Thanks very much for your assistance, Carolyn. Here are the logs you requested; I will patiently await your response:
DDS (Ver_09-02-01.01) - NTFSx86
Run by [removed] at 10:58:48.59 on Sun 03/15/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1093 [GMT -7:00]
AV: McAfee VirusScan *On-access scanning enabled* (Updated)
FW: McAfee Personal Firewall *enabled*
============== Running Processes ===============
F:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
F:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
F:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Google\Update\GoogleUpdate.exe
F:\Program Files\McAfee.com\Agent\mcagent.exe
F:\Program Files\ASUS\AI Nap\AiNap.exe
F:\WINDOWS\system32\RUNDLL32.EXE
F:\WINDOWS\essspk.exe
F:\Program Files\AMD\RAIDXpert\jetty\extra\win32\Wrapper.exe
F:\WINDOWS\RTHDCPL.EXE
F:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
F:\Program Files\Java\jre6\bin\jqs.exe
F:\Program Files\Roxio\CinePlayer\DMXLauncher.exe
F:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
F:\Program Files\AMD\RAIDXpert\_jvm\bin\java.exe
F:\Program Files\Common Files\LightScribe\LSSrvc.exe
F:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
F:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe
F:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
F:\Program Files\McAfee\SiteAdvisor\McSACore.exe
F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
F:\WINDOWS\system32\ctfmon.exe
F:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
F:\Program Files\Messenger\msmsgs.exe
f:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
f:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
F:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
F:\Program Files\McAfee\MPF\MPFSrv.exe
F:\WINDOWS\system32\nvsvc32.exe
F:\Program Files\Logitech\SetPoint\SetPoint.exe
F:\WINDOWS\system32\IoctlSvc.exe
F:\Program Files\Windows Desktop Search\WindowsSearch.exe
F:\WINDOWS\System32\snmp.exe
F:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
F:\WINDOWS\system32\svchost.exe -k imgsvc
F:\WINDOWS\system32\fxssvc.exe
F:\WINDOWS\system32\SearchIndexer.exe
F:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
F:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
F:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
F:\WINDOWS\system32\SearchProtocolHost.exe
F:\Documents and Settings\Study\Desktop\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - f:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - f:\progra~1\spybot~1\SDHelper.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - f:\program files\mcafee\virusscan\scriptsn.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - f:\program files\google\googletoolbarnotifier\4.1.805.4472\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - f:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - f:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - f:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - f:\progra~1\mcafee\sitead~1\mcieplg.dll
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "f:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [Uniblue RegistryBooster 2009] f:\program files\uniblue\registrybooster\RegistryBooster.exe /S
uRun: [LightScribe Control Panel] f:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [SpybotSD TeaTimer] f:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] f:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "f:\program files\messenger\msmsgs.exe" /background
mRun: [IMJPMIG8.1] "f:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [PHIME2002ASync] f:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] f:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [mcagent_exe] f:\program files\mcafee.com\agent\mcagent.exe /runkey
mRun: [Adobe Reader Speed Launcher] "f:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [MediaFace Integration] f:\program files\fellowes\mediaface 4.2\SetHook.exe
mRun: [Ai Nap] "f:\program files\asus\ai nap\AiNap.exe"
mRun: [NvMediaCenter] RUNDLL32.EXE f:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [EssSpkPhone] essspk.exe -c
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Ad-Watch] f:\program files\lavasoft\ad-aware\AAWTray.exe
mRun: [NvCplDaemon] RUNDLL32.EXE f:\windows\system32\NvCpl.dll,NvStartup
mRun: [<NO NAME>]
mRun: [RoxWatchTray] "f:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [DMXLauncher] "f:\program files\roxio\cineplayer\DMXLauncher.exe"
mRun: [RoxioDragToDisc] "f:\program files\roxio\drag-to-disc\DrgToDsc.exe"
StartupFolder: f:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - f:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: f:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - f:\program files\logitech\setpoint\SetPoint.exe
StartupFolder: f:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - f:\program files\windows desktop search\WindowsSearch.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - f:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - f:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - f:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - f:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1224128433955
