Start a Conversation

Unsolved

This post is more than 5 years old

M

8632

November 25th, 2008 20:00

Various computer problems... Hijack this log

I am new to this forum so let me know if I have forgotten to include anything.

My computer has been running a lot more slowly than usual. Programs tend to lock up a lot (especially Internet Explorer). It seems that my memory is very low for some reason, even when I do not have much open. (I am attaching a screen shot).

 

 

I have had a couple pop ups saying a Trojan had been detected and removed. Could have been from Windows Defender or McAfee Security Center... I'm sorry but I do not remember which one. I did have Utorrent on my computer but I uninstalled it.

sfc/scannow says there are corrupt files that it cannot fix. I cannot get chkdsk to run without using the Vista installation CD. Every time I schedule it to run at reboot, it does not run. I have reformatted and reinstalled the OS since the first time this happened with chkdsk... still no luck.

Dell PC Tuneup tells me there are hard drive errors and to run chkdsk every time I run it.

I have scanned with McAfee Security Center and Windows Defender and it finds nothing.

I do own this computer. I am the administrator.

I am running Windows Vista Home Premium on a Dell Inspiron 1720 laptop.

Here is my Hijack this Log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:00:52 PM, on 11/25/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Dell\PC TuneUp\SMSystemAnalyzer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: CafeMom Toolbar - {8151A608-00FB-4D5C-8B8D-40E239E32A42} - C:\Program Files\CafeMom Toolbar\cmtb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.5470\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: CafeMom Toolbar - {8151A608-00FB-4D5C-8B8D-40E239E32A42} - C:\Program Files\CafeMom Toolbar\cmtb.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [Dell PC TuneUp Startup] "C:\Program Files\iolo\Common\Lib\ioloLManager.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [Device Detector] DevDetect.exe -autorun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: (no name) - {07DB8C18-9FD9-4e43-AF16-043E44D89768} - C:\Program Files\CafeMom Toolbar\cmtb.dll
O9 - Extra 'Tools' menuitem: CafeMom Toolbar - {07DB8C18-9FD9-4e43-AF16-043E44D89768} - C:\Program Files\CafeMom Toolbar\cmtb.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/control/en-US/activex/TmHcmsX.CAB
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} - http://www.infospace.com/mypoints.main/tbar/mypointsSetup.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {C8E7CBFB-9F2E-42C7-B4CB-D4B7FC89A363} (Gather Photo Uploader Control) - http://www.gather.com/imageuploader/GatherUploader5.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: McAfee Application Installer Cleanup (0007421227543704) (0007421227543704mcinstcleanup) - Unknown owner - C:\Windows\TEMP\000742~1.EXE (file missing)
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\Windows\system32\CTsvcCDA.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Procedure Call (RPC) Net (rpcnet) - Absolute Software Corp. - C:\Windows\System32\rpcnet.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 12588 bytes

I would appreciate any help with these problems.

Thanks,

Monica

10.4K Posts

November 26th, 2008 06:00


monicav

Getting hard drive errors is not a good thing, It could be a sign of a failing Hard Drive

We can check for infections, if they come up clean, then it may mean a visit to the shop

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    If an update is found, it will download and install the latest version.
    Once the program has loaded, select " Perform Quick Scan", then click Scan.
    The scan may take some time to finish,so please be patient.
    When the scan is complete, click OK, then Show Results to view the results.
    Make sure that everything is checked, and click Remove Selected.
    When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    Copy&Paste the entire report in your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

7 Posts

November 26th, 2008 11:00

Hi bamajim,

Thanks for the response. I downloaded and installed Malwarebytes' Anti-Malware per your instructions, and ran a quick scan. Here is the log from the scan.

Malwarebytes' Anti-Malware 1.30
Database version: 1425
Windows 6.0.6001 Service Pack 1

11/26/2008 2:26:32 PM
mbam-log-2008-11-26 (14-26-32).txt

Scan type: Quick Scan
Objects scanned: 48488
Time elapsed: 3 minute(s), 24 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9522b3fb-7a2b-4646-8af6-36e7f593073c} (Adware.Coupons) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CLASSES_ROOT\scrfile\shell\open\command\ (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" /S) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\regfile\shell\open\command\ (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

10.4K Posts

November 26th, 2008 13:00


monicav

You are most welcome.

If the exe key was borked in the Registry, that could cause a number of problems.

Let's do this to make sure it's o.k. This tool will produce a longer log

Go HERE and Download System Repair Engineer by smallfrogs
Select local download
  • Save it to your Desktop
    Rt Click sreng2.zip->>Extract all->>Extract it to your desktop
    Open the sreng folder
    Double click SREngPS.exe->>Click Run
    At the main Window, in the left Pane,Select Smart Scan
    At the next window make sure all of the boxes are checked and Select Scan
    When the scan is complete Select Save reports
    Save it to your desktop and Close the tool
    Double Click SREngLog.txt copy and paste that log as a reply to this thread


Do not run any other options with this tool unless instructed to do so.

7 Posts

November 26th, 2008 15:00

Here is the System Repair Engineer log, thanks again.

2008-11-26,18:14:08

System Repair Engineer 2.7.0.1210
Smallfrogs (http://www.KZTechs.com)

Windows Vista Home Premium Edition Service Pack 1 (Build 6001) - Administrative User - Completed Functions Allowed

Follow item(s) have been selected:
    All Boot Items (Including Registry, Startup Folders, Services and so on)
    Browser Add-ons
    Running Processes (Including process model information)
    File Associations
    Winsock Provider
    Autorun.Inf
    HOSTS File
    Process Privileges Scan
    Scheduled Tasks
    API HOOK
    Hidden Process


Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <"C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter>  [(Verified)Dell Inc.]
    <>  [N/A]
      [N/A]
      [(Verified)Microsoft Windows]
      [(Verified)Microsoft Windows]
      [(Verified)Microsoft Windows]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <%ProgramFiles%\Windows Defender\MSASCui.exe -hide>  [(Verified)Microsoft Windows]
    <"C:\Program Files\Dell\MediaDirect\PCMService.exe">  [(Verified)CyberLink]
      [(Verified)Intel Corporation]
    <"C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe">  [ ]
      [(Verified)"McAfee, Inc."]
      [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <"C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s>  [Creative Technology Ltd.]
    <"C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter>  [(Verified)Dell Inc.]
    <"C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" /r>  [Creative Technology Ltd]
      [Creative Technology Ltd.]
    <"C:\Program Files\iolo\Common\Lib\ioloLManager.exe">  [(Verified)"iolo technologies, LLC"]
      [(Verified)Microsoft Windows Hardware Compatibility Publisher]
      [(Verified)Microsoft Windows Hardware Compatibility Publisher]
      [(Verified)Microsoft Windows Hardware Compatibility Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
      [(Verified)Microsoft Windows]
      [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
      [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
      [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
      [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
      [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <"%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
      [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
      [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
      [(Verified)Microsoft Windows]
[HKEY_CURRENT_USER\Control Panel\Desktop]
      [(Verified)Microsoft Windows]

==================================
Startup Folders
[Bluetooth]
  C:\PROGRA~1\WIDCOMM\BLUETO~1\BTTray.exe [Broadcom Corporation.]>
[QuickSet]
  C:\PROGRA~1\Dell\QuickSet\quickset.exe [Dell Inc.]>
[Bluetooth]
  C:\PROGRA~1\WIDCOMM\BLUETO~1\BTTray.exe [Broadcom Corporation.]>
[QuickSet]
  C:\PROGRA~1\Dell\QuickSet\quickset.exe [Dell Inc.]>

==================================
Services
[McAfee Application Installer Cleanup (0007421227543704) / 0007421227543704mcinstcleanup][Stopped/Auto Start]
  <(File is missing)>
[Andrea ST Filters Service / AESTFilters][Running/Auto Start]
 
[Apple Mobile Device / Apple Mobile Device][Running/Auto Start]
  <"C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe">
[Bonjour Service / Bonjour Service][Running/Auto Start]
  <"C:\Program Files\Bonjour\mDNSResponder.exe">
[Creative Labs Licensing Service / Creative Labs Licensing Service][Running/Auto Start]
  <"C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe">
[Creative Service for CDROM Access / Creative Service for CDROM Access][Running/Auto Start]
 
[Intel(R) PROSet/Wireless Event Log / EvtEng][Running/Auto Start]
 
[Google Updater Service / gusvc][Stopped/Manual Start]
  <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe">
[Intel(R) Matrix Storage Event Monitor / IAANTMON][Running/Auto Start]
 
[iolo FileInfoList Service / ioloFileInfoList][Running/Auto Start]
  <>
[iolo System Service / ioloSystemService][Running/Auto Start]
  <>
[McAfee SiteAdvisor Service / McAfee SiteAdvisor Service][Running/Auto Start]
  <"C:\Program Files\McAfee\SiteAdvisor\McSACore.exe"><>
[McAfee Services / mcmscsvc][Running/Auto Start]
 
[McAfee Network Agent / McNASvc][Running/Auto Start]
  <"c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe">
[McAfee Scanner / McODS][Stopped/Manual Start]
 
[McAfee Proxy Service / McProxy][Running/Auto Start]
 
[McAfee Real-time Scanner / McShield][Running/Auto Start]
 
[McAfee SystemGuards / McSysmon][Running/Manual Start]
 
[McAfee Personal Firewall Service / MpfService][Running/Auto Start]
  <"C:\Program Files\McAfee\MPF\MPFSrv.exe">
[McAfee Anti-Spam Service / MSK80Service][Running/Auto Start]
  <"C:\Program Files\McAfee\MSK\MskSrver.exe">
[NVIDIA Display Driver Service / nvsvc][Running/Auto Start]
 
[ProtexisLicensing / ProtexisLicensing][Running/Auto Start]
  <>
[Intel(R) PROSet/Wireless Registry Service / RegSrvc][Running/Auto Start]
 
[Remote Procedure Call (RPC) Net / rpcnet][Running/Auto Start]
 
[SupportSoft Sprocket Service (dellsupportcenter) / sprtsvc_dellsupportcenter][Running/Auto Start]
 
[SigmaTel Audio Service / STacSV][Running/Auto Start]
 
[XAudioService / XAudioService][Running/Auto Start]
 

==================================
Drivers
[adp94xx / adp94xx][Stopped/Disabled]
  <\SystemRoot\system32\drivers\adp94xx.sys>
[adpahci / adpahci][Stopped/Disabled]
  <\SystemRoot\system32\drivers\adpahci.sys>
[adpu160m / adpu160m][Stopped/Disabled]
  <\SystemRoot\system32\drivers\adpu160m.sys>
[adpu320 / adpu320][Stopped/Disabled]
  <\SystemRoot\system32\drivers\adpu320.sys>
[aic78xx / aic78xx][Stopped/Disabled]
  <\SystemRoot\system32\drivers\djsvs.sys>
[aliide / aliide][Stopped/Disabled]
  <\SystemRoot\system32\drivers\aliide.sys>
[Alps Touch Pad Filter Driver for Windows 2000/XP/Vista / ApfiltrService][Running/Manual Start]
 
[arc / arc][Stopped/Disabled]
  <\SystemRoot\system32\drivers\arc.sys>
[arcsas / arcsas][Stopped/Disabled]
  <\SystemRoot\system32\drivers\arcsas.sys>
[Broadcom 440x 10/100 Integrated Controller XP Driver / bcm4sbxp][Running/Manual Start]
 
[Brother USB Mass-Storage Lower Filter Driver / BrFiltLo][Stopped/Manual Start]
  <\SystemRoot\system32\drivers\brfiltlo.sys>
[Brother USB Mass-Storage Upper Filter Driver / BrFiltUp][Stopped/Manual Start]
  <\SystemRoot\system32\drivers\brfiltup.sys>
[Brother MFC Serial Port Interface Driver (WDM) / Brserid][Stopped/Disabled]
  <\SystemRoot\system32\drivers\brserid.sys>
[Brother WDM Serial driver / BrSerWdm][Stopped/Disabled]
  <\SystemRoot\system32\drivers\brserwdm.sys>
[Brother MFC USB Fax Only Modem / BrUsbMdm][Stopped/Disabled]
  <\SystemRoot\system32\drivers\brusbmdm.sys>
[Brother MFC USB Serial WDM Driver / BrUsbSer][Stopped/Manual Start]
  <\SystemRoot\system32\drivers\brusbser.sys>
[Bluetooth Audio Device Service / btwaudio][Running/Manual Start]
 
[Bluetooth AVDT / btwavdt][Running/Manual Start]
 
[btwrchid / btwrchid][Running/Manual Start]
 
[cmdide / cmdide][Stopped/Disabled]
  <\SystemRoot\system32\drivers\cmdide.sys>
[WIDCOMM USB Bluetooth Driver in DFU State / DFUBTUSB][Stopped/Manual Start]
 
[Intel(R) PRO/1000 NDIS 6 Adapter Driver / E1G60][Stopped/Manual Start]
 
[ElRawDisk / ElRawDisk][Running/System Start]
  <\??\C:\Windows\system32\drivers\elrawdsk.sys>
[elxstor / elxstor][Stopped/Disabled]
  <\SystemRoot\system32\drivers\elxstor.sys>
[HpCISSs / HpCISSs][Stopped/Disabled]
  <\SystemRoot\system32\drivers\hpcisss.sys>
[HSFHWAZL / HSFHWAZL][Stopped/Manual Start]
 
[HSF_DPV / HSF_DPV][Running/Manual Start]
 
[HSXHWAZL / HSXHWAZL][Running/Manual Start]
 
[Intel AHCI Controller / iaStor][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\iaStor.sys>
[Intel RAID Controller Vista / iaStorV][Stopped/Disabled]
  <\SystemRoot\system32\drivers\iastorv.sys>
[iirsp / iirsp][Stopped/Disabled]
  <\SystemRoot\system32\drivers\iirsp.sys>
[IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start]
 
[ITEATAPI_Service_Install / iteatapi][Stopped/Disabled]
  <\SystemRoot\system32\drivers\iteatapi.sys>
[ITERAID_Service_Install / iteraid][Stopped/Disabled]
  <\SystemRoot\system32\drivers\iteraid.sys>
[LSI_FC / LSI_FC][Stopped/Disabled]
  <\SystemRoot\system32\drivers\lsi_fc.sys>
[LSI_SAS / LSI_SAS][Stopped/Disabled]
  <\SystemRoot\system32\drivers\lsi_sas.sys>
[LSI_SCSI / LSI_SCSI][Stopped/Disabled]
  <\SystemRoot\system32\drivers\lsi_scsi.sys>
[mdmxsdk / mdmxsdk][Running/Auto Start]
 
[megasas / megasas][Stopped/Disabled]
  <\SystemRoot\system32\drivers\megasas.sys>
[MegaSR / MegaSR][Stopped/Disabled]
  <\SystemRoot\system32\drivers\megasr.sys>
[McAfee Inc. mfeavfk / mfeavfk][Running/Manual Start]
 
[McAfee Inc. mfebopk / mfebopk][Running/Manual Start]
 
[McAfee Inc. mfehidk / mfehidk][Running/System Start]
 
[McAfee Inc. mferkdk / mferkdk][Stopped/Manual Start]
 
[McAfee Inc. mfesmfk / mfesmfk][Running/Manual Start]
 
[MPFP / MPFP][Running/System Start]
 
[Mraid35x / Mraid35x][Stopped/Disabled]
  <\SystemRoot\system32\drivers\mraid35x.sys>
[Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit / NETw4v32][Running/Manual Start]
 
[nfrd960 / nfrd960][Stopped/Disabled]
  <\SystemRoot\system32\drivers\nfrd960.sys>
[N-trig HID Tablet Driver / ntrigdigi][Stopped/Disabled]
  <\SystemRoot\system32\drivers\ntrigdigi.sys>
[nvlddmkm / nvlddmkm][Running/Manual Start]
 
[NVIDIA nForce RAID Driver    / nvraid][Stopped/Disabled]
  <\SystemRoot\system32\drivers\nvraid.sys>
[nvstor / nvstor][Stopped/Disabled]
  <\SystemRoot\system32\drivers\nvstor.sys>
[IPX Traffic Filter Driver / NwlnkFlt][Stopped/Manual Start]
 
[IPX Traffic Forwarder Driver / NwlnkFwd][Stopped/Manual Start]
 
[Creative Camera OEM002 Driver / OEM02Dev][Running/Manual Start]
 
[Creative Camera OEM002 Video VFX Driver / OEM02Vfx][Running/Manual Start]
 
[QLogic Fibre Channel Miniport Driver / ql2300][Stopped/Disabled]
  <\SystemRoot\system32\drivers\ql2300.sys>
[QLogic iSCSI Miniport Driver / ql40xx][Stopped/Disabled]
  <\SystemRoot\system32\drivers\ql40xx.sys>
[rimmptsk / rimmptsk][Running/Auto Start]
 
[rimsptsk / rimsptsk][Running/Auto Start]
 
[Ricoh xD-Picture Card Driver / rismxdp][Running/Auto Start]
 
[SiSRaid4 / SiSRaid4][Stopped/Disabled]
  <\SystemRoot\system32\drivers\sisraid4.sys>
[SigmaTel High Definition Audio CODEC / STHDA][Running/Manual Start]
 
[Symc8xx / Symc8xx][Stopped/Disabled]
  <\SystemRoot\system32\drivers\symc8xx.sys>
[Sym_hi / Sym_hi][Stopped/Disabled]
  <\SystemRoot\system32\drivers\sym_hi.sys>
[Sym_u3 / Sym_u3][Stopped/Disabled]
  <\SystemRoot\system32\drivers\sym_u3.sys>
[uliahci / uliahci][Stopped/Disabled]
  <\SystemRoot\system32\drivers\uliahci.sys>
[UlSata / UlSata][Stopped/Disabled]
  <\SystemRoot\system32\drivers\ulsata.sys>
[ulsata2 / ulsata2][Stopped/Disabled]
  <\SystemRoot\system32\drivers\ulsata2.sys>
[viaide / viaide][Stopped/Disabled]
  <\SystemRoot\system32\drivers\viaide.sys>
[vsmraid / vsmraid][Stopped/Disabled]
  <\SystemRoot\system32\drivers\vsmraid.sys>
[winachsf / winachsf][Running/Manual Start]
 
[XAudio / XAudio][Running/Auto Start]
 

==================================
Browser Add-ons
[Adobe PDF Link Helper]
  {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
[Skype add-on (mastermind)]
  {22BF413B-C6D2-4d91-82A9-A0F997BA588C}
[McAfee Phishing Filter]
  {377C180E-6F0E-4D4C-980F-F45BD3D40CF4}
[Java(tm) Plug-In SSV Helper]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
[scriptproxy]
  {7DB2D5A0-7241-4E79-B68D-6309F01C5231}
[CafeMom Toolbar]
  {8151A608-00FB-4D5C-8B8D-40E239E32A42}
[Google Toolbar Helper]
  {AA58ED58-01DD-4d91-8333-CF10577473F7}
[Google Toolbar Notifier BHO]
  {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
[McAfee SiteAdvisor BHO]
  {B164E929-A1B6-4A06-B104-2CD0E90A88FF}
[Java(tm) Plug-In 2 SSV Helper]
  {DBC80044-A445-435b-BC74-9C25C1C588A9}
[CafeMom Toolbar]
  {07DB8C18-9FD9-4e43-AF16-043E44D89768}
[ieSpell]
  {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} <, >
[]
  {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} <, >
[Skype add-on (button)]
  {77BF5300-1474-4EC7-9980-D32B190E9B07}
[&Research]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263}
[@btrez.dll,-4015]
  {CCA281CA-C863-46ef-9331-5C8D4460577F} <, >
[&Google Toolbar]
  {2318C2B1-4965-11d4-9B18-009027A5CD4F}
[McAfee SiteAdvisor Toolbar]
  {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}
[CafeMom Toolbar]
  {8151A608-00FB-4D5C-8B8D-40E239E32A42}
[]
  {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} <, >
[Shockwave ActiveX Control]
  {166B1BCA-3F9C-11CF-8075-444553540000}
[TmHcmsX Control]
  {1EF9F042-C2EB-4293-8213-474CAEEF531D}
[Trend Micro ActiveX Scan Agent 6.6]
  {215B8138-A3CF-44C5-803F-8226143CFC0A}
[]
  {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} <, >
[]
  {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} <, >
[Symantec RuFSI Utility Class]
  {644E432F-49D3-41A1-8DD5-E099162EEEC5} <, >
[Java Plug-in 1.6.0_10]
  {8AD9C840-044E-11D1-B3E9-00805F499D93}
[]
  {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} <, >
[Gather Photo Uploader Control]
  {C8E7CBFB-9F2E-42C7-B4CB-D4B7FC89A363}
[Java Plug-in 1.6.0_10]
  {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
[Java Plug-in 1.6.0_10]
  {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
[Oberon Flash Game Host]
  {D0C0F75C-683A-4390-A791-1ACFD5599AB8}
[]
  {00000000-0000-0000-0000-000000000000} <, >
[Microsoft Works Imaging Server]
  {00E1DB59-6EFD-4CE7-8C0A-2DA3BCAAD9C6}
[Google Script Object]
  {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB}
[Support.com Configuration Class]
  {01113300-3E00-11D2-8470-0060089874ED}
[]
  {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} <, >
[]
  {03F998B2-0E00-11D3-A498-00104B6EB52E} <, >
[Outlook Today's Data-binding control]
  {0468C085-CA5B-11D0-AF08-00609797F0E0}
[]
  {07DB8C18-9FD9-4E43-AF16-043E44D89768} <, >
[]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <, >
[]
  {0E17D5B7-9F5D-4FEE-9DF6-CA6EE38B68A8} <, >
[McAfee SiteAdvisor Toolbar]
  {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}
[PeerDraw Class]
  {10072CEC-8CC1-11D1-986E-00A0C955B42E} <%CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll, (Signed) N/A>
[]
  {1606D6F9-9D3B-4AEA-A025-ED5B2FD488E7} <, >
[Windows Genuine Advantage Validation Tool]
  {17492023-C23A-453E-A040-C7C580BBF700}
[Adobe PDF Link Helper]
  {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
[TmHcmsX Control]
  {1EF9F042-C2EB-4293-8213-474CAEEF531D}
[Trend Micro ActiveX Scan Agent 6.6]
  {215B8138-A3CF-44C5-803F-8226143CFC0A}
[Skype add-on (mastermind)]
  {22BF413B-C6D2-4D91-82A9-A0F997BA588C}
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95}
[&Google Toolbar]
  {2318C2B1-4965-11D4-9B18-009027A5CD4F}
[Shockwave ActiveX Control]
  {233C1507-6A77-46A4-9443-F871F945D258}
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13}
[XML DOM Document]
  {2933BF90-7B36-11D2-B20E-00C04F983E60} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[]
  {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} <, >
[McAfee Phishing Filter]
  {377C180E-6F0E-4D4C-980F-F45BD3D40CF4}
[IETag Factory]
  {38481807-CA0E-42D2-BF39-B33AF135CC4D}
[]
  {4063BE15-3B08-470D-A0D5-B37161CFFD69} <, >
[XML Document]
  {48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[]
  {48DD0448-9209-4F81-9F6D-D83562940134} <, >
[]
  {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} <, >
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C}
[Symantec RuFSI Utility Class]
  {644E432F-49D3-41A1-8DD5-E099162EEEC5} <, >
[DivXBrowserPlugin Object]
  {67DABFBF-D0AB-41FA-9C46-CC0F21721616}
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
[Recovery ActiveX Control Module]
  {700EF03F-A472-4D26-8ACB-300F4D04FD96}
[Java(tm) Plug-In SSV Helper]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
[Skype add-on (button)]
  {77BF5300-1474-4EC7-9980-D32B190E9B07}
[scriptproxy]
  {7DB2D5A0-7241-4E79-B68D-6309F01C5231}
[CafeMom Toolbar]
  {8151A608-00FB-4D5C-8B8D-40E239E32A42}
[Microsoft Web Browser]
  {8856F961-340A-11D0-A96B-00C04FD705A2}
[XML DOM Document 4.0]
  {88D969C0-F192-11D4-A65F-0040963251E5}
[XML HTTP 4.0]
  {88D969C5-F192-11D4-A65F-0040963251E5}
[XML DOM Document 5.0]
  {88D969E5-F192-11D4-A65F-0040963251E5}
[XML DOM Document 6.0]
  {88D96A05-F192-11D4-A65F-0040963251E5} <%SystemRoot%\System32\msxml6.dll, (Signed) N/A>
[Free Threaded XML DOM Document 6.0]
  {88D96A06-F192-11D4-A65F-0040963251E5} <%SystemRoot%\System32\msxml6.dll, (Signed) N/A>
[XSL Template 6.0]
  {88D96A08-F192-11D4-A65F-0040963251E5} <%SystemRoot%\System32\msxml6.dll, (Signed) N/A>
[XML HTTP 6.0]
  {88D96A0A-F192-11D4-A65F-0040963251E5} <%SystemRoot%\System32\msxml6.dll, (Signed) N/A>
[Java Plug-in 1.6.0_10]
  {8AD9C840-044E-11D1-B3E9-00805F499D93}
[]
  {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} <, >
[]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <, >
[]
  {9E385F0A-0BA2-430C-96AA-4399C5E40F6C} <, >
[AxPlayer Control]
  {9F81C14C-04C0-4378-9A0F-70B5F25397BC}
[]
  {A057A204-BACC-4D26-CEC4-75A487FD6484} <, >
[RMGetLicense Class]
  {A9FC132B-096D-460B-B7D5-1DB0FAE0C062}
[Google Toolbar Helper]
  {AA58ED58-01DD-4D91-8333-CF10577473F7}
[Google Toolbar Notifier BHO]
  {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
[McAfee SiteAdvisor BHO]
  {B164E929-A1B6-4A06-B104-2CD0E90A88FF}
[AxVersion Control]
  {B3E658DF-D425-430C-82C2-D54295915020}
[Symantec RuFSI File information Class]
  {C2FCEF4E-ACE9-11D3-BEBD-00105AA9B6AE} <, >
[Symantec RuFSI Registry Information Class]
  {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} <, >
[Gather Photo Uploader Control]
  {C8E7CBFB-9F2E-42C7-B4CB-D4B7FC89A363}
[Adobe PDF Reader]
  {CA8A9780-280D-11CF-A24D-444553540000}
[]
  {CCA281CA-C863-46EF-9331-5C8D4460577F} <, >
[AUDIO__MID Moniker Class]
  {CD3AFA74-B84F-48F0-9393-7EDC34128127} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
[AUDIO__MP3 Moniker Class]
  {CD3AFA76-B84F-48F0-9393-7EDC34128127} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
[AUDIO__WAV Moniker Class]
  {CD3AFA7B-B84F-48F0-9393-7EDC34128127} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
[VIDEO__AVI Moniker Class]
  {CD3AFA88-B84F-48F0-9393-7EDC34128127} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
[VIDEO__X_MS_ASF Moniker Class]
  {CD3AFA8F-B84F-48F0-9393-7EDC34128127} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
[Microsoft Url Search Hook]
  {CFBFAE00-17A6-11D0-99CB-00C04FD64497}
[Msxml]
  {CFC399AF-D876-11D0-9C10-00C04FC99C8E} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[Oberon Flash Game Host]
  {D0C0F75C-683A-4390-A791-1ACFD5599AB8}
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000}
[Java(tm) Plug-In 2 SSV Helper]
  {DBC80044-A445-435B-BC74-9C25C1C588A9}
[]
  {DE4AF3B0-F4D4-11D3-B41A-0050DA2E6C21} <, >
[Microsoft Silverlight]
  {DFEAF541-F3E1-4C24-ACAC-99C30715084A}
[Google Find Bar]
  {E16DC1FE-7C34-43F2-B754-F3AD12DDF97C}
[NameCtrl Class]
  {E18FEC31-2EA1-49A2-A7A6-902DC0D1FF05}
[]
  {E3E02F12-2ADB-478C-8742-5F0819F9F0F4} <"C:\Users\Via\AppData\Roaming\Move Networks\ie_bin\qsp2ie071101000055.dll", N/A>
[]
  {e473a65c-8087-49a3-affd-c5bc4a10669b} <"C:\Users\Via\AppData\Roaming\Move Networks\ie_bin\qsp2ie071101000055.dll", N/A>
[XML HTTP Request]
  {ED8C108E-4349-11D2-91A4-00C04F7969E8} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[XML DOM Document 3.0]
  {F5078F32-C551-11D3-89B9-0000F81FE221} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[XML DOM Document]
  {F6D90F11-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[XML HTTP]
  {F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[]
  {FC345D4C-B8F4-4674-BFF7-3C37D2E535EE} <"C:\Users\Via\AppData\Roaming\Move Networks\ie_bin\qsp2ie071101000055.dll", N/A>
[]
  {fd6484ed-ebe3-4c3d-938a-8238003b41b7} <"C:\Users\Via\AppData\Roaming\Move Networks\ie_bin\qsp2ie071101000055.dll", N/A>
[&ieSpell Options]
 
