========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\tempo-41F.tmp moved successfully.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\tempo-E7B.tmp moved successfully.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\tempo-EAD.tmp moved successfully.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\tmp18.tmp moved successfully.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\tmp197.tmp moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\visser\LOCALS~1\Temp\etilqs_L6oeuaFsmI3Qkz5orJM3 scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\visser\Local Settings\Application Data\Mozilla\Firefox\Profiles\3m1kd21e.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\visser\Local Settings\Application Data\Mozilla\Firefox\Profiles\3m1kd21e.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\visser\Local Settings\Application Data\Mozilla\Firefox\Profiles\3m1kd21e.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\visser\Local Settings\Application Data\Mozilla\Firefox\Profiles\3m1kd21e.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\visser\Local Settings\Application Data\Mozilla\Firefox\Profiles\3m1kd21e.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\visser\Local Settings\Application Data\Mozilla\Firefox\Profiles\3m1kd21e.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01282009_141800
Files moved on Reboot...
File C:\DOCUME~1\visser\LOCALS~1\Temp\etilqs_L6oeuaFsmI3Qkz5orJM3 not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
C:\Documents and Settings\visser\Local Settings\Application Data\Mozilla\Firefox\Profiles\3m1kd21e.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\visser\Local Settings\Application Data\Mozilla\Firefox\Profiles\3m1kd21e.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\visser\Local Settings\Application Data\Mozilla\Firefox\Profiles\3m1kd21e.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\visser\Local Settings\Application Data\Mozilla\Firefox\Profiles\3m1kd21e.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\visser\Local Settings\Application Data\Mozilla\Firefox\Profiles\3m1kd21e.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\visser\Local Settings\Application Data\Mozilla\Firefox\Profiles\3m1kd21e.default\XUL.mfl moved successfully.
GMER 1.0.14.14536 -
http://www.gmer.netRootkit scan 2009-01-28 15:02:39
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.14 ----
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xBA8F887E]
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xBA8F8C10]
SSDT \??\C:\WINDOWS\system32\Drivers\uphcleanhlp.sys ZwUnloadKey [0xA93416D0]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xA9036ABD]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xA9036AE7]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xA9036A51]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xA9036A7D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xA9036B11]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xA9036A27]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xA9036AD1]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xA9036A67]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xA9036AA9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xA9036B27]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xA9036AFB]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
---- Kernel code sections - GMER 1.0.14 ----
.text ntkrnlpa.exe!ZwYieldExecution 805021FC 7 Bytes JMP A9036AFF \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtCreateFile 8056DF7C 5 Bytes JMP A9036AC1 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 805A70D8 7 Bytes JMP A9036B15 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805A7EEE 5 Bytes JMP A9036B2B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 805AD66C 7 Bytes JMP A9036AD5 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcess 805C6F40 5 Bytes JMP A9036AEB \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805C8720 5 Bytes JMP A9036AAD \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRenameKey 8061987A 7 Bytes JMP A9036A6B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteKey 8061A2E4 7 Bytes JMP A9036A55 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteValueKey 8061A4B4 7 Bytes JMP A9036A81 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwOpenKey 8061B1EA 5 Bytes JMP A9036A2B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
? C:\WINDOWS\system32\Drivers\uphcleanhlp.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.14 ----
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 0069000A
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 006900A4
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00690FAF
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00690FC0
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00690073
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00690051
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 006900D0
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 006900BF
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00690F52
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00690F63
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 006900FC
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00690062
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00690025
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00690F94
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00690FE5
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00690040
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 006900E1
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 0068001B
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 0068006C
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00680000
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00680FCA
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00680051
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00680040
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00680FEF
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00680FAF
.text C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe[124] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00660FEF
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00DC0FE5
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00DC0F72
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00DC0F8D
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00DC0067
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00DC004A
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00DC0025
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00DC00AE
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00DC009D
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00DC0F29
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00DC0F3A