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1224135004234
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - hxxp://www.superadblocker.com/activex/sabspx.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - f:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: LBTWlgn - f:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - f:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - f:\program files\windows desktop search\MSNLNamespaceMgr.dll
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;f:\windows\system32\drivers\Lbd.sys [2009-3-9 64160]
R1 mfehidk;McAfee Inc. mfehidk;f:\windows\system32\drivers\mfehidk.sys [2008-10-17 201320]
R2 AMDRAIDXpert;AMD RAIDXpert;f:\program files\amd\raidxpert\jetty\extra\win32\Wrapper.exe [2003-9-29 110592]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;f:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 921936]
R2 LBeepKE;LBeepKE;f:\windows\system32\drivers\LBeepKE.sys [2008-12-3 10384]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;f:\program files\mcafee\siteadvisor\McSACore.exe [2008-10-17 206096]
R2 McProxy;McAfee Proxy Service;f:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2008-10-17 359248]
R2 McShield;McAfee Real-time Scanner;f:\progra~1\mcafee\viruss~1\mcshield.exe [2008-10-17 144704]
R3 McSysmon;McAfee SystemGuards;f:\progra~1\mcafee\viruss~1\mcsysmon.exe [2008-10-17 695624]
R3 mfeavfk;McAfee Inc. mfeavfk;f:\windows\system32\drivers\mfeavfk.sys [2008-10-17 79304]
R3 mfebopk;McAfee Inc. mfebopk;f:\windows\system32\drivers\mfebopk.sys [2008-10-17 35240]
R3 mfesmfk;McAfee Inc. mfesmfk;f:\windows\system32\drivers\mfesmfk.sys [2008-10-17 40488]
S2 gupdate1c98cb92d37006c;Google Update Service (gupdate1c98cb92d37006c);f:\program files\google\update\GoogleUpdate.exe [2009-2-11 133104]
S3 mferkdk;McAfee Inc. mferkdk;f:\windows\system32\drivers\mferkdk.sys [2008-10-17 33832]
S3 papycpu;papycpu;f:\windows\system32\drivers\papycpu.sys [2008-11-29 1888]
=============== Created Last 30 ================
2009-03-10 20:51 56,056 a------- f:\windows\system32\DLAAPI_W.DLL
2009-03-10 20:51 51,768 a------- f:\windows\system32\drivers\DRVNDDM.SYS
2009-03-10 20:51 28,120 a------- f:\windows\system32\drivers\DLARTL_M.SYS
2009-03-10 20:51 12,856 a------- f:\windows\system32\drivers\DLACDBHM.SYS
2009-03-10 20:51 92,920 a------- f:\windows\DLA.EXE
2009-03-10 20:51 <DIR> --d----- f:\windows\system32\DLA
2009-03-10 20:50 <DIR> --d----- f:\program files\common files\SureThing Shared
2009-03-09 11:15 15,688 a------- f:\windows\system32\lsdelete.exe
2009-03-09 10:46 <DIR> --d----- f:\program files\Spybot - Search & Destroy
2009-03-09 10:46 <DIR> --d----- f:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-03-09 10:31 64,160 a------- f:\windows\system32\drivers\Lbd.sys
2009-03-09 09:42 <DIR> -cd-h--- f:\docume~1\alluse~1\applic~1\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-03-09 09:42 <DIR> --d----- f:\program files\Lavasoft
2009-03-09 09:19 <DIR> --d----- f:\program files\SpywareBlaster
2009-03-07 12:14 <DIR> --d----- f:\program files\Trend Micro
2009-03-05 20:28 <DIR> --d----- f:\docume~1\study\applic~1\McAfee
2009-03-05 17:16 <DIR> --d----- f:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-03-05 17:15 <DIR> --d----- f:\program files\SUPERAntiSpyware
2009-03-05 17:15 <DIR> --d----- f:\docume~1\study\applic~1\SUPERAntiSpyware.com
2009-02-28 20:15 118,132 a------- F:\979772-US_Army_maps_v_16.kmz
2009-02-24 15:38 1,089,593 -c------ f:\windows\system32\dllcache\ntprint.cat
2009-02-19 19:16 <DIR> --d----- f:\program files\QuickMediaConverter
2009-02-18 22:57 <DIR> --d----- f:\docume~1\study\applic~1\AVS4YOU
2009-02-18 22:57 <DIR> --d----- f:\docume~1\alluse~1\applic~1\AVS4YOU
2009-02-18 22:56 <DIR> --d----- f:\program files\common files\AVSMedia
2009-02-18 22:56 1,700,352 a------- f:\windows\system32\GdiPlus.dll
2009-02-18 22:56 24,576 a------- f:\windows\system32\msxml3a.dll
2009-02-18 22:56 <DIR> --d----- f:\program files\AVS4YOU
2009-02-17 14:10 <DIR> --d----- F:\71e30bc844ae2a386853
2009-02-16 13:31 <DIR> --d----- f:\docume~1\study\applic~1\SuperNZB
2009-02-16 13:30 <DIR> --d----- f:\program files\SuperNZB
2009-02-15 18:23 <DIR> --d----- f:\program files\LightScribe Template Labeler
==================== Find3M ====================
2009-03-10 10:42 410,984 a------- f:\windows\system32\deploytk.dll
2009-02-09 04:13 1,846,784 a------- f:\windows\system32\win32k.sys
2008-12-20 16:15 826,368 a------- f:\windows\system32\wininet.dll
============= FINISH: 10:59:28.54 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-02-01.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 10/15/2008 7:37:35 PM
System Uptime: 3/13/2009 7:53:01 PM (39 hours ago)
Motherboard: ASUSTeK Computer INC. | | M3A78-EM
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 6000+ | AM2 | 3113/200mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 233 GiB total, 126.638 GiB free.
E: is FIXED (NTFS) - 6 GiB total, 5.883 GiB free.
F: is FIXED (NTFS) - 75 GiB total, 46.397 GiB free.
G: is FIXED (NTFS) - 70 GiB total, 22.51 GiB free.
H: is FIXED (NTFS) - 70 GiB total, 23.1 GiB free.
I: is FIXED (NTFS) - 37 GiB total, 16.26 GiB free.