[Check &Spelling]
 
[Lookup on Merriam Webster]
  < file://C:\Program Files\ieSpell\Merriam Webster.HTM, N/A>
[Lookup on Wikipedia]
  < file://C:\Program Files\ieSpell\wikipedia.HTM, N/A>

==================================
Running Processes
[PID: 444 / SYSTEM][\SystemRoot\System32\smss.exe]  [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 584 / SYSTEM][C:\Windows\system32\csrss.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 636 / SYSTEM][C:\Windows\system32\wininit.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 648 / SYSTEM][C:\Windows\system32\csrss.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 680 / SYSTEM][C:\Windows\system32\services.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 692 / SYSTEM][C:\Windows\system32\lsass.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 700 / SYSTEM][C:\Windows\system32\lsm.exe]  [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 804 / SYSTEM][C:\Windows\system32\winlogon.exe]  [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 888 / SYSTEM][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 932 / SYSTEM][C:\Windows\system32\nvvsvc.exe]  [NVIDIA Corporation, 7.15.11.7597]
[PID: 960 / NETWORK SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 996 / SYSTEM][C:\Windows\System32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1088 / LOCAL SERVICE][C:\Windows\System32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
    [C:\Windows\system32\stapo.dll]  [IDT, Inc., 1.0.5614.0  nd654 cp1]
    [C:\Windows\system32\ctapo32.dll]  [Creative Technology Ltd., 1.0.0.195]
[PID: 1116 / SYSTEM][C:\Windows\System32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1128 / SYSTEM][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
[PID: 1228 / SYSTEM][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1244 / NETWORK SERVICE][C:\Windows\system32\SLsvc.exe]  [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 1368 / LOCAL SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
[PID: 1388 / SYSTEM][C:\Windows\system32\rundll32.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\system32\NVSVC.DLL]  [NVIDIA Corporation, 7.15.11.7597]
    [C:\Windows\system32\nvapi.dll]  [NVIDIA Corporation, 7.15.11.7597]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 1572 / NETWORK SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
[PID: 1728 / SYSTEM][C:\Windows\system32\WLANExt.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\System32\IWMSSvc.dll]  [Intel Corporation , 11, 1, 1, 4]
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  [Intel Corporation, 11, 1, 1, 1]
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  [Intel Corporation, 11, 1, 1, 0]
    [C:\Program Files\Intel\Wireless\Bin\Dot1xCfg.dll]  [Intel Corporation, 11.1.1.0  ]
    [C:\Program Files\Intel\Wireless\Bin\acAuth.dll]  [, 4.1.0.91 2007-03-30 10:41:31]
    [C:\Program Files\Intel\Wireless\Bin\IntStngs.dll]  [Intel Corporation, 11.1.1.0  ]
    [C:\Program Files\Intel\Wireless\Bin\IWMSPROV.DLL]  [N/A, ]
    [C:\Program Files\Intel\Wireless\Bin\C1XStngs.dll]  [Intel Corporation, 11.1.1.1  ]
    [C:\Program Files\Intel\Wireless\Bin\LSAWRAPI.dll]  [Intel Corporation, 11.1.1.0]
    [C:\Program Files\Intel\Wireless\Bin\PfMgrApi.dll]  [Intel Corporation, 11.1.1.4]
    [C:\Program Files\Intel\Wireless\Bin\LIBEAY32.dll]  [The OpenSSL Project, http://www.openssl.org/, 0.9.8]
    [C:\Program Files\Intel\Wireless\Bin\DbEngine.dll]  [Intel Corporation, 11, 1, 1, 6]
[PID: 1836 / SYSTEM][C:\Windows\System32\spoolsv.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\System32\hpzlllhn.dll]  [Hewlett-Packard Company, 61.053.25.9]
    [C:\Windows\system32\spool\PRTPROCS\W32X86\hpzpplhn.dll]  [Hewlett-Packard Corporation, 61.053.25.9]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
[PID: 1876 / LOCAL SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 324 / SYSTEM][C:\Windows\system32\aestsrv.exe]  [Andrea Electronics Corporation, 1.0.32.2]
[PID: 340 / SYSTEM][C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe]  [Apple Inc., 2.11.32.0]
[PID: 360 / SYSTEM][C:\Program Files\Bonjour\mDNSResponder.exe]  [Apple Inc., 1,0,5,11]
[PID: 384 / LOCAL SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 452 / SYSTEM][C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe]  [Creative Labs, 2.70.000]
[PID: 536 / SYSTEM][C:\Windows\system32\CTsvcCDA.exe]  [Creative Technology Ltd, 1.0.1.0]
[PID: 724 / SYSTEM][C:\Program Files\Intel\Wireless\Bin\EvtEng.exe]  [Intel Corporation, 11.1.1.1  ]
    [C:\Program Files\Intel\Wireless\Bin\PfMgrApi.dll]  [Intel Corporation, 11.1.1.4]
    [C:\Program Files\Intel\Wireless\Bin\LIBEAY32.dll]  [The OpenSSL Project, http://www.openssl.org/, 0.9.8]
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  [Intel Corporation, 11, 1, 1, 1]
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  [Intel Corporation, 11, 1, 1, 0]
    [C:\Program Files\Intel\Wireless\Bin\DbEngine.dll]  [Intel Corporation, 11, 1, 1, 6]
    [C:\Program Files\Intel\Wireless\Bin\IntStngs.dll]  [Intel Corporation, 11.1.1.0  ]
    [C:\Program Files\Intel\Wireless\Bin\MurocApi.dll]  [Intel Corporation, 11.1.1.2]
    [C:\Program Files\Intel\Wireless\Bin\S24MUDLL.dll]  [Intel Corporation, 11.1.1.0]
[PID: 1536 / SYSTEM][C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe]  [Intel Corporation, 7.0.0.1020]
    [C:\Program Files\Intel\Intel Matrix Storage Manager\ISDI.dll]  [Intel Corporation, 7.0.0.1020]
    [C:\Program Files\Intel\Intel Matrix Storage Manager\PlugInRAID_ENU.dll]  [Intel Corporation, 7.0.0.1020]
[PID: 1608 / SYSTEM][C:\Program Files\iolo\common\lib\ioloServiceManager.exe]  [, ]
    [C:\Program Files\iolo\Common\Lib\fbembed.dll]  [The Firebird Project, WI-V1.5.2.4731]
[PID: 2104 / SYSTEM][C:\Program Files\McAfee\SiteAdvisor\McSACore.exe]  [, ]
    [c:\PROGRA~1\mcafee\SITEAD~1\apengine.dll]  [, ]
    [c:\PROGRA~1\mcafee\SITEAD~1\saupkeep.dll]  [, ]
    [c:\PROGRA~1\mcafee\SITEAD~1\McFrmWk.dll]  [, ]
    [c:\PROGRA~1\mcafee\SITEAD~1\CntScan.dll]  [, ]
    [C:\Program Files\McAfee\SiteAdvisor\SACore.dll]  [, ]
    [C:\Program Files\McAfee\SiteAdvisor\SASet.dll]  [, ]
    [c:\PROGRA~1\mcafee\SITEAD~1\MCSACO~1.DLL]  [, ]
    [c:\PROGRA~1\mcafee\msc\mcregobj\8_0_22~1\mcregobj.dll]  [McAfee, Inc., 8,0,226,0]
    [c:\PROGRA~1\COMMON~1\mcafee\msc\mcutil\8_1_11~1\McUtil.dll]  [McAfee, Inc., 8,1,114,0]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
[PID: 2132 / SYSTEM][c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe]  [McAfee, Inc., 2,0,151,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\escnplug.dll]  [McAfee, Inc., 12,1,109,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\EsPlgRes.dll]  [McAfee, Inc., 12,0,188,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\mvscfg.dll]  [McAfee, Inc., 12,1,118,0]
    [c:\PROGRA~1\mcafee\mps\mps.dll]  [McAfee, Inc., 10.1.141.0]
    [c:\PROGRA~1\mcafee\mps\mpscfg.dll]  [McAfee, Inc., 10.1.137.0]
    [c:\PROGRA~1\mcafee\msk\mskpxplg.dll]  [McAfee, Inc., 9.1.107.0]
    [C:\Windows\system32\Dunzip32.dll]  [Inner Media, Inc., 5.00.06]
    [c:\PROGRA~1\mcafee\msc\mcmispps.dll]  [McAfee, Inc., 8,0,226,0]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mcevtbrk.dll]  [McAfee, Inc., 3,0,117,0]
    [c:\PROGRA~1\mcafee\mps\mpsevh.dll]  [McAfee, Inc., 10.1.133.0]
    [c:\PROGRA~1\mcafee\mps\mpsmisp.dll]  [McAfee, Inc., 10.1.137.0]
    [c:\PROGRA~1\mcafee\msc\mcsubmgr\8_1_13~1\mcsubmgr.dll]  [McAfee, Inc., 8,1,133,0]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mccoreps.dll]  [McAfee, Inc., 3,0,117,0]
    [C:\Program Files\McAfee\VirusScan\mvslog.dll]  [McAfee, Inc., 12,0,172,0]
[PID: 2152 / SYSTEM][C:\Windows\system32\rundll32.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 2184 / SYSTEM][C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe]  [McAfee, Inc., VSCORE.14.0.0.349.x86]
    [C:\PROGRA~1\McAfee\VIRUSS~1\LockDown.dll]  [McAfee, Inc., VSCORE.14.0.0.349.x86]
    [C:\PROGRA~1\McAfee\VIRUSS~1\mytilus3.dll]  [McAfee, Inc., VSCORE.14.0.0.349.x86]
    [C:\PROGRA~1\McAfee\VIRUSS~1\mytilus3_worker.dll]  [McAfee, Inc., VSCORE.14.0.0.349.x86]
    [C:\PROGRA~1\McAfee\VIRUSS~1\mytilus3_server.dll]  [McAfee, Inc., VSCORE.14.0.0.349.x86]
    [C:\PROGRA~1\McAfee\VIRUSS~1\RES00\McShield.dll]  [McAfee, Inc., VSCORE.14.0.0.349]
    [C:\PROGRA~1\McAfee\VIRUSS~1\FTL.Dll]  [McAfee, Inc., VSCORE.14.0.0.349.x86]
    [C:\PROGRA~1\McAfee\VIRUSS~1\naiann.dll]  [McAfee, Inc., 12,0,188,0]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mccoreps.dll]  [McAfee, Inc., 3,0,117,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\mcvsps.dll]  [McAfee, Inc., 12,0,188,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\naiannps.dll]  [McAfee, Inc., 12,0,188,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\mvscfg.dll]  [McAfee, Inc., 12,1,118,0]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mcevtbrk.dll]  [McAfee, Inc., 3,0,117,0]
    [C:\PROGRA~1\McAfee\VIRUSS~1\mvslog.dll]  [McAfee, Inc., 12,0,172,0]
    [C:\Program Files\McAfee\VirusScan\Engine\5300.2777\mcscan32.dll]  [McAfee, Inc., 5.3.00]
    [C:\PROGRA~1\McAfee\VIRUSS~1\mfebopa.dll]  [McAfee, Inc., SYSCORE.14.0.0.291.x86]
    [C:\PROGRA~1\McAfee\VIRUSS~1\mfehida.dll]  [McAfee, Inc., SYSCORE.14.0.0.291.x86]
    [C:\PROGRA~1\McAfee\VIRUSS~1\mfeavfa.dll]  [McAfee, Inc., SYSCORE.14.0.0.291.x86]
    [c:\PROGRA~1\mcafee\msc\mcsubmgr\8_1_13~1\mcsubmgr.dll]  [McAfee, Inc., 8,1,133,0]
[PID: 2224 / SYSTEM][C:\Program Files\McAfee\MPF\MPFSrv.exe]  [McAfee, Inc., 9.0.136.0]
    [c:\PROGRA~1\COMMON~1\mcafee\HACKER~1\hwapi.dll]  [McAfee, Inc., 9.0.119.0]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mcevtbrk.dll]  [McAfee, Inc., 3,0,117,0]
    [c:\PROGRA~1\mcafee\mpf\mc\mpfmisp.dll]  [McAfee, Inc., 9.0.136.0]
    [c:\PROGRA~1\mcafee\msc\mccfgpv.dll]  [McAfee, Inc., 8,1,133,0]
    [C:\PROGRA~1\McAfee\MSC\McRes.dll]  [McAfee, Inc., 8,0,226,0]
    [C:\PROGRA~1\McAfee\MSC\McLocRes.dll]  [McAfee, Inc., 8,1,153,0]
    [C:\Program Files\McAfee\MSC\oem\105-257\Mccobres.dll]  [McAfee, Inc., 8, 1, 165, 1]
    [C:\PROGRA~1\McAfee\MSC\Mccobres.dll]  [McAfee, Inc., 8,1,165,0]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
[PID: 2308 / SYSTEM][C:\Program Files\McAfee\MSK\MskSrver.exe]  [McAfee, Inc., 9.1.107.0]
    [c:\PROGRA~1\mcafee\msk\mskengn.dll]  [McAfee, Inc., 9.1.107.0]
    [c:\PROGRA~1\mcafee\msk\mskwm.dll]  [McAfee, Inc., 9.1.107.0]
    [c:\PROGRA~1\mcafee\msk\mskxaif.dll]  [McAfee, Inc., 9.1.107.0]
    [C:\Program Files\McAfee\MSK\MSKSet.dll]  [McAfee, Inc., 9.1.107.0]
    [C:\Program Files\McAfee\MSK\MSKMFW.dll]  [McAfee, Inc., 9.1.107.0]
    [C:\Program Files\McAfee\MSK\MSKMCmn.dll]  [McAfee, Inc., 9.1.109.0]
    [C:\Program Files\McAfee\MSK\MSKMUF.dll]  [McAfee, Inc., 9.1.107.0]
    [C:\Program Files\McAfee\MSK\MSKMSF.dll]  [McAfee, Inc., 9.1.107.0]
    [C:\Program Files\McAfee\MSK\MSKMRLS.dll]  [McAfee, Inc., 9.1.107.0]
    [C:\Program Files\McAfee\MSK\MSKMB52.dll]  [McAfee, Inc., 9.1.107.0]
    [C:\Program Files\McAfee\MSK\MSKGRE.dll]  [McAfee, Inc., 9.1.107.0]
    [C:\Program Files\McAfee\MSK\McAPFilt.dll]  [McAfee, Inc., 9.1.107.0]
[PID: 2372 / NETWORK SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2444 / SYSTEM][C:\Windows\system32\PSIService.exe]  [, 2.0.0.1]
    [C:\Windows\system32\PSIKey.dll]  [Protexis Inc., 2.0.0.1]
[PID: 2520 / SYSTEM][C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe]  [Intel Corporation, 11.1.1.0  ]
[PID: 2560 / SYSTEM][C:\Windows\System32\rpcnet.exe]  [Absolute Software Corp., 8.0.879.0]
    [C:\Windows\System32\rpcnet.dll]  [Absolute Software Corp., 8.0.879.0]
[PID: 2648 / SYSTEM][C:\Program Files\Dell Support Center\bin\sprtsvc.exe]  [SupportSoft, Inc., 7.0.1117.0]
    [C:\Program Files\Dell Support Center\bin\sprtsched.dll]  [SupportSoft, Inc., 7.0.940.0]
    [C:\Program Files\Dell Support Center\bin\sprtfod.dll]  [SupportSoft, Inc., 7.0.940.0]
    [C:\Program Files\Dell Support Center\bin\LIBEAY32.dll]  [SupportSoft, Inc., 0, 9, 8, 4, 1]
    [C:\Program Files\Dell Support Center\bin\sprtsync.dll]  [SupportSoft, Inc., 7.0.1302.0]
    [C:\Program Files\Dell Support Center\bin\sprtupdate.dll]  [SupportSoft, Inc., 7.0.940.0]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
[PID: 2676 / SYSTEM][C:\Windows\system32\STacSV.exe]  [IDT, Inc., 1.0.5614.0  nd654 cp1]
    [C:\Windows\system32\stapi32.dll]  [IDT, Inc., 1.0.5614.0  nd654 cp1]
[PID: 2720 / LOCAL SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2748 / SYSTEM][C:\Windows\System32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2856 / SYSTEM][C:\Windows\system32\DRIVERS\xaudio.exe]  [Conexant Systems, Inc., 1.00.00]
[PID: 3328 / SYSTEM][C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe]  [McAfee, Inc., 8,1,159,0]
    [c:\PROGRA~1\COMMON~1\mcafee\msc\mcutil\8_1_11~1\McUtil.dll]  [McAfee, Inc., 8,1,114,0]
    [C:\PROGRA~1\McAfee\MSC\McRes.dll]  [McAfee, Inc., 8,0,226,0]
    [C:\PROGRA~1\McAfee\MSC\McLocRes.dll]  [McAfee, Inc., 8,1,153,0]
    [C:\Program Files\McAfee\MSC\oem\105-257\Mccobres.dll]  [McAfee, Inc., 8, 1, 165, 1]
    [C:\PROGRA~1\McAfee\MSC\Mccobres.dll]  [McAfee, Inc., 8,1,165,0]
    [C:\PROGRA~1\COMMON~1\McAfee\MSC\sqlite3.dll]  [McAfee, Inc., 8,1,125,0]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mccoreps.dll]  [McAfee, Inc., 3,0,117,0]
    [c:\PROGRA~1\mcafee\msc\mcmispps.dll]  [McAfee, Inc., 8,0,226,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\mvsap.dll]  [McAfee, Inc., 12,0,172,0]
    [c:\PROGRA~1\mcafee\mpf\mc\mpfmisp.dll]  [McAfee, Inc., 9.0.136.0]
    [C:\Program Files\McAfee\MPF\L10N.DLL]  [McAfee, Inc., 9.1.108.0]
    [c:\PROGRA~1\mcafee\msk\mskmisp.dll]  [McAfee, Inc., 9.1.107.0]
    [c:\PROGRA~1\mcafee\mps\mpsmisp.dll]  [McAfee, Inc., 10.1.137.0]
    [C:\Program Files\McAfee\MPS\MpsRes.DLL]  [McAfee, Inc., 10.0.263.0]
    [c:\PROGRA~1\mcafee\msc\mcshllps.dll]  [McAfee, Inc., 8,1,133,0]
    [c:\PROGRA~1\mcafee\msc\mcsubmgr\8_1_13~1\mcsubmgr.dll]  [McAfee, Inc., 8,1,133,0]
    [c:\PROGRA~1\mcafee\msc\mcmscver.dll]  [McAfee, Inc., 8,1,136,0]
    [c:\PROGRA~1\mcafee\msc\mcprotpv.dll]  [McAfee, Inc., 8,0,226,0]
    [C:\PROGRA~1\McAfee\MSC\McNmcRes.dll]  [McAfee, Inc., 2,1,151,0]
    [C:\PROGRA~1\McAfee\MSC\McNmcLoR.dll]  [McAfee, Inc., 2,1,151,0]
    [C:\PROGRA~1\McAfee\MSC\McNmcCoR.dll]  [McAfee, Inc., 2,1,151,0]
    [C:\PROGRA~1\McAfee\MSC\McProHlp.dll]  [McAfee, Inc., 8,0,226,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\mvsver.dll]  [McAfee, Inc., 12,0,188,0]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mcevtbrk.dll]  [McAfee, Inc., 3,0,117,0]
    [c:\PROGRA~1\COMMON~1\mcafee\mcproxy\proxyver.dll]  [McAfee, Inc., 2,0,151,0]
    [c:\PROGRA~1\COMMON~1\mcafee\HACKER~1\hwapi.dll]  [McAfee, Inc., 9.0.119.0]
    [c:\PROGRA~1\mcafee\mps\mpsver.dll]  [McAfee, Inc., 10.0.263.0]
    [c:\PROGRA~1\mcafee\msc\mcnmcver.dll]  [McAfee, Inc., 2,0,115,0]
    [c:\PROGRA~1\mcafee\mqc\qcmisp.dll]  [McAfee, Inc., 8,1,106,0]
    [c:\PROGRA~1\mcafee\mqc\QcLite.dll]  [McAfee, Inc., 8,1,106,0]
    [c:\PROGRA~1\mcafee\msc\mcdemenu.dll]  [McAfee, Inc., 8,0,226,0]
    [c:\PROGRA~1\mcafee\mps\mpspii.dll]  [McAfee, Inc., 10.1.141.0]
    [c:\PROGRA~1\mcafee\mps\mpscfg.dll]  [McAfee, Inc., 10.1.137.0]
    [c:\PROGRA~1\mcafee\mps\mpspv.dll]  [McAfee, Inc., 10.1.133.0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\mvscp.dll]  [McAfee, Inc., 12,0,172,0]
    [c:\PROGRA~1\mcafee\msc\mcuicfg.dll]  [McAfee, Inc., 8,0,226,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\mvscfg.dll]  [McAfee, Inc., 12,1,118,0]
    [c:\PROGRA~1\mcafee\mps\mpspc.dll]  [McAfee, Inc., 10.1.141.0]
    [c:\PROGRA~1\mcafee\msc\mccfgpv.dll]  [McAfee, Inc., 8,1,133,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\mcvspp.dll]  [McAfee, Inc., 12,1,109,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\naiannps.dll]  [McAfee, Inc., 12,0,188,0]
    [c:\PROGRA~1\mcafee\msc\mcregobj\8_0_22~1\mcregobj.dll]  [McAfee, Inc., 8,0,226,0]
    [c:\PROGRA~1\mcafee\msc\mcnmcprv.dll]  [McAfee, Inc., 2,1,151,0]
    [c:\PROGRA~1\COMMON~1\mcafee\mna\MCNASV~1.DLL]  [McAfee, Inc., 2,1,143,0]
    [c:\PROGRA~1\mcafee\msc\mcnmcsps.dll]  [McAfee, Inc., 2,0,115,0]
    [c:\PROGRA~1\mcafee\mpf\mc\mpfp.dll]  [McAfee, Inc., 9.0.136.0]
[PID: 3624 / SYSTEM][C:\Windows\system32\taskeng.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2768 / Via][c:\PROGRA~1\mcafee.com\agent\mcagent.exe]  [McAfee, Inc., 8,0,237,0]
    [C:\PROGRA~1\McAfee\MSC\McRes.dll]  [McAfee, Inc., 8,0,226,0]
    [C:\PROGRA~1\McAfee\MSC\McLocRes.dll]  [McAfee, Inc., 8,1,153,0]
    [C:\Program Files\McAfee\MSC\oem\105-257\Mccobres.dll]  [McAfee, Inc., 8, 1, 165, 1]
    [C:\PROGRA~1\McAfee\MSC\Mccobres.dll]  [McAfee, Inc., 8,1,165,0]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [c:\PROGRA~1\mcafee\msc\mcsubmgr\8_1_13~1\mcsubmgr.dll]  [McAfee, Inc., 8,1,133,0]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mccoreps.dll]  [McAfee, Inc., 3,0,117,0]
    [c:\PROGRA~1\mcafee\msc\mcmispps.dll]  [McAfee, Inc., 8,0,226,0]
    [c:\PROGRA~1\mcafee.com\agent\mcagntps.dll]  [McAfee, Inc., 8,0,226,0]
    [c:\PROGRA~1\mcafee\msc\mccfgpv.dll]  [McAfee, Inc., 8,1,133,0]
    [c:\PROGRA~1\mcafee\msc\mcuicfg.dll]  [McAfee, Inc., 8,0,226,0]
[PID: 1380 / Via][C:\Windows\system32\taskeng.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Windows\system32\nvapi.dll]  [NVIDIA Corporation, 7.15.11.7597]
[PID: 3396 / Via][C:\Windows\system32\Dwm.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Windows\system32\nvd3dum.dll]  [NVIDIA Corporation, 7.15.11.7597]
    [C:\Program Files\Dell\QuickSet\dadkeyb.dll]  [Dell Inc., 8, 2, 20, 0]
    [C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll]  [N/A, ]
[PID: 3204 / Via][C:\Windows\Explorer.EXE]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Windows\system32\btncopy.dll]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Program Files\Dell\QuickSet\dadkeyb.dll]  [Dell Inc., 8, 2, 20, 0]
    [C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll]  [N/A, ]
[PID: 4008 / Via][C:\Program Files\Windows Defender\MSASCui.exe]  [Microsoft Corporation, 1.1.1600.0]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
[PID: 4044 / Via][C:\Program Files\Dell\MediaDirect\PCMService.exe]  [CyberLink Corp., 4, 5, 0, 0]
    [C:\Program Files\Dell\MediaDirect\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Dell\MediaDirect\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Dell\MediaDirect\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Program Files\Dell\MediaDirect\Kernel\common\CLRCEngine3.dll]  [CyberLink Corp., 4.07.1305]
    [C:\Program Files\Dell\MediaDirect\Kernel\Movie\CLNavX.ax]  [CyberLink Corp., 6.00.4601]
[PID: 2452 / Via][C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe]  [Intel Corporation, 7.0.0.1020]
    [C:\Program Files\Intel\Intel Matrix Storage Manager\ISDI.dll]  [Intel Corporation, 7.0.0.1020]
    [C:\Program Files\Intel\Intel Matrix Storage Manager\IAAMon_ENU.dll]  [Intel Corporation, 7.0.0.1020]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 3992 / Via][C:\Windows\OEM02Mon.exe]  [Creative Technology Ltd., 1.01.01.00]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 3340 / Via][C:\Program Files\Dell Support Center\bin\sprtcmd.exe]  [SupportSoft, Inc., 7.0.1117.0]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Program Files\Dell Support Center\bin\sprtmessage.dll]  [SupportSoft, Inc., 7.2.955.0]
    [C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\5b3e3b0551bcaa722c27dbb089c431e4\mscorlib.ni.dll]  [Microsoft Corporation, 2.0.50727.1434 (REDBITS.050727-1400)]
    [C:\Program Files\Dell Support Center\bin\sprtsched.dll]  [SupportSoft, Inc., 7.0.940.0]
    [C:\Program Files\Dell Support Center\bin\sprtevent.dll]  [SupportSoft, Inc., 7.0.940.0]
    [C:\Program Files\Dell Support Center\bin\sprtfod.dll]  [SupportSoft, Inc., 7.0.940.0]
    [C:\Program Files\Dell Support Center\bin\LIBEAY32.dll]  [SupportSoft, Inc., 0, 9, 8, 4, 1]
    [C:\Program Files\Dell Support Center\bin\sprtsync.dll]  [SupportSoft, Inc., 7.0.1302.0]
    [C:\Program Files\Dell Support Center\bin\sprtui.dll]  [SupportSoft, Inc., 7.0.1057.0]
    [C:\Program Files\Dell Support Center\bin\SupportSoft.Agent.Sprocket.SupportMessage.dll]  [SupportSoft, Inc., 7.2.955.0]
    [C:\Program Files\Dell Support Center\bin\SupportSoft.Agent.Sprocket.dll]  [SupportSoft, Inc., 7.2.955.0]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
    [C:\Windows\assembly\NativeImages_v2.0.50727_32\System\267d4c344058092e6950c11594244f90\System.ni.dll]  [Microsoft Corporation, 2.0.50727.1434 (REDBITS.050727-1400)]
    [C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\02cf61328d59df9b3ec09544f449a781\System.Xml.ni.dll]  [Microsoft Corporation, 2.0.50727.1434 (REDBITS.050727-1400)]
[PID: 676 / Via][C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe]  [Creative Technology Ltd, 2.20.6.0]
    [C:\Program Files\Creative\SBAudigy\Volume Panel\CTAudSeu.dll]  [Creative Technology Ltd, 1.0.2.0]
    [C:\Program Files\Creative\SBAudigy\Volume Panel\CTAudEp.dll]  [Creative Technology Ltd, 1.1.6.0]
    [C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanel.crl]  [Creative Technology Ltd, 2.10.3.0]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Program Files\Creative\ShareDLL\CADI\CTCadiEP.dll]  [Creative Technology Ltd, 1.0.0.6]
    [C:\Windows\system32\CmdRtr.dll]  [, ]
    [C:\Windows\system32\APOMngr.dll]  [, ]
    [C:\Windows\system32\ctapo32.dll]  [Creative Technology Ltd., 1.0.0.195]
    [C:\Program Files\Creative\SBAudigy\Volume Panel\CTThemeU.dll]  [Creative Technology Ltd, 3.1.16.0]
    [C:\Program Files\Creative\SBAudigy\Volume Panel\CtrlSrcU.dll]  [Creative Technology Ltd., 3.1.2.0]
    [C:\Program Files\Creative\SBAudigy\Volume Panel\CTIniFu.dll]  [Creative Technology Ltd, 1.2.0.0]
    [C:\Program Files\Creative\SBAudigy\Volume Panel\GDICtrl.sku]  [Creative Technology Ltd, 3.1.30.0]
    [C:\Program Files\Creative\SBAudigy\Volume Panel\GDICtrl2.sku]  [Creative Technology Ltd, 3.1.20.0]
    [C:\Program Files\Creative\SBAudigy\Volume Panel\GDICtrl3.sku]  [Creative Technology Ltd, 3.1.16.0]
    [C:\Program Files\Creative\SBAudigy\Volume Panel\RtxCtrl.sku]  [Creative Technology Ltd, 3.1.15.0]
[PID: 3672 / SYSTEM][C:\Windows\system32\SearchIndexer.exe]  [(Verified) Microsoft Corporation, 7.0.6001.16503 (longhorn(wmbla).080526-2159)]
[PID: 2876 / Via][C:\Program Files\DellTPad\Apoint.exe]  [Alps Electric Co., Ltd., 7.0.101.204]
    [C:\Program Files\DellTPad\Apoint.dll]  [Alps Electric Co., Ltd., 5.5.104.336]
    [C:\Windows\system32\Vxdif.dll]  [Alps Electric Co., Ltd., 6.0.3.17]
    [C:\Program Files\DellTPad\EzAuto.dll]  [Alps Electric Co., Ltd., 5.5.1.92]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 1320 / Via][C:\Windows\System32\rundll32.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\system32\nvHotkey.dll]  [NVIDIA Corporation, 7.15.11.7597]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 1044 / Via][C:\Program Files\DellTPad\ApMsgFwd.exe]  [Alps Electric Co., Ltd., 7, 0, 0, 18]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 3088 / Via][C:\Program Files\DellTPad\Apntex.exe]  [Alps Electric Co., Ltd., 7.0.1.27]
    [C:\Windows\system32\VXDIF.DLL]  [Alps Electric Co., Ltd., 6.0.3.17]
    [C:\Program Files\DellTPad\Apoint.DLL]  [Alps Electric Co., Ltd., 5.5.104.336]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 1788 / Via][C:\Program Files\DellTPad\HidFind.exe]  [Alps Electric Co., Ltd., 7.0.0.26]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 4104 / Via][C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe]  [ACD Systems, 5,0,49,0]
    [C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80U.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Windows\WinSxS\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131\MFC80ENU.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 4136 / Via][C:\Windows\ehome\ehtray.exe]  [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 4144 / Via][C:\Program Files\Windows Media Player\wmpnscfg.exe]  [Microsoft Corporation, 11.0.6000.6324 (vista_rtm.061101-2205)]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 4164 / Via][C:\Windows\ehome\ehmsas.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 4172 / Via][C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Windows\system32\btwapi.dll]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Windows\system32\btosif.dll]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Windows\system32\btwhidcs.DLL]  [N/A, ]
    [C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80U.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\WIDCOMM\Bluetooth Software\BtBalloon.dll]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Windows\WinSxS\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131\MFC80ENU.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Windows\system32\btrez.dll]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll]  [N/A, ]
    [C:\Windows\system32\btmmhook.dll]  [Broadcom Corporation., 6.0.1.3100]
[PID: 4224 / NETWORK SERVICE][C:\Program Files\Windows Media Player\wmpnetwk.exe]  [Microsoft Corporation, 11.0.6000.6324 (vista_rtm.061101-2205)]
[PID: 4232 / Via][C:\Program Files\Dell\QuickSet\quickset.exe]  [Dell Inc., 8, 2, 20, 0]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Program Files\Dell\QuickSet\dadkeyb.dll]  [Dell Inc., 8, 2, 20, 0]
[PID: 4328 / SYSTEM][C:\Windows\system32\wbem\wmiprvse.exe]  [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 4476 / Via][C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Windows\system32\btins.dll]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Windows\system32\btosif.dll]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Windows\system32\BtAudioHelper.dll]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Windows\WinSxS\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131\MFC80ENU.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Windows\system32\btosif_ol.dll]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Windows\system32\btosif_olx.dll]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Windows\system32\btosif_notes.dll]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 4932 / Via][C:\Program Files\Dell\PC TuneUp\SMSystemAnalyzer.exe]  [, ]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Program Files\iolo\Common\Lib\LMResource.dll]  [N/A, ]
    [C:\Program Files\iolo\Common\Lib\Antila.dll]  [N/A, ]
[PID: 5988 / SYSTEM][C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe]  [McAfee, Inc., 12,1,111,0]
    [c:\PROGRA~1\mcafee\msc\mcmispps.dll]  [McAfee, Inc., 8,0,226,0]
    [C:\PROGRA~1\McAfee\VIRUSS~1\mvslog.dll]  [McAfee, Inc., 12,0,172,0]
    [C:\PROGRA~1\McAfee\VIRUSS~1\mfesmfa.dll]  [McAfee, Inc., SYSCORE.14.0.0.291.x86]
    [C:\PROGRA~1\McAfee\VIRUSS~1\mfehida.dll]  [McAfee, Inc., SYSCORE.14.0.0.291.x86]
    [c:\PROGRA~1\COMMON~1\mcafee\HACKER~1\hwapi.dll]  [McAfee, Inc., 9.0.119.0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\mvscfg.dll]  [McAfee, Inc., 12,1,118,0]
    [c:\PROGRA~1\mcafee\msc\mcsubmgr\8_1_13~1\mcsubmgr.dll]  [McAfee, Inc., 8,1,133,0]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mccoreps.dll]  [McAfee, Inc., 3,0,117,0]
[PID: 3160 / SYSTEM][c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe]  [McAfee, Inc., 2,1,143,0]
    [c:\PROGRA~1\COMMON~1\mcafee\msc\mcutil\8_1_11~1\McUtil.dll]  [McAfee, Inc., 8,1,114,0]
    [c:\PROGRA~1\mcafee\msc\mcnmcsrv.dll]  [McAfee, Inc., 2,1,151,0]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mccoreps.dll]  [McAfee, Inc., 3,0,117,0]
    [c:\PROGRA~1\mcafee\msc\mcshllps.dll]  [McAfee, Inc., 8,1,133,0]
    [c:\PROGRA~1\COMMON~1\mcafee\mna\MCNASV~1.DLL]  [McAfee, Inc., 2,1,143,0]
    [c:\PROGRA~1\mcafee\msc\mcnmcsps.dll]  [McAfee, Inc., 2,0,115,0]
    [c:\PROGRA~1\mcafee\mpf\mc\mpfp.dll]  [McAfee, Inc., 9.0.136.0]
    [c:\PROGRA~1\mcafee\msc\mcregobj\8_0_22~1\mcregobj.dll]  [McAfee, Inc., 8,0,226,0]
    [c:\PROGRA~1\mcafee\msc\mcmismgr.dll]  [McAfee, Inc., 8,1,149,0]
    [C:\PROGRA~1\McAfee\MSC\McRes.dll]  [McAfee, Inc., 8,0,226,0]
    [C:\PROGRA~1\McAfee\MSC\McLocRes.dll]  [McAfee, Inc., 8,1,153,0]
    [C:\Program Files\McAfee\MSC\oem\105-257\Mccobres.dll]  [McAfee, Inc., 8, 1, 165, 1]
    [C:\PROGRA~1\McAfee\MSC\Mccobres.dll]  [McAfee, Inc., 8,1,165,0]
    [c:\PROGRA~1\mcafee\msc\mcsubmgr\8_1_13~1\mcsubmgr.dll]  [McAfee, Inc., 8,1,133,0]
    [c:\PROGRA~1\COMMON~1\mcafee\mna\mcuj.dll]  [McAfee, Inc., 2,1,143,0]
    [C:\PROGRA~1\McAfee\MSC\McNmcRes.dll]  [McAfee, Inc., 2,1,151,0]
    [C:\PROGRA~1\McAfee\MSC\McNmcLoR.dll]  [McAfee, Inc., 2,1,151,0]
    [C:\PROGRA~1\McAfee\MSC\McNmcCoR.dll]  [McAfee, Inc., 2,1,151,0]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
[PID: 920 / Via][C:\Program Files\Windows Sidebar\sidebar.exe]  [Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Program Files\McAfee\VirusScan\scriptsn.dll]  [McAfee, Inc., VSCORE.14.0.0.366.x86]
    [C:\Windows\system32\icm32.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 5512 / Via][C:\Program Files\Windows Sidebar\sidebar.exe]  [Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Program Files\McAfee\VirusScan\scriptsn.dll]  [McAfee, Inc., VSCORE.14.0.0.366.x86]
    [C:\Windows\system32\icm32.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\system32\nvd3dum.dll]  [NVIDIA Corporation, 7.15.11.7597]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
[PID: 4868 / NETWORK SERVICE][C:\Windows\ehome\ehsched.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 5740 / NETWORK SERVICE][C:\Windows\ehome\ehRecvr.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1776 / Via][C:\Program Files\Internet Explorer\IEUser.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 3880 / Via][C:\Program Files\Internet Explorer\iexplore.exe]  [Microsoft Corporation, 7.00.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Program Files\CafeMom Toolbar\cmtb.dll]  [CMI Marketing, Inc., 1.0.0.18]
    [C:\Windows\system32\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Windows\system32\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
    [C:\Program Files\Java\jre6\bin\ssv.dll]  [Sun Microsystems, Inc., 6.0.100.33]
    [C:\Program Files\Java\jre6\bin\jp2ssv.dll]  [Sun Microsystems, Inc., 6.0.100.33]
    [C:\Program Files\McAfee\VirusScan\scriptsn.dll]  [McAfee, Inc., VSCORE.14.0.0.366.x86]
    [C:\Program Files\McAfee\VirusScan\mytilus3.dll]  [McAfee, Inc., VSCORE.14.0.0.349.x86]
    [C:\Program Files\McAfee\VirusScan\mytilus3_worker.dll]  [McAfee, Inc., VSCORE.14.0.0.349.x86]
    [C:\Program Files\McAfee\VirusScan\RES00\McShield.dll]  [McAfee, Inc., VSCORE.14.0.0.349]
    [C:\Windows\system32\Macromed\Flash\Flash10a.ocx]  [Adobe Systems, Inc., 10,0,12,36]
[PID: 4056 / SYSTEM][C:\Windows\system32\SearchProtocolHost.exe]  [(Verified) Microsoft Corporation, 7.0.6001.16503 (longhorn(wmbla).080526-2159)]
[PID: 3476 / SYSTEM][C:\Windows\system32\SearchFilterHost.exe]  [(Verified) Microsoft Corporation, 7.0.6001.16503 (longhorn(wmbla).080526-2159)]
[PID: 3964 / Via][C:\Users\Via\Downloads\SREngLdr.EXE]  [Smallfrogs Studio, 2.7.0.1210]
[PID: 4448 / Via][C:\Users\Via\Downloads\SRE15372752.EXE]  [Smallfrogs Studio, 2.7.0.1210]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Users\Via\Downloads\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]

