<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Tech Support Guy Forums</title>
		<link>http://forums.techguy.org/</link>
		<description>Tech Support Guy offers free support for Windows 8, 7, Vista, XP, and much more!</description>
		<language>en</language>
		<lastBuildDate>Fri, 24 May 2013 03:48:54 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>30</ttl>
		<image>
			<url>http://a.tsgstatic.com/v38/images/misc/rss.jpg</url>
			<title>Tech Support Guy Forums</title>
			<link>http://forums.techguy.org/</link>
		</image>
		<item>
			<title>Realtek wireless driver for Windows 2008 R2 enterprise server</title>
			<link>http://forums.techguy.org/windows-server/1099575-realtek-wireless-driver-windows-2008-a.html</link>
			<pubDate>Fri, 24 May 2013 03:44:13 GMT</pubDate>
			<description>Hi All 
 
I recently installed Windows server 2008 R2 enterprise on my personal laptop on a 40 GB drive.On the rest of disk space, I have Win 7 homepremiuim installed and has secure Wifi internet connectivity. Now, I am trying to connect the wifi on...</description>
			<content:encoded><![CDATA[<div>Hi All<br />
<br />
I recently installed Windows server 2008 R2 enterprise on my personal laptop on a 40 GB drive.On the rest of disk space, I have Win 7 homepremiuim installed and has secure Wifi internet connectivity. Now, I am trying to connect the wifi on my server, but its just not showing anything. I downloaded driver Realtek RTL8191se Wireless LAN 802.11n in HomePremium and ran it on server disk partition. So, my device manager is showing up to date however its still not connecting the wifi and saying that there is a problem with wireless adapter. I am totally cluless...please help!!!</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/85-windows-server/">Windows Server</category>
			<dc:creator>freespirited17</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/windows-server/1099575-realtek-wireless-driver-windows-2008-a.html</guid>
		</item>
		<item>
			<title><![CDATA[Can't connect to internet]]></title>
			<link>http://forums.techguy.org/networking/1099574-cant-connect-internet.html</link>
			<pubDate>Fri, 24 May 2013 03:27:37 GMT</pubDate>
			<description>Hi, 
 
My computer has recently become incapable of connecting to my home internet. My apartment building is wired, and I have an internet jack in my apartment. The jack in my apartment is connected to a netgear router. The building also has two...</description>
			<content:encoded><![CDATA[<div>Hi,<br />
<br />
My computer has recently become incapable of connecting to my home internet. My apartment building is wired, and I have an internet jack in my apartment. The jack in my apartment is connected to a netgear router. The building also has two routers for general use, linksys and netgear. Since I moved into the building in October, every few weeks I would lose my access to the internet. Usually I just reset the router and it was fine.<br />
<br />
In the past three weeks, this has not worked. I often go several days at a time being unable to access the internet, whether I am using my own router or the two general ones in the building. Then it will work for a few hours before becoming unusable again. I have also tried plugging my computer directly into the internet jack, but I get the same result. Resetting the router multiple times does not improve the situation. I have been assured by the building manager that the system has had no problems and everyone else in the building can connect. When this problem occurs, my network and sharing system shows that my computer is connected to the router but that the router is not connected to the internet. I have also tried a system restore to a month ago, before this problem arose, but nothing changed.<br />
<br />
I have an HP Pavilion dv4 Notebook PC, running Windows 7 home premium.<br />
<br />
Any ideas? All help will be greatly appreciated.<br />
<br />
Thanks.</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/53-networking/">Networking</category>
			<dc:creator>Blocho</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/networking/1099574-cant-connect-internet.html</guid>
		</item>
		<item>
			<title>need input/advice what kind of new laptop to get</title>
			<link>http://forums.techguy.org/hardware/1099573-need-input-advice-what-kind.html</link>
			<pubDate>Fri, 24 May 2013 02:41:37 GMT</pubDate>
			<description><![CDATA[After putting my beloved 10 years old or so Toshiba on lifesupport 2 years ago, it shows signs of getting too hot again too often. 
Now I don't know what to replace it with, I am so used to XP and I see so many problems with Windows 8, would I be...]]></description>
			<content:encoded><![CDATA[<div>After putting my beloved 10 years old or so Toshiba on lifesupport 2 years ago, it shows signs of getting too hot again too often.<br />
Now I don't know what to replace it with, I am so used to XP and I see so many problems with Windows 8, would I be better off trying to find a Windows7 laptop?  Can&quot;t afford a  Mac and it is probably too hard to learn its OS.<br />
I never play games, or download anything but use it for email and family pix organizing. I need 4 USB ports, because the new computers don't seem to have a modem, needed for dial-up to get some kind of device unfortunately.<br />
Any advise what brand is reliable? Is there a laptop with matte screen still? Will I have to replace my old programs, like Word and Paintshop Pro? <br />
I' ll appreciate any advise.</div>


	<br />
	<div style="padding:6px">

	
		<fieldset class="fieldset">
			<legend>Attached Thumbnails</legend>
			<div style="padding:3px">
			
<a href="{attachment-server}attachment.php?attachmentid=223777&amp;d=1369363131" rel="Lightbox" id="attachment223777" target="_blank"><img class="thumbnail" src="{attachment-server}attachment.php?attachmentid=223777&amp;stc=1&amp;thumb=1&amp;d=1369363131" border="0" alt="Click image for larger version

Name:	myToshiba.JPG
Views:	N/A
Size:	59.7 KB
ID:	223777" /></a>
&nbsp;

			</div>
		</fieldset>
	

	

	

	

	</div>
]]></content:encoded>
			<category domain="http://forums.techguy.org/19-hardware/">Hardware</category>
			<dc:creator>bp936</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/hardware/1099573-need-input-advice-what-kind.html</guid>
		</item>
		<item>
			<title>Sound devices not recognized</title>
			<link>http://forums.techguy.org/hardware/1099572-sound-devices-not-recognized.html</link>
			<pubDate>Fri, 24 May 2013 01:53:03 GMT</pubDate>
			<description>OK, 
 
Last night my sound was fine. This morning I had to hardkill my computer. When it started again, my sound would not work. Mousing over the sound icon in the tray said no sound devices were plugged in, even though they are. When I go to the...</description>
			<content:encoded><![CDATA[<div>OK,<br />
<br />
Last night my sound was fine. This morning I had to hardkill my computer. When it started again, my sound would not work. Mousing over the sound icon in the tray said no sound devices were plugged in, even though they are. When I go to the audio tab in control panel devices are there but are grayed out. I tried reinstalling realtek HD drivers. They seemed to install correctly, but still same problem. Checked BIOS and sound is enabled. Tried installing generic Windows drivers but that did not work either. When I try to open Realtek sound manager, I get an error that says dirver is Vista only. But driver download is for XP/7/8/Vista versions. When I look at the file on my drive, it looks there are folder for vista, but not Windows 7 (my OS).<br />
<br />
If I go control panel I can see the audio devices, but they are grayed out. Have run reg scans and virus scans but still nothing.</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/19-hardware/">Hardware</category>
			<dc:creator>kalalaug</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/hardware/1099572-sound-devices-not-recognized.html</guid>
		</item>
		<item>
			<title>MSE Number of Files Changing</title>
			<link>http://forums.techguy.org/general-security/1099567-mse-number-files-changing.html</link>
			<pubDate>Fri, 24 May 2013 01:28:28 GMT</pubDate>
			<description><![CDATA[Some time last year when I ran a full-system scan on Microsoft Security Essentials, the total number of files scanned was 375,752.  I recorded this number, because I was curious about how many files MSE scans. 
  
I don't usually pay much attention...]]></description>
			<content:encoded><![CDATA[<div>Some time last year when I ran a full-system scan on Microsoft Security Essentials, the total number of files scanned was 375,752.  I recorded this number, because I was curious about how many files MSE scans.<br />
 <br />
I don't usually pay much attention to this number, but yesterday when I completed a full-system scan the total came out as 344,937.<br />
 <br />
Since I haven't really deleted much I was curious about why the number had dropped like this.  I figured that MSE must be skipping some files like NIS 2012 does after repeated scans, but when I restart the computer and run the full-system scan again, the total comes out different each time.  I've even tried turning-off and then turning-on real-time protection to see if it would make a difference, but the numbers continue to fluctuate each time.<br />
 <br />
So far I've had the following results:<br />
 <br />
326,542<br />
344,442<br />
276,683<br />
344,654<br />
 <br />
I'm probably worrying over nothing, but is this normal and what is the cause of this?<br />
 <br />
Thanks in advanced,<br />
 <br />
- Unlucky Pete</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/78-general-security/">General Security</category>
			<dc:creator>Unlucky_Pete</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/general-security/1099567-mse-number-files-changing.html</guid>
		</item>
		<item>
			<title>Windows 7, dtuser.exe, explorer closes</title>
			<link>http://forums.techguy.org/windows-7/1099566-windows-7-dtuser-exe-explorer.html</link>
			<pubDate>Fri, 24 May 2013 01:15:16 GMT</pubDate>
			<description><![CDATA[Hello techs: 
  
I have a bunch of problems so there is no ONE problem.   
Explorer closes and maybe I can reopen a page or I have to close and reopen...this happens for regular online and even worse I can't send emails, they freeze and I can't...]]></description>
			<content:encoded><![CDATA[<div>Hello techs:<br />
 <br />
I have a bunch of problems so there is no ONE problem.  <br />
Explorer closes and maybe I can reopen a page or I have to close and reopen...this happens for regular online and even worse I can't send emails, they freeze and I can't continue them and I loose all my message.  Can't copy and paste.  Ticks me off when emailing with 4 paragraphs and it freezes before the save time and I could be 2 paragraphs behind.  I have to constantly re-click to continue typing.<br />
 <br />
Tired of getting kicked out of my ONLINE games.  When playing sometimes the game will stay up and I can play for hours, OR it flips to my desktop about every 30 seconds.  I then have to stop and run all of scans and try again...<br />
 <br />
I have Speedy PC Pro, PC Tuneup Maestro, and Fix Cleaner.  I can't run Spybot and my system will not allow me to download McAfee even though my boyfriend has a subscription for both machines.<br />
 <br />
I have a memory problem so I will do my best to give you the required information.<br />
Windows 7, Dell XPS 8300, Service Pack 1, 64-bit operating system, DtUser error msg.<br />
 <br />
I have tried different sites, and most of them state...&quot;Free download&quot; yeah that part is FREE, but that's it!<br />
 <br />
Tech Support Guy System Info Utility version 1.0.0.2<br />
OS Version: Microsoft Windows 7 Home Premium, Service Pack 1, 64 bit<br />
Processor: Intel(R) Core(TM) i7-2600 CPU @ 3.40GHz, Intel64 Family 6 Model 42 Stepping 7<br />
Processor Count: 8<br />
RAM: 8174 Mb<br />
Graphics Card: AMD Radeon HD 6700 Series, 1024 Mb<br />
Hard Drives: C: Total - 1417191 MB, Free - 1267407 MB;<br />
Motherboard: Dell Inc., 0Y2MRG<br />
Antivirus: PC Cleaner Pro, Updated: Yes, On-Demand Scanner: Disabled<br />
 <br />
Thank you I hope to hear from someone with help.<br />
 <br />
Vernonproblems</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/86-windows-7/">Windows 7</category>
			<dc:creator>vernonproblems</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/windows-7/1099566-windows-7-dtuser-exe-explorer.html</guid>
		</item>
		<item>
			<title>Solved: How Best To Downgrade Internet Explorer</title>
			<link>http://forums.techguy.org/windows-7/1099565-solved-how-best-downgrade-internet.html</link>
			<pubDate>Fri, 24 May 2013 01:13:07 GMT</pubDate>
			<description><![CDATA[Hello, 
 