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00DC0F04
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00DC0F9E
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00DC0FD4
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00DC008C
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00DC0FB9
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00DC000A
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00DC0F4B
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00DB0FCA
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00DB0051
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00DB0025
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00DB000A
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00DB0F94
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00DB0040
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00DB0FEF
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00DB0FB9
.text C:\Program Files\Network Associates\Common Framework\FrameworkService.exe[656] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00D90FEF
.text C:\WINDOWS\system32\services.exe[908] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00070000
.text C:\WINDOWS\system32\services.exe[908] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00070062
.text C:\WINDOWS\system32\services.exe[908] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00070F6D
.text C:\WINDOWS\system32\services.exe[908] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00070F88
.text C:\WINDOWS\system32\services.exe[908] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00070FAF
.text C:\WINDOWS\system32\services.exe[908] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00070040
.text C:\WINDOWS\system32\services.exe[908] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 000700AB
.text C:\WINDOWS\system32\services.exe[908] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 0007008E
.text C:\WINDOWS\system32\services.exe[908] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 000700F2
.text C:\WINDOWS\system32\services.exe[908] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 000700D7
.text C:\WINDOWS\system32\services.exe[908] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00070F34
.text C:\WINDOWS\system32\services.exe[908] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00070051
.text C:\WINDOWS\system32\services.exe[908] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00070FEF
.text C:\WINDOWS\system32\services.exe[908] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 0007007D
.text C:\WINDOWS\system32\services.exe[908] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00070FD4
.text C:\WINDOWS\system32\services.exe[908] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00070025
.text C:\WINDOWS\system32\services.exe[908] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 000700BC
.text C:\WINDOWS\system32\services.exe[908] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00060FA8
.text C:\WINDOWS\system32\services.exe[908] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00060051
.text C:\WINDOWS\system32\services.exe[908] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00060FB9
.text C:\WINDOWS\system32\services.exe[908] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00060FCA
.text C:\WINDOWS\system32\services.exe[908] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00060040
.text C:\WINDOWS\system32\services.exe[908] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00060025
.text C:\WINDOWS\system32\services.exe[908] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00060FEF
.text C:\WINDOWS\system32\services.exe[908] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 0006000A
.text C:\WINDOWS\system32\services.exe[908] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00040FE5
.text C:\WINDOWS\system32\lsass.exe[920] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00F30000
.text C:\WINDOWS\system32\lsass.exe[920] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00F30FA3
.text C:\WINDOWS\system32\lsass.exe[920] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00F30098
.text C:\WINDOWS\system32\lsass.exe[920] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00F30087
.text C:\WINDOWS\system32\lsass.exe[920] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00F30076
.text C:\WINDOWS\system32\lsass.exe[920] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00F30040
.text C:\WINDOWS\system32\lsass.exe[920] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00F30F66
.text C:\WINDOWS\system32\lsass.exe[920] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00F30F77
.text C:\WINDOWS\system32\lsass.exe[920] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00F30F44
.text C:\WINDOWS\system32\lsass.exe[920] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00F30F55
.text C:\WINDOWS\system32\lsass.exe[920] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00F30F33
.text C:\WINDOWS\system32\lsass.exe[920] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00F3005B
.text C:\WINDOWS\system32\lsass.exe[920] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00F3001B
.text C:\WINDOWS\system32\lsass.exe[920] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00F30F88
.text C:\WINDOWS\system32\lsass.exe[920] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00F30FD4
.text C:\WINDOWS\system32\lsass.exe[920] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00F30FE5
.text C:\WINDOWS\system32\lsass.exe[920] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00F300C9
.text C:\WINDOWS\system32\lsass.exe[920] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00F20FCA
.text C:\WINDOWS\system32\lsass.exe[920] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00F20040
.text C:\WINDOWS\system32\lsass.exe[920] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00F20FE5
.text C:\WINDOWS\system32\lsass.exe[920] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00F2001B
.text C:\WINDOWS\system32\lsass.exe[920] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00F20F83
.text C:\WINDOWS\system32\lsass.exe[920] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00F20FA8
.text C:\WINDOWS\system32\lsass.exe[920] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00F2000A
.text C:\WINDOWS\system32\lsass.exe[920] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00F20FB9
.text C:\WINDOWS\system32\lsass.exe[920] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00F00FEF
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00810000
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00810F57
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00810F68
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00810F83
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00810040