==================================
File Associations
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["%SystemRoot%\hh.exe" %1]
.HLP  OK. [%SystemRoot%\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  Error. [NOTEPAD.EXE %1]
.JS   Error. [NOTEPAD.EXE %1]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock Provider
N/A

==================================
Autorun.Inf
N/A

==================================
HOSTS File
127.0.0.1       localhost

==================================
Process Privileges Scan
N/A

==================================
Scheduled Tasks
[Enabled] \\McDefragTask
        c:\PROGRA~1\mcafee\mqc\QcConsol.exe "C:\Windows\system32\defrag.exe" C: -f
[Enabled] \\McQcTask
        c:\PROGRA~1\mcafee\mqc\QcConsol.exe 14 0
[Enabled] \Apple\AppleSoftwareUpdate
        C:\Program Files\Apple Software Update\SoftwareUpdate.exe -task
[Disabled] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
        N/A
[Enabled] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)
        N/A
[Enabled] \Microsoft\Windows\Bluetooth\UninstallDeviceTask
        BthUdTask.exe $(Arg0)
[Enabled] \Microsoft\Windows\CertificateServicesClient\SystemTask
        N/A
[Enabled] \Microsoft\Windows\CertificateServicesClient\UserTask
        N/A
[Enabled] \Microsoft\Windows\CertificateServicesClient\UserTask-Roam
        N/A
[Enabled] \Microsoft\Windows\Customer Experience Improvement Program\Consolidator
        %SystemRoot%\System32\wsqmcons.exe
[Enabled] \Microsoft\Windows\Customer Experience Improvement Program\OptinNotification
        %SystemRoot%\System32\wsqmcons.exe -n 0x1C577FA2B69CAD0
[Enabled] \Microsoft\Windows\Defrag\ManualDefrag
        %windir%\system32\defrag.exe -c
[Enabled] \Microsoft\Windows\Defrag\ScheduledDefrag
        %windir%\system32\defrag.exe -c -i
[Enabled] \Microsoft\Windows\Media Center\ehDRMInit
        %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
[Enabled] \Microsoft\Windows\Media Center\mcupdate
        %SystemRoot%\ehome\mcupdate $(Arg0) -gc
[Enabled] \Microsoft\Windows\Media Center\OCURActivate
        %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
[Enabled] \Microsoft\Windows\Media Center\OCURDiscovery
        %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery
[Enabled] \Microsoft\Windows\Media Center\UpdateRecordPath
        %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
[Enabled] \Microsoft\Windows\MobilePC\HotStart
        N/A
[Enabled] \Microsoft\Windows\MobilePC\TMM
        N/A
[Enabled] \Microsoft\Windows\MUI\LPRemove
        %windir%\system32\lpremove.exe
[Enabled] \Microsoft\Windows\Multimedia\SystemSoundsService
        N/A
[Enabled] \Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
        N/A
[Enabled] \Microsoft\Windows\Shell\CrawlStartPages
        N/A
[Disabled] \Microsoft\Windows\SideShow\AutoWake
        N/A
[Enabled] \Microsoft\Windows\SideShow\GadgetManager
        N/A
[Disabled] \Microsoft\Windows\SideShow\SessionAgent
        N/A
[Disabled] \Microsoft\Windows\SideShow\SystemDataProviders
        N/A
[Enabled] \Microsoft\Windows\SystemRestore\SR
        %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
[Enabled] \Microsoft\Windows\Tcpip\IpAddressConflict1
        rundll32 ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
[Enabled] \Microsoft\Windows\Tcpip\IpAddressConflict2
        rundll32 ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
[Enabled] \Microsoft\Windows\UPnP\UPnPHostConfig
        sc.exe config upnphost start= auto
[Enabled] \Microsoft\Windows\Windows Error Reporting\QueueReporting
        %windir%\system32\wermgr.exe -queuereporting
[Enabled] \Microsoft\Windows\WindowsCalendar\Reminders - Via
        C:\Program Files\Windows Calendar\WinCal.exe /reminder
[Enabled] \Microsoft\Windows\Wired\GatherWiredInfo
        %windir%\system32\gatherWiredInfo.vbs
[Enabled] \Microsoft\Windows\Wireless\GatherWirelessInfo
        %windir%\system32\gatherWirelessInfo.vbs

==================================
API HOOK
N/A

==================================
Hidden Process
N/A

==================================


10.4K Posts

November 28th, 2008 05:00




Rerun SRE2
  • In the Left pane Select System Repair
    In the Right pane under the " File Associations" tab
    Place checks in the boxes beside


.VBS Error. [NOTEPAD.EXE %1]
.JS Error. [NOTEPAD.EXE %1]

And Select the Repair button

After you do so the errors should be gone and the 2 checked items should read Normal or O.K.

If all went well, close SRE2, reboot your PC ->> Rerun Hijackthis and post a fresh Hijackthis log. If the errors persist, then reply

7 Posts

November 30th, 2008 15:00

I followed your instructions, and repaired the .VBS Error. [NOTEPAD.EXE %1] and .JS Error. [NOTEPAD.EXE %1], and they now both say normal.

There are 2 other things that say error. I did not repair them, because you only said to repair the two. I just left them.

They are: .REG NOTEPAD.EXE 1% AND .SCR NOTEPAD.EXE 1%

Here is the fresh Hijackthis log.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:04:38 PM, on 11/30/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Dell\PC TuneUp\SMSystemAnalyzer.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Dell Support Center\gs_agent\dsc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: CafeMom Toolbar - {8151A608-00FB-4D5C-8B8D-40E239E32A42} - C:\Program Files\CafeMom Toolbar\cmtb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.5470\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: CafeMom Toolbar - {8151A608-00FB-4D5C-8B8D-40E239E32A42} - C:\Program Files\CafeMom Toolbar\cmtb.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [Dell PC TuneUp Startup] "C:\Program Files\iolo\Common\Lib\ioloLManager.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [Device Detector] DevDetect.exe -autorun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: (no name) - {07DB8C18-9FD9-4e43-AF16-043E44D89768} - C:\Program Files\CafeMom Toolbar\cmtb.dll
O9 - Extra 'Tools' menuitem: CafeMom Toolbar - {07DB8C18-9FD9-4e43-AF16-043E44D89768} - C:\Program Files\CafeMom Toolbar\cmtb.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/control/en-US/activex/TmHcmsX.CAB
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} - http://www.infospace.com/mypoints.main/tbar/mypointsSetup.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {C8E7CBFB-9F2E-42C7-B4CB-D4B7FC89A363} (Gather Photo Uploader Control) - http://www.gather.com/imageuploader/GatherUploader5.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: McAfee Application Installer Cleanup (0108721227797665) (0108721227797665mcinstcleanup) - Unknown owner - C:\Windows\TEMP\010872~1.EXE (file missing)
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\Windows\system32\CTsvcCDA.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Procedure Call (RPC) Net (rpcnet) - Absolute Software Corp. - C:\Windows\System32\rpcnet.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 12433 bytes

 

 

10.4K Posts

December 1st, 2008 06:00


monicav

"There are 2 other things that say error. I did not repair them, because you only said to repair the two. I just left them.

They are: .REG NOTEPAD.EXE 1% AND .SCR NOTEPAD.EXE 1%"


If those errors are there, then rerun SRE2 and fix those using the instructions to correct the other error. Then reply with the results.

7 Posts

December 1st, 2008 07:00

I repaired them, and they both said normal afterward, so I closed SRE2. I opened it again a few minutes later just to make sure they still said normal, and now these 4 all say error again:

.REG NOTEPAD.EXE %

.SCR NOTEPAD.EXE %

.VBS NOTEPAD.EXE %

.JS NOTEPAD.EXE %

 (The same 4 as before)

I ran another smart scan on SRE2 after seeing the four errors there again- here is the log from that.

 

2008-12-01,10:45:46

System Repair Engineer 2.7.0.1210
Smallfrogs (http://www.KZTechs.com)

Windows Vista Home Premium Edition Service Pack 1 (Build 6001) - Administrative User - Completed Functions Allowed

Follow item(s) have been selected:
    All Boot Items (Including Registry, Startup Folders, Services and so on)
    Browser Add-ons
    Running Processes (Including process model information)
    File Associations
    Winsock Provider
    Autorun.Inf
    HOSTS File
    Process Privileges Scan
    Scheduled Tasks
    API HOOK
    Hidden Process


Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <"C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter>  [(Verified)Dell Inc.]
    <>  [N/A]
      [N/A]
      [(Verified)Microsoft Windows]
      [(Verified)Microsoft Windows]
      [(Verified)Microsoft Windows]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <%ProgramFiles%\Windows Defender\MSASCui.exe -hide>  [(Verified)Microsoft Windows]
    <"C:\Program Files\Dell\MediaDirect\PCMService.exe">  [(Verified)CyberLink]
      [(Verified)Intel Corporation]
    <"C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe">  [ ]
      [(Verified)"McAfee, Inc."]
      [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <"C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s>  [Creative Technology Ltd.]
    <"C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter>  [(Verified)Dell Inc.]
    <"C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" /r>  [Creative Technology Ltd]
      [Creative Technology Ltd.]
    <"C:\Program Files\iolo\Common\Lib\ioloLManager.exe">  [(Verified)"iolo technologies, LLC"]
      [(Verified)Microsoft Windows Hardware Compatibility Publisher]
      [(Verified)Microsoft Windows Hardware Compatibility Publisher]
      [(Verified)Microsoft Windows Hardware Compatibility Publisher]
    <"C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m>  [(Verified)Dell Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    <>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
      [(Verified)Microsoft Windows]
      [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <>  [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
      [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    <{8C7461EF-2B13-11d2-BE35-3078302C2030}><%SystemRoot%\system32\browseui.dll>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
      [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
      [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
      [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
    <%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
    <"%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE>  [File is missing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    <%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI>  [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
      [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
      [(Verified)Microsoft Windows]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
      [(Verified)Microsoft Windows]
[HKEY_CURRENT_USER\Control Panel\Desktop]
      [(Verified)Microsoft Windows]

==================================
Startup Folders
[Bluetooth]
  C:\PROGRA~1\WIDCOMM\BLUETO~1\BTTray.exe [Broadcom Corporation.]>
[QuickSet]
  C:\PROGRA~1\Dell\QuickSet\quickset.exe [Dell Inc.]>
[Bluetooth]
  C:\PROGRA~1\WIDCOMM\BLUETO~1\BTTray.exe [Broadcom Corporation.]>
[QuickSet]
  C:\PROGRA~1\Dell\QuickSet\quickset.exe [Dell Inc.]>

==================================
Services
[Andrea ST Filters Service / AESTFilters][Running/Auto Start]
 
[Apple Mobile Device / Apple Mobile Device][Running/Auto Start]
  <"C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe">
[Bonjour Service / Bonjour Service][Running/Auto Start]
  <"C:\Program Files\Bonjour\mDNSResponder.exe">
[Creative Labs Licensing Service / Creative Labs Licensing Service][Running/Auto Start]
  <"C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe">
[Creative Service for CDROM Access / Creative Service for CDROM Access][Running/Auto Start]
 
[Intel(R) PROSet/Wireless Event Log / EvtEng][Running/Auto Start]
 
[Google Updater Service / gusvc][Stopped/Manual Start]
  <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe">
[Intel(R) Matrix Storage Event Monitor / IAANTMON][Running/Auto Start]
 
[iolo FileInfoList Service / ioloFileInfoList][Running/Auto Start]
  <>
[iolo System Service / ioloSystemService][Running/Auto Start]
  <>
[McAfee SiteAdvisor Service / McAfee SiteAdvisor Service][Running/Auto Start]
  <"C:\Program Files\McAfee\SiteAdvisor\McSACore.exe"><>
[McAfee Services / mcmscsvc][Running/Auto Start]
 
[McAfee Network Agent / McNASvc][Running/Auto Start]
  <"c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe">
[McAfee Scanner / McODS][Running/Manual Start]
 
[McAfee Proxy Service / McProxy][Running/Auto Start]
 
[McAfee Real-time Scanner / McShield][Running/Auto Start]
 
[McAfee SystemGuards / McSysmon][Running/Manual Start]
 
[McAfee Personal Firewall Service / MpfService][Running/Auto Start]
  <"C:\Program Files\McAfee\MPF\MPFSrv.exe">
[McAfee Anti-Spam Service / MSK80Service][Running/Auto Start]
  <"C:\Program Files\McAfee\MSK\MskSrver.exe">
[NVIDIA Display Driver Service / nvsvc][Running/Auto Start]
 
[ProtexisLicensing / ProtexisLicensing][Running/Auto Start]
  <>
[Intel(R) PROSet/Wireless Registry Service / RegSrvc][Running/Auto Start]
 
[Remote Procedure Call (RPC) Net / rpcnet][Running/Auto Start]
 
[SupportSoft Sprocket Service (dellsupportcenter) / sprtsvc_dellsupportcenter][Running/Auto Start]
 
[SigmaTel Audio Service / STacSV][Running/Auto Start]
 
[XAudioService / XAudioService][Running/Auto Start]
 
[McAfee Application Installer Cleanup (0225291228142403) / 0225291228142403mcinstcleanup][Stopped/Auto Start]
  <(File is missing)>

==================================
Drivers
[adp94xx / adp94xx][Stopped/Disabled]
  <\SystemRoot\system32\drivers\adp94xx.sys>
[adpahci / adpahci][Stopped/Disabled]
  <\SystemRoot\system32\drivers\adpahci.sys>
[adpu160m / adpu160m][Stopped/Disabled]
  <\SystemRoot\system32\drivers\adpu160m.sys>
[adpu320 / adpu320][Stopped/Disabled]
  <\SystemRoot\system32\drivers\adpu320.sys>
[aic78xx / aic78xx][Stopped/Disabled]
  <\SystemRoot\system32\drivers\djsvs.sys>
[aliide / aliide][Stopped/Disabled]
  <\SystemRoot\system32\drivers\aliide.sys>
[Alps Touch Pad Filter Driver for Windows 2000/XP/Vista / ApfiltrService][Running/Manual Start]
 
[arc / arc][Stopped/Disabled]
  <\SystemRoot\system32\drivers\arc.sys>
[arcsas / arcsas][Stopped/Disabled]
  <\SystemRoot\system32\drivers\arcsas.sys>
[Broadcom 440x 10/100 Integrated Controller XP Driver / bcm4sbxp][Running/Manual Start]
 
[Brother USB Mass-Storage Lower Filter Driver / BrFiltLo][Stopped/Manual Start]
  <\SystemRoot\system32\drivers\brfiltlo.sys>
[Brother USB Mass-Storage Upper Filter Driver / BrFiltUp][Stopped/Manual Start]
  <\SystemRoot\system32\drivers\brfiltup.sys>
[Brother MFC Serial Port Interface Driver (WDM) / Brserid][Stopped/Disabled]
  <\SystemRoot\system32\drivers\brserid.sys>
[Brother WDM Serial driver / BrSerWdm][Stopped/Disabled]
  <\SystemRoot\system32\drivers\brserwdm.sys>
[Brother MFC USB Fax Only Modem / BrUsbMdm][Stopped/Disabled]
  <\SystemRoot\system32\drivers\brusbmdm.sys>
[Brother MFC USB Serial WDM Driver / BrUsbSer][Stopped/Manual Start]
  <\SystemRoot\system32\drivers\brusbser.sys>
[Bluetooth Audio Device Service / btwaudio][Running/Manual Start]
 
[Bluetooth AVDT / btwavdt][Running/Manual Start]
 
[btwrchid / btwrchid][Running/Manual Start]
 
[cmdide / cmdide][Stopped/Disabled]
  <\SystemRoot\system32\drivers\cmdide.sys>
[WIDCOMM USB Bluetooth Driver in DFU State / DFUBTUSB][Stopped/Manual Start]
 
[Intel(R) PRO/1000 NDIS 6 Adapter Driver / E1G60][Stopped/Manual Start]
 
[ElRawDisk / ElRawDisk][Running/System Start]
  <\??\C:\Windows\system32\drivers\elrawdsk.sys>
[elxstor / elxstor][Stopped/Disabled]
  <\SystemRoot\system32\drivers\elxstor.sys>
[HpCISSs / HpCISSs][Stopped/Disabled]
  <\SystemRoot\system32\drivers\hpcisss.sys>
[HSFHWAZL / HSFHWAZL][Stopped/Manual Start]
 
[HSF_DPV / HSF_DPV][Running/Manual Start]
 
[HSXHWAZL / HSXHWAZL][Running/Manual Start]
 
[Intel AHCI Controller / iaStor][Running/Boot Start]
  <\SystemRoot\system32\DRIVERS\iaStor.sys>
[Intel RAID Controller Vista / iaStorV][Stopped/Disabled]
  <\SystemRoot\system32\drivers\iastorv.sys>
[iirsp / iirsp][Stopped/Disabled]
  <\SystemRoot\system32\drivers\iirsp.sys>
[IP in IP Tunnel Driver / IpInIp][Stopped/Manual Start]
 
[ITEATAPI_Service_Install / iteatapi][Stopped/Disabled]
  <\SystemRoot\system32\drivers\iteatapi.sys>
[ITERAID_Service_Install / iteraid][Stopped/Disabled]
  <\SystemRoot\system32\drivers\iteraid.sys>
[LSI_FC / LSI_FC][Stopped/Disabled]
  <\SystemRoot\system32\drivers\lsi_fc.sys>
[LSI_SAS / LSI_SAS][Stopped/Disabled]
  <\SystemRoot\system32\drivers\lsi_sas.sys>
[LSI_SCSI / LSI_SCSI][Stopped/Disabled]
  <\SystemRoot\system32\drivers\lsi_scsi.sys>
[mdmxsdk / mdmxsdk][Running/Auto Start]
 