Whatever recent IE upgrade that took place has sidelined my dad so he called me for help.  Because I do not use IE, I personally am not effected nor know what he's talking about.  From what I can gather, there must have been an auto update...]]></description>
			<content:encoded><![CDATA[<div>Hello,<br />
<br />
Whatever recent IE upgrade that took place has sidelined my dad so he called me for help.  Because I do not use IE, I personally am not effected nor know what he's talking about.  From what I can gather, there must have been an auto update to a new version of IE that took place on his computer recently.  <br />
<br />
He doesn't know how to use the new version as it apparently looks different.  Plus, whatever he's doing in regard to his  business requires the previous version, I guess some business app or website does not work right now.   <br />
<br />
How best to downgrade to the previous version?  Is there a way to do this without loosing all his IE settings? <br />
<br />
Thanks!</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/86-windows-7/">Windows 7</category>
			<dc:creator>Pandimensional</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/windows-7/1099565-solved-how-best-downgrade-internet.html</guid>
		</item>
		<item>
			<title>Hal.dll file missing and cannot boot to any CD (XP)</title>
			<link>http://forums.techguy.org/windows-xp/1099564-hal-dll-file-missing-cannot.html</link>
			<pubDate>Fri, 24 May 2013 01:12:50 GMT</pubDate>
			<description><![CDATA[For no apparent reason this error has occurred on my wife's PC and after Googling everywhere I  have found that the most common solution is to simply insert the Installation CD into the PC and then respond to the "boot from any CD" prompt and after...]]></description>
			<content:encoded><![CDATA[<div>For no apparent reason this error has occurred on my wife's PC and after Googling everywhere I  have found that the most common solution is to simply insert the Installation CD into the PC and then respond to the &quot;boot from any CD&quot; prompt and after that I think I could fix it all OK...........<br />
<br />
But I can't get the &quot;boot from any PC prompt&quot; up i.e appears the system is not finding the Windows disc and then reverts to the error message!<br />
<br />
I have tried the F5, F8, pressing DEL or TAB during the reboot but no joy!<br />
<br />
Help!!:(:o</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/21-windows-xp/">Windows XP</category>
			<dc:creator>cuttlefish</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/windows-xp/1099564-hal-dll-file-missing-cannot.html</guid>
		</item>
		<item>
			<title>Need help with cell phone outbox</title>
			<link>http://forums.techguy.org/android-phones-tablets/1099563-need-help-cell-phone-outbox.html</link>
			<pubDate>Fri, 24 May 2013 01:05:32 GMT</pubDate>
			<description>Now that I finally got a cell, it worked for 3 month, but then email outbox stopped working. I thought its the Samsung, but then I  found out, many Android and many brands (per Google) have this problem.  
Anyone ever found out how to fix this? I...</description>
			<content:encoded><![CDATA[<div>Now that I finally got a cell, it worked for 3 month, but then email outbox stopped working. I thought its the Samsung, but then I  found out, many Android and many brands (per Google) have this problem. <br />
Anyone ever found out how to fix this? I brought mine back to the store, the guy worked on it for 70 minutes and finally got it, didn't remember what he changed. It only worked for 3 days and lost its capabilities again to send emails from OUTBOX. I personally reset everything at least 20 times, nothing seems to work. Google does not give anyone for any brand an answer.<br />
Tried K0 but that also seems to be blocked to send.<br />
<br />
Is it better to get an Iphone or Blackberry? I just don't like the price, mine was kind of free with Koodo and I didn't have to sign up for 3 years.<br />
<br />
Hope someone has a miracle answer, because the rest of Samsung Ace, I really like.</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/97-android-phones-tablets/">Android Phones and Tablets</category>
			<dc:creator>bp936</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/android-phones-tablets/1099563-need-help-cell-phone-outbox.html</guid>
		</item>
		<item>
			<title>bogus software ?</title>
			<link>http://forums.techguy.org/general-security/1099562-bogus-software.html</link>
			<pubDate>Fri, 24 May 2013 01:02:15 GMT</pubDate>
			<description>I RECENTLY DOWNLOADED REGSERVO software AND FOOLISHLY PAID FOR IT IMMEDIATELY. THE COMPANY SENT ME A LICENCE KEY WHICH I INSERTED INTO THE PROPER SPACE PROVIDED.THE MESSAGE I RECEIVED WAS ----WRONG KEY NUMBER SEQUENCE---WHICH I TRIPLE CHECKED IT FOR...</description>
			<content:encoded><![CDATA[<div>I RECENTLY DOWNLOADED REGSERVO software AND FOOLISHLY PAID FOR IT IMMEDIATELY. THE COMPANY SENT ME A LICENCE KEY WHICH I INSERTED INTO THE PROPER SPACE PROVIDED.THE MESSAGE I RECEIVED WAS ----WRONG KEY NUMBER SEQUENCE---WHICH I TRIPLE CHECKED IT FOR ACCURACY AND IT WAS THE KEY THAT THEY HAD SENT ME. IS THIS COMPANY LEGIT ? ALL CORRESPONDENCE IS LIKE A BROKEN RECORD FROM THEIR END,TELLING ME TO FORWARD AN ID NUMER WHICH I DON,T HAVE !<br />
ANYWAY, THANKS FOR LISTENING .<br />
 <br />
SAMMI44</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/78-general-security/">General Security</category>
			<dc:creator>sammi44</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/general-security/1099562-bogus-software.html</guid>
		</item>
		<item>
			<title>CCTV dvr. Net Suveillance</title>
			<link>http://forums.techguy.org/do-yourself-not-computer-related/1099561-cctv-dvr-net-suveillance.html</link>
			<pubDate>Fri, 24 May 2013 00:56:52 GMT</pubDate>
			<description>Hey Guys;  
I have a dilema and a problem that I am very frustrating trying to resolve. 
 
Ive just bought a dvr 8 cameras. 
 
 
 
I basically set up everything like this 
 
Att router to bridge - apple router to dhcp ppoe log in to att.</description>
			<content:encoded><![CDATA[<div>Hey Guys; <br />
I have a dilema and a problem that I am very frustrating trying to resolve.<br />
<br />
Ive just bought a dvr 8 cameras.<br />
<br />
<br />
<br />
I basically set up everything like this<br />
<br />
Att router to bridge - apple router to dhcp ppoe log in to att. <br />
<br />
then I add another apple router to expand the wireless as well connected to the cat5 to the cameras netwrok port so it stream back to main router.<br />
<br />
Open the port 88 for the port forwarding and kaboom everything working flawlessly, port open you can log in in the cameras with the ip address and so far.<br />
<br />
If i log on inside my network i can see the cameras fine.<br />
<br />
Once I log on the outside network so I can view it from far away it opens the page open the square for each camera but it jsut thinks and i cannot see the picture( cameras image) it stays on quicktime loading screen for EVER.<br />
<br />
I need help.<br />
<br />
<br />
is my internet band enought ?<br />
maybe because I am streaming it wirelessly not plugged fisicaly on the main router  is not sending enought speed?<br />
<br />
<br />
Well basically I had a 4 channel dvr and it worked flawlessly oNline and offline.<br />
<br />
<br />
Si now I say what gives..... i change many times the setting for quif D1, dif.... still no luck.<br />
<br />
<br />
Help will be awesome! thanks</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/73-do-yourself-not-computer-related/">Do It Yourself (Not Computer-Related)</category>
			<dc:creator>carlospassow</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/do-yourself-not-computer-related/1099561-cctv-dvr-net-suveillance.html</guid>
		</item>
		<item>
			<title>Do I still use thermal paste on a cooling fan with insulating tape?</title>
			<link>http://forums.techguy.org/hardware/1099560-do-i-still-use-thermal.html</link>
			<pubDate>Fri, 24 May 2013 00:50:46 GMT</pubDate>
			<description><![CDATA[I bought a Cooler Master 212 EVO and am ready to install it. I noticed that at the end it says "Don't peel off the insulating tape. The insulating tape must face the motherboard" 
 
So my question is, do I still apple the pea sized amount of thermal...]]></description>
			<content:encoded><![CDATA[<div>I bought a Cooler Master 212 EVO and am ready to install it. I noticed that at the end it says &quot;Don't peel off the insulating tape. The insulating tape must face the motherboard&quot;<br />
<br />
So my question is, do I still apple the pea sized amount of thermal paste on my CPU before I install the heatsink?<br />
<br />
What does the insulating tape do?</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/19-hardware/">Hardware</category>
			<dc:creator>sh1ftelliott</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/hardware/1099560-do-i-still-use-thermal.html</guid>
		</item>
		<item>
			<title><![CDATA[Solved: A People's Computer]]></title>
			<link>http://forums.techguy.org/hardware/1099559-solved-peoples-computer.html</link>
			<pubDate>Fri, 24 May 2013 00:44:46 GMT</pubDate>
			<description>Why am I offered in the retail marketplace for personal computers only computers that require much larger  hard-drives and RAM than I need?   My need is after all determined by my activities and what available  computer software can do for me.  As...</description>
			<content:encoded><![CDATA[<div>Why am I offered in the retail marketplace for personal computers only computers that require much larger  hard-drives and RAM than I need?   My need is after all determined by my activities and what available  computer software can do for me.  As far as I know,  there are no new applications that would either extend my activities, or make them less difficult or more pleasurable than now.   I can accomplish what I wish to do with my 38GB HD, 2GB RAM, and 256MB video RAM, using Windows XP.    When my system fails, as sooner or later it will,  I am faced with having to choose from desktops with 500GB HD and 6GB RAM and Windows 7 or 8.   The latter OSs require a great deal of HD and RAM to run properly, I am told.   With all the extra stuff, I shall still only wish to use email. word-process, surf the internet, use an internet phone service.   I can do all that with XP and my limited system.  <br />
<br />
Since 2004, when my no-brand computer was assembled, the cost of a GB of HD or RAM has probably much diminished.   The chipset in my system,  its CPU,  circuit boards, are probably cheaper to make than nine years ago.   I should be able to buy a computer like the one I now have but brand new for less than $150.  Why must I consider spending $500 for a computer without a monitor and only one year's manufacturer's warranty and very limited tech support?<br />
<br />
I do not wish to store 50,000 photos or musical clips or videos from youtube.   I just want to do the same old thing, because the software designers have not come up with anything new that I just have to have!</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/19-hardware/">Hardware</category>
			<dc:creator>goedel</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/hardware/1099559-solved-peoples-computer.html</guid>
		</item>
		<item>
			<title>HDTV power supply board blown?</title>
			<link>http://forums.techguy.org/do-yourself-not-computer-related/1099558-hdtv-power-supply-board-blown.html</link>
			<pubDate>Fri, 24 May 2013 00:40:07 GMT</pubDate>
			<description><![CDATA[Yesterday my community had a five hour power failure which  included a power surge strong enough to blow the electric meters off  several houses and cause a few small fires. 
  