X: is CDROM ()
Y: is CDROM ()
Z: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP1: 3/5/2009 7:14:52 PM - System Checkpoint
RP2: 3/5/2009 7:16:12 PM - Post-Trojan Removal Attempts
RP3: 3/6/2009 7:54:01 PM - System Checkpoint
RP4: 3/7/2009 12:04:48 PM - Removed Roxio Update Manager
RP5: 3/7/2009 12:07:53 PM - Removed Roxio Easy Media Creator
RP6: 3/8/2009 8:16:31 AM - Uniblue RegistryBooster 2009
RP7: 3/9/2009 5:49:03 AM - Removed SUPERAntiSpyware Free Edition
RP8: 3/9/2009 10:15:35 AM - Ad-Aware Checkpoint
RP9: 3/9/2009 10:29:27 AM - Uniblue RegistryBooster 2009
RP10: 3/10/2009 9:41:37 AM - Removed Java(TM) 6 Update 11
RP11: 3/10/2009 9:42:03 AM - Installed Java(TM) 6 Update 12
RP12: 3/10/2009 11:28:27 AM - Uniblue RegistryBooster 2009
RP13: 3/10/2009 7:46:27 PM - Installed Roxio Easy Media Creator
RP14: 3/10/2009 9:00:14 PM - Software Distribution Service 3.0
RP15: 3/12/2009 4:00:58 PM - System Checkpoint
RP16: 3/13/2009 4:10:59 PM - System Checkpoint
RP17: 3/14/2009 4:21:51 PM - System Checkpoint
RP18: 3/15/2009 6:41:34 AM - Software Distribution Service 3.0
==== Installed Programs ======================
2007 Microsoft Office Suite Service Pack 1 (SP1)
Ad-Aware
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Photoshop Elements 2.0
Adobe Reader 9
AI Nap
ASUSUpdate
Canon iP4500 series
CDDRV_Installer
Colin McRae Rally 2
Colin McRae Rally 2005
Cool & Quiet
Critical Update for Windows Media Player 11 (KB959772)
EPSON Copy Utility 3
EPSON Scan
Google Earth
Google Update Helper
Google Updater
Grand Prix Legends
GTR
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Java(TM) 6 Update 12
Java(TM) 6 Update 7
KhalInstallWrapper
LightScribe System Software 1.17.90.1
LightScribe Template Labeler
Logitech SetPoint
McAfee SecurityCenter
MediaFACE 4.2
MediaFACE 4.2 Image Library
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Midtown Madness
Microsoft Monster Truck Madness 2
Microsoft National Language Support Downlevel APIs
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Pinball Arcade
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Nero 7 Ultra Edition
neroxml
NVIDIA Drivers
PC Probe II
Player
RAIDXpert
Rally Trophy
REALTEK GbE & FE Ethernet PCI-E NIC Driver
Realtek High Definition Audio Driver
Roxio Drag-to-Disc
Roxio Easy Media Creator
Security Update for 2007 Microsoft Office System (KB951550)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for 2007 Microsoft Office System (KB958439)
Security Update for Microsoft Office Excel 2007 (KB958437)
Security Update for Microsoft Office OneNote 2007 (KB950130)
Security Update for Microsoft Office PowerPoint 2007 (KB951338)
Security Update for Microsoft Office system 2007 (KB954326)
Security Update for Microsoft Office system 2007 (KB956828)
Security Update for Microsoft Office Word 2007 (KB956358)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Shockwave
SideWinder Force Feedback Wheel (USB)
Sierra Utilities
Spybot - Search & Destroy
SpywareBlaster 4.1
SuperNZB v3.2.1
U.S. Robotics V.92 PCI Faxmodem
Uniblue RegistryBooster 2009
Update for Microsoft Office 2007 Help for Common Features (KB957244)
Update for Microsoft Office Excel 2007 Help (KB957242)
Update for Microsoft Office OneNote 2007 Help (KB957245)
Update for Microsoft Office PowerPoint 2007 Help (KB957247)
Update for Microsoft Office Word 2007 Help (KB957252)
Update for Microsoft Script Editor Help (KB957253)
Update for Office 2007 (KB946691)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Player 11
Windows Search 4.0
Windows XP Service Pack 3
==== Event Viewer Messages From Past Week ========
3/9/2009 5:49:06 AM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
3/9/2009 10:32:14 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the mcmscsvc service.