[megasas / megasas][Stopped/Disabled]
  <\SystemRoot\system32\drivers\megasas.sys>
[MegaSR / MegaSR][Stopped/Disabled]
  <\SystemRoot\system32\drivers\megasr.sys>
[McAfee Inc. mfeavfk / mfeavfk][Running/Manual Start]
 
[McAfee Inc. mfebopk / mfebopk][Running/Manual Start]
 
[McAfee Inc. mfehidk / mfehidk][Running/System Start]
 
[McAfee Inc. mferkdk / mferkdk][Running/Manual Start]
 
[McAfee Inc. mfesmfk / mfesmfk][Running/Manual Start]
 
[MPFP / MPFP][Running/System Start]
 
[Mraid35x / Mraid35x][Stopped/Disabled]
  <\SystemRoot\system32\drivers\mraid35x.sys>
[Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit / NETw4v32][Running/Manual Start]
 
[nfrd960 / nfrd960][Stopped/Disabled]
  <\SystemRoot\system32\drivers\nfrd960.sys>
[N-trig HID Tablet Driver / ntrigdigi][Stopped/Disabled]
  <\SystemRoot\system32\drivers\ntrigdigi.sys>
[nvlddmkm / nvlddmkm][Running/Manual Start]
 
[NVIDIA nForce RAID Driver    / nvraid][Stopped/Disabled]
  <\SystemRoot\system32\drivers\nvraid.sys>
[nvstor / nvstor][Stopped/Disabled]
  <\SystemRoot\system32\drivers\nvstor.sys>
[IPX Traffic Filter Driver / NwlnkFlt][Stopped/Manual Start]
 
[IPX Traffic Forwarder Driver / NwlnkFwd][Stopped/Manual Start]
 
[Creative Camera OEM002 Driver / OEM02Dev][Running/Manual Start]
 
[Creative Camera OEM002 Video VFX Driver / OEM02Vfx][Running/Manual Start]
 
[QLogic Fibre Channel Miniport Driver / ql2300][Stopped/Disabled]
  <\SystemRoot\system32\drivers\ql2300.sys>
[QLogic iSCSI Miniport Driver / ql40xx][Stopped/Disabled]
  <\SystemRoot\system32\drivers\ql40xx.sys>
[rimmptsk / rimmptsk][Running/Auto Start]
 
[rimsptsk / rimsptsk][Running/Auto Start]
 
[Ricoh xD-Picture Card Driver / rismxdp][Running/Auto Start]
 
[SiSRaid4 / SiSRaid4][Stopped/Disabled]
  <\SystemRoot\system32\drivers\sisraid4.sys>
[SigmaTel High Definition Audio CODEC / STHDA][Running/Manual Start]
 
[Symc8xx / Symc8xx][Stopped/Disabled]
  <\SystemRoot\system32\drivers\symc8xx.sys>
[Sym_hi / Sym_hi][Stopped/Disabled]
  <\SystemRoot\system32\drivers\sym_hi.sys>
[Sym_u3 / Sym_u3][Stopped/Disabled]
  <\SystemRoot\system32\drivers\sym_u3.sys>
[uliahci / uliahci][Stopped/Disabled]
  <\SystemRoot\system32\drivers\uliahci.sys>
[UlSata / UlSata][Stopped/Disabled]
  <\SystemRoot\system32\drivers\ulsata.sys>
[ulsata2 / ulsata2][Stopped/Disabled]
  <\SystemRoot\system32\drivers\ulsata2.sys>
[viaide / viaide][Stopped/Disabled]
  <\SystemRoot\system32\drivers\viaide.sys>
[vsmraid / vsmraid][Stopped/Disabled]
  <\SystemRoot\system32\drivers\vsmraid.sys>
[winachsf / winachsf][Running/Manual Start]
 
[XAudio / XAudio][Running/Auto Start]
 

==================================
Browser Add-ons
[Adobe PDF Link Helper]
  {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
[Skype add-on (mastermind)]
  {22BF413B-C6D2-4d91-82A9-A0F997BA588C}
[McAfee Phishing Filter]
  {377C180E-6F0E-4D4C-980F-F45BD3D40CF4}
[Java(tm) Plug-In SSV Helper]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
[scriptproxy]
  {7DB2D5A0-7241-4E79-B68D-6309F01C5231}
[CafeMom Toolbar]
  {8151A608-00FB-4D5C-8B8D-40E239E32A42}
[Google Toolbar Helper]
  {AA58ED58-01DD-4d91-8333-CF10577473F7}
[Google Toolbar Notifier BHO]
  {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
[McAfee SiteAdvisor BHO]
  {B164E929-A1B6-4A06-B104-2CD0E90A88FF}
[Java(tm) Plug-In 2 SSV Helper]
  {DBC80044-A445-435b-BC74-9C25C1C588A9}
[CafeMom Toolbar]
  {07DB8C18-9FD9-4e43-AF16-043E44D89768}
[ieSpell]
  {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} <, >
[]
  {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} <, >
[Skype add-on (button)]
  {77BF5300-1474-4EC7-9980-D32B190E9B07}
[&Research]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263}
[@btrez.dll,-4015]
  {CCA281CA-C863-46ef-9331-5C8D4460577F} <, >
[&Google Toolbar]
  {2318C2B1-4965-11d4-9B18-009027A5CD4F}
[McAfee SiteAdvisor Toolbar]
  {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}
[CafeMom Toolbar]
  {8151A608-00FB-4D5C-8B8D-40E239E32A42}
[]
  {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} <, >
[Shockwave ActiveX Control]
  {166B1BCA-3F9C-11CF-8075-444553540000}
[TmHcmsX Control]
  {1EF9F042-C2EB-4293-8213-474CAEEF531D}
[Trend Micro ActiveX Scan Agent 6.6]
  {215B8138-A3CF-44C5-803F-8226143CFC0A}
[]
  {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} <, >
[]
  {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} <, >
[Symantec RuFSI Utility Class]
  {644E432F-49D3-41A1-8DD5-E099162EEEC5} <, >
[Java Plug-in 1.6.0_10]
  {8AD9C840-044E-11D1-B3E9-00805F499D93}
[]
  {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} <, >
[Gather Photo Uploader Control]
  {C8E7CBFB-9F2E-42C7-B4CB-D4B7FC89A363}
[Java Plug-in 1.6.0_10]
  {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
[Java Plug-in 1.6.0_10]
  {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
[Oberon Flash Game Host]
  {D0C0F75C-683A-4390-A791-1ACFD5599AB8}
[]
  {00000000-0000-0000-0000-000000000000} <, >
[Microsoft Works Imaging Server]
  {00E1DB59-6EFD-4CE7-8C0A-2DA3BCAAD9C6}
[Google Script Object]
  {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB}
[Support.com Configuration Class]
  {01113300-3E00-11D2-8470-0060089874ED}
[]
  {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} <, >
[]
  {03F998B2-0E00-11D3-A498-00104B6EB52E} <, >
[Outlook Today's Data-binding control]
  {0468C085-CA5B-11D0-AF08-00609797F0E0}
[]
  {07DB8C18-9FD9-4E43-AF16-043E44D89768} <, >
[]
  {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <, >
[]
  {0E17D5B7-9F5D-4FEE-9DF6-CA6EE38B68A8} <, >
[McAfee SiteAdvisor Toolbar]
  {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}
[PeerDraw Class]
  {10072CEC-8CC1-11D1-986E-00A0C955B42E} <%CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll, (Signed) N/A>
[]
  {1606D6F9-9D3B-4AEA-A025-ED5B2FD488E7} <, >
[Windows Genuine Advantage Validation Tool]
  {17492023-C23A-453E-A040-C7C580BBF700}
[Adobe PDF Link Helper]
  {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
[TmHcmsX Control]
  {1EF9F042-C2EB-4293-8213-474CAEEF531D}
[Trend Micro ActiveX Scan Agent 6.6]
  {215B8138-A3CF-44C5-803F-8226143CFC0A}
[Skype add-on (mastermind)]
  {22BF413B-C6D2-4D91-82A9-A0F997BA588C}
[Windows Media Player]
  {22D6F312-B0F6-11D0-94AB-0080C74C7E95}
[&Google Toolbar]
  {2318C2B1-4965-11D4-9B18-009027A5CD4F}
[Shockwave ActiveX Control]
  {233C1507-6A77-46A4-9443-F871F945D258}
[HTML Document]
  {25336920-03F9-11CF-8FD0-00AA00686F13}
[XML DOM Document]
  {2933BF90-7B36-11D2-B20E-00C04F983E60} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[]
  {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} <, >
[McAfee Phishing Filter]
  {377C180E-6F0E-4D4C-980F-F45BD3D40CF4}
[IETag Factory]
  {38481807-CA0E-42D2-BF39-B33AF135CC4D}
[]
  {4063BE15-3B08-470D-A0D5-B37161CFFD69} <, >
[XML Document]
  {48123BC4-99D9-11D1-A6B3-00C04FD91555} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[]
  {48DD0448-9209-4F81-9F6D-D83562940134} <, >
[]
  {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} <, >
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C}
[Symantec RuFSI Utility Class]
  {644E432F-49D3-41A1-8DD5-E099162EEEC5} <, >
[DivXBrowserPlugin Object]
  {67DABFBF-D0AB-41FA-9C46-CC0F21721616}
[Windows Media Player]
  {6BF52A52-394A-11D3-B153-00C04F79FAA6} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
[Recovery ActiveX Control Module]
  {700EF03F-A472-4D26-8ACB-300F4D04FD96}
[Java(tm) Plug-In SSV Helper]
  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
[Skype add-on (button)]
  {77BF5300-1474-4EC7-9980-D32B190E9B07}
[scriptproxy]
  {7DB2D5A0-7241-4E79-B68D-6309F01C5231}
[CafeMom Toolbar]
  {8151A608-00FB-4D5C-8B8D-40E239E32A42}
[Microsoft Web Browser]
  {8856F961-340A-11D0-A96B-00C04FD705A2}
[XML DOM Document 4.0]
  {88D969C0-F192-11D4-A65F-0040963251E5}
[XML HTTP 4.0]
  {88D969C5-F192-11D4-A65F-0040963251E5}
[XML DOM Document 5.0]
  {88D969E5-F192-11D4-A65F-0040963251E5}
[XML DOM Document 6.0]
  {88D96A05-F192-11D4-A65F-0040963251E5} <%SystemRoot%\System32\msxml6.dll, (Signed) N/A>
[Free Threaded XML DOM Document 6.0]
  {88D96A06-F192-11D4-A65F-0040963251E5} <%SystemRoot%\System32\msxml6.dll, (Signed) N/A>
[XSL Template 6.0]
  {88D96A08-F192-11D4-A65F-0040963251E5} <%SystemRoot%\System32\msxml6.dll, (Signed) N/A>
[XML HTTP 6.0]
  {88D96A0A-F192-11D4-A65F-0040963251E5} <%SystemRoot%\System32\msxml6.dll, (Signed) N/A>
[Java Plug-in 1.6.0_10]
  {8AD9C840-044E-11D1-B3E9-00805F499D93}
[]
  {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} <, >
[]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} <, >
[]
  {9E385F0A-0BA2-430C-96AA-4399C5E40F6C} <, >
[AxPlayer Control]
  {9F81C14C-04C0-4378-9A0F-70B5F25397BC}
[]
  {A057A204-BACC-4D26-CEC4-75A487FD6484} <, >
[RMGetLicense Class]
  {A9FC132B-096D-460B-B7D5-1DB0FAE0C062}
[Google Toolbar Helper]
  {AA58ED58-01DD-4D91-8333-CF10577473F7}
[Google Toolbar Notifier BHO]
  {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
[McAfee SiteAdvisor BHO]
  {B164E929-A1B6-4A06-B104-2CD0E90A88FF}
[AxVersion Control]
  {B3E658DF-D425-430C-82C2-D54295915020}
[Symantec RuFSI File information Class]
  {C2FCEF4E-ACE9-11D3-BEBD-00105AA9B6AE} <, >
[Symantec RuFSI Registry Information Class]
  {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} <, >
[Gather Photo Uploader Control]
  {C8E7CBFB-9F2E-42C7-B4CB-D4B7FC89A363}
[Adobe PDF Reader]
  {CA8A9780-280D-11CF-A24D-444553540000}
[]
  {CCA281CA-C863-46EF-9331-5C8D4460577F} <, >
[AUDIO__MID Moniker Class]
  {CD3AFA74-B84F-48F0-9393-7EDC34128127} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
[AUDIO__MP3 Moniker Class]
  {CD3AFA76-B84F-48F0-9393-7EDC34128127} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
[AUDIO__WAV Moniker Class]
  {CD3AFA7B-B84F-48F0-9393-7EDC34128127} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
[VIDEO__AVI Moniker Class]
  {CD3AFA88-B84F-48F0-9393-7EDC34128127} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
[VIDEO__X_MS_ASF Moniker Class]
  {CD3AFA8F-B84F-48F0-9393-7EDC34128127} <%SystemRoot%\system32\wmp.dll, (Signed) N/A>
[Microsoft Url Search Hook]
  {CFBFAE00-17A6-11D0-99CB-00C04FD64497}
[Msxml]
  {CFC399AF-D876-11D0-9C10-00C04FC99C8E} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[Oberon Flash Game Host]
  {D0C0F75C-683A-4390-A791-1ACFD5599AB8}
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000}
[Java(tm) Plug-In 2 SSV Helper]
  {DBC80044-A445-435B-BC74-9C25C1C588A9}
[]
  {DE4AF3B0-F4D4-11D3-B41A-0050DA2E6C21} <, >
[Microsoft Silverlight]
  {DFEAF541-F3E1-4C24-ACAC-99C30715084A}
[Google Find Bar]
  {E16DC1FE-7C34-43F2-B754-F3AD12DDF97C}
[NameCtrl Class]
  {E18FEC31-2EA1-49A2-A7A6-902DC0D1FF05}
[]
  {E3E02F12-2ADB-478C-8742-5F0819F9F0F4} <"C:\Users\Via\AppData\Roaming\Move Networks\ie_bin\qsp2ie071101000055.dll", N/A>
[]
  {e473a65c-8087-49a3-affd-c5bc4a10669b} <"C:\Users\Via\AppData\Roaming\Move Networks\ie_bin\qsp2ie071101000055.dll", N/A>
[XML HTTP Request]
  {ED8C108E-4349-11D2-91A4-00C04F7969E8} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[XML DOM Document 3.0]
  {F5078F32-C551-11D3-89B9-0000F81FE221} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[XML DOM Document]
  {F6D90F11-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[XML HTTP]
  {F6D90F16-9C73-11D3-B32E-00C04F990BB4} <%SystemRoot%\System32\msxml3.dll, (Signed) N/A>
[]
  {FC345D4C-B8F4-4674-BFF7-3C37D2E535EE} <"C:\Users\Via\AppData\Roaming\Move Networks\ie_bin\qsp2ie071101000055.dll", N/A>
[]
  {fd6484ed-ebe3-4c3d-938a-8238003b41b7} <"C:\Users\Via\AppData\Roaming\Move Networks\ie_bin\qsp2ie071101000055.dll", N/A>
[&ieSpell Options]
 
[Check &Spelling]
 
[Lookup on Merriam Webster]
  < file://C:\Program Files\ieSpell\Merriam Webster.HTM, N/A>
[Lookup on Wikipedia]
  < file://C:\Program Files\ieSpell\wikipedia.HTM, N/A>