My losses  included failure of two identical two year-old Toshiba 32"...]]></description>
			<content:encoded><![CDATA[<div>Yesterday my community had a five hour power failure which  included a power surge strong enough to blow the electric meters off  several houses and cause a few small fires.<br />
 <br />
My losses  included failure of two identical two year-old Toshiba 32&quot; HDTVs, model  32C100U2 (and a ceiling fan).  Neither TV would start via the remote or  the power button.<br />
 <br />
Surprisingly, this TV does not have a  consumer-replaceable fuse so I opened-up the back of each and easily  determined the fuse had blown in each.  Unfortunately, replacing the  fuses resulted in another pair of blown fuses. On one TV, I pulled the  cables leading to the other boards and tried another fuse -- which  immediately fried.<br />
<br />
This leads me to believe the power supply  board (PK101V1550I) is damaged.  There are no obvious blown components  on either board. The caps look intact.<br />
 <br />
I'm seeking second  opinions on if replacing the boards is in order before I buy them.  Lots  of places have the out-of-stock but I found several on eBay for about  $50 each.<br />
 <br />
Thanks....</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/73-do-yourself-not-computer-related/">Do It Yourself (Not Computer-Related)</category>
			<dc:creator>dacker</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/do-yourself-not-computer-related/1099558-hdtv-power-supply-board-blown.html</guid>
		</item>
		<item>
			<title>Excel 2010: Need assistance with creating a lookup tool.</title>
			<link>http://forums.techguy.org/business-applications/1099557-excel-2010-need-assistance-creating.html</link>
			<pubDate>Thu, 23 May 2013 23:28:35 GMT</pubDate>
			<description><![CDATA[Hi, 
 
I'm trying to create a simple lookup tool, which displays cable and equipment data relevant to a selection from a drop down menu. I have attached an example workbook. 
 
There are three worksheets. The first, LOOKUP, has the dropdown menu,...]]></description>
			<content:encoded><![CDATA[<div>Hi,<br />
<br />
I'm trying to create a simple lookup tool, which displays cable and equipment data relevant to a selection from a drop down menu. I have attached an example workbook.<br />
<br />
There are three worksheets. The first, LOOKUP, has the dropdown menu, sourcing it's data for the list from the second worksheet, T_CODES. On the first worksheet I want one column that will display all of the cables relevant to the selction in the drop down menu. The third sheet, RAW_DATA, has the cable information listed under their respective systems (named by their Turnover Codes); notice how the different systems share some of the same cables.<br />
<br />
My biggest difficulty is getting the Column &quot;Cable Number&quot; on the first sheet to dynamically populate the cables (down the sheet, in individual cells) depending on what Turnover Code is selected from the drop down list. Is this even possible?<br />
<br />
The live workbook that will be used will contain a lot of data, hence why I'm trying to make an easy tool for people to use. They can simply select the Turnover Code for the system they are working on, and it will display all the cables that concern their system.<br />
<br />
Any ideas on how I can do this, or am I coming at this from the wrong direction?<br />
<br />
Cheers!</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://e.tsgstatic.com/v38/images/attach/xlsx.gif" alt="File Type: xlsx" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="{attachment-server}attachment.php?attachmentid=223774&amp;d=1369351669">Example.xlsx</a> (14.3 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://forums.techguy.org/16-business-applications/">Business Applications</category>
			<dc:creator>kaputcha</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/business-applications/1099557-excel-2010-need-assistance-creating.html</guid>
		</item>
		<item>
			<title>virus n error loading problem</title>
			<link>http://forums.techguy.org/virus-other-malware-removal/1099556-virus-n-error-loading-problem.html</link>
			<pubDate>Thu, 23 May 2013 23:26:14 GMT</pubDate>
			<description>The following message keep coming up when I start my computer: 
Kp Quicken Function.exe has encounter a problem and needs to close.  We are sorry for the inconvenience. 
 
Also the following error message appears: 
Errorloading...</description>
			<content:encoded><![CDATA[<div>The following message keep coming up when I start my computer:<br />
Kp Quicken Function.exe has encounter a problem and needs to close.  We are sorry for the inconvenience.<br />
<br />
Also the following error message appears:<br />
Errorloading C:\WINDOWS\ojexiyayidad.dll<br />
<br />
the specific module could not be found.<br />
<br />
there are other unwanted website pops up as well.<br />
<br />
Can u help me to fix it.<br />
<br />
Thank you</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-virus-other-malware-removal/"><![CDATA[Virus & Other Malware Removal]]></category>
			<dc:creator>errorloading</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/virus-other-malware-removal/1099556-virus-n-error-loading-problem.html</guid>
		</item>
		<item>
			<title>Sound Troubles</title>
			<link>http://forums.techguy.org/windows-7/1099555-sound-troubles.html</link>
			<pubDate>Thu, 23 May 2013 23:07:44 GMT</pubDate>
			<description><![CDATA[On a laptop running Windows 7, I'm having trouble with the sound. The sound device has somehow been set to Speakers & Headphones (IDT High Definition Audio CODEC), which is forcing about half of my sound playback through headphones (which I can't...]]></description>
			<content:encoded><![CDATA[<div>On a laptop running Windows 7, I'm having trouble with the sound. The sound device has somehow been set to Speakers &amp; Headphones (IDT High Definition Audio CODEC), which is forcing about half of my sound playback through headphones (which I can't simply leave plugged in) and the other half through the speakers. For example, video call sounds come through the headphones, whilst system sounds come through speakers. What I need to do is set everything to come through the speakers unless the headphones are plugged in. The problem is, whether I go through Control Panel or my Taskbar, I can't seem to find a way to set it back to the default.</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/86-windows-7/">Windows 7</category>
			<dc:creator>b_alasdair</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/windows-7/1099555-sound-troubles.html</guid>
		</item>
		<item>
			<title>Gmail voice plugin problem</title>
			<link>http://forums.techguy.org/web-email/1099554-gmail-voice-plugin-problem.html</link>
			<pubDate>Thu, 23 May 2013 23:05:44 GMT</pubDate>
			<description>Greetings, 
I have recently purchased an Accer Ultrabook equipped with Win 8 OS; I have tried to download the Gmail voice plug in to make calls via my Gmail but when I click on the link for the download, nothing happens, no download; I am launching...</description>
			<content:encoded><![CDATA[<div>Greetings,<br />
I have recently purchased an Accer Ultrabook equipped with Win 8 OS; I have tried to download the Gmail voice plug in to make calls via my Gmail but when I click on the link for the download, nothing happens, no download; I am launching Google CHrome from the desktop mode.<br />
Let me know if there is anything I can do to solve this problem.<br />
<br />
Cheers</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/17-web-email/"><![CDATA[Web & Email]]></category>
			<dc:creator>Ironlung</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/web-email/1099554-gmail-voice-plugin-problem.html</guid>
		</item>
		<item>
			<title>APC Battery back up</title>
			<link>http://forums.techguy.org/hardware/1099553-apc-battery-back-up.html</link>
			<pubDate>Thu, 23 May 2013 22:39:26 GMT</pubDate>
			<description>My company is getting rid of a few APC 1500 battery back ups, what do they do , are they use to a house application 
 
Dan</description>
			<content:encoded><![CDATA[<div>My company is getting rid of a few APC 1500 battery back ups, what do they do , are they use to a house application<br />
<br />
Dan</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/19-hardware/">Hardware</category>
			<dc:creator>dano_61</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/hardware/1099553-apc-battery-back-up.html</guid>
		</item>
		<item>
			<title>Do not know how bad my problem si but looks real bad</title>
			<link>http://forums.techguy.org/windows-7/1099552-do-not-know-how-bad.html</link>
			<pubDate>Thu, 23 May 2013 22:32:10 GMT</pubDate>
			<description>I first noticed that on youtube,a video will start and run between 10 and 15 seconds and stop. Some videos before starting would say it needs to have adobe flash player to run. I reinstalled adobe but still no go. When I was installing adobe flash...</description>
			<content:encoded><![CDATA[<div>I first noticed that on youtube,a video will start and run between 10 and 15 seconds and stop. Some videos before starting would say it needs to have adobe flash player to run. I reinstalled adobe but still no go. When I was installing adobe flash it would appear to stop downloading and I would have to &quot;stop&quot; and then restart it manually. This seems to be saying that downloads are stopping just like videos on youtube does.<br />
<br />
I was using internet explorer 7, but decided I would try Mozilla Firefox and I get the same problem. Norton antivirus says there are no virus or malware on my computer. This just started within the last couple of days . Seems like I remember everything being ok on Wednesday May 22, 2013.<br />
<br />
Anyone have such a problem or know a fix for this?<br />
<br />
Thanks and Have a Great Day,<br />
Jraquel</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/86-windows-7/">Windows 7</category>
			<dc:creator>jraquel</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/windows-7/1099552-do-not-know-how-bad.html</guid>
		</item>
		<item>
			<title>windows update freezes then reboots</title>
			<link>http://forums.techguy.org/windows-vista/1099551-windows-update-freezes-then-reboots.html</link>
			<pubDate>Thu, 23 May 2013 22:05:44 GMT</pubDate>
			<description>At wits end , my desktop pc is Windows Vista , 3 days ago updated some drivers now screen shows ‘updating 3 of 3 0% don’t turn off computer’ after 1 minute shuts down and restarts, never complete the download, I have tried the F8 last good config,...</description>
			<content:encoded><![CDATA[<div>At wits end , my desktop pc is Windows Vista , 3 days ago updated some drivers now screen shows ‘updating 3 of 3 0% don’t turn off computer’ after 1 minute shuts down and restarts, never complete the download, I have tried the F8 last good config, still goes back to the update screen, loaded in safe mode nothing happens, in desperation put in the re installation operating system CD, that wouldn’t load up either, still starts up at that updating screen, checked the BIOS to ensure would boot from CD all correct but whatever I try just goes back to that same screen and keeps re-starting,cant get past that screen to do anything, all advice from Microsoft forum to find the fault hopeless because need to get into system to do the checks and repair, as this happened to anyone else and how can I get past it and into system, having to send this message on borrowed laptop</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/75-windows-vista/">Windows Vista</category>
			<dc:creator>patcaessr</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/windows-vista/1099551-windows-update-freezes-then-reboots.html</guid>
		</item>
		<item>
			<title>Help buying new motherboard</title>
			<link>http://forums.techguy.org/hardware/1099550-help-buying-new-motherboard.html</link>
			<pubDate>Thu, 23 May 2013 21:58:46 GMT</pubDate>
			<description>My PC motherboard died about a week ago and since you guys helped me figure it out, I thought that you might also be able help me choose a new motherboard. Any suggestions would be really appreciated.</description>
			<content:encoded><![CDATA[<div>My PC motherboard died about a week ago and since you guys helped me figure it out, I thought that you might also be able help me choose a new motherboard. Any suggestions would be really appreciated.</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/19-hardware/">Hardware</category>
			<dc:creator>OmALY04</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/hardware/1099550-help-buying-new-motherboard.html</guid>
		</item>
		<item>
			<title>Slow internet</title>
			<link>http://forums.techguy.org/windows-vista/1099549-slow-internet.html</link>
			<pubDate>Thu, 23 May 2013 21:51:10 GMT</pubDate>
			<description><![CDATA[Hi, my Wi-Fi internet connection on my Vista is very slow or doesn't work at all many times, even though the icon at the notification area says that the connection is good, and other devices getting the same connection will work, can anyone help?]]></description>
			<content:encoded><![CDATA[<div>Hi, my Wi-Fi internet connection on my Vista is very slow or doesn't work at all many times, even though the icon at the notification area says that the connection is good, and other devices getting the same connection will work, can anyone help?</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/75-windows-vista/">Windows Vista</category>
			<dc:creator>simricht</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/windows-vista/1099549-slow-internet.html</guid>
		</item>
		<item>
			<title>How to uninstall Revo Unintall software</title>
			<link>http://forums.techguy.org/all-other-software/1099548-how-uninstall-revo-unintall-software.html</link>
			<pubDate>Thu, 23 May 2013 21:20:17 GMT</pubDate>
			<description>Hi,  
 