==== End Of File ===========================
GMER 1.0.15.14939 - http://www.gmer.net
Rootkit scan 2009-03-15 13:05:43
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xBA92887E]
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xBA928C10]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xB2F5B9AA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xB2F5B958]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xB2F5B96C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xB2F5BA57]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xB2F5BA83]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xB2F5BAF1]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xB2F5BADB]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xB2F5B9EA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xB2F5BB1D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xB2F5BA2D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xB2F5B930]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xB2F5B944]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xB2F5B9BE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xB2F5BB59]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xB2F5BAC5]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xB2F5BAAF]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xB2F5BA6D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xB2F5BB45]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xB2F5BB31]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xB2F5B996]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xB2F5B982]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xB2F5BA19]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xB2F5BB07]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xB2F5BA00]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xB2F5B9D4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwYieldExecution 80504AE8 7 Bytes JMP B2F5B9D8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtCreateFile 80579084 5 Bytes JMP B2F5B9AE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 805B2006 7 Bytes JMP B2F5B9EE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805B2E14 5 Bytes JMP B2F5BA04 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 805B83E6 7 Bytes JMP B2F5B9C2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess 805CB408 5 Bytes JMP B2F5B934 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 805CB694 5 Bytes JMP B2F5B948 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetInformationProcess 805CDE52 5 Bytes JMP B2F5B986 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805D1142 7 Bytes JMP B2F5B970 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcess 805D11F8 5 Bytes JMP B2F5B95C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetContextThread 805D1702 5 Bytes JMP B2F5B99A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805D29AA 5 Bytes JMP B2F5BA1D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryValueKey 806219CA 7 Bytes JMP B2F5BAB3 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnloadKey 80622042 7 Bytes JMP B2F5BB0B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryMultipleValueKey 806228E0 7 Bytes JMP B2F5BAC9 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRenameKey 806231B4 7 Bytes JMP B2F5BA71 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteKey 80623C22 7 Bytes JMP B2F5BA5B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteValueKey 80623DF2 7 Bytes JMP B2F5BA87 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateKey 80623FD2 7 Bytes JMP B2F5BAF5 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateValueKey 8062423C 7 Bytes JMP B2F5BADF \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwOpenKey 80624B64 5 Bytes JMP B2F5BA31 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryKey 80624E8A 7 Bytes JMP B2F5BB5D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRestoreKey 8062514A 5 Bytes JMP B2F5BB35 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwReplaceKey 8062583E 5 Bytes JMP B2F5BB49 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwNotifyChangeKey 80625958 5 Bytes JMP B2F5BB21 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
---- User code sections - GMER 1.0.15 ----
.text F:\Program Files\Messenger\msmsgs.exe[192] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 021C0000
.text F:\Program Files\Messenger\msmsgs.exe[192] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 021C0073
.text F:\Program Files\Messenger\msmsgs.exe[192] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 021C0F7E
.text F:\Program Files\Messenger\msmsgs.exe[192] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 021C0058
.text F:\Program Files\Messenger\msmsgs.exe[192] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 021C0047
.text F:\Program Files\Messenger\msmsgs.exe[192] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 021C0FAF
.text F:\Program Files\Messenger\msmsgs.exe[192] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 021C0F41
.text F:\Program Files\Messenger\msmsgs.exe[192] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 021C0F52
.text F:\Program Files\Messenger\msmsgs.exe[192] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 021C00C9
.text F:\Program Files\Messenger\msmsgs.exe[192] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 021C0F26
.text F:\Program Files\Messenger\msmsgs.exe[192] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 021C0F0B
.text F:\Program Files\Messenger\msmsgs.exe[192] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 021C002C
.text F:\Program Files\Messenger\msmsgs.exe[192] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 021C0FDB
.text F:\Program Files\Messenger\msmsgs.exe[192] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 021C0F63
.text F:\Program Files\Messenger\msmsgs.exe[192] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 021C001B
.text F:\Program Files\Messenger\msmsgs.exe[192] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 021C0FCA
.text F:\Program Files\Messenger\msmsgs.exe[192] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 021C00A4
.text F:\Program Files\Messenger\msmsgs.exe[192] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00FE0F9C
.text F:\Program Files\Messenger\msmsgs.exe[192] msvcrt.dll!system 77C293C7 5 Bytes JMP 00FE0027
.text F:\Program Files\Messenger\msmsgs.exe[192] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00FE000C
.text F:\Program Files\Messenger\msmsgs.exe[192] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00FE0FEF
.text F:\Program Files\Messenger\msmsgs.exe[192] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00FE0FAD
.text F:\Program Files\Messenger\msmsgs.exe[192] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00FE0FDE
.text F:\Program Files\Messenger\msmsgs.exe[192] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00FF001B
.text F:\Program Files\Messenger\msmsgs.exe[192] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00FF006C
.text F:\Program Files\Messenger\msmsgs.exe[192] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00FF0FD4
.text F:\Program Files\Messenger\msmsgs.exe[192] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00FF000A