==================================
Running Processes
[PID: 508 / SYSTEM][\SystemRoot\System32\smss.exe]  [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 568 / SYSTEM][C:\Windows\system32\csrss.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 640 / SYSTEM][C:\Windows\system32\wininit.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 652 / SYSTEM][C:\Windows\system32\csrss.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 684 / SYSTEM][C:\Windows\system32\services.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 700 / SYSTEM][C:\Windows\system32\lsass.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 708 / SYSTEM][C:\Windows\system32\lsm.exe]  [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 840 / SYSTEM][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 888 / SYSTEM][C:\Windows\system32\nvvsvc.exe]  [NVIDIA Corporation, 7.15.11.7597]
[PID: 916 / NETWORK SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 968 / SYSTEM][C:\Windows\System32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1004 / LOCAL SERVICE][C:\Windows\System32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
    [C:\Windows\system32\stapo.dll]  [IDT, Inc., 1.0.5614.0  nd654 cp1]
    [C:\Windows\system32\ctapo32.dll]  [Creative Technology Ltd., 1.0.0.195]
[PID: 1040 / SYSTEM][C:\Windows\System32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1056 / SYSTEM][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
[PID: 1160 / SYSTEM][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1176 / NETWORK SERVICE][C:\Windows\system32\SLsvc.exe]  [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 1220 / LOCAL SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
[PID: 1332 / SYSTEM][C:\Windows\system32\winlogon.exe]  [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 1400 / NETWORK SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
[PID: 1520 / SYSTEM][C:\Windows\system32\WLANExt.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\System32\IWMSSvc.dll]  [Intel Corporation , 11, 1, 1, 4]
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  [Intel Corporation, 11, 1, 1, 1]
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  [Intel Corporation, 11, 1, 1, 0]
    [C:\Program Files\Intel\Wireless\Bin\Dot1xCfg.dll]  [Intel Corporation, 11.1.1.0  ]
    [C:\Program Files\Intel\Wireless\Bin\acAuth.dll]  [, 4.1.0.91 2007-03-30 10:41:31]
    [C:\Program Files\Intel\Wireless\Bin\IntStngs.dll]  [Intel Corporation, 11.1.1.0  ]
    [C:\Program Files\Intel\Wireless\Bin\IWMSPROV.DLL]  [N/A, ]
    [C:\Program Files\Intel\Wireless\Bin\C1XStngs.dll]  [Intel Corporation, 11.1.1.1  ]
    [C:\Program Files\Intel\Wireless\Bin\LSAWRAPI.dll]  [Intel Corporation, 11.1.1.0]
    [C:\Program Files\Intel\Wireless\Bin\PfMgrApi.dll]  [Intel Corporation, 11.1.1.4]
    [C:\Program Files\Intel\Wireless\Bin\LIBEAY32.dll]  [The OpenSSL Project, http://www.openssl.org/, 0.9.8]
    [C:\Program Files\Intel\Wireless\Bin\DbEngine.dll]  [Intel Corporation, 11, 1, 1, 6]
[PID: 1636 / SYSTEM][C:\Windows\System32\spoolsv.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\System32\hpzlllhn.dll]  [Hewlett-Packard Company, 61.053.25.9]
    [C:\Windows\system32\spool\PRTPROCS\W32X86\hpzpplhn.dll]  [Hewlett-Packard Corporation, 61.053.25.9]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
[PID: 1664 / LOCAL SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 1896 / SYSTEM][C:\Windows\system32\rundll32.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\system32\NVSVC.DLL]  [NVIDIA Corporation, 7.15.11.7597]
    [C:\Windows\system32\nvapi.dll]  [NVIDIA Corporation, 7.15.11.7597]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 1976 / SYSTEM][C:\Windows\system32\aestsrv.exe]  [Andrea Electronics Corporation, 1.0.32.2]
[PID: 2024 / SYSTEM][C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe]  [Apple Inc., 2.11.32.0]
[PID: 348 / SYSTEM][C:\Program Files\Bonjour\mDNSResponder.exe]  [Apple Inc., 1,0,5,11]
[PID: 376 / LOCAL SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 412 / SYSTEM][C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe]  [Creative Labs, 2.70.000]
[PID: 452 / SYSTEM][C:\Windows\system32\CTsvcCDA.exe]  [Creative Technology Ltd, 1.0.1.0]
[PID: 532 / SYSTEM][C:\Program Files\Intel\Wireless\Bin\EvtEng.exe]  [Intel Corporation, 11.1.1.1  ]
    [C:\Program Files\Intel\Wireless\Bin\PfMgrApi.dll]  [Intel Corporation, 11.1.1.4]
    [C:\Program Files\Intel\Wireless\Bin\LIBEAY32.dll]  [The OpenSSL Project, http://www.openssl.org/, 0.9.8]
    [C:\Program Files\Intel\Wireless\Bin\TraceAPI.DLL]  [Intel Corporation, 11, 1, 1, 1]
    [C:\Program Files\Intel\Wireless\Bin\PsRegApi.dll]  [Intel Corporation, 11, 1, 1, 0]
    [C:\Program Files\Intel\Wireless\Bin\DbEngine.dll]  [Intel Corporation, 11, 1, 1, 6]
    [C:\Program Files\Intel\Wireless\Bin\IntStngs.dll]  [Intel Corporation, 11.1.1.0  ]
    [C:\Program Files\Intel\Wireless\Bin\MurocApi.dll]  [Intel Corporation, 11.1.1.2]
    [C:\Program Files\Intel\Wireless\Bin\S24MUDLL.dll]  [Intel Corporation, 11.1.1.0]
[PID: 500 / SYSTEM][C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe]  [Intel Corporation, 7.0.0.1020]
    [C:\Program Files\Intel\Intel Matrix Storage Manager\ISDI.dll]  [Intel Corporation, 7.0.0.1020]
    [C:\Program Files\Intel\Intel Matrix Storage Manager\PlugInRAID_ENU.dll]  [Intel Corporation, 7.0.0.1020]
[PID: 796 / SYSTEM][C:\Program Files\iolo\common\lib\ioloServiceManager.exe]  [, ]
    [C:\Program Files\iolo\Common\Lib\fbembed.dll]  [The Firebird Project, WI-V1.5.2.4731]
[PID: 1732 / SYSTEM][C:\Program Files\McAfee\SiteAdvisor\McSACore.exe]  [, ]
    [c:\PROGRA~1\mcafee\SITEAD~1\apengine.dll]  [, ]
    [c:\PROGRA~1\mcafee\SITEAD~1\saupkeep.dll]  [, ]
    [c:\PROGRA~1\mcafee\SITEAD~1\McFrmWk.dll]  [, ]
    [c:\PROGRA~1\mcafee\SITEAD~1\CntScan.dll]  [, ]
    [C:\Program Files\McAfee\SiteAdvisor\SACore.dll]  [, ]
    [C:\Program Files\McAfee\SiteAdvisor\SASet.dll]  [, ]
    [c:\PROGRA~1\mcafee\SITEAD~1\MCSACO~1.DLL]  [, ]
    [c:\PROGRA~1\mcafee\msc\mcregobj\8_0_22~1\mcregobj.dll]  [McAfee, Inc., 8,0,226,0]
    [c:\PROGRA~1\COMMON~1\mcafee\msc\mcutil\8_1_11~1\McUtil.dll]  [McAfee, Inc., 8,1,114,0]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
[PID: 2160 / SYSTEM][c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe]  [McAfee, Inc., 2,0,151,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\escnplug.dll]  [McAfee, Inc., 12,1,109,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\EsPlgRes.dll]  [McAfee, Inc., 12,0,188,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\mvscfg.dll]  [McAfee, Inc., 12,1,118,0]
    [c:\PROGRA~1\mcafee\mps\mps.dll]  [McAfee, Inc., 10.1.141.0]
    [c:\PROGRA~1\mcafee\msk\mskpxplg.dll]  [McAfee, Inc., 9.1.107.0]
    [c:\PROGRA~1\mcafee\mps\mpscfg.dll]  [McAfee, Inc., 10.1.137.0]
    [C:\Windows\system32\Dunzip32.dll]  [Inner Media, Inc., 5.00.06]
    [c:\PROGRA~1\mcafee\msc\mcmispps.dll]  [McAfee, Inc., 8,0,226,0]
    [c:\PROGRA~1\mcafee\msc\mcsubmgr\8_1_13~1\mcsubmgr.dll]  [McAfee, Inc., 8,1,133,0]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mccoreps.dll]  [McAfee, Inc., 3,0,117,0]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mcevtbrk.dll]  [McAfee, Inc., 3,0,117,0]
    [c:\PROGRA~1\mcafee\mps\mpsevh.dll]  [McAfee, Inc., 10.1.133.0]
    [c:\PROGRA~1\mcafee\mps\mpsmisp.dll]  [McAfee, Inc., 10.1.137.0]
    [C:\Program Files\McAfee\VirusScan\mvslog.dll]  [McAfee, Inc., 12,0,172,0]
[PID: 2168 / SYSTEM][C:\Windows\system32\rundll32.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 2208 / SYSTEM][C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe]  [McAfee, Inc., VSCORE.14.0.0.349.x86]
    [C:\PROGRA~1\McAfee\VIRUSS~1\LockDown.dll]  [McAfee, Inc., VSCORE.14.0.0.349.x86]
    [C:\PROGRA~1\McAfee\VIRUSS~1\mytilus3.dll]  [McAfee, Inc., VSCORE.14.0.0.349.x86]
    [C:\PROGRA~1\McAfee\VIRUSS~1\mytilus3_worker.dll]  [McAfee, Inc., VSCORE.14.0.0.349.x86]
    [C:\PROGRA~1\McAfee\VIRUSS~1\mytilus3_server.dll]  [McAfee, Inc., VSCORE.14.0.0.349.x86]
    [C:\PROGRA~1\McAfee\VIRUSS~1\RES00\McShield.dll]  [McAfee, Inc., VSCORE.14.0.0.349]
    [C:\PROGRA~1\McAfee\VIRUSS~1\FTL.Dll]  [McAfee, Inc., VSCORE.14.0.0.349.x86]
    [C:\PROGRA~1\McAfee\VIRUSS~1\naiann.dll]  [McAfee, Inc., 12,0,188,0]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mccoreps.dll]  [McAfee, Inc., 3,0,117,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\mcvsps.dll]  [McAfee, Inc., 12,0,188,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\naiannps.dll]  [McAfee, Inc., 12,0,188,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\mvscfg.dll]  [McAfee, Inc., 12,1,118,0]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mcevtbrk.dll]  [McAfee, Inc., 3,0,117,0]
    [C:\PROGRA~1\McAfee\VIRUSS~1\mvslog.dll]  [McAfee, Inc., 12,0,172,0]
    [C:\Program Files\McAfee\VirusScan\Engine\5300.2777\mcscan32.dll]  [McAfee, Inc., 5.3.00]
    [C:\PROGRA~1\McAfee\VIRUSS~1\mfebopa.dll]  [McAfee, Inc., SYSCORE.14.0.0.291.x86]
    [C:\PROGRA~1\McAfee\VIRUSS~1\mfehida.dll]  [McAfee, Inc., SYSCORE.14.0.0.291.x86]
    [C:\PROGRA~1\McAfee\VIRUSS~1\mfeavfa.dll]  [McAfee, Inc., SYSCORE.14.0.0.291.x86]
    [c:\PROGRA~1\mcafee\msc\mcsubmgr\8_1_13~1\mcsubmgr.dll]  [McAfee, Inc., 8,1,133,0]
[PID: 2240 / SYSTEM][C:\Program Files\McAfee\MPF\MPFSrv.exe]  [McAfee, Inc., 9.0.136.0]
    [c:\PROGRA~1\COMMON~1\mcafee\HACKER~1\hwapi.dll]  [McAfee, Inc., 9.0.119.0]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mcevtbrk.dll]  [McAfee, Inc., 3,0,117,0]
    [c:\PROGRA~1\mcafee\mpf\mc\mpfmisp.dll]  [McAfee, Inc., 9.0.136.0]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
[PID: 2560 / SYSTEM][C:\Program Files\McAfee\MSK\MskSrver.exe]  [McAfee, Inc., 9.1.107.0]
    [c:\PROGRA~1\mcafee\msk\mskengn.dll]  [McAfee, Inc., 9.1.107.0]
    [c:\PROGRA~1\mcafee\msk\mskwm.dll]  [McAfee, Inc., 9.1.107.0]
    [c:\PROGRA~1\mcafee\msk\mskxaif.dll]  [McAfee, Inc., 9.1.107.0]
    [C:\Program Files\McAfee\MSK\MSKSet.dll]  [McAfee, Inc., 9.1.107.0]
    [C:\Program Files\McAfee\MSK\MSKMFW.dll]  [McAfee, Inc., 9.1.107.0]
    [C:\Program Files\McAfee\MSK\MSKMCmn.dll]  [McAfee, Inc., 9.1.109.0]
    [C:\Program Files\McAfee\MSK\MSKMUF.dll]  [McAfee, Inc., 9.1.107.0]
    [C:\Program Files\McAfee\MSK\MSKMSF.dll]  [McAfee, Inc., 9.1.107.0]
    [C:\Program Files\McAfee\MSK\MSKMRLS.dll]  [McAfee, Inc., 9.1.107.0]
    [C:\Program Files\McAfee\MSK\MSKMB52.dll]  [McAfee, Inc., 9.1.107.0]
    [C:\Program Files\McAfee\MSK\MSKGRE.dll]  [McAfee, Inc., 9.1.107.0]
    [C:\Program Files\McAfee\MSK\McAPFilt.dll]  [McAfee, Inc., 9.1.107.0]
[PID: 2648 / NETWORK SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 2684 / SYSTEM][C:\Windows\system32\PSIService.exe]  [, 2.0.0.1]
    [C:\Windows\system32\PSIKey.dll]  [Protexis Inc., 2.0.0.1]
[PID: 2780 / SYSTEM][C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe]  [Intel Corporation, 11.1.1.0  ]
[PID: 2800 / SYSTEM][C:\Windows\System32\rpcnet.exe]  [Absolute Software Corp., 8.0.879.0]
    [C:\Windows\System32\rpcnet.dll]  [Absolute Software Corp., 8.0.879.0]
[PID: 2916 / SYSTEM][C:\Program Files\Dell Support Center\bin\sprtsvc.exe]  [SupportSoft, Inc., 7.0.1117.0]
    [C:\Program Files\Dell Support Center\bin\sprtsched.dll]  [SupportSoft, Inc., 7.0.940.0]
    [C:\Program Files\Dell Support Center\bin\sprtfod.dll]  [SupportSoft, Inc., 7.0.940.0]
    [C:\Program Files\Dell Support Center\bin\LIBEAY32.dll]  [SupportSoft, Inc., 0, 9, 8, 4, 1]
    [C:\Program Files\Dell Support Center\bin\sprtsync.dll]  [SupportSoft, Inc., 7.0.1302.0]
    [C:\Program Files\Dell Support Center\bin\sprtupdate.dll]  [SupportSoft, Inc., 7.0.940.0]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
[PID: 2932 / SYSTEM][C:\Windows\system32\STacSV.exe]  [IDT, Inc., 1.0.5614.0  nd654 cp1]
    [C:\Windows\system32\stapi32.dll]  [IDT, Inc., 1.0.5614.0  nd654 cp1]
[PID: 2976 / LOCAL SERVICE][C:\Windows\system32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 3036 / SYSTEM][C:\Windows\System32\svchost.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 3096 / SYSTEM][C:\Windows\system32\SearchIndexer.exe]  [(Verified) Microsoft Corporation, 7.0.6001.16503 (longhorn(wmbla).080526-2159)]
[PID: 3188 / SYSTEM][C:\Windows\system32\DRIVERS\xaudio.exe]  [Conexant Systems, Inc., 1.00.00]
[PID: 3280 / SYSTEM][C:\Windows\system32\taskeng.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 3640 / SYSTEM][C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe]  [McAfee, Inc., 8,1,159,0]
    [c:\PROGRA~1\COMMON~1\mcafee\msc\mcutil\8_1_11~1\McUtil.dll]  [McAfee, Inc., 8,1,114,0]
    [C:\PROGRA~1\McAfee\MSC\McRes.dll]  [McAfee, Inc., 8,0,226,0]
    [C:\PROGRA~1\McAfee\MSC\McLocRes.dll]  [McAfee, Inc., 8,1,153,0]
    [C:\Program Files\McAfee\MSC\oem\105-257\Mccobres.dll]  [McAfee, Inc., 8, 1, 165, 1]
    [C:\PROGRA~1\McAfee\MSC\Mccobres.dll]  [McAfee, Inc., 8,1,165,0]
    [C:\PROGRA~1\COMMON~1\McAfee\MSC\sqlite3.dll]  [McAfee, Inc., 8,1,125,0]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mccoreps.dll]  [McAfee, Inc., 3,0,117,0]
    [c:\PROGRA~1\mcafee\msc\mcmispps.dll]  [McAfee, Inc., 8,0,226,0]
    [c:\PROGRA~1\mcafee\msc\mcsubmgr\8_1_13~1\mcsubmgr.dll]  [McAfee, Inc., 8,1,133,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\mvsap.dll]  [McAfee, Inc., 12,0,172,0]
    [c:\PROGRA~1\mcafee\msc\mcshllps.dll]  [McAfee, Inc., 8,1,133,0]
    [c:\PROGRA~1\mcafee\mpf\mc\mpfmisp.dll]  [McAfee, Inc., 9.0.136.0]
    [C:\Program Files\McAfee\MPF\L10N.DLL]  [McAfee, Inc., 9.1.108.0]
    [c:\PROGRA~1\mcafee\msk\mskmisp.dll]  [McAfee, Inc., 9.1.107.0]
    [c:\PROGRA~1\mcafee\mps\mpsmisp.dll]  [McAfee, Inc., 10.1.137.0]
    [C:\Program Files\McAfee\MPS\MpsRes.DLL]  [McAfee, Inc., 10.0.263.0]
    [c:\PROGRA~1\mcafee\msc\mcprotpv.dll]  [McAfee, Inc., 8,0,226,0]
    [C:\PROGRA~1\McAfee\MSC\McNmcRes.dll]  [McAfee, Inc., 2,1,151,0]
    [C:\PROGRA~1\McAfee\MSC\McNmcLoR.dll]  [McAfee, Inc., 2,1,151,0]
    [C:\PROGRA~1\McAfee\MSC\McNmcCoR.dll]  [McAfee, Inc., 2,1,151,0]
    [C:\PROGRA~1\McAfee\MSC\McProHlp.dll]  [McAfee, Inc., 8,0,226,0]
    [c:\PROGRA~1\mcafee\msc\mcregobj\8_0_22~1\mcregobj.dll]  [McAfee, Inc., 8,0,226,0]
[PID: 3976 / Via][C:\Windows\system32\Dwm.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Windows\system32\nvd3dum.dll]  [NVIDIA Corporation, 7.15.11.7597]
[PID: 3988 / Via][C:\Windows\system32\taskeng.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Windows\system32\nvapi.dll]  [NVIDIA Corporation, 7.15.11.7597]
[PID: 4080 / Via][C:\Windows\Explorer.EXE]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Program Files\Dell DataSafe Online\cpputils.dll]  [N/A, ]
    [C:\Windows\system32\nvcpl.dll]  [NVIDIA Corporation, 7.15.11.7597]
    [C:\Windows\system32\nvapi.dll]  [NVIDIA Corporation, 7.15.11.7597]
    [C:\Program Files\Dell\QuickSet\dadkeyb.dll]  [Dell Inc., 8, 2, 20, 0]
    [C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll]  [N/A, ]
[PID: 2108 / Via][c:\PROGRA~1\mcafee.com\agent\mcagent.exe]  [McAfee, Inc., 8,0,237,0]
    [C:\PROGRA~1\McAfee\MSC\McRes.dll]  [McAfee, Inc., 8,0,226,0]
    [C:\PROGRA~1\McAfee\MSC\McLocRes.dll]  [McAfee, Inc., 8,1,153,0]
    [C:\Program Files\McAfee\MSC\oem\105-257\Mccobres.dll]  [McAfee, Inc., 8, 1, 165, 1]
    [C:\PROGRA~1\McAfee\MSC\Mccobres.dll]  [McAfee, Inc., 8,1,165,0]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [c:\PROGRA~1\mcafee\msc\mcsubmgr\8_1_13~1\mcsubmgr.dll]  [McAfee, Inc., 8,1,133,0]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mccoreps.dll]  [McAfee, Inc., 3,0,117,0]
    [c:\PROGRA~1\mcafee\msc\mcmispps.dll]  [McAfee, Inc., 8,0,226,0]
    [c:\PROGRA~1\mcafee.com\agent\mcagntps.dll]  [McAfee, Inc., 8,0,226,0]
    [c:\PROGRA~1\mcafee\msc\mccfgpv.dll]  [McAfee, Inc., 8,1,133,0]
    [c:\PROGRA~1\mcafee\msc\mcuicfg.dll]  [McAfee, Inc., 8,0,226,0]
    [c:\PROGRA~1\mcafee\msc\mcshllps.dll]  [McAfee, Inc., 8,1,133,0]
    [c:\PROGRA~1\mcafee\msc\mcregobj\8_0_22~1\mcregobj.dll]  [McAfee, Inc., 8,0,226,0]
[PID: 3428 / Via][C:\Program Files\Windows Defender\MSASCui.exe]  [Microsoft Corporation, 1.1.1600.0]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 1872 / Via][C:\Program Files\Dell\MediaDirect\PCMService.exe]  [CyberLink Corp., 4, 5, 0, 0]
    [C:\Program Files\Dell\MediaDirect\MFC71.DLL]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\Dell\MediaDirect\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
    [C:\Program Files\Dell\MediaDirect\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Program Files\Dell\MediaDirect\Kernel\common\CLRCEngine3.dll]  [CyberLink Corp., 4.07.1305]
[PID: 3660 / Via][C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe]  [Intel Corporation, 7.0.0.1020]
    [C:\Program Files\Intel\Intel Matrix Storage Manager\ISDI.dll]  [Intel Corporation, 7.0.0.1020]
    [C:\Program Files\Intel\Intel Matrix Storage Manager\IAAMon_ENU.dll]  [Intel Corporation, 7.0.0.1020]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 2904 / Via][C:\Windows\OEM02Mon.exe]  [Creative Technology Ltd., 1.01.01.00]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 1868 / Via][C:\Program Files\Dell Support Center\bin\sprtcmd.exe]  [SupportSoft, Inc., 7.0.1117.0]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Program Files\Dell Support Center\bin\sprtmessage.dll]  [SupportSoft, Inc., 7.2.955.0]
    [C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\5b3e3b0551bcaa722c27dbb089c431e4\mscorlib.ni.dll]  [Microsoft Corporation, 2.0.50727.1434 (REDBITS.050727-1400)]
    [C:\Program Files\Dell Support Center\bin\sprtsched.dll]  [SupportSoft, Inc., 7.0.940.0]
    [C:\Program Files\Dell Support Center\bin\sprtevent.dll]  [SupportSoft, Inc., 7.0.940.0]
    [C:\Program Files\Dell Support Center\bin\sprtfod.dll]  [SupportSoft, Inc., 7.0.940.0]
    [C:\Program Files\Dell Support Center\bin\LIBEAY32.dll]  [SupportSoft, Inc., 0, 9, 8, 4, 1]
    [C:\Program Files\Dell Support Center\bin\sprtsync.dll]  [SupportSoft, Inc., 7.0.1302.0]
    [C:\Program Files\Dell Support Center\bin\sprtui.dll]  [SupportSoft, Inc., 7.0.1057.0]
    [C:\Program Files\Dell Support Center\bin\SupportSoft.Agent.Sprocket.SupportMessage.dll]  [SupportSoft, Inc., 7.2.955.0]
    [C:\Program Files\Dell Support Center\bin\SupportSoft.Agent.Sprocket.dll]  [SupportSoft, Inc., 7.2.955.0]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
    [C:\Windows\assembly\NativeImages_v2.0.50727_32\System\267d4c344058092e6950c11594244f90\System.ni.dll]  [Microsoft Corporation, 2.0.50727.1434 (REDBITS.050727-1400)]
    [C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\02cf61328d59df9b3ec09544f449a781\System.Xml.ni.dll]  [Microsoft Corporation, 2.0.50727.1434 (REDBITS.050727-1400)]
[PID: 3376 / Via][C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe]  [Creative Technology Ltd, 2.20.6.0]
    [C:\Program Files\Creative\SBAudigy\Volume Panel\CTAudSeu.dll]  [Creative Technology Ltd, 1.0.2.0]
    [C:\Program Files\Creative\SBAudigy\Volume Panel\CTAudEp.dll]  [Creative Technology Ltd, 1.1.6.0]
    [C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanel.crl]  [Creative Technology Ltd, 2.10.3.0]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Program Files\Creative\ShareDLL\CADI\CTCadiEP.dll]  [Creative Technology Ltd, 1.0.0.6]
    [C:\Windows\system32\CmdRtr.dll]  [, ]
    [C:\Windows\system32\APOMngr.dll]  [, ]
    [C:\Windows\system32\ctapo32.dll]  [Creative Technology Ltd., 1.0.0.195]
    [C:\Program Files\Creative\SBAudigy\Volume Panel\CTThemeU.dll]  [Creative Technology Ltd, 3.1.16.0]
    [C:\Program Files\Creative\SBAudigy\Volume Panel\CtrlSrcU.dll]  [Creative Technology Ltd., 3.1.2.0]
    [C:\Program Files\Creative\SBAudigy\Volume Panel\CTIniFu.dll]  [Creative Technology Ltd, 1.2.0.0]
    [C:\Program Files\Creative\SBAudigy\Volume Panel\GDICtrl.sku]  [Creative Technology Ltd, 3.1.30.0]
    [C:\Program Files\Creative\SBAudigy\Volume Panel\GDICtrl2.sku]  [Creative Technology Ltd, 3.1.20.0]
    [C:\Program Files\Creative\SBAudigy\Volume Panel\GDICtrl3.sku]  [Creative Technology Ltd, 3.1.16.0]
    [C:\Program Files\Creative\SBAudigy\Volume Panel\RtxCtrl.sku]  [Creative Technology Ltd, 3.1.15.0]
[PID: 1948 / Via][C:\Program Files\DellTPad\Apoint.exe]  [Alps Electric Co., Ltd., 7.0.101.204]
    [C:\Program Files\DellTPad\Apoint.dll]  [Alps Electric Co., Ltd., 5.5.104.336]
    [C:\Windows\system32\Vxdif.dll]  [Alps Electric Co., Ltd., 6.0.3.17]
    [C:\Program Files\DellTPad\EzAuto.dll]  [Alps Electric Co., Ltd., 5.5.1.92]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 2116 / Via][C:\Windows\System32\rundll32.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\system32\nvHotkey.dll]  [NVIDIA Corporation, 7.15.11.7597]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 752 / Via][C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe]  [, 1.1.0.6775]
    [C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\5b3e3b0551bcaa722c27dbb089c431e4\mscorlib.ni.dll]  [Microsoft Corporation, 2.0.50727.1434 (REDBITS.050727-1400)]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Windows\assembly\NativeImages_v2.0.50727_32\System\267d4c344058092e6950c11594244f90\System.ni.dll]  [Microsoft Corporation, 2.0.50727.1434 (REDBITS.050727-1400)]
    [C:\Program Files\Dell DataSafe Online\SdbShared.dll]  [, 1.1.0.6775]
    [C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\a35f567c4c67d6b1ca9a0023852847a2\System.Drawing.ni.dll]  [Microsoft Corporation, 2.0.50727.1434 (REDBITS.050727-1400)]
    [C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\45ee94a63c463b93e3ff694c6ecd0820\System.Windows.Forms.ni.dll]  [Microsoft Corporation, 2.0.50727.1434 (REDBITS.050727-1400)]
    [C:\Program Files\Dell DataSafe Online\BalloonWindow.dll]  [, 1.2.0.0]
    [C:\Program Files\Dell DataSafe Online\SdbUI.dll]  [, 1.1.0.6775]
    [C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\15366cc16c2550064601b5167821667d\System.Configuration.ni.dll]  [Microsoft Corporation, 2.0.50727.1434 (REDBITS.050727-1400)]
    [C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\02cf61328d59df9b3ec09544f449a781\System.Xml.ni.dll]  [Microsoft Corporation, 2.0.50727.1434 (REDBITS.050727-1400)]
    [C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\af61137b092f7167a1bb6d5f8ee294d8\System.Web.Services.ni.dll]  [Microsoft Corporation, 2.0.50727.1434 (REDBITS.050727-1400)]
    [C:\Program Files\Dell DataSafe Online\SdbShared.XmlSerializers.dll]  [, 1.1.0.6775]
    [C:\Program Files\Dell DataSafe Online\OlbEng.dll]  [TODO: , 1.0.0.1]
    [C:\Program Files\Dell DataSafe Online\BuEng.dll]  [SwapDrive, Inc., 2.00.305]
    [C:\Program Files\Dell DataSafe Online\cpputils.dll]  [N/A, ]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
    [C:\Program Files\Dell\QuickSet\dadkeyb.dll]  [Dell Inc., 8, 2, 20, 0]
    [C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll]  [N/A, ]
    [C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\369cdfcbaefd8f28200e295c26c2141f\System.Web.ni.dll]  [Microsoft Corporation, 2.0.50727.1434 (REDBITS.050727-1400)]
[PID: 2484 / Via][C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe]  [ACD Systems, 5,0,49,0]
    [C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80U.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Windows\WinSxS\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131\MFC80ENU.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 2496 / Via][C:\Windows\ehome\ehtray.exe]  [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 3500 / Via][C:\Program Files\Windows Sidebar\sidebar.exe]  [Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Program Files\McAfee\VirusScan\scriptsn.dll]  [McAfee, Inc., VSCORE.14.0.0.366.x86]
    [C:\Windows\system32\icm32.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
[PID: 4108 / Via][C:\Program Files\Windows Media Player\wmpnscfg.exe]  [Microsoft Corporation, 11.0.6000.6324 (vista_rtm.061101-2205)]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 4164 / Via][C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Windows\system32\btwapi.dll]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Windows\system32\btosif.dll]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Windows\system32\btwhidcs.DLL]  [N/A, ]
    [C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80U.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Program Files\WIDCOMM\Bluetooth Software\BtBalloon.dll]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Windows\WinSxS\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131\MFC80ENU.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Windows\system32\btrez.dll]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll]  [N/A, ]
    [C:\Windows\system32\btmmhook.dll]  [Broadcom Corporation., 6.0.1.3100]
[PID: 4184 / Via][C:\Program Files\Dell\QuickSet\quickset.exe]  [Dell Inc., 8, 2, 20, 0]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Program Files\Dell\QuickSet\dadkeyb.dll]  [Dell Inc., 8, 2, 20, 0]
[PID: 4268 / Via][C:\Program Files\DellTPad\ApMsgFwd.exe]  [Alps Electric Co., Ltd., 7, 0, 0, 18]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 4292 / Via][C:\Windows\ehome\ehmsas.exe]  [(Verified) Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 4360 / NETWORK SERVICE][C:\Program Files\Windows Media Player\wmpnetwk.exe]  [Microsoft Corporation, 11.0.6000.6324 (vista_rtm.061101-2205)]
[PID: 4432 / Via][C:\Program Files\DellTPad\Apntex.exe]  [Alps Electric Co., Ltd., 7.0.1.27]
    [C:\Windows\system32\VXDIF.DLL]  [Alps Electric Co., Ltd., 6.0.3.17]
    [C:\Program Files\DellTPad\Apoint.DLL]  [Alps Electric Co., Ltd., 5.5.104.336]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 4440 / Via][C:\Program Files\DellTPad\HidFind.exe]  [Alps Electric Co., Ltd., 7.0.0.26]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 4524 / SYSTEM][C:\Windows\system32\wbem\wmiprvse.exe]  [(Verified) Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
[PID: 4744 / Via][C:\Program Files\Dell\PC TuneUp\SMSystemAnalyzer.exe]  [, ]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Program Files\iolo\Common\Lib\LMResource.dll]  [N/A, ]
    [C:\Program Files\iolo\Common\Lib\Antila.dll]  [N/A, ]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
    [C:\PROGRA~1\iolo\Common\Lib\IOLOCO~1.DLL]  [N/A, ]
    [C:\PROGRA~1\iolo\Common\Lib\IOLOSM~1.DLL]  [N/A, ]
    [C:\Program Files\iolo\Common\Lib\fbembed.dll]  [The Firebird Project, WI-V1.5.2.4731]
    [C:\Program Files\iolo\Common\Lib\ioloSearchFunctions.dll]  [, ]
[PID: 4888 / Via][C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Windows\system32\btins.dll]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Windows\system32\btosif.dll]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed\MFC80.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Windows\system32\BtAudioHelper.dll]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Windows\WinSxS\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131\MFC80ENU.DLL]  [Microsoft Corporation, 8.00.50727.762]
    [C:\Windows\system32\btosif_ol.dll]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Windows\system32\btosif_olx.dll]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Windows\system32\btosif_notes.dll]  [Broadcom Corporation., 6.0.1.3100]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 4936 / Via][C:\Program Files\Windows Sidebar\sidebar.exe]  [Microsoft Corporation, 6.0.6001.18000 (longhorn_rtm.080118-1840)]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Program Files\McAfee\VirusScan\scriptsn.dll]  [McAfee, Inc., VSCORE.14.0.0.366.x86]
    [C:\Windows\system32\icm32.dll]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Windows\system32\nvd3dum.dll]  [NVIDIA Corporation, 7.15.11.7597]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
[PID: 4068 / SYSTEM][C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe]  [McAfee, Inc., 12,1,111,0]
    [c:\PROGRA~1\mcafee\msc\mcmispps.dll]  [McAfee, Inc., 8,0,226,0]
    [C:\PROGRA~1\McAfee\VIRUSS~1\mvslog.dll]  [McAfee, Inc., 12,0,172,0]
    [C:\PROGRA~1\McAfee\VIRUSS~1\mfesmfa.dll]  [McAfee, Inc., SYSCORE.14.0.0.291.x86]
    [C:\PROGRA~1\McAfee\VIRUSS~1\mfehida.dll]  [McAfee, Inc., SYSCORE.14.0.0.291.x86]
    [c:\PROGRA~1\COMMON~1\mcafee\HACKER~1\hwapi.dll]  [McAfee, Inc., 9.0.119.0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\mvscfg.dll]  [McAfee, Inc., 12,1,118,0]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
    [c:\PROGRA~1\mcafee\msc\mcsubmgr\8_1_13~1\mcsubmgr.dll]  [McAfee, Inc., 8,1,133,0]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mccoreps.dll]  [McAfee, Inc., 3,0,117,0]
[PID: 5316 / SYSTEM][c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe]  [McAfee, Inc., 2,1,143,0]
    [c:\PROGRA~1\COMMON~1\mcafee\msc\mcutil\8_1_11~1\McUtil.dll]  [McAfee, Inc., 8,1,114,0]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mccoreps.dll]  [McAfee, Inc., 3,0,117,0]
    [c:\PROGRA~1\COMMON~1\mcafee\mna\MCNASV~1.DLL]  [McAfee, Inc., 2,1,143,0]
    [c:\PROGRA~1\mcafee\msc\mcnmcsrv.dll]  [McAfee, Inc., 2,1,151,0]
    [c:\PROGRA~1\mcafee\msc\mcnmcsps.dll]  [McAfee, Inc., 2,0,115,0]
    [c:\PROGRA~1\mcafee\msc\mcshllps.dll]  [McAfee, Inc., 8,1,133,0]
    [c:\PROGRA~1\mcafee\mpf\mc\mpfp.dll]  [McAfee, Inc., 9.0.136.0]
    [c:\PROGRA~1\mcafee\msc\mcregobj\8_0_22~1\mcregobj.dll]  [McAfee, Inc., 8,0,226,0]
    [c:\PROGRA~1\mcafee\msc\mcmismgr.dll]  [McAfee, Inc., 8,1,149,0]
    [C:\PROGRA~1\McAfee\MSC\McRes.dll]  [McAfee, Inc., 8,0,226,0]
    [C:\PROGRA~1\McAfee\MSC\McLocRes.dll]  [McAfee, Inc., 8,1,153,0]
    [C:\Program Files\McAfee\MSC\oem\105-257\Mccobres.dll]  [McAfee, Inc., 8, 1, 165, 1]
    [C:\PROGRA~1\McAfee\MSC\Mccobres.dll]  [McAfee, Inc., 8,1,165,0]
    [c:\PROGRA~1\mcafee\msc\mcsubmgr\8_1_13~1\mcsubmgr.dll]  [McAfee, Inc., 8,1,133,0]
    [c:\PROGRA~1\COMMON~1\mcafee\mna\mcuj.dll]  [McAfee, Inc., 2,1,143,0]
    [C:\PROGRA~1\McAfee\MSC\McNmcRes.dll]  [McAfee, Inc., 2,1,151,0]
    [C:\PROGRA~1\McAfee\MSC\McNmcLoR.dll]  [McAfee, Inc., 2,1,151,0]
    [C:\PROGRA~1\McAfee\MSC\McNmcCoR.dll]  [McAfee, Inc., 2,1,151,0]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]
[PID: 2304 / Via][C:\PROGRA~1\mcafee\msc\mcshell.exe]  [McAfee, Inc., 8,1,133,0]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [c:\PROGRA~1\COMMON~1\mcafee\msc\mcutil\8_1_11~1\McUtil.dll]  [McAfee, Inc., 8,1,114,0]
    [C:\PROGRA~1\COMMON~1\McAfee\MSC\McBrwsr2.dll]  [McAfee, Inc., 8,1,116,0]
    [c:\PROGRA~1\mcafee\msc\mcuicfg.dll]  [McAfee, Inc., 8,0,226,0]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mccoreps.dll]  [McAfee, Inc., 3,0,117,0]
    [c:\PROGRA~1\mcafee\msc\mcshllps.dll]  [McAfee, Inc., 8,1,133,0]
    [C:\PROGRA~1\COMMON~1\McAfee\MSC\MispLF.dll]  [McAfee, Inc., 8,0,157,0]
    [C:\PROGRA~1\McAfee\MSC\McRes.dll]  [McAfee, Inc., 8,0,226,0]
    [C:\PROGRA~1\McAfee\MSC\McLocRes.dll]  [McAfee, Inc., 8,1,153,0]
    [C:\Program Files\McAfee\MSC\oem\105-257\Mccobres.dll]  [McAfee, Inc., 8, 1, 165, 1]
    [c:\PROGRA~1\mcafee\msc\mcmispps.dll]  [McAfee, Inc., 8,0,226,0]
    [C:\PROGRA~1\McAfee\MSC\Mccobres.dll]  [McAfee, Inc., 8,1,165,0]
    [c:\PROGRA~1\mcafee\msc\mcprtcnt.dll]  [McAfee, Inc., 8,0,226,0]
    [c:\progra~1\mcafee\msc\mcshlui.dll]  [McAfee, Inc., 8,1,162,0]
    [c:\PROGRA~1\mcafee\msc\mcmismgr.dll]  [McAfee, Inc., 8,1,149,0]
    [c:\PROGRA~1\mcafee\msc\mcmnumgr.dll]  [McAfee, Inc., 8,0,226,0]
    [c:\PROGRA~1\mcafee\msc\mccfgmgr.dll]  [McAfee, Inc., 8,0,226,0]
    [c:\PROGRA~1\mcafee\msc\mcsubmgr\8_1_13~1\mcsubmgr.dll]  [McAfee, Inc., 8,1,133,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\mvsmp.dll]  [McAfee, Inc., 12,1,109,0]
    [c:\PROGRA~1\mcafee\mqc\qcmisp.dll]  [McAfee, Inc., 8,1,106,0]
    [c:\PROGRA~1\mcafee\mqc\QcLite.dll]  [McAfee, Inc., 8,1,106,0]
    [c:\PROGRA~1\mcafee\mpf\mc\mpfmisp.dll]  [McAfee, Inc., 9.0.136.0]
    [c:\PROGRA~1\mcafee\msk\mskmisp.dll]  [McAfee, Inc., 9.1.107.0]
    [C:\Program Files\McAfee\MSK\MskUI.dll]  [McAfee, Inc., 9.1.107.0]
    [C:\Program Files\McAfee\MSK\MSKSet.dll]  [McAfee, Inc., 9.1.107.0]
    [c:\PROGRA~1\mcafee\mshr\shrmisp.dll]  [McAfee, Inc., 8,1,106,0]
    [c:\PROGRA~1\mcafee\mshr\ShrRes.dll]  [, ]
    [c:\PROGRA~1\mcafee\mqc\QCRes.dll]  [McAfee, Inc., 8,1,106,0]
    [C:\Program Files\McAfee\MPF\L10N.DLL]  [McAfee, Inc., 9.1.108.0]
    [C:\Program Files\McAfee\VirusScan\scriptsn.dll]  [McAfee, Inc., VSCORE.14.0.0.366.x86]
    [c:\PROGRA~1\mcafee\msc\mccfgpv.dll]  [McAfee, Inc., 8,1,133,0]
    [c:\progra~1\mcafee\viruss~1\vsui.dll]  [McAfee, Inc., 12,0,172,0]
    [c:\PROGRA~1\COMMON~1\mcafee\msc\mccomctl.dll]  [McAfee, Inc., 8,0,157,0]
    [c:\PROGRA~1\COMMON~1\mcafee\msc\mcscrhlp.dll]  [McAfee, Inc., 8,0,157,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\mcodsax.dll]  [McAfee, Inc., 12,0,172,0]
    [C:\Program Files\Dell\QuickSet\dadkeyb.dll]  [Dell Inc., 8, 2, 20, 0]
    [C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll]  [N/A, ]
[PID: 3504 / SYSTEM][C:\Program Files\Common Files\McAfee\Core\mchost.exe]  [McAfee, Inc., 3,0,117,0]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mccoreps.dll]  [McAfee, Inc., 3,0,117,0]
    [c:\PROGRA~1\COMMON~1\mcafee\msc\mcscrhlp.dll]  [McAfee, Inc., 8,0,157,0]
[PID: 4212 / SYSTEM][C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe]  [McAfee, Inc., 12,0,172,0]
    [c:\PROGRA~1\COMMON~1\mcafee\msc\mcutil\8_1_11~1\McUtil.dll]  [McAfee, Inc., 8,1,114,0]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mccoreps.dll]  [McAfee, Inc., 3,0,117,0]
    [C:\PROGRA~1\McAfee\VIRUSS~1\mvslog.dll]  [McAfee, Inc., 12,0,172,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\mvsscan.dll]  [McAfee, Inc., 12,0,188,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\mvscfg.dll]  [McAfee, Inc., 12,1,118,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\mytilus3.dll]  [McAfee, Inc., VSCORE.14.0.0.349.x86]
    [C:\PROGRA~1\McAfee\VIRUSS~1\mytilus3_worker.dll]  [McAfee, Inc., VSCORE.14.0.0.349.x86]
    [C:\PROGRA~1\McAfee\VIRUSS~1\RES00\McShield.dll]  [McAfee, Inc., VSCORE.14.0.0.349]
    [C:\Program Files\McAfee\VirusScan\Engine\5300.2777\mcscan32.dll]  [McAfee, Inc., 5.3.00]
    [c:\PROGRA~1\COMMON~1\mcafee\core\mcevtbrk.dll]  [McAfee, Inc., 3,0,117,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\mcodsps.dll]  [McAfee, Inc., 12,0,172,0]
    [C:\PROGRA~1\McAfee\VIRUSS~1\ftl.dll]  [McAfee, Inc., VSCORE.14.0.0.349.x86]
[PID: 5060 / Via][c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe]  [McAfee, Inc., 12,0,172,0]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\PROGRA~1\McAfee\MSC\McAltLib.dll]  [McAfee, Inc., 8,1,133,0]
    [C:\PROGRA~1\McAfee\MSC\McRes.dll]  [McAfee, Inc., 8,0,226,0]
    [C:\PROGRA~1\McAfee\MSC\McLocRes.dll]  [McAfee, Inc., 8,1,153,0]
    [C:\Program Files\McAfee\MSC\oem\105-257\Mccobres.dll]  [McAfee, Inc., 8, 1, 165, 1]
    [C:\PROGRA~1\McAfee\MSC\Mccobres.dll]  [McAfee, Inc., 8,1,165,0]
    [c:\PROGRA~1\mcafee\VIRUSS~1\mcodsps.dll]  [McAfee, Inc., 12,0,172,0]
[PID: 3728 / Via][C:\Windows\system32\SearchProtocolHost.exe]  [(Verified) Microsoft Corporation, 7.0.6001.16503 (longhorn(wmbla).080526-2159)]
[PID: 3800 / Via][C:\Program Files\Internet Explorer\IEUser.exe]  [Microsoft Corporation, 6.0.6000.16386 (vista_rtm.061101-2205)]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
[PID: 2528 / SYSTEM][C:\Windows\system32\SearchFilterHost.exe]  [(Verified) Microsoft Corporation, 7.0.6001.16503 (longhorn(wmbla).080526-2159)]
[PID: 312 / Via][C:\Users\Via\Downloads\SREngLdr.EXE]  [Smallfrogs Studio, 2.7.0.1210]
[PID: 3716 / Via][C:\Users\Via\Downloads\SRE15372752.EXE]  [Smallfrogs Studio, 2.7.0.1210]
    [C:\Program Files\McAfee\SiteAdvisor\saHook.dll]  [, ]
    [C:\Users\Via\Downloads\Upload\3rdUpd.DLL]  [Smallfrogs Studio, 2, 1, 0, 15]
    [C:\Program Files\Bonjour\mdnsNSP.dll]  [Apple Inc., 1,0,5,11]