I would like to unistall Revo Uninstall Pro, It is listed as an option in Control Panel.  If I click on Programs and Features in Control Panel to uninstall it is not listed? I also have the software CCleaner and it is not listed in the...</description>
			<content:encoded><![CDATA[<div>Hi, <br />
<br />
I would like to unistall <i>Revo Uninstall Pro</i>, It is listed as an option in Control Panel.  If I click on Programs and Features in Control Panel to uninstall it is not listed? I also have the software CCleaner and it is not listed in the remove program option. In Program Files/VS Revo Group there is not an uninstall option in that folder.<br />
<br />
OS:Windows Vista Home Premium<br />
Service Pack 2<br />
AMD Athlon 64 X2 Dual Core Processor 4400+ 2.30GHz<br />
4GB RAM<br />
32 bit operating system<br />
<br />
Thank you for your help.<br />
<br />
Jay</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/18-all-other-software/">All Other Software</category>
			<dc:creator>jsklaroff</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/all-other-software/1099548-how-uninstall-revo-unintall-software.html</guid>
		</item>
		<item>
			<title>virtual network</title>
			<link>http://forums.techguy.org/networking/1099547-virtual-network.html</link>
			<pubDate>Thu, 23 May 2013 21:08:40 GMT</pubDate>
			<description>I am a poor typist. Before posting details, I would like to know if anyone can help with configuring a network I am attempting to build entirely within VirtualBox. The firewall/router interface between VBox and the outside world is pfSense. 
...</description>
			<content:encoded><![CDATA[<div>I am a poor typist. Before posting details, I would like to know if anyone can help with configuring a network I am attempting to build entirely within VirtualBox. The firewall/router interface between VBox and the outside world is pfSense.<br />
<br />
Thanks for your replies.</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/53-networking/">Networking</category>
			<dc:creator>welf</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/networking/1099547-virtual-network.html</guid>
		</item>
		<item>
			<title>Windows 7 laptop connecting to network - mapped drives</title>
			<link>http://forums.techguy.org/windows-7/1099546-windows-7-laptop-connecting-network.html</link>
			<pubDate>Thu, 23 May 2013 20:47:18 GMT</pubDate>
			<description>I’m setting a new laptop for my boss, he will map to several network shares as it boots up. Each share requires a username and password. I mapped these drives, logged in the first time, put in the username and passwords etc with no problems. (we are...</description>
			<content:encoded><![CDATA[<div>I’m setting a new laptop for my boss, he will map to several network shares as it boots up. Each share requires a username and password. I mapped these drives, logged in the first time, put in the username and passwords etc with no problems. (we are not on a domain)<br />
We have a DHCP server that gives the IP address to the Laptop. <br />
<br />
When I reboot, I get a message from Windows “Could not connect to all Network drives” “Click here to check  the status of your network drives”<br />
<br />
I see all the mapped drives with little red x’s, clicking on them prompts me to enter a username and password, even though I’ve checked “remember my credentials”  <br />
<br />
He is going to be pissed if he has to put in his username and password every time he logs on, can you tell me how to fix this?<br />
<br />
Is there a “network connection wizard” buried somewhere in Windows 7?</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/86-windows-7/">Windows 7</category>
			<dc:creator>don_1953</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/windows-7/1099546-windows-7-laptop-connecting-network.html</guid>
		</item>
		<item>
			<title>Windows 7 Restarts When I Establish Internet Connection</title>
			<link>http://forums.techguy.org/virus-other-malware-removal/1099545-windows-7-restarts-when-i.html</link>
			<pubDate>Thu, 23 May 2013 20:31:20 GMT</pubDate>
			<description>Hey All, 
  
I have been having an issue with a Windows 7 Home Premium laptop where, when I establish a connection to the internet, it restarts. This happens if I connect to wireless or wired connections. I went so far as to perform a factory...</description>
			<content:encoded><![CDATA[<div>Hey All,<br />
 <br />
I have been having an issue with a Windows 7 Home Premium laptop where, when I establish a connection to the internet, it restarts. This happens if I connect to wireless or wired connections. I went so far as to perform a factory restore from the system partition and it is still doing it.<br />
 <br />
I came across this thread: <a href="http://forums.techguy.org/virus-other-malware-removal/1095674-computer-restarts-when-connecting-internet.html" target="_blank">http://forums.techguy.org/virus-othe...-internet.html</a> and am having the same exact issue.<br />
 <br />
There were some instructions in that thread that were specific to that persons system so I was wondering if someone would be able to walk me through the steps to get rid of whatever is causing the issue on this laptop.<br />
 <br />
Thanks in advance!</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-virus-other-malware-removal/"><![CDATA[Virus & Other Malware Removal]]></category>
			<dc:creator>zkostrzewa</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/virus-other-malware-removal/1099545-windows-7-restarts-when-i.html</guid>
		</item>
		<item>
			<title>Unable to install Win7</title>
			<link>http://forums.techguy.org/windows-7/1099544-unable-install-win7.html</link>
			<pubDate>Thu, 23 May 2013 20:22:00 GMT</pubDate>
			<description><![CDATA[A friend of mine got the FBI virus, so she backed up all her data, then began the process of a "system restore", but it did not work.   
 
I've walked her through downloading the original ISO file for Win7 (Home Premium) from Digital River, and she...]]></description>
			<content:encoded><![CDATA[<div>A friend of mine got the FBI virus, so she backed up all her data, then began the process of a &quot;system restore&quot;, but it did not work.  <br />
<br />
I've walked her through downloading the original ISO file for Win7 (Home Premium) from Digital River, and she has the product key attached to the side of her computer, so licensing isn't an issue.<br />
<br />
I also had her download the USB-ISO tool, so she can make her USB drive bootable with the ISO, as she doesn't have blank DVD's to burn the ISO.  I'm having her get some blank DVD's to see if that will work.<br />
<br />
The problem is that the installation starts, and comes up with the &quot;Install Now&quot; button, and she clicks on that, but the install comes up asking for drivers for additional drives, as it can't find the existing Windows installation.  I've tried having her remove the partition completely via &quot;Diskpart&quot;, but that's proving too difficult (for her), and I can't get to her location to do this myself, as I'm about 2000 miles away, trying to do this all over facebook IM...  lol<br />
<br />
Anyone know what type of drivers this thing needs to get Win7 reinstalled?  She doesn't have the factory disks, otherwise I would have just told her to stick that in and go from there...</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/86-windows-7/">Windows 7</category>
			<dc:creator>gurutech</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/windows-7/1099544-unable-install-win7.html</guid>
		</item>
		<item>
			<title><![CDATA[Outlook Express attachments & Eudora]]></title>
			<link>http://forums.techguy.org/web-email/1099543-outlook-express-attachments-eudora.html</link>
			<pubDate>Thu, 23 May 2013 20:16:19 GMT</pubDate>
			<description><![CDATA[Just earlier today I saw a post by Alex Ethridge regarding trying to find where Outlook attachments were stored on the hard drive.  That posting is now Closed so I wasn't able to do a Reply.  His posting also said  that he used Eudora.  I would like...]]></description>
			<content:encoded><![CDATA[<div>Just earlier today I saw a post by Alex Ethridge regarding trying to find where Outlook attachments were stored on the hard drive.  That posting is now Closed so I wasn't able to do a Reply.  His posting also said  that he used Eudora.  I would like to ask with what server are you able to use the Eudora email program?  I'm having a time finding a server who does.  Presently, I'm using Outlook Express (in complete desperation), and I cannot find where it stores my attachments from incoming emails.  It is supposed to be under Temporary Internet Files, but those files are hidden, even though I have checked Show Hidden Files in the Folder Options.<br />
<br />
Thanks!</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/17-web-email/"><![CDATA[Web & Email]]></category>
			<dc:creator>Kathy_H</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/web-email/1099543-outlook-express-attachments-eudora.html</guid>
		</item>
		<item>
			<title>Open Office on Mac</title>
			<link>http://forums.techguy.org/business-applications/1099542-open-office-mac.html</link>
			<pubDate>Thu, 23 May 2013 20:13:34 GMT</pubDate>
			<description>Hello, 
I am running Open Office on my iMac5, I want to print envelopes, how do I set up(step by step instructions would be great) 
 
 a data base to enable me to do this? 
Many thanks for any help.</description>
			<content:encoded><![CDATA[<div>Hello,<br />
I am running Open Office on my iMac5, I want to print envelopes, how do I set up(step by step instructions would be great)<br />
<br />
 a data base to enable me to do this?<br />
Many thanks for any help.</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/16-business-applications/">Business Applications</category>
			<dc:creator>Babs1</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/business-applications/1099542-open-office-mac.html</guid>
		</item>
		<item>
			<title>Solved: Vista hangs on shutdown (urgent please)</title>
			<link>http://forums.techguy.org/windows-vista/1099541-solved-vista-hangs-shutdown-urgent.html</link>
			<pubDate>Thu, 23 May 2013 20:00:36 GMT</pubDate>
			<description><![CDATA[Hello, 
 
I tried to shut down my Vista. (HP Pavillion) 
 
It hangs on blue "Logging off ..." screen. No activity on disk for some hours. 
 
No special activity lately, no updates etc. 
 
Screensaver and hibernate works. F8 does not work after...]]></description>
			<content:encoded><![CDATA[<div>Hello,<br />
<br />
I tried to shut down my Vista. (HP Pavillion)<br />
<br />
It hangs on blue &quot;Logging off ...&quot; screen. No activity on disk for some hours.<br />
<br />
No special activity lately, no updates etc.<br />
<br />
Screensaver and hibernate works. F8 does not work after hibernate (maybe that is as it should be).<br />
<br />
Nothing on ctrl/alt/del<br />
<br />
Please I need urgent help. Computer completely hung.<br />
<br />
Thanks.<br />
<br />
ycc</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/75-windows-vista/">Windows Vista</category>
			<dc:creator>ycc</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/windows-vista/1099541-solved-vista-hangs-shutdown-urgent.html</guid>
		</item>
		<item>
			<title>Outlook 2010 - Mail Delay to Only One User on Domain</title>
			<link>http://forums.techguy.org/business-applications/1099540-outlook-2010-mail-delay-only.html</link>
			<pubDate>Thu, 23 May 2013 19:50:03 GMT</pubDate>
			<description>Exchange 2010 
 
Client with the issue is running Outlook 2010 on Windows 7 Enterprise x64 (90% of users on this same OS). Desktop, hard wired on a steady internet connection. 
 