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00810FAF
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00810082
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00810F3A
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00810093
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00810F04
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 008100AE
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00810F9E
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00810FE5
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00810067
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 0081001B
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00810FD4
.text C:\WINDOWS\system32\svchost.exe[1096] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00810F1F
.text C:\WINDOWS\system32\svchost.exe[1096] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00800FC0
.text C:\WINDOWS\system32\svchost.exe[1096] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 0080005F
.text C:\WINDOWS\system32\svchost.exe[1096] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00800FE5
.text C:\WINDOWS\system32\svchost.exe[1096] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00800011
.text C:\WINDOWS\system32\svchost.exe[1096] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 0080004E
.text C:\WINDOWS\system32\svchost.exe[1096] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 0080003D
.text C:\WINDOWS\system32\svchost.exe[1096] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00800000
.text C:\WINDOWS\system32\svchost.exe[1096] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 0080002C
.text C:\WINDOWS\system32\svchost.exe[1096] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 007E0FEF
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00900FEF
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00900F8D
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00900FA8
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00900FC3
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00900FD4
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 0090005B
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00900F7C
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 009000C4
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00900F6B
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00900104
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00900F50
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00900076
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 0090000A
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 009000A7
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 0090004A
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 0090002F
.text C:\WINDOWS\system32\svchost.exe[1180] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 009000DF
.text C:\WINDOWS\system32\svchost.exe[1180] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 008F0FA8
.text C:\WINDOWS\system32\svchost.exe[1180] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 008F002F
.text C:\WINDOWS\system32\svchost.exe[1180] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 008F0FB9
.text C:\WINDOWS\system32\svchost.exe[1180] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 008F0FCA
.text C:\WINDOWS\system32\svchost.exe[1180] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 008F0F7C
.text C:\WINDOWS\system32\svchost.exe[1180] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 008F001E
.text C:\WINDOWS\system32\svchost.exe[1180] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 008F0FE5
.text C:\WINDOWS\system32\svchost.exe[1180] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 008F0F97
.text C:\WINDOWS\system32\svchost.exe[1180] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 008D0FEF
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 022F0000
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 022F0F63
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 022F0F7E
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 022F0058
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 022F0047
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 022F0FC0
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 022F0F26
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 022F0F41
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 022F00AB
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 022F009A
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 022F0EF7
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 022F0FAF
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 022F0011
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 022F0F52
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 022F002C
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 022F0FDB
.text C:\WINDOWS\System32\svchost.exe[1320] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 022F0089
.text C:\WINDOWS\System32\svchost.exe[1320] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 022C002C
.text C:\WINDOWS\System32\svchost.exe[1320] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 022C0069
.text C:\WINDOWS\System32\svchost.exe[1320] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 022C001B
.text C:\WINDOWS\System32\svchost.exe[1320] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 022C000A
.text C:\WINDOWS\System32\svchost.exe[1320] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 022C0058
.text C:\WINDOWS\System32\svchost.exe[1320] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 022C0FB6
.text C:\WINDOWS\System32\svchost.exe[1320] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 022C0FE5
.text C:\WINDOWS\System32\svchost.exe[1320] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 022C003D
.text C:\WINDOWS\System32\svchost.exe[1320] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 01C90000
.text C:\WINDOWS\System32\svchost.exe[1320] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 022D0FEF
.text C:\WINDOWS\System32\svchost.exe[1320] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 022D0FCA
.text C:\WINDOWS\System32\svchost.exe[1320] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 022D0FB9
.text C:\WINDOWS\System32\svchost.exe[1320] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 022D0FA8
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 008F0000
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 008F0087
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 008F0076
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 008F0FA8
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 008F0065
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 008F0FB9
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 008F00BF
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 008F00A4