.text F:\Program Files\Messenger\msmsgs.exe[192] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00FF0FA5
.text F:\Program Files\Messenger\msmsgs.exe[192] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00FF0FEF
.text F:\Program Files\Messenger\msmsgs.exe[192] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00FF0047
.text F:\Program Files\Messenger\msmsgs.exe[192] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00FF0036
.text F:\Program Files\Messenger\msmsgs.exe[192] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00F60000
.text F:\Program Files\Messenger\msmsgs.exe[192] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 021B0FEF
.text F:\Program Files\Messenger\msmsgs.exe[192] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 021B000A
.text F:\Program Files\Messenger\msmsgs.exe[192] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 021B0FDE
.text F:\Program Files\Messenger\msmsgs.exe[192] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 021B0FCD
.text f:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[544] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0041C340 f:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text f:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[544] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 0041C3C0 f:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text F:\WINDOWS\system32\services.exe[788] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01350FEF
.text F:\WINDOWS\system32\services.exe[788] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01350089
.text F:\WINDOWS\system32\services.exe[788] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01350F94
.text F:\WINDOWS\system32\services.exe[788] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01350078
.text F:\WINDOWS\system32\services.exe[788] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01350051
.text F:\WINDOWS\system32\services.exe[788] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01350FC0
.text F:\WINDOWS\system32\services.exe[788] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01350F4B
.text F:\WINDOWS\system32\services.exe[788] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01350F68
.text F:\WINDOWS\system32\services.exe[788] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01350F1F
.text F:\WINDOWS\system32\services.exe[788] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01350F30
.text F:\WINDOWS\system32\services.exe[788] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 013500DD
.text F:\WINDOWS\system32\services.exe[788] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 01350FAF
.text F:\WINDOWS\system32\services.exe[788] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 0135000A
.text F:\WINDOWS\system32\services.exe[788] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 01350F79
.text F:\WINDOWS\system32\services.exe[788] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 0135002C
.text F:\WINDOWS\system32\services.exe[788] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 0135001B
.text F:\WINDOWS\system32\services.exe[788] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 013500AE
.text F:\WINDOWS\system32\services.exe[788] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 01340011
.text F:\WINDOWS\system32\services.exe[788] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 01340069
.text F:\WINDOWS\system32\services.exe[788] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 01340000
.text F:\WINDOWS\system32\services.exe[788] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 01340FD4
.text F:\WINDOWS\system32\services.exe[788] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 0134004E
.text F:\WINDOWS\system32\services.exe[788] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 01340FEF
.text F:\WINDOWS\system32\services.exe[788] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 0134003D
.text F:\WINDOWS\system32\services.exe[788] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 0134002C
.text F:\WINDOWS\system32\services.exe[788] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01330FCA
.text F:\WINDOWS\system32\services.exe[788] msvcrt.dll!system 77C293C7 5 Bytes JMP 01330055
.text F:\WINDOWS\system32\services.exe[788] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01330FEF
.text F:\WINDOWS\system32\services.exe[788] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01330000
.text F:\WINDOWS\system32\services.exe[788] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01330044
.text F:\WINDOWS\system32\services.exe[788] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0133001D
.text F:\WINDOWS\system32\services.exe[788] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01320000
.text F:\WINDOWS\system32\lsass.exe[800] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F50FEF
.text F:\WINDOWS\system32\lsass.exe[800] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F50F57
.text F:\WINDOWS\system32\lsass.exe[800] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F5004C
.text F:\WINDOWS\system32\lsass.exe[800] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F50F72
.text F:\WINDOWS\system32\lsass.exe[800] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F50F8D
.text F:\WINDOWS\system32\lsass.exe[800] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F50FA8
.text F:\WINDOWS\system32\lsass.exe[800] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F50098
.text F:\WINDOWS\system32\lsass.exe[800] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F50071
.text F:\WINDOWS\system32\lsass.exe[800] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F500BD
.text F:\WINDOWS\system32\lsass.exe[800] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F50F24
.text F:\WINDOWS\system32\lsass.exe[800] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00F500D8
.text F:\WINDOWS\system32\lsass.exe[800] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00F5002F
.text F:\WINDOWS\system32\lsass.exe[800] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00F50FDE
.text F:\WINDOWS\system32\lsass.exe[800] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00F50F46
.text F:\WINDOWS\system32\lsass.exe[800] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00F5000A
.text F:\WINDOWS\system32\lsass.exe[800] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00F50FB9
.text F:\WINDOWS\system32\lsass.exe[800] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00F50F35
.text F:\WINDOWS\system32\lsass.exe[800] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00F40000
.text F:\WINDOWS\system32\lsass.exe[800] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00F40040
.text F:\WINDOWS\system32\lsass.exe[800] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00F40FAF
.text F:\WINDOWS\system32\lsass.exe[800] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00F40FCA
.text F:\WINDOWS\system32\lsass.exe[800] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00F40F83
.text F:\WINDOWS\system32\lsass.exe[800] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00F40FE5
.text F:\WINDOWS\system32\lsass.exe[800] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 00F40F94
.text F:\WINDOWS\system32\lsass.exe[800] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [14, 89] {ADC AL, 0x89}