==================================
File Associations
.TXT  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  Error. [NOTEPAD.EXE %1]
.BAT  OK. ["%1" %*]
.SCR  Error. [NOTEPAD.EXE %1]
.CHM  OK. ["%SystemRoot%\hh.exe" %1]
.HLP  OK. [%SystemRoot%\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.VBS  Error. [NOTEPAD.EXE %1]
.JS   Error. [NOTEPAD.EXE %1]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock Provider
N/A

==================================
Autorun.Inf
N/A

==================================
HOSTS File
127.0.0.1       localhost

==================================
Process Privileges Scan
N/A

==================================
Scheduled Tasks
[Enabled] \\McDefragTask
        c:\PROGRA~1\mcafee\mqc\QcConsol.exe "C:\Windows\system32\defrag.exe" C: -f
[Enabled] \\McQcTask
        c:\PROGRA~1\mcafee\mqc\QcConsol.exe 14 0
[Enabled] \Apple\AppleSoftwareUpdate
        C:\Program Files\Apple Software Update\SoftwareUpdate.exe -task
[Disabled] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
        N/A
[Enabled] \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)
        N/A
[Enabled] \Microsoft\Windows\Bluetooth\UninstallDeviceTask
        BthUdTask.exe $(Arg0)
[Enabled] \Microsoft\Windows\CertificateServicesClient\SystemTask
        N/A
[Enabled] \Microsoft\Windows\CertificateServicesClient\UserTask
        N/A
[Enabled] \Microsoft\Windows\CertificateServicesClient\UserTask-Roam
        N/A
[Enabled] \Microsoft\Windows\Customer Experience Improvement Program\Consolidator
        %SystemRoot%\System32\wsqmcons.exe
[Enabled] \Microsoft\Windows\Customer Experience Improvement Program\OptinNotification
        %SystemRoot%\System32\wsqmcons.exe -n 0x1C577FA2B69CAD0
[Enabled] \Microsoft\Windows\Defrag\ManualDefrag
        %windir%\system32\defrag.exe -c
[Enabled] \Microsoft\Windows\Defrag\ScheduledDefrag
        %windir%\system32\defrag.exe -c -i
[Enabled] \Microsoft\Windows\Media Center\ehDRMInit
        %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
[Enabled] \Microsoft\Windows\Media Center\mcupdate
        %SystemRoot%\ehome\mcupdate $(Arg0) -gc
[Enabled] \Microsoft\Windows\Media Center\OCURActivate
        %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
[Enabled] \Microsoft\Windows\Media Center\OCURDiscovery
        %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery
[Enabled] \Microsoft\Windows\Media Center\UpdateRecordPath
        %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
[Enabled] \Microsoft\Windows\MobilePC\HotStart
        N/A
[Enabled] \Microsoft\Windows\MobilePC\TMM
        N/A
[Enabled] \Microsoft\Windows\MUI\LPRemove
        %windir%\system32\lpremove.exe
[Enabled] \Microsoft\Windows\Multimedia\SystemSoundsService
        N/A
[Enabled] \Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
        N/A
[Enabled] \Microsoft\Windows\Shell\CrawlStartPages
        N/A
[Disabled] \Microsoft\Windows\SideShow\AutoWake
        N/A
[Enabled] \Microsoft\Windows\SideShow\GadgetManager
        N/A
[Disabled] \Microsoft\Windows\SideShow\SessionAgent
        N/A
[Disabled] \Microsoft\Windows\SideShow\SystemDataProviders
        N/A
[Enabled] \Microsoft\Windows\SystemRestore\SR
        %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
[Enabled] \Microsoft\Windows\Tcpip\IpAddressConflict1
        rundll32 ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
[Enabled] \Microsoft\Windows\Tcpip\IpAddressConflict2
        rundll32 ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
[Enabled] \Microsoft\Windows\UPnP\UPnPHostConfig
        sc.exe config upnphost start= auto
[Enabled] \Microsoft\Windows\Windows Error Reporting\QueueReporting
        %windir%\system32\wermgr.exe -queuereporting
[Enabled] \Microsoft\Windows\WindowsCalendar\Reminders - Via
        C:\Program Files\Windows Calendar\WinCal.exe /reminder
[Enabled] \Microsoft\Windows\Wired\GatherWiredInfo
        %windir%\system32\gatherWiredInfo.vbs
[Enabled] \Microsoft\Windows\Wireless\GatherWirelessInfo
        %windir%\system32\gatherWirelessInfo.vbs

==================================
API HOOK
N/A

==================================
Hidden Process
N/A

==================================


 

Here is a new Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:53:07 AM, on 12/1/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe
C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Dell\PC TuneUp\SMSystemAnalyzer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\PROGRA~1\mcafee\msc\mcshell.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: CafeMom Toolbar - {8151A608-00FB-4D5C-8B8D-40E239E32A42} - C:\Program Files\CafeMom Toolbar\cmtb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.5470\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: CafeMom Toolbar - {8151A608-00FB-4D5C-8B8D-40E239E32A42} - C:\Program Files\CafeMom Toolbar\cmtb.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [Dell PC TuneUp Startup] "C:\Program Files\iolo\Common\Lib\ioloLManager.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [Device Detector] DevDetect.exe -autorun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: (no name) - {07DB8C18-9FD9-4e43-AF16-043E44D89768} - C:\Program Files\CafeMom Toolbar\cmtb.dll
O9 - Extra 'Tools' menuitem: CafeMom Toolbar - {07DB8C18-9FD9-4e43-AF16-043E44D89768} - C:\Program Files\CafeMom Toolbar\cmtb.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/control/en-US/activex/TmHcmsX.CAB
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} - http://www.infospace.com/mypoints.main/tbar/mypointsSetup.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {C8E7CBFB-9F2E-42C7-B4CB-D4B7FC89A363} (Gather Photo Uploader Control) - http://www.gather.com/imageuploader/GatherUploader5.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: McAfee Application Installer Cleanup (0225291228142403) (0225291228142403mcinstcleanup) - Unknown owner - C:\Windows\TEMP\022529~1.EXE (file missing)
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\Windows\system32\CTsvcCDA.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Procedure Call (RPC) Net (rpcnet) - Absolute Software Corp. - C:\Windows\System32\rpcnet.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 12860 bytes

Thanks for all your help!

-Monica

 

10.4K Posts

December 1st, 2008 09:00


monicav

We have to get the errors fixed related to .exe files fixed before we can do anything else.

Did you say you reloaded the OS and still have the same issue?

We may have to uninstall some programs you have until we get this fixed, but for now

Download gmer from HERE
  • Save it To your Desktop
    Rt click->>Extract All->>and extract it to your Desktop
    Open the gmer folder->>Double click the gmer.exe to run it
    Select the rootkit tab, press the "Scan" button
    Make sure the "Show all" box is NOT checked
    When it finishes Select "copy"
    Copy and paste that log as a reply to this thread

7 Posts

December 1st, 2008 10:00

Okay, thanks. Yes, I have reformatted and reinstalled the OS twice since I've had the laptop... and I haven't had it long.

Here is the gmer log:

 

GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-12-01 13:25:26
Windows 6.0.6001 Service Pack 1


---- System - GMER 1.0.14 ----

Code            \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwCreateFile [0x906189BE]
Code            \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwCreateProcess [0x90618958]
Code            \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwCreateProcessEx [0x9061896C]
Code            \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwMapViewOfSection [0x906189FC]
Code            \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwNotifyChangeKey [0x90618A3F]
Code            \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwOpenProcess [0x90618930]
Code            \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwOpenThread [0x90618944]
Code            \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwProtectVirtualMemory [0x906189D2]
Code            \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwReplaceKey [0x90618A67]
Code            \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwRestoreKey [0x90618A53]
Code            \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwSetContextThread [0x906189AA]
Code            \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwSetInformationProcess [0x90618996]
Code            \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwTerminateProcess [0x90618A2B]
Code            \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwUnmapViewOfSection [0x90618A12]
Code            \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwYieldExecution [0x906189E8]
Code            \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  ZwCreateUserProcess [0x90618982]
Code            \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  NtCreateFile
Code            \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  NtMapViewOfSection
Code            \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  NtOpenProcess
Code            \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  NtOpenThread
Code            \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)  NtSetInformationProcess

---- Kernel code sections - GMER 1.0.14 ----

.text           ntkrnlpa.exe!ZwYieldExecution                                                                 8203118C 5 Bytes  JMP 906189EC \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE            ntkrnlpa.exe!ZwNotifyChangeKey                                                                821CB17C 5 Bytes  JMP 90618A43 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE            ntkrnlpa.exe!ZwCreateUserProcess                                                              821D2DCA 5 Bytes  JMP 90618986 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE            ntkrnlpa.exe!ZwTerminateProcess                                                               821ECF80 5 Bytes  JMP 90618A2F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE            ntkrnlpa.exe!NtOpenThread                                                                     8220C1DC 5 Bytes  JMP 90618948 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE            ntkrnlpa.exe!NtOpenProcess                                                                    8221BB18 5 Bytes  JMP 90618934 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE            ntkrnlpa.exe!NtMapViewOfSection                                                               8222E74E 7 Bytes  JMP 90618A00 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE            ntkrnlpa.exe!ZwUnmapViewOfSection                                                             8222EDA5 5 Bytes  JMP 90618A16 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE            ntkrnlpa.exe!NtCreateFile                                                                     82230FB6 5 Bytes  JMP 906189C2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE            ntkrnlpa.exe!NtSetInformationProcess                                                          8223E674 5 Bytes  JMP 9061899A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE            ntkrnlpa.exe!ZwProtectVirtualMemory                                                           822408CE 7 Bytes  JMP 906189D6 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE            ntkrnlpa.exe!ZwRestoreKey                                                                     8225F452 5 Bytes  JMP 90618A57 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE            ntkrnlpa.exe!ZwReplaceKey                                                                     8226049E 5 Bytes  JMP 90618A6B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE            ntkrnlpa.exe!ZwCreateProcess                                                                  8229E1C1 5 Bytes  JMP 9061895C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE            ntkrnlpa.exe!ZwCreateProcessEx                                                                8229E20C 7 Bytes  JMP 90618970 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE            ntkrnlpa.exe!ZwSetContextThread                                                               8229ECCB 5 Bytes  JMP 906189AE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

