc.)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp mfewfpk.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\Udp mfewfpk.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
---- EOF - GMER 1.0.15 ----
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-11-05 01:00:49
-----------------------------
01:00:49.614 OS Version: Windows 6.0.6002 Service Pack 2
01:00:49.614 Number of processors: 1 586 0x1601
01:00:49.616 ComputerName: HOME UserName:
01:00:50.720 Initialize success
01:00:58.033 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-4
01:00:58.035 Disk 0 Vendor: Hitachi_HTS542512K9SA00 BB2OC33P Size: 114473MB BusType: 3
01:01:00.337 Disk 0 MBR read successfully
01:01:00.343 Disk 0 MBR scan
01:01:00.346 Disk 0 Windows VISTA default MBR code
01:01:00.429 Disk 0 scanning sectors +234440704
01:01:00.637 Disk 0 scanning C:\Windows\system32\drivers
01:01:34.715 Service scanning
01:01:36.651 Modules scanning
01:02:21.337 Disk 0 trace - called modules:
01:02:21.380 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS hal.dll PCIIDEX.SYS msahci.sys
01:02:21.384 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85dcdac8]
01:02:21.388 3 CLASSPNP.SYS[835798b3] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-4[0x857da390]
01:02:21.393 Scan finished successfully
01:02:32.858 Disk 0 MBR has been saved successfully to "C:\Users\cliff\Downloads\MBR.dat"
01:02:32.886 The log file has been saved successfully to "C:\Users\cliff\Downloads\aswMBR.txt"