.text F:\WINDOWS\system32\lsass.exe[800] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00F4001B
.text F:\WINDOWS\system32\lsass.exe[800] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00C40070
.text F:\WINDOWS\system32\lsass.exe[800] msvcrt.dll!system 77C293C7 5 Bytes JMP 00C4005F
.text F:\WINDOWS\system32\lsass.exe[800] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00C40FEF
.text F:\WINDOWS\system32\lsass.exe[800] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00C40000
.text F:\WINDOWS\system32\lsass.exe[800] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00C40044
.text F:\WINDOWS\system32\lsass.exe[800] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00C40029
.text F:\WINDOWS\system32\lsass.exe[800] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00BF0FE5
.text F:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 025F0FE5
.text F:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 025F0F79
.text F:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 025F006E
.text F:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 025F0F94
.text F:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 025F0051
.text F:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 025F0036
.text F:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 025F00AB
.text F:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 025F009A
.text F:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 025F00C6
.text F:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 025F0F2D
.text F:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 025F0F08
.text F:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 025F0FA5
.text F:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 025F0000
.text F:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 025F0089
.text F:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 025F0FD4
.text F:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 025F0025
.text F:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 025F0F3E
.text F:\WINDOWS\system32\svchost.exe[1028] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 025E0FD4
.text F:\WINDOWS\system32\svchost.exe[1028] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 025E004A
.text F:\WINDOWS\system32\svchost.exe[1028] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 025E0FEF
.text F:\WINDOWS\system32\svchost.exe[1028] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 025E0025
.text F:\WINDOWS\system32\svchost.exe[1028] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 025E0F8D
.text F:\WINDOWS\system32\svchost.exe[1028] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 025E0000
.text F:\WINDOWS\system32\svchost.exe[1028] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 025E0FA8
.text F:\WINDOWS\system32\svchost.exe[1028] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [7E, 8A] {JLE 0xffffffffffffff8c}
.text F:\WINDOWS\system32\svchost.exe[1028] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 025E0FB9
.text F:\WINDOWS\system32\svchost.exe[1028] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 025D0038
.text F:\WINDOWS\system32\svchost.exe[1028] msvcrt.dll!system 77C293C7 5 Bytes JMP 025D0027
.text F:\WINDOWS\system32\svchost.exe[1028] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 025D0FC8
.text F:\WINDOWS\system32\svchost.exe[1028] msvcrt.dll!_open 77C2F566 5 Bytes JMP 025D0000
.text F:\WINDOWS\system32\svchost.exe[1028] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 025D0FB7
.text F:\WINDOWS\system32\svchost.exe[1028] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 025D0FE3
.text F:\WINDOWS\system32\svchost.exe[1028] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FF0000
.text F:\WINDOWS\system32\svchost.exe[1092] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01090000
.text F:\WINDOWS\system32\svchost.exe[1092] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01090093
.text F:\WINDOWS\system32\svchost.exe[1092] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01090F9E
.text F:\WINDOWS\system32\svchost.exe[1092] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01090FAF
.text F:\WINDOWS\system32\svchost.exe[1092] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01090062
.text F:\WINDOWS\system32\svchost.exe[1092] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01090040
.text F:\WINDOWS\system32\svchost.exe[1092] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01090F72
.text F:\WINDOWS\system32\svchost.exe[1092] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01090F83
.text F:\WINDOWS\system32\svchost.exe[1092] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01090F3F
.text F:\WINDOWS\system32\svchost.exe[1092] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01090F50
.text F:\WINDOWS\system32\svchost.exe[1092] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 010900FD
.text F:\WINDOWS\system32\svchost.exe[1092] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 01090051
.text F:\WINDOWS\system32\svchost.exe[1092] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 01090FE5
.text F:\WINDOWS\system32\svchost.exe[1092] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 010900AE
.text F:\WINDOWS\system32\svchost.exe[1092] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 0109002F
.text F:\WINDOWS\system32\svchost.exe[1092] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 01090FD4
.text F:\WINDOWS\system32\svchost.exe[1092] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 01090F61
.text F:\WINDOWS\system32\svchost.exe[1092] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00FF0FD4
.text F:\WINDOWS\system32\svchost.exe[1092] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00FF0076
.text F:\WINDOWS\system32\svchost.exe[1092] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00FF0025
.text F:\WINDOWS\system32\svchost.exe[1092] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00FF0FEF
.text F:\WINDOWS\system32\svchost.exe[1092] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00FF0FB9
.text F:\WINDOWS\system32\svchost.exe[1092] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00FF0000
.text F:\WINDOWS\system32\svchost.exe[1092] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00FF005B
.text F:\WINDOWS\system32\svchost.exe[1092] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00FF0036
.text F:\WINDOWS\system32\svchost.exe[1092] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00FE003D
.text F:\WINDOWS\system32\svchost.exe[1092] msvcrt.dll!system 77C293C7 5 Bytes JMP 00FE002C
.text F:\WINDOWS\system32\svchost.exe[1092] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00FE0FCD
.text F:\WINDOWS\system32\svchost.exe[1092] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00FE0FEF
.text F:\WINDOWS\system32\svchost.exe[1092] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00FE0FBC
.text F:\WINDOWS\system32\svchost.exe[1092] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00FE0FDE
.text F:\WINDOWS\system32\svchost.exe[1092] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FD0FEF
.text F:\WINDOWS\System32\svchost.exe[1188] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 023B0FEF