---- User code sections - GMER 1.0.14 ----

.text           C:\Windows\system32\svchost.exe[376] kernel32.dll!GetStartupInfoW                             77661929 5 Bytes  JMP 006C0082
.text           C:\Windows\system32\svchost.exe[376] kernel32.dll!GetStartupInfoA                             776619C9 5 Bytes  JMP 006C0F46
.text           C:\Windows\system32\svchost.exe[376] kernel32.dll!CreateProcessW                              77661C01 5 Bytes  JMP 006C0F06
.text           C:\Windows\system32\svchost.exe[376] kernel32.dll!CreateProcessA                              77661C36 5 Bytes  JMP 006C009D
.text           C:\Windows\system32\svchost.exe[376] kernel32.dll!VirtualProtect                              77661DD1 5 Bytes  JMP 006C0F8D
.text           C:\Windows\system32\svchost.exe[376] kernel32.dll!CreateNamedPipeW                            77665C44 5 Bytes  JMP 006C0036
.text           C:\Windows\system32\svchost.exe[376] kernel32.dll!LoadLibraryExW                              776830C3 5 Bytes  JMP 006C0F9E
.text           C:\Windows\system32\svchost.exe[376] kernel32.dll!LoadLibraryW                                7768361F 5 Bytes  JMP 006C0FCA
.text           C:\Windows\system32\svchost.exe[376] kernel32.dll!VirtualProtectEx                            77688D7E 5 Bytes  JMP 006C0F7C
.text           C:\Windows\system32\svchost.exe[376] kernel32.dll!LoadLibraryExA                              77689469 5 Bytes  JMP 006C0FAF
.text           C:\Windows\system32\svchost.exe[376] kernel32.dll!LoadLibraryA                                77689491 5 Bytes  JMP 006C0047
.text           C:\Windows\system32\svchost.exe[376] kernel32.dll!CreatePipe                                  77690284 5 Bytes  JMP 006C0F57
.text           C:\Windows\system32\svchost.exe[376] kernel32.dll!GetProcAddress                              776AB8B6 5 Bytes  JMP 006C0EF5
.text           C:\Windows\system32\svchost.exe[376] kernel32.dll!CreateFileW                                 776ACC4E 5 Bytes  JMP 006C0011
.text           C:\Windows\system32\svchost.exe[376] kernel32.dll!CreateFileA                                 776ACF71 5 Bytes  JMP 006C0000
.text           C:\Windows\system32\svchost.exe[376] kernel32.dll!CreateNamedPipeA                            776F41F6 5 Bytes  JMP 006C0FE5
.text           C:\Windows\system32\svchost.exe[376] kernel32.dll!WinExec                                     776F53E7 5 Bytes  JMP 006C0F17
.text           C:\Windows\system32\svchost.exe[376] ADVAPI32.dll!RegCreateKeyExA                             774AB5E7 5 Bytes  JMP 006B0FA5
.text           C:\Windows\system32\svchost.exe[376] ADVAPI32.dll!RegCreateKeyA                               774AB8AE 5 Bytes  JMP 006B002C
.text           C:\Windows\system32\svchost.exe[376] ADVAPI32.dll!RegOpenKeyA                                 774B0BF5 5 Bytes  JMP 006B0FE5
.text           C:\Windows\system32\svchost.exe[376] ADVAPI32.dll!RegCreateKeyW                               774BB83D 5 Bytes  JMP 006B0047
.text           C:\Windows\system32\svchost.exe[376] ADVAPI32.dll!RegCreateKeyExW                             774BBCE1 5 Bytes  JMP 006B0F8A
.text           C:\Windows\system32\svchost.exe[376] ADVAPI32.dll!RegOpenKeyExA                               774BD4E8 5 Bytes  JMP 006B0FC0
.text           C:\Windows\system32\svchost.exe[376] ADVAPI32.dll!RegOpenKeyW                                 774C3CB0 5 Bytes  JMP 006B0000
.text           C:\Windows\system32\svchost.exe[376] ADVAPI32.dll!RegOpenKeyExW                               774CF09D 5 Bytes  JMP 006B001B
.text           C:\Windows\system32\svchost.exe[376] WS2_32.dll!socket                                        765236D1 5 Bytes  JMP 00190FEF
.text           C:\Windows\system32\services.exe[684] kernel32.dll!GetStartupInfoW                            77661929 5 Bytes  JMP 00D6008A
.text           C:\Windows\system32\services.exe[684] kernel32.dll!GetStartupInfoA                            776619C9 5 Bytes  JMP 00D60079
.text           C:\Windows\system32\services.exe[684] kernel32.dll!CreateProcessW                             77661C01 5 Bytes  JMP 00D600B6
.text           C:\Windows\system32\services.exe[684] kernel32.dll!CreateProcessA                             77661C36 5 Bytes  JMP 00D600A5
.text           C:\Windows\system32\services.exe[684] kernel32.dll!VirtualProtect                             77661DD1 5 Bytes  JMP 00D60F5F
.text           C:\Windows\system32\services.exe[684] kernel32.dll!CreateNamedPipeW                           77665C44 5 Bytes  JMP 00D60FB2
.text           C:\Windows\system32\services.exe[684] kernel32.dll!LoadLibraryExW                             776830C3 5 Bytes  JMP 00D60043
.text           C:\Windows\system32\services.exe[684] kernel32.dll!LoadLibraryW                               7768361F 5 Bytes  JMP 00D60FA1
.text           C:\Windows\system32\services.exe[684] kernel32.dll!VirtualProtectEx                           77688D7E 5 Bytes  JMP 00D6005E
.text           C:\Windows\system32\services.exe[684] kernel32.dll!LoadLibraryExA                             77689469 5 Bytes  JMP 00D60F86
.text           C:\Windows\system32\services.exe[684] kernel32.dll!LoadLibraryA                               77689491 5 Bytes  JMP 00D60028
.text           C:\Windows\system32\services.exe[684] kernel32.dll!CreatePipe                                 77690284 5 Bytes  JMP 00D60F4E
.text           C:\Windows\system32\services.exe[684] kernel32.dll!GetProcAddress                             776AB8B6 5 Bytes  JMP 00D600D1
.text           C:\Windows\system32\services.exe[684] kernel32.dll!CreateFileW                                776ACC4E 5 Bytes  JMP 00D60FDE
.text           C:\Windows\system32\services.exe[684] kernel32.dll!CreateFileA                                776ACF71 5 Bytes  JMP 00D60FEF
.text           C:\Windows\system32\services.exe[684] kernel32.dll!CreateNamedPipeA                           776F41F6 5 Bytes  JMP 00D60FC3
.text           C:\Windows\system32\services.exe[684] kernel32.dll!WinExec                                    776F53E7 5 Bytes  JMP 00D60F29
.text           C:\Windows\system32\services.exe[684] ADVAPI32.dll!RegCreateKeyExA                            774AB5E7 5 Bytes  JMP 00980FC0
.text           C:\Windows\system32\services.exe[684] ADVAPI32.dll!RegCreateKeyA                              774AB8AE 5 Bytes  JMP 00980062
.text           C:\Windows\system32\services.exe[684] ADVAPI32.dll!RegOpenKeyA                                774B0BF5 5 Bytes  JMP 00980000
.text           C:\Windows\system32\services.exe[684] ADVAPI32.dll!RegCreateKeyW                              774BB83D 5 Bytes  JMP 00980FD1
.text           C:\Windows\system32\services.exe[684] ADVAPI32.dll!RegCreateKeyExW                            774BBCE1 5 Bytes  JMP 0098007D
.text           C:\Windows\system32\services.exe[684] ADVAPI32.dll!RegOpenKeyExA                              774BD4E8 5 Bytes  JMP 0098002C
.text           C:\Windows\system32\services.exe[684] ADVAPI32.dll!RegOpenKeyW                                774C3CB0 5 Bytes  JMP 0098001B
.text           C:\Windows\system32\services.exe[684] ADVAPI32.dll!RegOpenKeyExW                              774CF09D 5 Bytes  JMP 0098003D
.text           C:\Windows\system32\services.exe[684] WS2_32.dll!socket                                       765236D1 5 Bytes  JMP 00960000
.text           C:\Windows\system32\lsass.exe[700] kernel32.dll!GetStartupInfoW                               77661929 5 Bytes  JMP 00720082
.text           C:\Windows\system32\lsass.exe[700] kernel32.dll!GetStartupInfoA                               776619C9 5 Bytes  JMP 00720067
.text           C:\Windows\system32\lsass.exe[700] kernel32.dll!CreateProcessW                                77661C01 5 Bytes  JMP 00720EF5
.text           C:\Windows\system32\lsass.exe[700] kernel32.dll!CreateProcessA                                77661C36 5 Bytes  JMP 00720F10
.text           C:\Windows\system32\lsass.exe[700] kernel32.dll!VirtualProtect                                77661DD1 5 Bytes  JMP 00720038
.text           C:\Windows\system32\lsass.exe[700] kernel32.dll!CreateNamedPipeW                              77665C44 5 Bytes  JMP 00720FAF
.text           C:\Windows\system32\lsass.exe[700] kernel32.dll!LoadLibraryExW                                776830C3 5 Bytes  JMP 00720F5E
.text           C:\Windows\system32\lsass.exe[700] kernel32.dll!LoadLibraryW                                  7768361F 5 Bytes  JMP 00720F79
.text           C:\Windows\system32\lsass.exe[700] kernel32.dll!VirtualProtectEx                              77688D7E 5 Bytes  JMP 00720F4D
.text           C:\Windows\system32\lsass.exe[700] kernel32.dll!LoadLibraryExA                                77689469 5 Bytes  JMP 00720011
.text           C:\Windows\system32\lsass.exe[700] kernel32.dll!LoadLibraryA                                  77689491 5 Bytes  JMP 00720F94
.text           C:\Windows\system32\lsass.exe[700] kernel32.dll!CreatePipe                                    77690284 5 Bytes  JMP 00720F32
.text           C:\Windows\system32\lsass.exe[700] kernel32.dll!GetProcAddress                                776AB8B6 5 Bytes  JMP 007200A7
.text           C:\Windows\system32\lsass.exe[700] kernel32.dll!CreateFileW                                   776ACC4E 5 Bytes  JMP 00720000
.text           C:\Windows\system32\lsass.exe[700] kernel32.dll!CreateFileA                                   776ACF71 5 Bytes  JMP 00720FE5
.text           C:\Windows\system32\lsass.exe[700] kernel32.dll!CreateNamedPipeA                              776F41F6 5 Bytes  JMP 00720FCA
.text           C:\Windows\system32\lsass.exe[700] kernel32.dll!WinExec                                       776F53E7 5 Bytes  JMP 00720F21
.text           C:\Windows\system32\lsass.exe[700] ADVAPI32.dll!RegCreateKeyExA                               774AB5E7 5 Bytes  JMP 0014007D
.text           C:\Windows\system32\lsass.exe[700] ADVAPI32.dll!RegCreateKeyA                                 774AB8AE 5 Bytes  JMP 00140047
.text           C:\Windows\system32\lsass.exe[700] ADVAPI32.dll!RegOpenKeyA                                   774B0BF5 5 Bytes  JMP 00140000
.text           C:\Windows\system32\lsass.exe[700] ADVAPI32.dll!RegCreateKeyW                                 774BB83D 5 Bytes  JMP 00140062
.text           C:\Windows\system32\lsass.exe[700] ADVAPI32.dll!RegCreateKeyExW                               774BBCE1 5 Bytes  JMP 0014008E
.text           C:\Windows\system32\lsass.exe[700] ADVAPI32.dll!RegOpenKeyExA                                 774BD4E8 5 Bytes  JMP 0014002C
.text           C:\Windows\system32\lsass.exe[700] ADVAPI32.dll!RegOpenKeyW                                   774C3CB0 5 Bytes  JMP 0014001B
.text           C:\Windows\system32\lsass.exe[700] ADVAPI32.dll!RegOpenKeyExW                                 774CF09D 5 Bytes  JMP 00140FDB
.text           C:\Windows\system32\lsass.exe[700] WS2_32.dll!socket                                          765236D1 5 Bytes  JMP 00120FEF
.text           C:\Windows\system32\svchost.exe[840] kernel32.dll!GetStartupInfoW                             77661929 5 Bytes  JMP 00220F74
.text           C:\Windows\system32\svchost.exe[840] kernel32.dll!GetStartupInfoA                             776619C9 5 Bytes  JMP 002200BA
.text           C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateProcessW                              77661C01 5 Bytes  JMP 00220F41
.text           C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateProcessA                              77661C36 5 Bytes  JMP 00220F52
.text           C:\Windows\system32\svchost.exe[840] kernel32.dll!VirtualProtect                              77661DD1 5 Bytes  JMP 00220084
.text           C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateNamedPipeW                            77665C44 5 Bytes  JMP 00220036
.text           C:\Windows\system32\svchost.exe[840] kernel32.dll!LoadLibraryExW                              776830C3 5 Bytes  JMP 00220073
.text           C:\Windows\system32\svchost.exe[840] kernel32.dll!LoadLibraryW                                7768361F 5 Bytes  JMP 00220FCA
.text           C:\Windows\system32\svchost.exe[840] kernel32.dll!VirtualProtectEx                            77688D7E 5 Bytes  JMP 00220095
.text           C:\Windows\system32\svchost.exe[840] kernel32.dll!LoadLibraryExA                              77689469 5 Bytes  JMP 00220062
.text           C:\Windows\system32\svchost.exe[840] kernel32.dll!LoadLibraryA                                77689491 5 Bytes  JMP 00220051
.text           C:\Windows\system32\svchost.exe[840] kernel32.dll!CreatePipe                                  77690284 5 Bytes  JMP 00220F8F
.text           C:\Windows\system32\svchost.exe[840] kernel32.dll!GetProcAddress                              776AB8B6 5 Bytes  JMP 002200E9
.text           C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateFileW                                 776ACC4E 5 Bytes  JMP 0022000A
.text           C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateFileA                                 776ACF71 5 Bytes  JMP 00220FE5
.text           C:\Windows\system32\svchost.exe[840] kernel32.dll!CreateNamedPipeA                            776F41F6 5 Bytes  JMP 00220025
.text           C:\Windows\system32\svchost.exe[840] kernel32.dll!WinExec                                     776F53E7 5 Bytes  JMP 00220F63
.text           C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyExA                             774AB5E7 5 Bytes  JMP 0021002F
.text           C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyA                               774AB8AE 5 Bytes  JMP 00210FA8
.text           C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyA                                 774B0BF5 5 Bytes  JMP 00210FEF
.text           C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyW                               774BB83D 5 Bytes  JMP 00210F8D
.text           C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegCreateKeyExW                             774BBCE1 5 Bytes  JMP 00210F7C
.text           C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyExA                               774BD4E8 5 Bytes  JMP 0021000A
.text           C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyW                                 774C3CB0 5 Bytes  JMP 00210FD4
.text           C:\Windows\system32\svchost.exe[840] ADVAPI32.dll!RegOpenKeyExW                               774CF09D 5 Bytes  JMP 00210FC3
.text           C:\Windows\system32\svchost.exe[840] WS2_32.dll!socket                                        765236D1 5 Bytes  JMP 000E0000
.text           C:\Windows\system32\svchost.exe[916] kernel32.dll!GetStartupInfoW                             77661929 5 Bytes  JMP 00390F50
.text           C:\Windows\system32\svchost.exe[916] kernel32.dll!GetStartupInfoA                             776619C9 5 Bytes  JMP 00390096
.text           C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateProcessW                              77661C01 5 Bytes  JMP 00390F21
.text           C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateProcessA                              77661C36 5 Bytes  JMP 003900B8
.text           C:\Windows\system32\svchost.exe[916] kernel32.dll!VirtualProtect                              77661DD1 5 Bytes  JMP 00390F75
.text           C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateNamedPipeW                            77665C44 5 Bytes  JMP 00390FC3
.text           C:\Windows\system32\svchost.exe[916] kernel32.dll!LoadLibraryExW                              776830C3 5 Bytes  JMP 0039004F
.text           C:\Windows\system32\svchost.exe[916] kernel32.dll!LoadLibraryW                                7768361F 5 Bytes  JMP 00390F97
.text           C:\Windows\system32\svchost.exe[916] kernel32.dll!VirtualProtectEx                            77688D7E 5 Bytes  JMP 0039006A
.text           C:\Windows\system32\svchost.exe[916] kernel32.dll!LoadLibraryExA                              77689469 5 Bytes  JMP 00390F86
.text           C:\Windows\system32\svchost.exe[916] kernel32.dll!LoadLibraryA                                77689491 5 Bytes  JMP 00390FB2
.text           C:\Windows\system32\svchost.exe[916] kernel32.dll!CreatePipe                                  77690284 5 Bytes  JMP 00390085
.text           C:\Windows\system32\svchost.exe[916] kernel32.dll!GetProcAddress                              776AB8B6 5 Bytes  JMP 00390F10
.text           C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateFileW                                 776ACC4E 5 Bytes  JMP 00390FE5
.text           C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateFileA                                 776ACF71 5 Bytes  JMP 00390000
.text           C:\Windows\system32\svchost.exe[916] kernel32.dll!CreateNamedPipeA                            776F41F6 5 Bytes  JMP 00390FD4
.text           C:\Windows\system32\svchost.exe[916] kernel32.dll!WinExec                                     776F53E7 5 Bytes  JMP 003900A7
.text           C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegCreateKeyExA                             774AB5E7 5 Bytes  JMP 00300043
.text           C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegCreateKeyA                               774AB8AE 5 Bytes  JMP 00300014
.text           C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegOpenKeyA                                 774B0BF5 5 Bytes  JMP 00300FEF
.text           C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegCreateKeyW                               774BB83D 5 Bytes  JMP 00300F97
.text           C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegCreateKeyExW                             774BBCE1 5 Bytes  JMP 00300F86
.text           C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegOpenKeyExA                               774BD4E8 5 Bytes  JMP 00300FC3
.text           C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegOpenKeyW                                 774C3CB0 5 Bytes  JMP 00300FD4
.text           C:\Windows\system32\svchost.exe[916] ADVAPI32.dll!RegOpenKeyExW                               774CF09D 5 Bytes  JMP 00300FA8
.text           C:\Windows\system32\svchost.exe[916] WS2_32.dll!socket                                        765236D1 5 Bytes  JMP 002A0000
.text           C:\Windows\System32\svchost.exe[968] kernel32.dll!GetStartupInfoW                             77661929 5 Bytes  JMP 02210F77
.text           C:\Windows\System32\svchost.exe[968] kernel32.dll!GetStartupInfoA                             776619C9 5 Bytes  JMP 022100BD
.text           C:\Windows\System32\svchost.exe[968] kernel32.dll!CreateProcessW                              77661C01 5 Bytes  JMP 02210F37
.text           C:\Windows\System32\svchost.exe[968] kernel32.dll!CreateProcessA                              77661C36 5 Bytes  JMP 022100CE
.text           C:\Windows\System32\svchost.exe[968] kernel32.dll!VirtualProtect                              77661DD1 5 Bytes  JMP 02210087
.text           C:\Windows\System32\svchost.exe[968] kernel32.dll!CreateNamedPipeW                            77665C44 5 Bytes  JMP 02210FE5
.text           C:\Windows\System32\svchost.exe[968] kernel32.dll!LoadLibraryExW                              776830C3 5 Bytes  JMP 02210FAF
.text           C:\Windows\System32\svchost.exe[968] kernel32.dll!LoadLibraryW                                7768361F 5 Bytes  JMP 02210051
.text           C:\Windows\System32\svchost.exe[968] kernel32.dll!VirtualProtectEx                            77688D7E 5 Bytes  JMP 02210F92
.text           C:\Windows\System32\svchost.exe[968] kernel32.dll!LoadLibraryExA                              77689469 5 Bytes  JMP 0221006C
.text           C:\Windows\System32\svchost.exe[968] kernel32.dll!LoadLibraryA                                77689491 5 Bytes  JMP 02210FCA
.text           C:\Windows\System32\svchost.exe[968] kernel32.dll!CreatePipe                                  77690284 5 Bytes  JMP 022100A2
.text           C:\Windows\System32\svchost.exe[968] kernel32.dll!GetProcAddress                              776AB8B6 5 Bytes  JMP 022100E9
.text           C:\Windows\System32\svchost.exe[968] kernel32.dll!CreateFileW                                 776ACC4E 5 Bytes  JMP 02210025
.text           C:\Windows\System32\svchost.exe[968] kernel32.dll!CreateFileA                                 776ACF71 5 Bytes  JMP 02210000
.text           C:\Windows\System32\svchost.exe[968] kernel32.dll!CreateNamedPipeA                            776F41F6 5 Bytes  JMP 02210036
.text           C:\Windows\System32\svchost.exe[968] kernel32.dll!WinExec                                     776F53E7 5 Bytes  JMP 02210F52
.text           C:\Windows\System32\svchost.exe[968] ADVAPI32.dll!RegCreateKeyExA                             774AB5E7 5 Bytes  JMP 021C0047
.text           C:\Windows\System32\svchost.exe[968] ADVAPI32.dll!RegCreateKeyA                               774AB8AE 5 Bytes  JMP 021C0036
.text           C:\Windows\System32\svchost.exe[968] ADVAPI32.dll!RegOpenKeyA                                 774B0BF5 5 Bytes  JMP 021C000A
.text           C:\Windows\System32\svchost.exe[968] ADVAPI32.dll!RegCreateKeyW                               774BB83D 5 Bytes  JMP 021C0FA5
.text           C:\Windows\System32\svchost.exe[968] ADVAPI32.dll!RegCreateKeyExW                             774BBCE1 5 Bytes  JMP 021C0F94
.text           C:\Windows\System32\svchost.exe[968] ADVAPI32.dll!RegOpenKeyExA                               774BD4E8 5 Bytes  JMP 021C0FCA
.text           C:\Windows\System32\svchost.exe[968] ADVAPI32.dll!RegOpenKeyW                                 774C3CB0 5 Bytes  JMP 021C0FEF
.text           C:\Windows\System32\svchost.exe[968] ADVAPI32.dll!RegOpenKeyExW                               774CF09D 5 Bytes  JMP 021C001B
.text           C:\Windows\System32\svchost.exe[968] WS2_32.dll!socket                                        765236D1 5 Bytes  JMP 01440FE5
.text           C:\Windows\System32\svchost.exe[968] WININET.DLL!InternetOpenA                                760503DD 5 Bytes  JMP 01430FE5
.text           C:\Windows\System32\svchost.exe[968] WININET.DLL!InternetOpenUrlA                             760520A3 5 Bytes  JMP 01430FCA
.text           C:\Windows\System32\svchost.exe[968] WININET.DLL!InternetOpenW                                76052A58 5 Bytes  JMP 01430000
.text           C:\Windows\System32\svchost.exe[968] WININET.DLL!InternetOpenUrlW                             7609AF79 5 Bytes  JMP 01430025
.text           C:\Windows\System32\svchost.exe[1004] kernel32.dll!GetStartupInfoW                            77661929 5 Bytes  JMP 009D0F2B
.text           C:\Windows\System32\svchost.exe[1004] kernel32.dll!GetStartupInfoA                            776619C9 5 Bytes  JMP 009D0F46
.text           C:\Windows\System32\svchost.exe[1004] kernel32.dll!CreateProcessW                             77661C01 5 Bytes  JMP 009D00B8
.text           C:\Windows\System32\svchost.exe[1004] kernel32.dll!CreateProcessA                             77661C36 5 Bytes  JMP 009D00A7
.text           C:\Windows\System32\svchost.exe[1004] kernel32.dll!VirtualProtect                             77661DD1 5 Bytes  JMP 009D0F97
.text           C:\Windows\System32\svchost.exe[1004] kernel32.dll!CreateNamedPipeW                           77665C44 5 Bytes  JMP 009D0FD4
.text           C:\Windows\System32\svchost.exe[1004] kernel32.dll!LoadLibraryExW                             776830C3 5 Bytes  JMP 009D0065
.text           C:\Windows\System32\svchost.exe[1004] kernel32.dll!LoadLibraryW                               7768361F 5 Bytes  JMP 009D0FA8
.text           C:\Windows\System32\svchost.exe[1004] kernel32.dll!VirtualProtectEx                           77688D7E 5 Bytes  JMP 009D0F7C
.text           C:\Windows\System32\svchost.exe[1004] kernel32.dll!LoadLibraryExA                             77689469 5 Bytes  JMP 009D004A
.text           C:\Windows\System32\svchost.exe[1004] kernel32.dll!LoadLibraryA                               77689491 5 Bytes  JMP 009D0FB9
.text           C:\Windows\System32\svchost.exe[1004] kernel32.dll!CreatePipe                                 77690284 5 Bytes  JMP 009D0F57
.text           C:\Windows\System32\svchost.exe[1004] kernel32.dll!GetProcAddress                             776AB8B6 5 Bytes  JMP 009D0F06
.text           C:\Windows\System32\svchost.exe[1004] kernel32.dll!CreateFileW                                776ACC4E 5 Bytes  JMP 009D0FEF
.text           C:\Windows\System32\svchost.exe[1004] kernel32.dll!CreateFileA                                776ACF71 5 Bytes  JMP 009D0000
.text           C:\Windows\System32\svchost.exe[1004] kernel32.dll!CreateNamedPipeA                           776F41F6 5 Bytes  JMP 009D0025
.text           C:\Windows\System32\svchost.exe[1004] kernel32.dll!WinExec                                    776F53E7 5 Bytes  JMP 009D0096
.text           C:\Windows\System32\svchost.exe[1004] ADVAPI32.dll!RegCreateKeyExA                            774AB5E7 5 Bytes  JMP 009C0F86
.text           C:\Windows\System32\svchost.exe[1004] ADVAPI32.dll!RegCreateKeyA                              774AB8AE 1 Byte  [ E9 ]
.text           C:\Windows\System32\svchost.exe[1004] ADVAPI32.dll!RegCreateKeyA + 2                          774AB8B0 3 Bytes  [ 56, 51, 89 ]
.text           C:\Windows\System32\svchost.exe[1004] ADVAPI32.dll!RegOpenKeyA                                774B0BF5 5 Bytes  JMP 009C0FEF
.text           C:\Windows\System32\svchost.exe[1004] ADVAPI32.dll!RegCreateKeyW                              774BB83D 5 Bytes  JMP 009C0F97
.text           C:\Windows\System32\svchost.exe[1004] ADVAPI32.dll!RegCreateKeyExW                            774BBCE1 5 Bytes  JMP 009C0F6B
.text           C:\Windows\System32\svchost.exe[1004] ADVAPI32.dll!RegOpenKeyExA                              774BD4E8 5 Bytes  JMP 009C0014
.text           C:\Windows\System32\svchost.exe[1004] ADVAPI32.dll!RegOpenKeyW                                774C3CB0 5 Bytes  JMP 009C0FDE
.text           C:\Windows\System32\svchost.exe[1004] ADVAPI32.dll!RegOpenKeyExW                              774CF09D 5 Bytes  JMP 009C0FC3
.text           C:\Windows\System32\svchost.exe[1004] WS2_32.dll!socket                                       765236D1 5 Bytes  JMP 009A0000
.text           C:\Windows\System32\svchost.exe[1040] kernel32.dll!GetStartupInfoW                            77661929 5 Bytes  JMP 01070F33
.text           C:\Windows\System32\svchost.exe[1040] kernel32.dll!GetStartupInfoA                            776619C9 5 Bytes  JMP 0107006F
.text           C:\Windows\System32\svchost.exe[1040] kernel32.dll!CreateProcessW                             77661C01 5 Bytes  JMP 01070094
.text           C:\Windows\System32\svchost.exe[1040] kernel32.dll!CreateProcessA                             77661C36 5 Bytes  JMP 01070F07
.text           C:\Windows\System32\svchost.exe[1040] kernel32.dll!VirtualProtect                             77661DD1 5 Bytes  JMP 01070F66
.text           C:\Windows\System32\svchost.exe[1040] kernel32.dll!CreateNamedPipeW                           77665C44 5 Bytes  JMP 01070FD4
.text           C:\Windows\System32\svchost.exe[1040] kernel32.dll!LoadLibraryExW                             776830C3 5 Bytes  JMP 01070F8D
.text           C:\Windows\System32\svchost.exe[1040] kernel32.dll!LoadLibraryW                               7768361F 5 Bytes  JMP 01070FAF
.text           C:\Windows\System32\svchost.exe[1040] kernel32.dll!VirtualProtectEx                           77688D7E 5 Bytes  JMP 01070F55
.text           C:\Windows\System32\svchost.exe[1040] kernel32.dll!LoadLibraryExA                             77689469 5 Bytes  JMP 01070F9E
.text           C:\Windows\System32\svchost.exe[1040] kernel32.dll!LoadLibraryA                               77689491 5 Bytes  JMP 01070036
.text           C:\Windows\System32\svchost.exe[1040] kernel32.dll!CreatePipe                                 77690284 5 Bytes  JMP 01070F44
.text           C:\Windows\System32\svchost.exe[1040] kernel32.dll!GetProcAddress                             776AB8B6 5 Bytes  JMP 01070ED8
.text           C:\Windows\System32\svchost.exe[1040] kernel32.dll!CreateFileW                                776ACC4E 5 Bytes  JMP 01070FEF
.text           C:\Windows\System32\svchost.exe[1040] kernel32.dll!CreateFileA                                776ACF71 5 Bytes  JMP 01070000
.text           C:\Windows\System32\svchost.exe[1040] kernel32.dll!CreateNamedPipeA                           776F41F6 5 Bytes  JMP 01070025
.text           C:\Windows\System32\svchost.exe[1040] kernel32.dll!WinExec                                    776F53E7 5 Bytes  JMP 01070F18
.text           C:\Windows\System32\svchost.exe[1040] ADVAPI32.dll!RegCreateKeyExA                            774AB5E7 5 Bytes  JMP 01020065
.text           C:\Windows\System32\svchost.exe[1040] ADVAPI32.dll!RegCreateKeyA                              774AB8AE 5 Bytes  JMP 01020040
.text           C:\Windows\System32\svchost.exe[1040] ADVAPI32.dll!RegOpenKeyA                                774B0BF5 5 Bytes  JMP 01020FEF
.text           C:\Windows\System32\svchost.exe[1040] ADVAPI32.dll!RegCreateKeyW                              774BB83D 5 Bytes  JMP 01020FC3
.text           C:\Windows\System32\svchost.exe[1040] ADVAPI32.dll!RegCreateKeyExW                            774BBCE1 5 Bytes  JMP 01020FA8
.text           C:\Windows\System32\svchost.exe[1040] ADVAPI32.dll!RegOpenKeyExA                              774BD4E8 5 Bytes  JMP 01020025
.text           C:\Windows\System32\svchost.exe[1040] ADVAPI32.dll!RegOpenKeyW                                774C3CB0 5 Bytes  JMP 01020014
.text           C:\Windows\System32\svchost.exe[1040] ADVAPI32.dll!RegOpenKeyExW                              774CF09D 5 Bytes  JMP 01020FD4
.text           C:\Windows\System32\svchost.exe[1040] WS2_32.dll!socket                                       765236D1 5 Bytes  JMP 01000000
.text           C:\Windows\system32\svchost.exe[1056] kernel32.dll!GetStartupInfoW                            77661929 5 Bytes  JMP 00DF00C3
.text           C:\Windows\system32\svchost.exe[1056] kernel32.dll!GetStartupInfoA                            776619C9 5 Bytes  JMP 00DF00A8
.text           C:\Windows\system32\svchost.exe[1056] kernel32.dll!CreateProcessW                             77661C01 5 Bytes  JMP 00DF00EF
.text           C:\Windows\system32\svchost.exe[1056] kernel32.dll!CreateProcessA                             77661C36 5 Bytes  JMP 00DF00DE
.text           C:\Windows\system32\svchost.exe[1056] kernel32.dll!VirtualProtect                             77661DD1 5 Bytes  JMP 00DF0F9B
.text           C:\Windows\system32\svchost.exe[1056] kernel32.dll!CreateNamedPipeW                           77665C44 5 Bytes  JMP 00DF0FC0
.text           C:\Windows\system32\svchost.exe[1056] kernel32.dll!LoadLibraryExW                             776830C3 5 Bytes  JMP 00DF0075
.text           C:\Windows\system32\svchost.exe[1056] kernel32.dll!LoadLibraryW                               7768361F 5 Bytes  JMP 00DF003D
.text           C:\Windows\system32\svchost.exe[1056] kernel32.dll!VirtualProtectEx                           77688D7E 5 Bytes  JMP 00DF0086
.text           C:\Windows\system32\svchost.exe[1056] kernel32.dll!LoadLibraryExA                             77689469 5 Bytes  JMP 00DF0058
.text           C:\Windows\system32\svchost.exe[1056] kernel32.dll!LoadLibraryA                               77689491 5 Bytes  JMP 00DF002C
.text           C:\Windows\system32\svchost.exe[1056] kernel32.dll!CreatePipe                                 77690284 5 Bytes  JMP 00DF0097
.text           C:\Windows\system32\svchost.exe[1056] kernel32.dll!GetProcAddress                             776AB8B6 5 Bytes  JMP 00DF0100
.text           C:\Windows\system32\svchost.exe[1056] kernel32.dll!CreateFileW                                776ACC4E 5 Bytes  JMP 00DF0011
.text           C:\Windows\system32\svchost.exe[1056] kernel32.dll!CreateFileA                                776ACF71 5 Bytes  JMP 00DF0000
.text           C:\Windows\system32\svchost.exe[1056] kernel32.dll!CreateNamedPipeA                           776F41F6 5 Bytes  JMP 00DF0FDB
.text           C:\Windows\system32\svchost.exe[1056] kernel32.dll!WinExec                                    776F53E7 5 Bytes  JMP 00DF0F6C
.text           C:\Windows\system32\svchost.exe[1056] ADVAPI32.dll!RegCreateKeyExA                            774AB5E7 5 Bytes  JMP 00DA003D
.text           C:\Windows\system32\svchost.exe[1056] ADVAPI32.dll!RegCreateKeyA                              774AB8AE 5 Bytes  JMP 00DA001B
.text           C:\Windows\system32\svchost.exe[1056] ADVAPI32.dll!RegOpenKeyA                                774B0BF5 5 Bytes  JMP 00DA0FEF
.text           C:\Windows\system32\svchost.exe[1056] ADVAPI32.dll!RegCreateKeyW                              774BB83D 5 Bytes  JMP 00DA002C
.text           C:\Windows\system32\svchost.exe[1056] ADVAPI32.dll!RegCreateKeyExW                            774BBCE1 5 Bytes  JMP 00DA0F80
.text           C:\Windows\system32\svchost.exe[1056] ADVAPI32.dll!RegOpenKeyExA                              774BD4E8 5 Bytes  JMP 00DA0FAF
.text           C:\Windows\system32\svchost.exe[1056] ADVAPI32.dll!RegOpenKeyW                                774C3CB0 5 Bytes  JMP 00DA0FCA
.text           C:\Windows\system32\svchost.exe[1056] ADVAPI32.dll!RegOpenKeyExW                              774CF09D 5 Bytes  JMP 00DA0000
.text           C:\Windows\system32\svchost.exe[1056] WS2_32.dll!socket                                       765236D1 5 Bytes  JMP 00D00000
.text           C:\Windows\system32\svchost.exe[1160] kernel32.dll!GetStartupInfoW                            77661929 5 Bytes  JMP 001700A0
.text           C:\Windows\system32\svchost.exe[1160] kernel32.dll!GetStartupInfoA                            776619C9 5 Bytes  JMP 00170F50
.text           C:\Windows\system32\svchost.exe[1160] kernel32.dll!CreateProcessW                             77661C01 5 Bytes  JMP 00170F1A
.text           C:\Windows\system32\svchost.exe[1160] kernel32.dll!CreateProcessA                             77661C36 5 Bytes  JMP 001700B1
.text           C:\Windows\system32\svchost.exe[1160] kernel32.dll!VirtualProtect                             77661DD1 5 Bytes  JMP 0017004C
.text           C:\Windows\system32\svchost.exe[1160] kernel32.dll!CreateNamedPipeW                           77665C44 5 Bytes  JMP 00170FCA
.text           C:\Windows\system32\svchost.exe[1160] kernel32.dll!LoadLibraryExW                             776830C3 5 Bytes  JMP 00170F72
.text           C:\Windows\system32\svchost.exe[1160] kernel32.dll!LoadLibraryW                               7768361F 5 Bytes  JMP 00170F9E
.text           C:\Windows\system32\svchost.exe[1160] kernel32.dll!VirtualProtectEx                           77688D7E 5 Bytes  JMP 00170F61
.text           C:\Windows\system32\svchost.exe[1160] kernel32.dll!LoadLibraryExA                             77689469 5 Bytes  JMP 00170F8D
.text           C:\Windows\system32\svchost.exe[1160] kernel32.dll!LoadLibraryA                               77689491 5 Bytes  JMP 00170FB9
.text           C:\Windows\system32\svchost.exe[1160] kernel32.dll!CreatePipe                                 77690284 5 Bytes  JMP 00170071
.text           C:\Windows\system32\svchost.exe[1160] kernel32.dll!GetProcAddress                             776AB8B6 5 Bytes  JMP 001700D6
.text           C:\Windows\system32\svchost.exe[1160] kernel32.dll!CreateFileW                                776ACC4E 5 Bytes  JMP 00170FE5
.text           C:\Windows\system32\svchost.exe[1160] kernel32.dll!CreateFileA                                776ACF71 5 Bytes  JMP 00170000
.text           C:\Windows\system32\svchost.exe[1160] kernel32.dll!CreateNamedPipeA                           776F41F6 5 Bytes  JMP 00170011
.text           C:\Windows\system32\svchost.exe[1160] kernel32.dll!WinExec                                    776F53E7 5 Bytes  JMP 00170F35
.text           C:\Windows\system32\svchost.exe[1160] ADVAPI32.dll!RegCreateKeyExA                            774AB5E7 5 Bytes  JMP 00160043
.text           C:\Windows\system32\svchost.exe[1160] ADVAPI32.dll!RegCreateKeyA                              774AB8AE 1 Byte  [ E9 ]
.text           C:\Windows\system32\svchost.exe[1160] ADVAPI32.dll!RegCreateKeyA + 2                          774AB8B0 3 Bytes  [ 56, CB, 88 ]
.text           C:\Windows\system32\svchost.exe[1160] ADVAPI32.dll!RegOpenKeyA                                774B0BF5 5 Bytes  JMP 00160FE5
.text           C:\Windows\system32\svchost.exe[1160] ADVAPI32.dll!RegCreateKeyW                              774BB83D 5 Bytes  JMP 00160F97
.text           C:\Windows\system32\svchost.exe[1160] ADVAPI32.dll!RegCreateKeyExW                            774BBCE1 5 Bytes  JMP 00160054
.text           C:\Windows\system32\svchost.exe[1160] ADVAPI32.dll!RegOpenKeyExA                              774BD4E8 5 Bytes  JMP 00160FC3
.text           C:\Windows\system32\svchost.exe[1160] ADVAPI32.dll!RegOpenKeyW                                774C3CB0 5 Bytes  JMP 00160FD4
.text           C:\Windows\system32\svchost.exe[1160] ADVAPI32.dll!RegOpenKeyExW                              774CF09D 5 Bytes  JMP 0016001E
.text           C:\Windows\system32\svchost.exe[1160] WS2_32.dll!socket                                       765236D1 5 Bytes  JMP 0014000A
.text           C:\Windows\system32\svchost.exe[1220] kernel32.dll!GetStartupInfoW                            77661929 5 Bytes  JMP 00CA0F90
.text           C:\Windows\system32\svchost.exe[1220] kernel32.dll!GetStartupInfoA                            776619C9 5 Bytes  JMP 00CA00CC
.text           C:\Windows\system32\svchost.exe[1220] kernel32.dll!CreateProcessW                             77661C01 5 Bytes  JMP 00CA00FB
.text           C:\Windows\system32\svchost.exe[1220] kernel32.dll!CreateProcessA                             77661C36 5 Bytes  JMP 00CA0F64
.text           C:\Windows\system32\svchost.exe[1220] kernel32.dll!VirtualProtect                             77661DD1 5 Bytes  JMP 00CA0FA1
.text           C:\Windows\system32\svchost.exe[1220] kernel32.dll!CreateNamedPipeW                           77665C44 5 Bytes  JMP 00CA002F
.text           C:\Windows\system32\svchost.exe[1220] kernel32.dll!LoadLibraryExW                             776830C3 5 Bytes  JMP 00CA0FB2
.text           C:\Windows\system32\svchost.exe[1220] kernel32.dll!LoadLibraryW                               7768361F 5 Bytes  JMP 00CA005E
.text           C:\Windows\system32\svchost.exe[1220] kernel32.dll!VirtualProtectEx                           77688D7E 5 Bytes  JMP 00CA0096
.text           C:\Windows\system32\svchost.exe[1220] kernel32.dll!LoadLibraryExA                             77689469 5 Bytes  JMP 00CA006F
.text           C:\Windows\system32\svchost.exe[1220] kernel32.dll!LoadLibraryA                               77689491 5 Bytes  JMP 00CA0FCD
.text           C:\Windows\system32\svchost.exe[1220] kernel32.dll!CreatePipe                                 77690284 5 Bytes  JMP 00CA00B1
.text           C:\Windows\system32\svchost.exe[1220] kernel32.dll!GetProcAddress                             776AB8B6 5 Bytes  JMP 00CA0F49
.text           C:\Windows\system32\svchost.exe[1220] kernel32.dll!CreateFileW                                776ACC4E 5 Bytes  JMP 00CA0014
.text           C:\Windows\system32\svchost.exe[1220] kernel32.dll!CreateFileA                                776ACF71 5 Bytes  JMP 00CA0FEF
.text           C:\Windows\system32\svchost.exe[1220] kernel32.dll!CreateNamedPipeA                           776F41F6 5 Bytes  JMP 00CA0FDE
.text           C:\Windows\system32\svchost.exe[1220] kernel32.dll!WinExec                                    776F53E7 5 Bytes  JMP 00CA0F7F
.text           C:\Windows\system32\svchost.exe[1220] ADVAPI32.dll!RegCreateKeyExA                            774AB5E7 5 Bytes  JMP 00C10F83
.text           C:\Windows\system32\svchost.exe[1220] ADVAPI32.dll!RegCreateKeyA                              774AB8AE 5 Bytes  JMP 00C1001B
.text           C:\Windows\system32\svchost.exe[1220] ADVAPI32.dll!RegOpenKeyA                                774B0BF5 5 Bytes  JMP 00C10FEF
.text           C:\Windows\system32\svchost.exe[1220] ADVAPI32.dll!RegCreateKeyW                              774BB83D 5 Bytes  JMP 00C10F94
.text           C:\Windows\system32\svchost.exe[1220] ADVAPI32.dll!RegCreateKeyExW                            774BBCE1 5 Bytes  JMP 00C10036
.text           C:\Windows\system32\svchost.exe[1220] ADVAPI32.dll!RegOpenKeyExA                              774BD4E8 5 Bytes  JMP 00C1000A
.text           C:\Windows\system32\svchost.exe[1220] ADVAPI32.dll!RegOpenKeyW                                774C3CB0 5 Bytes  JMP 00C10FD4
.text           C:\Windows\system32\svchost.exe[1220] ADVAPI32.dll!RegOpenKeyExW                              774CF09D 5 Bytes  JMP 00C10FB9
.text           C:\Windows\system32\svchost.exe[1220] WS2_32.dll!socket                                       765236D1 5 Bytes  JMP 009C0FEF
.text           C:\Windows\system32\svchost.exe[1220] WinInet.dll!InternetOpenA                               760503DD 5 Bytes  JMP 00320000
.text           C:\Windows\system32\svchost.exe[1220] WinInet.dll!InternetOpenUrlA                            760520A3 5 Bytes  JMP 00320FD4
.text           C:\Windows\system32\svchost.exe[1220] WinInet.dll!InternetOpenW                               76052A58 5 Bytes  JMP 00320FE5
.text           C:\Windows\system32\svchost.exe[1220] WinInet.dll!InternetOpenUrlW                            7609AF79 5 Bytes  JMP 00320FC3
.text           C:\Windows\system32\svchost.exe[1400] kernel32.dll!GetStartupInfoW                            77661929 5 Bytes  JMP 00CD00D7
.text           C:\Windows\system32\svchost.exe[1400] kernel32.dll!GetStartupInfoA                            776619C9 5 Bytes  JMP 00CD00BC
.text           C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreateProcessW                             77661C01 5 Bytes  JMP 00CD010D
.text           C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreateProcessA                             77661C36 5 Bytes  JMP 00CD0F76
.text           C:\Windows\system32\svchost.exe[1400] kernel32.dll!VirtualProtect                             77661DD1 5 Bytes  JMP 00CD007F
.text           C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreateNamedPipeW                           77665C44 5 Bytes  JMP 00CD0FCA
.text           C:\Windows\system32\svchost.exe[1400] kernel32.dll!LoadLibraryExW                             776830C3 5 Bytes  JMP 00CD006E
.text           C:\Windows\system32\svchost.exe[1400] kernel32.dll!LoadLibraryW                               7768361F 5 Bytes  JMP 00CD0FAF
.text           C:\Windows\system32\svchost.exe[1400] kernel32.dll!VirtualProtectEx                           77688D7E 5 Bytes  JMP 00CD0090
.text           C:\Windows\system32\svchost.exe[1400] kernel32.dll!LoadLibraryExA                             77689469 5 Bytes  JMP 00CD0051
.text           C:\Windows\system32\svchost.exe[1400] kernel32.dll!LoadLibraryA                               77689491 5 Bytes  JMP 00CD0036
.text           C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreatePipe                                 77690284 5 Bytes  JMP 00CD00AB
.text           C:\Windows\system32\svchost.exe[1400] kernel32.dll!GetProcAddress                             776AB8B6 5 Bytes  JMP 00CD0F5B
.text           C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreateFileW                                776ACC4E 5 Bytes  JMP 00CD0011
.text           C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreateFileA                                776ACF71 5 Bytes  JMP 00CD0000
.text           C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreateNamedPipeA                           776F41F6 5 Bytes  JMP 00CD0FDB
.text           C:\Windows\system32\svchost.exe[1400] kernel32.dll!WinExec                                    776F53E7 5 Bytes  JMP 00CD00F2
.text           C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyExA                            774AB5E7 5 Bytes  JMP 00CC0F8A
.text           C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyA                              774AB8AE 5 Bytes  JMP 00CC002C
.text           C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyA                                774B0BF5 5 Bytes  JMP 00CC0FEF
.text           C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyW                              774BB83D 5 Bytes  JMP 00CC0FA5
.text           C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyExW                            774BBCE1 5 Bytes  JMP 00CC0047
.text           C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyExA                              774BD4E8 5 Bytes  JMP 00CC001B
.text           C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyW                                774C3CB0 5 Bytes  JMP 00CC000A
.text           C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyExW                              774CF09D 5 Bytes  JMP 00CC0FCA
.text           C:\Windows\system32\svchost.exe[1400] WS2_32.dll!socket                                       765236D1 5 Bytes  JMP 0091000A
.text           C:\Windows\system32\svchost.exe[1664] kernel32.dll!GetStartupInfoW                            77661929 5 Bytes  JMP 00CD00C7
.text           C:\Windows\system32\svchost.exe[1664] kernel32.dll!GetStartupInfoA                            776619C9 5 Bytes  JMP 00CD00A2
.text           C:\Windows\system32\svchost.exe[1664] kernel32.dll!CreateProcessW                             77661C01 5 Bytes  JMP 00CD0F41
.text           C:\Windows\system32\svchost.exe[1664] kernel32.dll!CreateProcessA                             77661C36 5 Bytes  JMP 00CD0F5C
.text           C:\Windows\system32\svchost.exe[1664] kernel32.dll!VirtualProtect                             77661DD1 5 Bytes  JMP 00CD0FA3
.text           C:\Windows\system32\svchost.exe[1664] kernel32.dll!CreateNamedPipeW                           77665C44 5 Bytes  JMP 00CD0FCA
.text           C:\Windows\system32\svchost.exe[1664] kernel32.dll!LoadLibraryExW                             776830C3 5 Bytes  JMP 00CD007D
.text           C:\Windows\system32\svchost.exe[1664] kernel32.dll!LoadLibraryW                               7768361F 5 Bytes  JMP 00CD0051
.text           C:\Windows\system32\svchost.exe[1664] kernel32.dll!VirtualProtectEx                           77688D7E 5 Bytes  JMP 00CD0F88
.text           C:\Windows\system32\svchost.exe[1664] kernel32.dll!LoadLibraryExA                             77689469 5 Bytes  JMP 00CD0062
.text           C:\Windows\system32\svchost.exe[1664] kernel32.dll!LoadLibraryA                               77689491 5 Bytes  JMP 00CD0036
.text           C:\Windows\system32\svchost.exe[1664] kernel32.dll!CreatePipe                                 77690284 5 Bytes  JMP 00CD0F77
.text           C:\Windows\system32\svchost.exe[1664] kernel32.dll!GetProcAddress                             776AB8B6 5 Bytes  JMP 00CD0F30
.text           C:\Windows\system32\svchost.exe[1664] kernel32.dll!CreateFileW                                776ACC4E 5 Bytes  JMP 00CD0FE5
.text           C:\Windows\system32\svchost.exe[1664] kernel32.dll!CreateFileA                                776ACF71 5 Bytes  JMP 00CD0000
.text           C:\Windows\system32\svchost.exe[1664] kernel32.dll!CreateNamedPipeA                           776F41F6 5 Bytes  JMP 00CD0011
.text           C:\Windows\system32\svchost.exe[1664] kernel32.dll!WinExec                                    776F53E7 5 Bytes  JMP 00CD00D8
.text           C:\Windows\system32\svchost.exe[1664] ADVAPI32.dll!RegCreateKeyExA                            774AB5E7 5 Bytes  JMP 00CC004A
.text           C:\Windows\system32\svchost.exe[1664] ADVAPI32.dll!RegCreateKeyA                              774AB8AE 5 Bytes  JMP 00CC0FC3
.text           C:\Windows\system32\svchost.exe[1664] ADVAPI32.dll!RegOpenKeyA                                774B0BF5 5 Bytes  JMP 00CC000A
.text           C:\Windows\system32\svchost.exe[1664] ADVAPI32.dll!RegCreateKeyW                              774BB83D 5 Bytes  JMP 00CC0FB2
.text           C:\Windows\system32\svchost.exe[1664] ADVAPI32.dll!RegCreateKeyExW                            774BBCE1 5 Bytes  JMP 00CC0F83
.text           C:\Windows\system32\svchost.exe[1664] ADVAPI32.dll!RegOpenKeyExA                              774BD4E8 5 Bytes  JMP 00CC0FEF
.text           C:\Windows\system32\svchost.exe[1664] ADVAPI32.dll!RegOpenKeyW                                774C3CB0 5 Bytes  JMP 00CC0025
.text           C:\Windows\system32\svchost.exe[1664] ADVAPI32.dll!RegOpenKeyExW                              774CF09D 5 Bytes  JMP 00CC0FDE
.text           C:\Windows\system32\svchost.exe[1664] WS2_32.dll!socket                                       765236D1 5 Bytes  JMP 00790000
.text           c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2160] kernel32.dll!LoadLibraryW               7768361F 5 Bytes  JMP 0041C1F0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text           c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2160] kernel32.dll!LoadLibraryA               77689491 5 Bytes  JMP 0041C170 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text           C:\Windows\system32\svchost.exe[2648] kernel32.dll!GetStartupInfoW                            77661929 5 Bytes  JMP 00C400D0
.text           C:\Windows\system32\svchost.exe[2648] kernel32.dll!GetStartupInfoA                            776619C9 5 Bytes  JMP 00C400BF
.text           C:\Windows\system32\svchost.exe[2648] kernel32.dll!CreateProcessW                             77661C01 5 Bytes  JMP 00C40106
.text           C:\Windows\system32\svchost.exe[2648] kernel32.dll!CreateProcessA                             77661C36 5 Bytes  JMP 00C40F6F
.text           C:\Windows\system32\svchost.exe[2648] kernel32.dll!VirtualProtect                             77661DD1 5 Bytes  JMP 00C4009D
.text           C:\Windows\system32\svchost.exe[2648] kernel32.dll!CreateNamedPipeW                           77665C44 5 Bytes  JMP 00C4004A
.text           C:\Windows\system32\svchost.exe[2648] kernel32.dll!LoadLibraryExW                             776830C3 5 Bytes  JMP 00C40FC3
.text           C:\Windows\system32\svchost.exe[2648] kernel32.dll!LoadLibraryW                               7768361F 5 Bytes  JMP 00C40065
.text           C:\Windows\system32\svchost.exe[2648] kernel32.dll!VirtualProtectEx                           77688D7E 5 Bytes  JMP 00C400AE
.text           C:\Windows\system32\svchost.exe[2648] kernel32.dll!LoadLibraryExA                             77689469 5 Bytes  JMP 00C40080
.text           C:\Windows\system32\svchost.exe[2648] kernel32.dll!LoadLibraryA                               77689491 5 Bytes  JMP 00C40FDE
.text           C:\Windows\system32\svchost.exe[2648] kernel32.dll!CreatePipe                                 77690284 5 Bytes  JMP 00C40F9E
.text           C:\Windows\system32\svchost.exe[2648] kernel32.dll!GetProcAddress                             776AB8B6 5 Bytes  JMP 00C40121
.text           C:\Windows\system32\svchost.exe[2648] kernel32.dll!CreateFileW                                776ACC4E 5 Bytes  JMP 00C40FEF
.text           C:\Windows\system32\svchost.exe[2648] kernel32.dll!CreateFileA                                776ACF71 5 Bytes  JMP 00C4000A
.text           C:\Windows\system32\svchost.exe[2648] kernel32.dll!CreateNamedPipeA                           776F41F6 5 Bytes  JMP 00C4002F
.text           C:\Windows\system32\svchost.exe[2648] kernel32.dll!WinExec                                    776F53E7 5 Bytes  JMP 00C400F5
.text           C:\Windows\system32\svchost.exe[2648] ADVAPI32.dll!RegCreateKeyExA                            774AB5E7 5 Bytes  JMP 00C30062
.text           C:\Windows\system32\svchost.exe[2648] ADVAPI32.dll!RegCreateKeyA                              774AB8AE 5 Bytes  JMP 00C30036
.text           C:\Windows\system32\svchost.exe[2648] ADVAPI32.dll!RegOpenKeyA                                774B0BF5 5 Bytes  JMP 00C30000
.text           C:\Windows\system32\svchost.exe[2648] ADVAPI32.dll!RegCreateKeyW                              774BB83D 5 Bytes  JMP 00C30051
.text           C:\Windows\system32\svchost.exe[2648] ADVAPI32.dll!RegCreateKeyExW                            774BBCE1 5 Bytes  JMP 00C30FA5
.text           C:\Windows\system32\svchost.exe[2648] ADVAPI32.dll!RegOpenKeyExA                              774BD4E8 5 Bytes  JMP 00C30FD4
.text           C:\Windows\system32\svchost.exe[2648] ADVAPI32.dll!RegOpenKeyW                                774C3CB0 5 Bytes  JMP 00C30FE5
.text           C:\Windows\system32\svchost.exe[2648] ADVAPI32.dll!RegOpenKeyExW                              774CF09D 5 Bytes  JMP 00C30025
.text           C:\Windows\system32\svchost.exe[2648] WS2_32.dll!socket                                       765236D1 5 Bytes  JMP 00C10000
.text           C:\Windows\system32\svchost.exe[2976] kernel32.dll!GetStartupInfoW                            77661929 5 Bytes  JMP 008C00C9
.text           C:\Windows\system32\svchost.exe[2976] kernel32.dll!GetStartupInfoA                            776619C9 5 Bytes  JMP 008C00AE
.text           C:\Windows\system32\svchost.exe[2976] kernel32.dll!CreateProcessW                             77661C01 5 Bytes  JMP 008C00EE
.text           C:\Windows\system32\svchost.exe[2976] kernel32.dll!CreateProcessA                             77661C36 5 Bytes  JMP 008C0F4D
.text           C:\Windows\system32\svchost.exe[2976] kernel32.dll!VirtualProtect                             77661DD1 5 Bytes  JMP 008C0F8D
.text           C:\Windows\system32\svchost.exe[2976] kernel32.dll!CreateNamedPipeW                           77665C44 5 Bytes  JMP 008C0FCA
.text           C:\Windows\system32\svchost.exe[2976] kernel32.dll!LoadLibraryExW                             776830C3 5 Bytes  JMP 008C0F9E
.text           C:\Windows\system32\svchost.exe[2976] kernel32.dll!LoadLibraryW                               7768361F 5 Bytes  JMP 008C0051
.text           C:\Windows\system32\svchost.exe[2976] kernel32.dll!VirtualProtectEx                           77688D7E 5 Bytes  JMP 008C008C
.text           C:\Windows\system32\svchost.exe[2976] kernel32.dll!LoadLibraryExA                             77689469 5 Bytes  JMP 008C0FAF
.text           C:\Windows\system32\svchost.exe[2976] kernel32.dll!LoadLibraryA                               77689491 5 Bytes  JMP 008C0036
.text           C:\Windows\system32\svchost.exe[2976] kernel32.dll!CreatePipe                                 77690284 5 Bytes  JMP 008C009D
.text           C:\Windows\system32\svchost.exe[2976] kernel32.dll!GetProcAddress                             776AB8B6 5 Bytes  JMP 008C0109
.text           C:\Windows\system32\svchost.exe[2976] kernel32.dll!CreateFileW                                776ACC4E 5 Bytes  JMP 008C0011
.text           C:\Windows\system32\svchost.exe[2976] kernel32.dll!CreateFileA                                776ACF71 5 Bytes  JMP 008C0000
.text           C:\Windows\system32\svchost.exe[2976] kernel32.dll!CreateNamedPipeA                           776F41F6 5 Bytes  JMP 008C0FDB
.text           C:\Windows\system32\svchost.exe[2976] kernel32.dll!WinExec                                    776F53E7 5 Bytes  JMP 008C0F68
.text           C:\Windows\system32\svchost.exe[2976] ADVAPI32.dll!RegCreateKeyExA                            774AB5E7 5 Bytes  JMP 008A005F
.text           C:\Windows\system32\svchost.exe[2976] ADVAPI32.dll!RegCreateKeyA                              774AB8AE 5 Bytes  JMP 008A0044
.text           C:\Windows\system32\svchost.exe[2976] ADVAPI32.dll!RegOpenKeyA                                774B0BF5 5 Bytes  JMP 008A0000
.text           C:\Windows\system32\svchost.exe[2976] ADVAPI32.dll!RegCreateKeyW                              774BB83D 5 Bytes  JMP 008A0FBD
.text           C:\Windows\system32\svchost.exe[2976] ADVAPI32.dll!RegCreateKeyExW                            774BBCE1 5 Bytes  JMP 008A0070
.text           C:\Windows\system32\svchost.exe[2976] ADVAPI32.dll!RegOpenKeyExA                              774BD4E8 5 Bytes  JMP 008A0022
.text           C:\Windows\system32\svchost.exe[2976] ADVAPI32.dll!RegOpenKeyW                                774C3CB0 5 Bytes  JMP 008A0011
.text           C:\Windows\system32\svchost.exe[2976] ADVAPI32.dll!RegOpenKeyExW                              774CF09D 5 Bytes  JMP 008A0033
.text           C:\Windows\system32\svchost.exe[2976] WS2_32.dll!socket                                       765236D1 5 Bytes  JMP 00880FEF
.text           C:\Program Files\McAfee\MQC\McpAdmin.exe[2992] USER32.dll!MessageBoxW                         7615D667 6 Bytes  JMP 00405910 C:\Program Files\McAfee\MQC\McpAdmin.exe (McAfee McpAdmin DLL/McAfee, Inc.)
.text           C:\Windows\System32\svchost.exe[3036] kernel32.dll!GetStartupInfoW                            77661929 5 Bytes  JMP 0018008C
.text           C:\Windows\System32\svchost.exe[3036] kernel32.dll!GetStartupInfoA                            776619C9 5 Bytes  JMP 00180F46
.text           C:\Windows\System32\svchost.exe[3036] kernel32.dll!CreateProcessW                             77661C01 5 Bytes  JMP 001800CC
.text           C:\Windows\System32\svchost.exe[3036] kernel32.dll!CreateProcessA                             77661C36 5 Bytes  JMP 00180F2B
.text           C:\Windows\System32\svchost.exe[3036] kernel32.dll!VirtualProtect                             77661DD1 5 Bytes  JMP 00180056
.text           C:\Windows\System32\svchost.exe[3036] kernel32.dll!CreateNamedPipeW                           77665C44 5 Bytes  JMP 00180FB9
.text           C:\Windows\System32\svchost.exe[3036] kernel32.dll!LoadLibraryExW                             776830C3 5 Bytes  JMP 00180045
.text           C:\Windows\System32\svchost.exe[3036] kernel32.dll!LoadLibraryW                               7768361F 5 Bytes  JMP 00180F97
.text           C:\Windows\System32\svchost.exe[3036] kernel32.dll!VirtualProtectEx                           77688D7E 5 Bytes  JMP 00180071
.text           C:\Windows\System32\svchost.exe[3036] kernel32.dll!LoadLibraryExA                             77689469 5 Bytes  JMP 00180F7C
.text           C:\Windows\System32\svchost.exe[3036] kernel32.dll!LoadLibraryA                               77689491 5 Bytes  JMP 00180FA8
.text           C:\Windows\System32\svchost.exe[3036] kernel32.dll!CreatePipe                                 77690284 5 Bytes  JMP 00180F61
.text           C:\Windows\System32\svchost.exe[3036] kernel32.dll!GetProcAddress                             776AB8B6 5 Bytes  JMP 001800E7
.text           C:\Windows\System32\svchost.exe[3036] kernel32.dll!CreateFileW                                776ACC4E 5 Bytes  JMP 00180FE5
.text           C:\Windows\System32\svchost.exe[3036] kernel32.dll!CreateFileA                                776ACF71 5 Bytes  JMP 0018000A
.text           C:\Windows\System32\svchost.exe[3036] kernel32.dll!CreateNamedPipeA                           776F41F6 5 Bytes  JMP 00180FD4
.text           C:\Windows\System32\svchost.exe[3036] kernel32.dll!WinExec                                    776F53E7 5 Bytes  JMP 0018009D
.text           C:\Windows\System32\svchost.exe[3036] ADVAPI32.dll!RegCreateKeyExA                            774AB5E7 5 Bytes  JMP 00070F9E
.text           C:\Windows\System32\svchost.exe[3036] ADVAPI32.dll!RegCreateKeyA                              774AB8AE 5 Bytes  JMP 00070FAF
.text           C:\Windows\System32\svchost.exe[3036] ADVAPI32.dll!RegOpenKeyA                                774B0BF5 5 Bytes  JMP 00070000
.text           C:\Windows\System32\svchost.exe[3036] ADVAPI32.dll!RegCreateKeyW                              774BB83D 5 Bytes  JMP 00070040
.text           C:\Windows\System32\svchost.exe[3036] ADVAPI32.dll!RegCreateKeyExW                            774BBCE1 5 Bytes  JMP 0007005B
.text           C:\Windows\System32\svchost.exe[3036] ADVAPI32.dll!RegOpenKeyExA                              774BD4E8 5 Bytes  JMP 00070FE5
.text           C:\Windows\System32\svchost.exe[3036] ADVAPI32.dll!RegOpenKeyW                                774C3CB0 5 Bytes  JMP 0007001B
.text           C:\Windows\System32\svchost.exe[3036] ADVAPI32.dll!RegOpenKeyExW                              774CF09D 5 Bytes  JMP 00070FD4
.text           C:\Windows\System32\svchost.exe[3036] WS2_32.dll!socket                                       765236D1 5 Bytes  JMP 005E0FEF
.text           C:\Windows\Explorer.EXE[4080] kernel32.dll!GetStartupInfoW                                    77661929 5 Bytes  JMP 00010F10
.text           C:\Windows\Explorer.EXE[4080] kernel32.dll!GetStartupInfoA                                    776619C9 5 Bytes  JMP 00010F35
.text           C:\Windows\Explorer.EXE[4080] kernel32.dll!CreateProcessW                                     77661C01 5 Bytes  JMP 00010EE4
.text           C:\Windows\Explorer.EXE[4080] kernel32.dll!CreateProcessA                                     77661C36 5 Bytes  JMP 0001007B
.text           C:\Windows\Explorer.EXE[4080] kernel32.dll!VirtualProtect                                     77661DD1 5 Bytes  JMP 00010F6B
.text           C:\Windows\Explorer.EXE[4080] kernel32.dll!CreateNamedPipeW                                   77665C44 5 Bytes  JMP 00010FB9
.text           C:\Windows\Explorer.EXE[4080] kernel32.dll!LoadLibraryExW                                     776830C3 5 Bytes  JMP 00010F7C
.text           C:\Windows\Explorer.EXE[4080] kernel32.dll!LoadLibraryW                                       7768361F 5 Bytes  JMP 00010FA8
.text           C:\Windows\Explorer.EXE[4080] kernel32.dll!VirtualProtectEx                                   77688D7E 5 Bytes  JMP 00010060
.text           C:\Windows\Explorer.EXE[4080] kernel32.dll!LoadLibraryExA                                     77689469 5 Bytes  JMP 00010F97
.text           C:\Windows\Explorer.EXE[4080] kernel32.dll!LoadLibraryA                                       77689491 5 Bytes  JMP 0001002F
.text           C:\Windows\Explorer.EXE[4080] kernel32.dll!CreatePipe                                         77690284 5 Bytes  JMP 00010F46
.text           C:\Windows\Explorer.EXE[4080] kernel32.dll!GetProcAddress                                     776AB8B6 5 Bytes  JMP 0001008C
.text           C:\Windows\Explorer.EXE[4080] kernel32.dll!CreateFileW                                        776ACC4E 5 Bytes  JMP 00010FDE
.text           C:\Windows\Explorer.EXE[4080] kernel32.dll!CreateFileA                                        776ACF71 5 Bytes  JMP 00010FEF
.text           C:\Windows\Explorer.EXE[4080] kernel32.dll!CreateNamedPipeA                                   776F41F6 5 Bytes  JMP 00010014
.text           C:\Windows\Explorer.EXE[4080] kernel32.dll!WinExec                                            776F53E7 5 Bytes  JMP 00010EFF
.text           C:\Windows\Explorer.EXE[4080] ADVAPI32.dll!RegCreateKeyExA                                    774AB5E7 5 Bytes  JMP 00050051
.text           C:\Windows\Explorer.EXE[4080] ADVAPI32.dll!RegCreateKeyA                                      774AB8AE 5 Bytes  JMP 00050FB9
.text           C:\Windows\Explorer.EXE[4080] ADVAPI32.dll!RegOpenKeyA                                        774B0BF5 5 Bytes  JMP 00050FEF
.text           C:\Windows\Explorer.EXE[4080] ADVAPI32.dll!RegCreateKeyW                                      774BB83D 5 Bytes  JMP 00050040
.text           C:\Windows\Explorer.EXE[4080] ADVAPI32.dll!RegCreateKeyExW                                    774BBCE1 5 Bytes  JMP 00050F94
.text           C:\Windows\Explorer.EXE[4080] ADVAPI32.dll!RegOpenKeyExA                                      774BD4E8 5 Bytes  JMP 0005001B
.text           C:\Windows\Explorer.EXE[4080] ADVAPI32.dll!RegOpenKeyW                                        774C3CB0 5 Bytes  JMP 0005000A
.text           C:\Windows\Explorer.EXE[4080] ADVAPI32.dll!RegOpenKeyExW                                      774CF09D 5 Bytes  JMP 00050FD4
.text           C:\Windows\Explorer.EXE[4080] WS2_32.dll!socket                                               765236D1 5 Bytes  JMP 01CC0FEF
.text           C:\Windows\Explorer.EXE[4080] WININET.dll!InternetOpenA                                       760503DD 5 Bytes  JMP 03090000
.text           C:\Windows\Explorer.EXE[4080] WININET.dll!InternetOpenUrlA                                    760520A3 5 Bytes  JMP 03090FCA
.text           C:\Windows\Explorer.EXE[4080] WININET.dll!InternetOpenW                                       76052A58 5 Bytes  JMP 03090FE5
.text           C:\Windows\Explorer.EXE[4080] WININET.dll!InternetOpenUrlW                                    7609AF79 5 Bytes  JMP 03090FB9