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 008F00E4
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 008F0F41
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 008F00F5
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 008F004A
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 008F0FDB
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 008F0F6D
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 008F0FCA
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 008F001B
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 008F0F52
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00760025
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 0076004A
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00760FDE
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 0076000A
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00760F8D
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00760FA8
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00760FEF
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00760FB9
.text C:\WINDOWS\system32\svchost.exe[1392] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00740000
.text C:\WINDOWS\system32\svchost.exe[1556] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 009C0000
.text C:\WINDOWS\system32\svchost.exe[1556] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 009C0F8D
.text C:\WINDOWS\system32\svchost.exe[1556] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 009C0F9E
.text C:\WINDOWS\system32\svchost.exe[1556] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 009C0FAF
.text C:\WINDOWS\system32\svchost.exe[1556] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 009C006C
.text C:\WINDOWS\system32\svchost.exe[1556] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 009C0051
.text C:\WINDOWS\system32\svchost.exe[1556] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 009C00CB
.text C:\WINDOWS\system32\svchost.exe[1556] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 009C00AE
.text C:\WINDOWS\system32\svchost.exe[1556] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 009C00FA
.text C:\WINDOWS\system32\svchost.exe[1556] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 009C0F61
.text C:\WINDOWS\system32\svchost.exe[1556] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 009C0F50
.text C:\WINDOWS\system32\svchost.exe[1556] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 009C0FCA
.text C:\WINDOWS\system32\svchost.exe[1556] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 009C0011
.text C:\WINDOWS\system32\svchost.exe[1556] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 009C009D
.text C:\WINDOWS\system32\svchost.exe[1556] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 009C0040
.text C:\WINDOWS\system32\svchost.exe[1556] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 009C0FE5
.text C:\WINDOWS\system32\svchost.exe[1556] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 009C0F72
.text C:\WINDOWS\system32\svchost.exe[1556] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 009A0F9E
.text C:\WINDOWS\system32\svchost.exe[1556] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 009A002C
.text C:\WINDOWS\system32\svchost.exe[1556] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 009A0FC3
.text C:\WINDOWS\system32\svchost.exe[1556] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 009A0FD4
.text C:\WINDOWS\system32\svchost.exe[1556] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 009A0F79
.text C:\WINDOWS\system32\svchost.exe[1556] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 009A001B
.text C:\WINDOWS\system32\svchost.exe[1556] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 009A0FEF
.text C:\WINDOWS\system32\svchost.exe[1556] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 009A000A
.text C:\WINDOWS\system32\svchost.exe[1556] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00980FEF
.text C:\WINDOWS\system32\svchost.exe[1556] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 009B0FEF
.text C:\WINDOWS\system32\svchost.exe[1556] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 009B0FCA
.text C:\WINDOWS\system32\svchost.exe[1556] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 009B0FB9
.text C:\WINDOWS\system32\svchost.exe[1556] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 009B0F94
.text C:\WINDOWS\system32\svchost.exe[2008] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 008A0000
.text C:\WINDOWS\system32\svchost.exe[2008] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 008A00A4
.text C:\WINDOWS\system32\svchost.exe[2008] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 008A0089
.text C:\WINDOWS\system32\svchost.exe[2008] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 008A0FAF
.text C:\WINDOWS\system32\svchost.exe[2008] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 008A0FC0
.text C:\WINDOWS\system32\svchost.exe[2008] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 008A0051
.text C:\WINDOWS\system32\svchost.exe[2008] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 008A0F88
.text C:\WINDOWS\system32\svchost.exe[2008] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 008A00D0
.text C:\WINDOWS\system32\svchost.exe[2008] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 008A0F63
.text C:\WINDOWS\system32\svchost.exe[2008] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 008A00F2
.text C:\WINDOWS\system32\svchost.exe[2008] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 008A0F48
.text C:\WINDOWS\system32\svchost.exe[2008] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 008A006C
.text C:\WINDOWS\system32\svchost.exe[2008] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 008A001B
.text C:\WINDOWS\system32\svchost.exe[2008] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 008A00BF
.text C:\WINDOWS\system32\svchost.exe[2008] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 008A0FE5
.text C:\WINDOWS\system32\svchost.exe[2008] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 008A002C
.text C:\WINDOWS\system32\svchost.exe[2008] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 008A00E1
.text C:\WINDOWS\system32\svchost.exe[2008] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00890FC0
.text C:\WINDOWS\system32\svchost.exe[2008] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00890F80
.text C:\WINDOWS\system32\svchost.exe[2008] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00890011
.text C:\WINDOWS\system32\svchost.exe[2008] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00890000
.text C:\WINDOWS\system32\svchost.exe[2008] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00890047
.text C:\WINDOWS\system32\svchost.exe[2008] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 0089002C