With this user, some (not all) emails that are sent via a distribution...</description>
			<content:encoded><![CDATA[<div>Exchange 2010<br />
<br />
Client with the issue is running Outlook 2010 on Windows 7 Enterprise x64 (90% of users on this same OS). Desktop, hard wired on a steady internet connection.<br />
<br />
With this user, some (not all) emails that are sent via a distribution group are delayed 5-20 minutes. For example, last week an email was sent out to all employees of our office at 4:50pm. This user got the email at 5:06pm. Looking at the header of the message, it does in fact show a time of 4:50. His send/receive settings match up with mine completely. <br />
<br />
Anyone have any suggestions as of what to try next?<br />
<br />
Thanks</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/16-business-applications/">Business Applications</category>
			<dc:creator>XpL0d3r</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/business-applications/1099540-outlook-2010-mail-delay-only.html</guid>
		</item>
		<item>
			<title><![CDATA[Can't resize picture in irfanview]]></title>
			<link>http://forums.techguy.org/digital-photography-imaging/1099539-cant-resize-picture-irfanview.html</link>
			<pubDate>Thu, 23 May 2013 19:35:25 GMT</pubDate>
			<description>Tech Support Guy System Info Utility version 1.0.0.2 
OS Version: Microsoft Windows 7 Home Premium, Service Pack 1, 64 bit 
Processor: AMD Athlon(tm) II X4 635 Processor, AMD64 Family 16 Model 5 Stepping 3 
Processor Count: 4 
RAM: 3839 Mb 
Graphics...</description>
			<content:encoded><![CDATA[<div>Tech Support Guy System Info Utility version 1.0.0.2<br />
OS Version: Microsoft Windows 7 Home Premium, Service Pack 1, 64 bit<br />
Processor: AMD Athlon(tm) II X4 635 Processor, AMD64 Family 16 Model 5 Stepping 3<br />
Processor Count: 4<br />
RAM: 3839 Mb<br />
Graphics Card: ATI Radeon HD 4200, 256 Mb<br />
Hard Drives: C: Total - 702932 MB, Free - 589223 MB; D: Total - 12368 MB, Free - 1511 MB;<br />
Motherboard: FOXCONN, 2AB1<br />
Antivirus: Microsoft Security Essentials, Updated and Enabled<br />
 <br />
I have been using IRFANVIEW for years with nary a problem, until the last few days.<br />
 <br />
When I try to RESIZE a picture nothing happens - what can I do to remedy this.<br />
 <br />
Thanks</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/60-digital-photography-imaging/"><![CDATA[Digital Photography & Imaging]]></category>
			<dc:creator>gtownflyer</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/digital-photography-imaging/1099539-cant-resize-picture-irfanview.html</guid>
		</item>
		<item>
			<title>ads over the speakers and slow computer</title>
			<link>http://forums.techguy.org/virus-other-malware-removal/1099538-ads-over-speakers-slow-computer.html</link>
			<pubDate>Thu, 23 May 2013 19:24:14 GMT</pubDate>
			<description>hello, There are ads playing over my speakers constantly even when no browsers are open.  Also my cpu is running at 100 % all the time.  I know I dont have the fastest computer, but its running deathly slow. My system clock is also very off, not...</description>
			<content:encoded><![CDATA[<div>hello, There are ads playing over my speakers constantly even when no browsers are open.  Also my cpu is running at 100 % all the time.  I know I dont have the fastest computer, but its running deathly slow. My system clock is also very off, not keeping time.  I tried doing a factory restore a few weeks ago, but that didnt help.  I have a hp 2000-369wm notebook pc running windows 7.  here is my log files:<br />
<br />
Logfile of Trend Micro HijackThis v2.0.4<br />
Scan saved at 12:08:11 PM, on 5/11/2013<br />
Platform: Windows 7 SP1 (WinNT 6.00.3505)<br />
MSIE: Internet Explorer v9.00 (9.00.8112.16421)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe<br />
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe<br />
C:\Program Files (x86)\Mozilla Firefox\firefox.exe<br />
C:\Users\matt\Downloads\HijackThis.exe<br />
C:\Windows\SysWOW64\DllHost.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://g.msn.com/HPNOT/1" target="_blank">http://g.msn.com/HPNOT/1</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://g.msn.com/HPNOT/1" target="_blank">http://g.msn.com/HPNOT/1</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://g.msn.com/HPNOT/1" target="_blank">http://g.msn.com/HPNOT/1</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://g.msn.com/HPNOT/1" target="_blank">http://g.msn.com/HPNOT/1</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
F2 - REG:system.ini: UserInit=userinit.exe<br />
O2 - BHO: &amp;Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn0\yt.dll<br />
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll<br />
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\IPS\IPSBHO.DLL<br />
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll<br />
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll<br />
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll<br />
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn0\yt.dll<br />
O4 - HKLM\..\Run: [StartCCC] &quot;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&quot; MSRun<br />
O4 - HKLM\..\Run: [HPQuickWebProxy] &quot;C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe&quot;<br />
O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe<br />
O4 - HKLM\..\Run: [SunJavaUpdateSched] &quot;C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe&quot;<br />
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10q_ActiveX.exe -update activex (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10q_ActiveX.exe -update activex (User 'Default user')<br />
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre7\bin\jp2iexp.dll<br />
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre7\bin\jp2iexp.dll<br />
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll<br />
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)<br />
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)<br />
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll<br />
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll<br />
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics<br />
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll<br />
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe<br />
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)<br />
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)<br />
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)<br />
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe<br />
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe<br />
O23 - Service: HP Client Services (HPClientSvc) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe<br />
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe<br />
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe<br />
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe<br />
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe<br />
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)<br />
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe<br />
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: RoxioNow Service - Roxio - C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe<br />
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)<br />
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)<br />
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)<br />
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
<br />
--<br />
End of file - 9953 bytes<br />
<br />
<br />
<br />
DDS (Ver_2012-11-20.01) - NTFS_AMD64 <br />
Internet Explorer: 9.0.8112.16421  BrowserJavaVersion: 10.21.2<br />
Run by matt at 12:02:22 on 2013-05-11<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
C:\Windows\system32\atiesrxx.exe<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\atieclxx.exe<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe<br />
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe<br />
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe<br />
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe<br />
C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe<br />
C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe<br />
C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe<br />
C:\Program Files (x86)\Mozilla Firefox\firefox.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE<br />
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe<br />
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe<br />
C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Windows\System32\svchost.exe -k LocalServicePeerNet<br />
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe<br />
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe<br />
C:\Windows\system32\taskmgr.exe<br />
C:\Windows\System32\perfmon.exe<br />
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe<br />
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe<br />
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\taskeng.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Users\matt\Downloads\HijackThis(1).exe<br />
C:\Users\matt\Downloads\HijackThis.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Windows\System32\svchost.exe -k WerSvcGroup<br />
C:\Windows\System32\cscript.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
mWinlogon: Userinit = userinit.exe<br />
BHO: &amp;Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll<br />
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br />
BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coieplg.dll<br />
BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ips\ipsbho.dll<br />
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll<br />
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll<br />
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coieplg.dll<br />
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coieplg.dll<br />
TB: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll<br />
mRun: [StartCCC] &quot;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&quot; MSRun<br />
mRun: [HPQuickWebProxy] &quot;C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe&quot;<br />
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe<br />
mRun: [SunJavaUpdateSched] &quot;C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe&quot;<br />
dRunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10q_ActiveX.exe -update activex<br />
mPolicies-Explorer: NoActiveDesktop = dword:1<br />
mPolicies-Explorer: NoActiveDesktopChanges = dword:1<br />
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5<br />
mPolicies-System: ConsentPromptBehaviorUser = dword:3<br />
mPolicies-System: EnableUIADesktopToggle = dword:0<br />
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC} - C:\Program Files (x86)\Java\jre7\bin\jp2iexp.dll<br />
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll<br />
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab<br />
DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab<br />
TCP: NameServer = 10.0.0.1<br />
TCP: Interfaces\{7160ECF7-6668-4539-9AEE-174F9E247A1C} : DHCPNameServer = 10.0.0.1<br />
TCP: Interfaces\{A1E67B58-BB03-4C30-A80E-227BCBFC9523} : DHCPNameServer = 10.0.0.1<br />
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll<br />
SSODL: WebCheck - &lt;orphaned&gt;<br />
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br />
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe<br />
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - &lt;orphaned&gt;<br />
x64-SSODL: WebCheck - &lt;orphaned&gt;<br />
.<br />
================= FIREFOX ===================<br />
.<br />
FF - ProfilePath - C:\Users\matt\AppData\Roaming\Mozilla\Firefox\Profiles\4js2esrz.default\<br />
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll<br />
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrlui.dll<br />
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll<br />
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll<br />
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll<br />
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll<br />
FF - ExtSQL: 2013-05-11 11:40; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\coFFPlgn<br />
FF - ExtSQL: 2013-05-11 11:41; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\IPSFFPlgn<br />
FF - ExtSQL: 2013-05-11 11:56; {635abd67-4fe9-1b23-4f01-e679fa7484c1}; C:\Users\matt\AppData\Roaming\Mozilla\Firefox\Profiles\4js2esrz.default\ext  ensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}<br />
.<br />
---- FIREFOX POLICIES ----<br />
                                                      <br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86<br />
R? clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64<br />
R? clwvd;CyberLink WebCam Virtual Driver<br />
R? GamesAppService;GamesAppService<br />
R? SrvHsfHDA;SrvHsfHDA<br />
R? SrvHsfV92;SrvHsfV92<br />
R? SrvHsfWinac;SrvHsfWinac<br />
R? TsUsbFlt;TsUsbFlt<br />
R? TsUsbGD;Remote Desktop Generic USB Device<br />
R? USBAAPL64;Apple Mobile USB Driver<br />
R? wlcrasvc;Windows Live Mesh remote connections service<br />
S? AERTFilters;Andrea RT Filters Service<br />
S? AMD External Events Utility;AMD External Events Utility<br />
S? AMD FUEL Service;AMD FUEL Service<br />
S? amd_sata;amd_sata<br />
S? amd_xata;amd_xata<br />
S? amdiox64;AMD IO Driver<br />
S? BHDrvx64;BHDrvx64<br />
S? ccSet_NIS;Norton Internet Security Settings Manager<br />
S? EraserUtilRebootDrv;EraserUtilRebootDrv<br />
S? HP Support Assistant Service;HP Support Assistant Service<br />
S? HPClientSvc;HP Client Services<br />
S? HPDrvMntSvc.exe;HP Quick Synchronization Service<br />
S? HPWMISVC;HPWMISVC<br />
S? IconMan_R;IconMan_R<br />
S? IDSVia64;IDSVia64<br />
S? netr28x;Ralink 802.11n Extensible Wireless Driver<br />
S? NIS;Norton Internet Security<br />
S? RoxioNow Service;RoxioNow Service<br />
S? RSPCIESTOR;Realtek PCIE CardReader Driver<br />
S? RTL8167;Realtek 8167 NT Driver<br />
S? SymDS;Symantec Data Store<br />
S? SymEFA;Symantec Extended File Attributes<br />
S? SymIRON;Symantec Iron Driver<br />
S? SymNetS;Symantec Network Security WFP Driver<br />
S? usbfilter;AMD USB Filter Driver<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2013-05-11 16:17:50    866720    ----a-w-    C:\Windows\SysWow64\npDeployJava1.dll<br />
2013-05-11 16:17:50    788896    ----a-w-    C:\Windows\SysWow64\deployJava1.dll<br />
2013-05-11 16:17:40    95648    ----a-w-    C:\Windows\SysWow64\WindowsAccessBridge-32.dll<br />
2013-05-11 16:07:18    --------    d-----w-    C:\Users\matt\AppData\Local\Mixxx<br />
2013-05-11 16:06:43    --------    d-----w-    C:\Users\matt\AppData\Local\Apple Computer<br />
2013-05-11 16:05:57    33240    ----a-w-    C:\Windows\System32\drivers\GEARAspiWDM.sys<br />
2013-05-11 16:05:13    --------    d-----w-    C:\Program Files\iPod<br />
2013-05-11 16:05:10    --------    d-----w-    C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69<br />
2013-05-11 16:05:10    --------    d-----w-    C:\Program Files\iTunes<br />
2013-05-11 16:05:10    --------    d-----w-    C:\Program Files (x86)\iTunes<br />
2013-05-11 15:57:49    --------    d-----w-    C:\Program Files (x86)\iPhoneBrowser<br />
2013-05-11 15:51:12    --------    d-----w-    C:\Users\matt\AppData\Local\AMD<br />
2013-05-11 15:50:35    --------    d-----w-    C:\Users\matt\AppData\Local\ATI<br />
2013-05-11 15:49:29    --------    d-----w-    C:\Users\matt\AppData\Roaming\hpqLog<br />
2013-05-11 15:49:14    --------    d-----w-    C:\Users\matt\AppData\Roaming\Synaptics<br />
2013-05-11 15:49:10    --------    d-----w-    C:\Users\matt\AppData\Local\CrashDumps<br />
2013-05-11 15:48:37    737952    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\srtsp64.sys<br />
2013-05-11 15:48:37    451192    ----a-r-    C:\Windows\System32\drivers\NISx64\1309010.00E\symds64.sys<br />
2013-05-11 15:48:37    405624    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\symnets.sys<br />
2013-05-11 15:48:37    37536    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\srtspx64.sys<br />
2013-05-11 15:48:37    190072    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\ironx64.sys<br />
2013-05-11 15:48:37    167072    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\ccsetx64.sys<br />
2013-05-11 15:48:37    1129120    ----a-w-    C:\Windows\System32\drivers\NISx64\1309010.00E\symefa64.sys<br />
2013-05-11 15:48:35    --------    d-----w-    C:\Users\matt\AppData\Local\Spotify<br />
2013-05-11 15:48:26    --------    d-----w-    C:\Windows\System32\drivers\NISx64\1309010.00E<br />
2013-05-11 15:47:16    --------    d-----w-    C:\Program Files (x86)\Yahoo!<br />
2013-05-11 15:45:48    --------    d-----w-    C:\Users\matt\AppData\Local\VirtualStore<br />
2013-05-11 15:45:43    --------    d-----w-    C:\Users\matt\AppData\Local\Apple<br />
2013-05-11 15:45:41    --------    d-----w-    C:\Users\matt\AppData\Local\RemEngine<br />
2013-05-11 15:45:17    --------    d-----w-    C:\Users\matt\AppData\Roaming\Spotify<br />
2013-05-11 15:43:57    --------    d-----w-    C:\Users\matt\AppData\Local\Adobe<br />
2013-05-11 15:43:41    692104    ----a-w-    C:\Windows\SysWow64\FlashPlayerApp.exe<br />
2013-05-11 15:43:25    --------    d-----w-    C:\Users\matt\AppData\Local\Mozilla<br />
2013-05-11 15:43:12    --------    d-----w-    C:\Users\matt\AppData\Local\Hewlett-Packard<br />
2013-05-11 15:43:11    --------    d-----w-    C:\Windows\SysWow64\%COREALLUSERPATH%<br />
2013-05-11 15:43:04    --------    d-----w-    C:\Program Files (x86)\Mozilla Maintenance Service<br />
2013-05-11 15:40:38    --------    d-----w-    C:\Users\matt\AppData\Local\Wide Angle Software<br />
2013-05-11 15:39:10    2622464    ----a-w-    C:\Windows\System32\wucltux.dll<br />
2013-05-11 15:39:04    --------    d-----w-    C:\Program Files (x86)\Wide Angle Software<br />
2013-05-11 15:37:30    --------    d-----w-    C:\Program Files (x86)\Common Files\Symantec Shared<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2013-05-11 15:45:04    175736    ----a-w-    C:\Windows\System32\drivers\SYMEVENT64x86.SYS<br />
2013-05-11 15:43:41    71048    ----a-w-    C:\Windows\SysWow64\FlashPlayerCPLApp.cpl<br />
.<br />
============= FINISH: 12:09:32.45 ===============<br />
<br />
.<br />
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.<br />
IF REQUESTED, ZIP IT UP &amp; ATTACH IT<br />
.<br />
DDS (Ver_2012-11-20.01)<br />
.<br />
Microsoft Windows 7 Home Premium <br />
Boot Device: \Device\HarddiskVolume1<br />
Install Date: 5/11/2013 11:37:53 AM<br />
System Uptime: 5/11/2013 11:36:25 AM (1 hours ago)<br />
.<br />
Motherboard: Hewlett-Packard |  | 3577<br />
Processor: AMD E-450 APU with Radeon(tm) HD Graphics | Socket FT1 | 1650/100mhz<br />
.<br />
==== Disk Partitions =========================<br />
.<br />
C: is FIXED (NTFS) - 447 GiB total, 413.138 GiB free.<br />
D: is FIXED (NTFS) - 15 GiB total, 1.625 GiB free.<br />
E: is FIXED (FAT32) - 4 GiB total, 1.084 GiB free.<br />
F: is CDROM ()<br />
.<br />
==== Disabled Device Manager Items =============<br />
.<br />
==== System Restore Points ===================<br />
.<br />
RP9: 5/11/2013 11:38:00 AM - Installed TouchCopy 12<br />
RP4: 5/11/2013 11:46:00 AM - Installed iTunes<br />
RP11: 5/11/2013 11:46:58 AM - Removed HP Documentation<br />
RP12: 5/11/2013 11:53:17 AM - Removed Evernote v. 4.2.3<br />
RP6: 5/11/2013 11:55:51 AM - Installed iPhoneBrowser<br />
RP3: 5/11/2013 11:56:07 AM - Installed J2SE Runtime Environment 5.0<br />
RP5: 5/11/2013 12:00:12 PM - Installed iTunes<br />
RP7: 5/11/2013 12:01:11 PM - Configured YouCam<br />
RP8: 5/11/2013 12:11:43 PM - Windows Update<br />
RP10: 5/11/2013 12:16:22 PM - Installed Java 7 Update 21<br />
.<br />
==== Installed Programs ======================<br />
.<br />
Adobe Flash Player 11 ActiveX<br />
Adobe Reader X MUI<br />
Adobe Shockwave Player 11.5<br />
Agatha Christie - Peril at End House<br />
AMD APP SDK Runtime<br />
AMD Fuel<br />
AMD Media Foundation Decoders<br />
AMD VISION Engine Control Center<br />
Apple Application Support<br />
Apple Mobile Device Support<br />
Apple Software Update<br />
ATI Catalyst Install Manager<br />
Bejeweled 3<br />
Blackhawk Striker 2<br />
Blasterball 3<br />
Blio<br />
Bonjour<br />
Bounce Symphony<br />
Cake Mania<br />
Catalyst Control Center - Branding<br />
Catalyst Control Center Graphics Previews Common<br />
Catalyst Control Center InstallProxy<br />
Catalyst Control Center Localization All<br />
ccc-utility64<br />
CCC Help Chinese Standard<br />
CCC Help Chinese Traditional<br />
CCC Help Czech<br />
CCC Help Danish<br />
CCC Help Dutch<br />
CCC Help English<br />
CCC Help Finnish<br />
CCC Help French<br />
CCC Help German<br />
CCC Help Greek<br />
CCC Help Hungarian<br />
CCC Help Italian<br />
CCC Help Japanese<br />
CCC Help Korean<br />
CCC Help Norwegian<br />
CCC Help Polish<br />
CCC Help Portuguese<br />
CCC Help Russian<br />
CCC Help Spanish<br />
CCC Help Swedish<br />
CCC Help Thai<br />
CCC Help Turkish<br />
Chronicles of Albian<br />
Chuzzle Deluxe<br />
Cradle of Rome 2<br />
D3DX10<br />
ESU for Microsoft Windows 7 SP1<br />
Evernote v. 4.2.3<br />
Farm Frenzy<br />
FATE<br />
Governor of Poker 2 Premium Edition<br />
Hewlett-Packard ACLM.NET v1.1.1.0<br />
HP Auto<br />
HP Client Services<br />
HP Customer Experience Enhancements<br />
HP Games<br />
HP Launch Box<br />
HP MovieStore<br />
HP On Screen Display<br />
HP Power Manager<br />
HP Quick Launch<br />
HP QuickWeb<br />
HP Setup<br />
HP Setup Manager<br />
HP Software Framework<br />
HP Support Assistant<br />
iPhoneBrowser<br />
iTunes<br />
J2SE Runtime Environment 5.0<br />
Java 7 Update 21<br />
Java Auto Updater<br />
Jewel Quest: The Sleepless Star - Collector's Edition<br />
Junk Mail filter update<br />
Mah Jong Medley<br />
Mesh Runtime<br />