---- Devices - GMER 1.0.14 ----

AttachedDevice  \FileSystem\Ntfs \Ntfs                                                                        mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice  \Driver\tdx \Device\Tcp                                                                       Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)

Device          \Driver\BTHUSB \Device\00000085                                                               bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device          \Driver\BTHUSB \Device\00000087                                                               bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)

AttachedDevice  \Driver\tdx \Device\Udp                                                                       Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice  \Driver\tdx \Device\RawIp                                                                     Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice  \FileSystem\fastfat \Fat                                                                      fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice  \FileSystem\fastfat \Fat                                                                      mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

---- Registry - GMER 1.0.14 ----

Reg             HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001fe1def98d                  
Reg             HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001fe1def98d                      

---- EOF - GMER 1.0.14 ----

10.4K Posts

December 1st, 2008 14:00



O.K. We are going to have to Uninstall and Remove McAfee.

If you have a paid for version with a product key you can reload it when we are finished.

1. Go HERE and Download the McAfee Removal tool and save it to your Desktop (BUT DO NOT RUN IT YET)

2. Uninstalll McAfee

Click Start (the Vista Icon) ->> Control Panel ->> Programs and Features ->> Hilite and uninstall McAfee.

Close Programs and Features

3. Run (Double Click to run) the McAfee Removal Tool that you saved to your Desktop earlier.

4. Reboot your PC ->> ReRun SRE2 and fix those errors we had previously. Close SRE2 ->> Reboot your PC ->> Rerun SRE2 and see if the errors stay fixed.

Reply with the results


7 Posts

December 1st, 2008 17:00

I hate to tell you this after all the time you have spent helping me, but today my computer randomly gave me a blue screen error twice out of nowhere, so I wiped it clean and reinstalled the OS.

It appears to be working fine now.... but I am wondering whther I need to do all of the steps you gave me over again to check things, or would the fresh reinstall have removed the problems we found while checking? I reformated and everything- fresh start.

Thanks for all your help

Monica

10.4K Posts

December 2nd, 2008 05:00

Monica

A clean re-install may be the best thing in the long run. I was curios why the clean install did not work the first time.

Nevertheless, my previous instructions are not necceesary. I would recommend that when you reload your programs that you do them one at a time, and make note of any problems as you re-install them, so that if there is a problem, it can be isolated.

 

surf safe

No Events found!

Top