.text C:\WINDOWS\system32\svchost.exe[2008] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00890FEF
.text C:\WINDOWS\system32\svchost.exe[2008] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00890FA5
.text C:\WINDOWS\Explorer.EXE[3580] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 001A0000
.text C:\WINDOWS\Explorer.EXE[3580] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001A0F68
.text C:\WINDOWS\Explorer.EXE[3580] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 001A0F79
.text C:\WINDOWS\Explorer.EXE[3580] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 001A0051
.text C:\WINDOWS\Explorer.EXE[3580] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 001A0F94
.text C:\WINDOWS\Explorer.EXE[3580] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 001A002C
.text C:\WINDOWS\Explorer.EXE[3580] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 001A00A9
.text C:\WINDOWS\Explorer.EXE[3580] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 001A008E
.text C:\WINDOWS\Explorer.EXE[3580] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001A0F21
.text C:\WINDOWS\Explorer.EXE[3580] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 001A0F3C
.text C:\WINDOWS\Explorer.EXE[3580] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 001A0F10
.text C:\WINDOWS\Explorer.EXE[3580] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 001A0FAF
.text C:\WINDOWS\Explorer.EXE[3580] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 001A0011
.text C:\WINDOWS\Explorer.EXE[3580] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 001A0F57
.text C:\WINDOWS\Explorer.EXE[3580] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 001A0FCA
.text C:\WINDOWS\Explorer.EXE[3580] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 001A0FDB
.text C:\WINDOWS\Explorer.EXE[3580] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 001A00BA
.text C:\WINDOWS\Explorer.EXE[3580] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00280FA5
.text C:\WINDOWS\Explorer.EXE[3580] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 0028003D
.text C:\WINDOWS\Explorer.EXE[3580] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00280FC0
.text C:\WINDOWS\Explorer.EXE[3580] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00280FE5
.text C:\WINDOWS\Explorer.EXE[3580] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00280F80
.text C:\WINDOWS\Explorer.EXE[3580] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 0028002C
.text C:\WINDOWS\Explorer.EXE[3580] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00280000
.text C:\WINDOWS\Explorer.EXE[3580] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 0028001B
.text C:\WINDOWS\Explorer.EXE[3580] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 002B0FEF
.text C:\WINDOWS\Explorer.EXE[3580] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 002B000A
.text C:\WINDOWS\Explorer.EXE[3580] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 002B0FD4
.text C:\WINDOWS\Explorer.EXE[3580] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 002B002F
.text C:\WINDOWS\Explorer.EXE[3580] ws2_32.dll!socket 71AB3B91 5 Bytes JMP 00EC0000
---- Devices - GMER 1.0.14 ----
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
---- Services - GMER 1.0.14 ----
Service system32\drivers\gaopdxhrmqsklv.sys (*** hidden *** ) [SYSTEM] gaopdxserv.sys <-- ROOTKIT !!!
---- Registry - GMER 1.0.14 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys@imagepath \systemroot\system32\drivers\gaopdxhrmqsklv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys\modules@gaopdxserv \\?\globalroot\systemroot\system32\drivers\gaopdxhrmqsklv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gaopdxserv.sys\modules@gaopdxl \\?\globalroot\systemroot\system32\gaopdxrowprtrf.dll
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys@imagepath \systemroot\system32\drivers\gaopdxhrmqsklv.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys\modules
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys\modules@gaopdxserv \\?\globalroot\systemroot\system32\drivers\gaopdxhrmqsklv.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gaopdxserv.sys\modules@gaopdxl \\?\globalroot\systemroot\system32\gaopdxrowprtrf.dll
---- EOF - GMER 1.0.14 ----
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:06:13 PM, on 1/28/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Symantec\Ghost\ngctw32.exe
C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\WINDOWS\system32\WebUpdateSvc4.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\Common Framework\UdaterUI.exe
C:\Program Files\Network Associates\Common Framework\McTray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\Symantec\Ghost\ngtray.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.sonoma.edu/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.sonoma.edu/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [NGTray] "C:\Program Files\Symantec\Ghost\ngtray.exe"
O4 - HKLM\..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
O4 - HKLM\..\Run: [PrintServer Diagnostic] C:\Program Files\Print Server\PTP\PSDiagnostic.exe
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Local Settings\Temp" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_02] rundll32 advpack.dll,LaunchINFSection nlite.inf,nLiteReg (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_03] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Local Settings\Temp" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
O8 - Extra context menu item: Append Link Target to Existing PDF -
res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF -
res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF -
res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF -
res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) -
http://www.linkedin.com/cab/LinkedInCon ... ontrol.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/microso ... 4861947838O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microso ... 4861938664O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) -
http://130.157.33.98/activex/AxisCamControl.cabO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = solar.sonoma.edu
O17 - HKLM\Software\..\Telephony: DomainName = solar.sonoma.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = solar.sonoma.edu
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Symantec Ghost Client Agent (NGCLIENT) - Symantec Corporation - C:\Program Files\Symantec\Ghost\ngctw32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: SlingAgent Service (SlingAgentService) - Sling Media Inc. - C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe
O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
O23 - Service: Web Update Wizard Service V4 (WebUpdate4) - Data Perceptions / PowerProgrammer - C:\WINDOWS\system32\WebUpdateSvc4.exe
--
End of file - 10206 bytes