Microsoft .NET Framework 4 Client Profile<br />
Microsoft Application Error Reporting<br />
Microsoft Office 2010<br />
Microsoft Silverlight<br />
Microsoft SQL Server 2005 Compact Edition [ENU]<br />
Microsoft Visual C++ 2005 Redistributable<br />
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17<br />
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148<br />
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319<br />
Microsoft WSE 3.0 Runtime<br />
Mixxx 1.11.0 (64-bit)<br />
Mozilla Firefox 20.0.1 (x86 en-US)<br />
Mozilla Maintenance Service<br />
MSVCRT<br />
MSVCRT_amd64<br />
Mystery of Mortlake Mansion<br />
Namco All-Stars: PAC-MAN<br />
Norton Internet Security<br />
Penguins!<br />
Plants vs. Zombies - Game of the Year<br />
PlayReady PC Runtime x86<br />
Poker Superstars III<br />
Polar Bowler<br />
Polar Golfer<br />
Ralink RT5390 802.11b/g/n WiFi Adapter<br />
Realtek Ethernet Controller Driver<br />
Realtek High Definition Audio Driver<br />
Realtek PCIE Card Reader<br />
Recovery Manager<br />
RoxioNow Player<br />
Slingo Supreme<br />
Spotify<br />
Synaptics TouchPad Driver<br />
TouchCopy 12<br />
Update Installer for WildTangent Games App<br />
Vacation Quest - The Hawaiian Islands<br />
Virtual Villagers 5 - New Believers<br />
WildTangent Games App (HP Games)<br />
Windows Live Communications Platform<br />
Windows Live Essentials<br />
Windows Live ID Sign-in Assistant<br />
Windows Live Installer<br />
Windows Live Language Selector<br />
Windows Live Mail<br />
Windows Live Mesh<br />
Windows Live Mesh ActiveX Control for Remote Connections<br />
Windows Live Messenger<br />
Windows Live MIME IFilter<br />
Windows Live Movie Maker<br />
Windows Live Photo Common<br />
Windows Live Photo Gallery<br />
Windows Live PIMT Platform<br />
Windows Live Remote Client<br />
Windows Live Remote Client Resources<br />
Windows Live Remote Service<br />
Windows Live Remote Service Resources<br />
Windows Live SOXE<br />
Windows Live SOXE Definitions<br />
Windows Live UX Platform<br />
Windows Live UX Platform Language Pack<br />
Windows Live Writer<br />
Windows Live Writer Resources<br />
Yahoo! Messenger<br />
Yahoo! Software Update<br />
Yahoo! Toolbar<br />
Zuma Deluxe<br />
.<br />
==== Event Viewer Messages From Past Week ========<br />
.<br />
5/11/2013 12:35:17 PM, Error: Service Control Manager [7000]  - The Multimedia Class Scheduler service failed to start due to the following error:  The client of a component requested an operation which is not valid given the state of the component instance.<br />
5/11/2013 11:48:29 AM, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the IKEEXT service.<br />
5/11/2013 11:45:59 AM, Error: Service Control Manager [7032]  - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Multimedia Class Scheduler service, but this action failed with the following error:  An instance of the service is already running.<br />
5/11/2013 11:45:58 AM, Error: Service Control Manager [7032]  - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error:  An instance of the service is already running.<br />
5/11/2013 11:44:58 AM, Error: Service Control Manager [7032]  - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Application Experience service, but this action failed with the following error:  An instance of the service is already running.<br />
5/11/2013 11:43:58 AM, Error: Service Control Manager [7034]  - The Application Information service terminated unexpectedly.  It has done this 1 time(s).<br />
5/11/2013 11:43:58 AM, Error: Service Control Manager [7031]  - The Windows Update service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.<br />
5/11/2013 11:43:58 AM, Error: Service Control Manager [7031]  - The Windows Management Instrumentation service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.<br />
5/11/2013 11:43:58 AM, Error: Service Control Manager [7031]  - The User Profile Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.<br />
5/11/2013 11:43:58 AM, Error: Service Control Manager [7031]  - The Themes service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.<br />
5/11/2013 11:43:58 AM, Error: Service Control Manager [7031]  - The Task Scheduler service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.<br />
5/11/2013 11:43:58 AM, Error: Service Control Manager [7031]  - The System Event Notification Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.<br />
5/11/2013 11:43:58 AM, Error: Service Control Manager [7031]  - The Shell Hardware Detection service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.<br />
5/11/2013 11:43:58 AM, Error: Service Control Manager [7031]  - The Server service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.<br />
5/11/2013 11:43:58 AM, Error: Service Control Manager [7031]  - The Multimedia Class Scheduler service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.<br />
5/11/2013 11:43:58 AM, Error: Service Control Manager [7031]  - The IP Helper service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.<br />
5/11/2013 11:43:58 AM, Error: Service Control Manager [7031]  - The IKE and AuthIP IPsec Keying Modules service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.<br />
5/11/2013 11:43:58 AM, Error: Service Control Manager [7031]  - The Group Policy Client service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.<br />
5/11/2013 11:43:58 AM, Error: Service Control Manager [7031]  - The Extensible Authentication Protocol service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.<br />
5/11/2013 11:43:58 AM, Error: Service Control Manager [7031]  - The Computer Browser service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.<br />
5/11/2013 11:43:58 AM, Error: Service Control Manager [7031]  - The Background Intelligent Transfer Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.<br />
5/11/2013 11:43:58 AM, Error: Service Control Manager [7031]  - The Application Experience service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.<br />
5/11/2013 11:43:29 AM, Error: Service Control Manager [7032]  - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the User Profile Service service, but this action failed with the following error:  An instance of the service is already running.<br />
5/11/2013 11:43:29 AM, Error: Service Control Manager [7032]  - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the IKE and AuthIP IPsec Keying Modules service, but this action failed with the following error:  An instance of the service is already running.<br />
5/11/2013 11:43:29 AM, Error: Service Control Manager [7032]  - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Computer Browser service, but this action failed with the following error:  An instance of the service is already running.<br />
5/11/2013 11:42:29 AM, Error: Service Control Manager [7032]  - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Server service, but this action failed with the following error:  An instance of the service is already running.<br />
5/11/2013 11:41:26 AM, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the AeLookupSvc service.<br />
5/11/2013 11:41:26 AM, Error: Service Control Manager [7000]  - The Application Experience service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.<br />
5/11/2013 11:40:56 AM, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the wuauserv service.<br />
5/11/2013 11:40:56 AM, Error: Service Control Manager [7000]  - The Windows Update service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.<br />
5/11/2013 11:36:36 AM, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the MMCSS service.<br />
5/11/2013 11:36:36 AM, Error: Service Control Manager [7000]  - The Multimedia Class Scheduler service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.<br />
.<br />
==== End Of File ===========================<br />
<br />
GMER 2.1.19163 - <a href="http://www.gmer.net" target="_blank">http://www.gmer.net</a><br />
Rootkit scan 2013-05-11 12:20:04<br />
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -&gt; \Device\00000069 TOSHIBA_ rev.GS00 465.76GB<br />
Running: vful24gu.exe; Driver: C:\Users\matt\AppData\Local\Temp\kwldypow.sys<br />
<br />
<br />
---- Threads - GMER 2.1 ----<br />
<br />
Thread  C:\Windows\SysWOW64\ntdll.dll [2492:2496]  0000000001080d9a<br />
Thread  C:\Windows\SysWOW64\ntdll.dll [2492:4728]  000000006766e196<br />
<br />
---- EOF - GMER 2.1 ----<br />
<br />
thanks, matt</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-virus-other-malware-removal/"><![CDATA[Virus & Other Malware Removal]]></category>
			<dc:creator>mmatt2004</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/virus-other-malware-removal/1099538-ads-over-speakers-slow-computer.html</guid>
		</item>
		<item>
			<title>cannot access internet</title>
			<link>http://forums.techguy.org/windows-vista/1099537-cannot-access-internet.html</link>
			<pubDate>Thu, 23 May 2013 19:20:07 GMT</pubDate>
			<description>Tech Support Guy System Info Utility version 1.0.0.2 
OS Version: Microsoft® Windows Vista™ Home Premium, Service Pack 2, 32 bit 
Processor: Genuine Intel(R) CPU T2250 @ 1.73GHz, x86 Family 6 Model 14 Stepping 8 
Processor Count: 2 
RAM: 2045 Mb...</description>
			<content:encoded><![CDATA[<div>Tech Support Guy System Info Utility version 1.0.0.2<br />
OS Version: Microsoft® Windows Vista™ Home Premium, Service Pack 2, 32 bit<br />
Processor: Genuine Intel(R) CPU T2250 @ 1.73GHz, x86 Family 6 Model 14 Stepping 8<br />
Processor Count: 2<br />
RAM: 2045 Mb<br />
Graphics Card: ATI Mobility Radeon X1300, 64 Mb<br />
Hard Drives: C: Total - 140289 MB, Free - 71609 MB; D: Total - 10239 MB, Free - 4 MB;<br />
Motherboard: Dell Inc., 0XD720<br />
Antivirus: Microsoft Security Essentials, Updated and Enabled<br />
 <br />
I am having a problem with my PC, a dell inspiron I6400. My ISP is Verizon. The info provided above is for my laptop , but my PC also has Windows Vista home premium Service Pack 2 32 bit. <br />
I can't connect on my pc. When i try to access my network and sharing center, I get the following message:<br />
&quot;Connection status unknown. The dependency servive or group failed to start&quot;.  I called my ISP and they checked the modem and ethernet cable connection and it was operating properly. My laptop that I'm using to contact you connects wirelessly and is working fine.  Can you provide me with a fix so I can reconnect to the internet on my PC?</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/75-windows-vista/">Windows Vista</category>
			<dc:creator>pallone1</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/windows-vista/1099537-cannot-access-internet.html</guid>
		</item>
		<item>
			<title>Virus Scanners not working</title>
			<link>http://forums.techguy.org/virus-other-malware-removal/1099536-virus-scanners-not-working.html</link>
			<pubDate>Thu, 23 May 2013 18:54:57 GMT</pubDate>
			<description>Hi, 
 