.text F:\WINDOWS\System32\svchost.exe[1188] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 023B0054
.text F:\WINDOWS\System32\svchost.exe[1188] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 023B0F5F
.text F:\WINDOWS\System32\svchost.exe[1188] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 023B0039
.text F:\WINDOWS\System32\svchost.exe[1188] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 023B0028
.text F:\WINDOWS\System32\svchost.exe[1188] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 023B0F97
.text F:\WINDOWS\System32\svchost.exe[1188] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 023B0085
.text F:\WINDOWS\System32\svchost.exe[1188] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 023B0F3D
.text F:\WINDOWS\System32\svchost.exe[1188] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 023B0F07
.text F:\WINDOWS\System32\svchost.exe[1188] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 023B0F18
.text F:\WINDOWS\System32\svchost.exe[1188] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 023B0EEC
.text F:\WINDOWS\System32\svchost.exe[1188] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 023B0F86
.text F:\WINDOWS\System32\svchost.exe[1188] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 023B0FDE
.text F:\WINDOWS\System32\svchost.exe[1188] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 023B0F4E
.text F:\WINDOWS\System32\svchost.exe[1188] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 023B0FB2
.text F:\WINDOWS\System32\svchost.exe[1188] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 023B0FC3
.text F:\WINDOWS\System32\svchost.exe[1188] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 023B0096
.text F:\WINDOWS\System32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 02390FC0
.text F:\WINDOWS\System32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 02390F8D
.text F:\WINDOWS\System32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 02390FDB
.text F:\WINDOWS\System32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 02390011
.text F:\WINDOWS\System32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 0239004A
.text F:\WINDOWS\System32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 02390000
.text F:\WINDOWS\System32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 02390F9E
.text F:\WINDOWS\System32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [59, 8A]
.text F:\WINDOWS\System32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 02390FAF
.text F:\WINDOWS\System32\svchost.exe[1188] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 02380049
.text F:\WINDOWS\System32\svchost.exe[1188] msvcrt.dll!system 77C293C7 5 Bytes JMP 02380038
.text F:\WINDOWS\System32\svchost.exe[1188] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 02380FD2
.text F:\WINDOWS\System32\svchost.exe[1188] msvcrt.dll!_open 77C2F566 5 Bytes JMP 02380000
.text F:\WINDOWS\System32\svchost.exe[1188] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 02380027
.text F:\WINDOWS\System32\svchost.exe[1188] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 02380FEF
.text F:\WINDOWS\System32\svchost.exe[1188] WS2_32.dll!socket 71AB4211 3 Bytes JMP 02370000
.text F:\WINDOWS\System32\svchost.exe[1188] WS2_32.dll!socket + 4 71AB4215 1 Byte [90]
.text F:\WINDOWS\System32\svchost.exe[1188] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 023A0000
.text F:\WINDOWS\System32\svchost.exe[1188] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 023A0011
.text F:\WINDOWS\System32\svchost.exe[1188] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 023A0FD1
.text F:\WINDOWS\System32\svchost.exe[1188] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 023A002C
.text F:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C70000
.text F:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C70F79
.text F:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C7006E
.text F:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C7005D
.text F:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C70036
.text F:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C70FB9
.text F:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C70090
.text F:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C7007F
.text F:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C70F12
.text F:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C70F23
.text F:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00C70EF7
.text F:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00C70F94
.text F:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00C70FEF
.text F:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00C70F5E
.text F:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00C70FCA
.text F:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00C7001B
.text F:\WINDOWS\system32\svchost.exe[1432] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00C700A1
.text F:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00A10036
.text F:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00A10062
.text F:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00A10025
.text F:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00A10000
.text F:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00A10FA5
.text F:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00A10FEF
.text F:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00A10051
.text F:\WINDOWS\system32\svchost.exe[1432] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00A10FCA
.text F:\WINDOWS\system32\svchost.exe[1432] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00A0002C
.text F:\WINDOWS\system32\svchost.exe[1432] msvcrt.dll!system 77C293C7 5 Bytes JMP 00A00011
.text F:\WINDOWS\system32\svchost.exe[1432] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00A00FC6
.text F:\WINDOWS\system32\svchost.exe[1432] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00A00FEF
.text F:\WINDOWS\system32\svchost.exe[1432] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00A00FA1
.text F:\WINDOWS\system32\svchost.exe[1432] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00A00000
.text F:\WINDOWS\system32\svchost.exe[1432] WS2_32.dll!socket 71AB4211 5 Bytes JMP 009F0000
.text F:\WINDOWS\system32\svchost.exe[1432] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 00A20FEF
.text F:\WINDOWS\system32\svchost.exe[1432] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 00A20FDE
.text F:\WINDOWS\system32\svchost.exe[1432] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00A2000A
.text F:\WINDOWS\system32\svchost.exe[1432] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 00A20025
.text F:\WINDOWS\Explorer.EXE[1892] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00E50FEF
.text F:\WINDOWS\Explorer.EXE[1892] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00E50F6D
.text F:\WINDOWS\Explorer.EXE[1892] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00E50062
.text F:\WINDOWS\Explorer.EXE[1892] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00E50051
.text F:\WINDOWS\Explorer.EXE[1892] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00E50F9E
.text F:\WINDOWS\Explorer.EXE[1892] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00E5002F
.text F:\WINDOWS\Explorer.EXE[1892] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00E50F52
.text F:\WINDOWS\Explorer.EXE[1892] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00E5008E
.text F:\WINDOWS\Explorer.EXE[1892] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E50F2D
.text F:\WINDOWS\Explorer.EXE[1892] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E500C6
.text F:\WINDOWS\Explorer.EXE[1892] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00E500E1
.text F:\WINDOWS\Explorer.EXE[1892] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00E50040
.text F:\WINDOWS\Explorer.EXE[1892] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00E50FD4
.text F:\WINDOWS\Explorer.EXE[1892] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00E5007D
.text F:\WINDOWS\Explorer.EXE[1892] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00E50014
.text F:\WINDOWS\Explorer.EXE[1892] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00E50FC3
.text F:\WINDOWS\Explorer.EXE[1892] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00E500B5
.text F:\WINDOWS\Explorer.EXE[1892] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00DD0FA8
.text F:\WINDOWS\Explorer.EXE[1892] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00DD0F7C
.text F:\WINDOWS\Explorer.EXE[1892] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00DD0FC3
.text F:\WINDOWS\Explorer.EXE[1892] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00DD0FD4
.text F:\WINDOWS\Explorer.EXE[1892] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00DD002F
.text F:\WINDOWS\Explorer.EXE[1892] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00DD0FE5
.text F:\WINDOWS\Explorer.EXE[1892] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00DD001E
.text F:\WINDOWS\Explorer.EXE[1892] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00DD0F97
.text F:\WINDOWS\Explorer.EXE[1892] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00DC0042
.text F:\WINDOWS\Explorer.EXE[1892] msvcrt.dll!system 77C293C7 5 Bytes JMP 00DC0031
.text F:\WINDOWS\Explorer.EXE[1892] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00DC0FC1
.text F:\WINDOWS\Explorer.EXE[1892] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00DC0FEF
.text F:\WINDOWS\Explorer.EXE[1892] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00DC0016
.text F:\WINDOWS\Explorer.EXE[1892] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00DC0FD2
.text F:\WINDOWS\Explorer.EXE[1892] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 00DE0000
.text F:\WINDOWS\Explorer.EXE[1892] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 00DE0FDB
.text F:\WINDOWS\Explorer.EXE[1892] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00DE0FC0
.text F:\WINDOWS\Explorer.EXE[1892] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 00DE0FA5
.text F:\WINDOWS\Explorer.EXE[1892] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00DA0FE5
.text F:\WINDOWS\system32\svchost.exe[2908] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BB0FEF
.text F:\WINDOWS\system32\svchost.exe[2908] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BB0071
.text F:\WINDOWS\system32\svchost.exe[2908] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BB0060
.text F:\WINDOWS\system32\svchost.exe[2908] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BB0F7C
.text F:\WINDOWS\system32\svchost.exe[2908] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BB002F
.text F:\WINDOWS\system32\svchost.exe[2908] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BB0FA8
.text F:\WINDOWS\system32\svchost.exe[2908] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BB0F50
.text F:\WINDOWS\system32\svchost.exe[2908] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BB0F61
.text F:\WINDOWS\system32\svchost.exe[2908] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BB0F10
.text F:\WINDOWS\system32\svchost.exe[2908] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BB0F2B
.text F:\WINDOWS\system32\svchost.exe[2908] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00BB00CE
.text F:\WINDOWS\system32\svchost.exe[2908] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00BB0F8D
.text F:\WINDOWS\system32\svchost.exe[2908] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00BB000A
.text F:\WINDOWS\system32\svchost.exe[2908] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00BB0082
.text F:\WINDOWS\system32\svchost.exe[2908] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00BB0FB9
.text F:\WINDOWS\system32\svchost.exe[2908] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00BB0FD4
.text F:\WINDOWS\system32\svchost.exe[2908] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00BB00B3
.text F:\WINDOWS\system32\svchost.exe[2908] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00BA0FCA
.text F:\WINDOWS\system32\svchost.exe[2908] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00BA0F8A
.text F:\WINDOWS\system32\svchost.exe[2908] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00BA0FDB
.text F:\WINDOWS\system32\svchost.exe[2908] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00BA0011
.text F:\WINDOWS\system32\svchost.exe[2908] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00BA0047
.text F:\WINDOWS\system32\svchost.exe[2908] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00BA0000
.text F:\WINDOWS\system32\svchost.exe[2908] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 00BA0FA5
.text F:\WINDOWS\system32\svchost.exe[2908] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [DA, 88]
.text F:\WINDOWS\system32\svchost.exe[2908] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00BA0036
.text F:\WINDOWS\system32\svchost.exe[2908] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00B90F9E
.text F:\WINDOWS\system32\svchost.exe[2908] msvcrt.dll!system 77C293C7 5 Bytes JMP 00B90FC3
.text F:\WINDOWS\system32\svchost.exe[2908] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00B90029
.text F:\WINDOWS\system32\svchost.exe[2908] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00B90FEF
.text F:\WINDOWS\system32\svchost.exe[2908] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00B90FDE
.text F:\WINDOWS\system32\svchost.exe[2908] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00B9000C
.text F:\WINDOWS\system32\SearchIndexer.exe[4012] kernel32.dll!WriteFile 7C810E17 7 Bytes JMP 00585C0C F:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
Device \Driver\atapi \Device\Ide\IdePort0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-1c sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort2 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort3 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP2T1L0-24 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
Device \Driver\ultra \Device\Scsi\ultra1Port4Path0Target3Lun0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\ultra \Device\Scsi\ultra1Port4Path0Target1Lun0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\ultra \Device\Scsi\ultra1Port4Path0Target2Lun0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\ultra \Device\Scsi\ultra1Port4Path0Target0Lun0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\ultra \Device\Scsi\ultra1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Roxio)
---- EOF - GMER 1.0.15 ----