Concerned I have viruses or something bad on my computer as when I try to run virus scans, they freeze the computer and so I have to close the whole thing down. 
I have tried running scans with Avast! and Malwarebytes and they both freeze. 
...</description>
			<content:encoded><![CDATA[<div>Hi,<br />
<br />
Concerned I have viruses or something bad on my computer as when I try to run virus scans, they freeze the computer and so I have to close the whole thing down.<br />
I have tried running scans with Avast! and Malwarebytes and they both freeze.<br />
<br />
I have seen a couple of dodgy programs in control panel but when I try to remove them, they come back - so basically want to make sure the computer is not infected with anything and get it back to normal.<br />
<br />
<b>HIJACK THIS</b><br />
Logfile of Trend Micro HijackThis v2.0.4<br />
Scan saved at 19:25:26, on 23/05/2013<br />
Platform: Windows 7 SP1 (WinNT 6.00.3505)<br />
MSIE: Internet Explorer v10.0 (10.00.9200.16576)<br />
Boot mode: Normal<br />
<br />
Running processes:<br />
C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe<br />
C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe<br />
C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe<br />
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe<br />
C:\Program Files\AVAST Software\Avast\AvastUI.exe<br />
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe<br />
C:\Program Files (x86)\Opera\opera.exe<br />
C:\Users\Gubbins\Desktop\HijackThis.exe<br />
<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.snap.do/?publisher=TightropeYB&amp;dpid=TightropeYB&amp;co=GB&amp;userid=e65b88a2-1a0a-4c32-b8a1-5756716edcbd&amp;searchtype=ds&amp;q={searchTerms}&amp;installDate=06/03/2013<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href="http://go.microsoft.com/fwlink/p/?LinkId=255141" target="_blank">http://go.microsoft.com/fwlink/p/?LinkId=255141</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a><br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href="http://go.microsoft.com/fwlink/p/?LinkId=255141" target="_blank">http://go.microsoft.com/fwlink/p/?LinkId=255141</a><br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snap.do/?publisher=TightropeYB&amp;dpid=TightropeYB&amp;co=GB&amp;userid=e65b88a2-1a0a-4c32-b8a1-5756716edcbd&amp;searchtype=ds&amp;q={searchTerms}&amp;installDate=06/03/2013<br />
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snap.do/?publisher=TightropeYB&amp;dpid=TightropeYB&amp;co=GB&amp;userid=e65b88a2-1a0a-4c32-b8a1-5756716edcbd&amp;searchtype=ds&amp;q={searchTerms}&amp;installDate=06/03/2013<br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <br />
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm<br />
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br />
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = <br />
F2 - REG:system.ini: UserInit=userinit.exe,<br />
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll<br />
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll<br />
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
O2 - BHO: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll<br />
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll<br />
O3 - Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - (no file)<br />
O3 - Toolbar: Nero Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll<br />
O4 - HKLM\..\Run: [NBAgent] &quot;c:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe&quot; /WinStart<br />
O4 - HKLM\..\Run: [StartCCC] &quot;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&quot; MSRun<br />
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL<br />
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP<br />
O4 - HKLM\..\Run: [KeNotify] &quot;C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe&quot; LPCM<br />
O4 - HKLM\..\Run: [TWebCamera] &quot;C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe&quot; autorun<br />
O4 - HKLM\..\Run: [avast] &quot;C:\Program Files\AVAST Software\Avast\avastUI.exe&quot; /nogui<br />
O4 - HKLM\..\Run: [APSDaemon] &quot;C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe&quot;<br />
O4 - HKLM\..\Run: [Adobe ARM] &quot;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
O4 - HKCU\..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressboot<br />
O4 - HKCU\..\Run: [FileHippo.com] &quot;C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe&quot; /background<br />
O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (User 'SYSTEM')<br />
O4 - HKUS\.DEFAULT\..\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (User 'Default user')<br />
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')<br />
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics<br />
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL<br />
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe<br />
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe<br />
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)<br />
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)<br />
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe<br />
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br />
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe<br />
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe<br />
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)<br />
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe<br />
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br />
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)<br />
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - c:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe<br />
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe<br />
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)<br />
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe<br />
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe<br />
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe<br />
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing)<br />
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe<br />
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe<br />
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)<br />
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)<br />
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)<br />
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)<br />
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)<br />
<br />
--<br />
End of file - 10608 bytes<br />
<br />
<b>DDS</b><br />
DDS (Ver_2012-11-20.01) - NTFS_AMD64 <br />
Internet Explorer: 10.0.9200.16576<br />
Run by Gubbins at 19:26:20 on 2013-05-23<br />
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.44.1033.18.2812.1504 [GMT 1:00]<br />
.<br />
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}<br />
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}<br />
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}<br />
.<br />
============== Running Processes ===============<br />
.<br />
C:\Windows\system32\lsm.exe<br />
C:\Windows\system32\svchost.exe -k DcomLaunch<br />
C:\Windows\system32\svchost.exe -k RPCSS<br />
C:\Windows\system32\atiesrxx.exe<br />
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted<br />
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted<br />
C:\Windows\system32\svchost.exe -k LocalService<br />
C:\Windows\system32\svchost.exe -k netsvcs<br />
C:\Windows\system32\svchost.exe -k NetworkService<br />
C:\Windows\system32\atieclxx.exe<br />
C:\Program Files\AVAST Software\Avast\AvastSvc.exe<br />
C:\Windows\System32\spoolsv.exe<br />
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork<br />
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe<br />
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br />
C:\Program Files\Bonjour\mDNSResponder.exe<br />
C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe<br />
c:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe<br />
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe<br />
C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe<br />
C:\Windows\system32\TODDSrv.exe<br />
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe<br />
C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe<br />
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe<br />
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE<br />
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation<br />
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe<br />
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe<br />
C:\Windows\System32\svchost.exe -k secsvcs<br />
C:\Program Files\Windows Media Player\wmpnetwk.exe<br />
C:\Windows\system32\SearchIndexer.exe<br />
C:\Windows\system32\wbem\wmiprvse.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Windows\system32\Dwm.exe<br />
C:\Windows\Explorer.EXE<br />
C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe<br />
C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe<br />
C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe<br />
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe<br />
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe<br />
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe<br />
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe<br />
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br />
C:\Windows\System32\svchost.exe -k LocalServicePeerNet<br />
C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe<br />
C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe<br />
C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe<br />
C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe<br />
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe<br />
C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe<br />
C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe<br />
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe<br />
C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe<br />
C:\Windows\system32\taskeng.exe<br />
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe<br />
C:\Program Files\AVAST Software\Avast\AvastUI.exe<br />
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe<br />
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe<br />
C:\Program Files (x86)\Opera\opera.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe<br />
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe<br />
C:\Windows\system32\SearchProtocolHost.exe<br />
C:\Windows\system32\SearchFilterHost.exe<br />
C:\Windows\system32\taskhost.exe<br />
C:\Windows\System32\cscript.exe<br />
.<br />
============== Pseudo HJT Report ===============<br />
.<br />
uSearch Bar = Preserve<br />
uSearch Page = hxxp://feed.snap.do/?publisher=TightropeYB&amp;dpid=TightropeYB&amp;co=GB&amp;userid=e65b88a2-1a0a-4c32-b8a1-5756716edcbd&amp;searchtype=ds&amp;q={searchTerms}&amp;installDate=06/03/2013<br />
uSearchAssistant = hxxp://feed.snap.do/?publisher=TightropeYB&amp;dpid=TightropeYB&amp;co=GB&amp;userid=e65b88a2-1a0a-4c32-b8a1-5756716edcbd&amp;searchtype=ds&amp;q={searchTerms}&amp;installDate=06/03/2013<br />
mWinlogon: Userinit = userinit.exe,<br />
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll<br />
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
BHO: Nero Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll<br />
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br />
BHO: TOSHIBA Media Controller Plug-in: {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll<br />
TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll<br />
TB: &lt;No Name&gt;: {ae07101b-46d4-4a98-af68-0333ea26e113} - LocalServer32 - &lt;no file&gt;<br />
TB: Nero Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll<br />
uRun: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressboot<br />
uRun: [FileHippo.com] &quot;C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe&quot; /background<br />
mRun: [NBAgent] &quot;c:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe&quot; /WinStart<br />
mRun: [StartCCC] &quot;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe&quot; MSRun<br />
mRun: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL<br />
mRun: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP<br />
mRun: [KeNotify] &quot;C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe&quot; LPCM<br />
mRun: [TWebCamera] &quot;C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe&quot; autorun<br />
mRun: [avast] &quot;C:\Program Files\AVAST Software\Avast\avastUI.exe&quot; /nogui<br />
mRun: [APSDaemon] &quot;C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe&quot;<br />
mRun: [Adobe ARM] &quot;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe&quot;<br />
dRun: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe<br />
mPolicies-Explorer: NoActiveDesktop = dword:1<br />
mPolicies-Explorer: NoActiveDesktopChanges = dword:1<br />
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5<br />
mPolicies-System: ConsentPromptBehaviorUser = dword:3<br />
mPolicies-System: EnableUIADesktopToggle = dword:0<br />
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab<br />
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab<br />
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab<br />
TCP: NameServer = 194.168.4.100 194.168.8.100<br />
TCP: Interfaces\{8D4190F4-D4B5-462F-A6C4-CB88E18C5670} : DHCPNameServer = 194.168.4.100 194.168.8.100<br />
TCP: Interfaces\{8D4190F4-D4B5-462F-A6C4-CB88E18C5670}\4596D6F6478697 : DHCPNameServer = 192.168.0.1<br />
TCP: Interfaces\{93771F3B-6276-44FE-8A45-D5313DE90EAD} : DHCPNameServer = 192.168.0.1<br />
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br />
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll<br />
SSODL: WebCheck - &lt;orphaned&gt;<br />
x64-BHO: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll<br />
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll<br />
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll<br />
x64-TB: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll<br />
x64-TB: &lt;No Name&gt;: {ae07101b-46d4-4a98-af68-0333ea26e113} - LocalServer32 - &lt;no file&gt;<br />
x64-Run: [TosNC] C:\Program Files (x86)\Toshiba\BulletinBoard\TosNcCore.exe<br />
x64-Run: [TosReelTimeMonitor] C:\Program Files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe<br />
x64-Run: [Toshiba TEMPRO] C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe<br />
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s<br />
x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3 <br />
x64-Run: [TPwrMain] C:\Program Files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE<br />
x64-Run: [SmoothView] C:\Program Files (x86)\Toshiba\SmoothView\SmoothView.exe<br />
x64-Run: [00TCrdMain] C:\Program Files (x86)\TOSHIBA\FlashCards\TCrdMain.exe<br />
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe<br />
x64-Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe<br />
x64-Run: [SmartFaceVWatcher] C:\Program Files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe<br />
x64-Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe<br />
x64-Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaReminder.exe<br />
x64-Run: [IntelliType Pro] &quot;C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe&quot;<br />
x64-Run: [IntelliPoint] &quot;C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe&quot;<br />
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - &lt;orphaned&gt;<br />
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - &lt;orphaned&gt;<br />
x64-SSODL: WebCheck - &lt;orphaned&gt;<br />
.<br />
============= SERVICES / DRIVERS ===============<br />
.<br />
R0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys [2013-3-25 65336]<br />
R0 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys [2013-3-25 189936]<br />
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2012-1-9 1025808]<br />
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2012-1-9 378432]<br />
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-11-28 203264]<br />
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2012-1-9 33400]<br />
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2012-1-9 80816]<br />
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-5-21 46808]<br />
R2 cfWiMAXService;ConfigFree WiMAX Service;C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-1-28 249200]<br />
R2 ConfigFree Service;ConfigFree Service;C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-3-10 46448]<br />
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624]<br />
R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2011-11-28 1811456]<br />
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-1 508776]<br />
R2 TeamViewer7;TeamViewer 7;C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-1-30 3027840]<br />
R2 Yontoo Desktop Updater;Yontoo Desktop Updater;C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe [2013-3-6 23552]<br />
R3 CeKbFilter;CeKbFilter;C:\Windows\System32\drivers\CeKbFilter.sys [2011-11-28 20592]<br />
R3 PGEffect;Pangu effect driver;C:\Windows\System32\drivers\PGEffect.sys [2011-11-28 35008]<br />
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-8-31 344680]<br />
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;C:\Windows\System32\drivers\rtl8192ce.sys [2011-11-28 932384]<br />
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2011-10-1 764264]<br />
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2011-10-1 268648]<br />
R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2011-10-1 25960]<br />
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2011-10-1 22376]<br />
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-1 219496]<br />
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-2-5 137560]<br />
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]<br />
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]<br />
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-2-28 161384]<br />
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2011-11-28 232992]<br />
S3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-5-11 124368]<br />
S3 TMachInfo;TMachInfo;C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2011-11-28 51512]<br />
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-1-15 59392]<br />
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-7-9 52736]<br />
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-1-13 1255736]<br />
.<br />
=============== Created Last 30 ================<br />
.<br />
2013-05-23 17:05:20	--------	d-----w-	C:\Program Files (x86)\Ask.com<br />
2013-05-21 09:53:19	--------	d-----w-	C:\Users\Gubbins\AppData\Roaming\Malwarebytes<br />
2013-05-21 09:53:03	--------	d-----w-	C:\ProgramData\Malwarebytes<br />
2013-05-21 09:53:00	25928	----a-w-	C:\Windows\System32\drivers\mbam.sys<br />
2013-05-21 09:53:00	--------	d-----w-	C:\Program Files (x86)\Malwarebytes' Anti-Malware<br />
2013-05-21 09:52:39	--------	d-----w-	C:\Users\Gubbins\AppData\Local\Programs<br />
2013-05-21 09:30:46	--------	d-----w-	C:\Program Files\iPod<br />
2013-05-21 09:30:45	--------	d-----w-	C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69<br />
2013-05-21 09:30:45	--------	d-----w-	C:\Program Files\iTunes<br />
2013-05-21 09:30:45	--------	d-----w-	C:\Program Files (x86)\iTunes<br />
2013-05-21 09:25:07	9460464	----a-w-	C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{09E7F397-A643-46BC-967F-6D9D761D8D8D}\mpengine.dll<br />
2013-05-21 07:31:27	--------	d-----w-	C:\Program Files (x86)\FileHippo.com<br />
2013-05-21 07:28:09	--------	d-----w-	C:\Users\Gubbins\AppData\Roaming\WinPatrol<br />
2013-05-21 07:28:04	--------	d-----w-	C:\ProgramData\InstallMate<br />
2013-05-21 07:28:04	--------	d-----w-	C:\Program Files (x86)\BillP Studios<br />
2013-05-01 16:52:46	108448	----a-w-	C:\Windows\System32\WindowsAccessBridge-64.dll<br />
2013-04-24 15:44:02	1656680	----a-w-	C:\Windows\System32\drivers\ntfs.sys<br />
.<br />
==================== Find3M  ====================<br />
.<br />
2013-05-15 19:15:11	71048	----a-w-	C:\Windows\SysWow64\FlashPlayerCPLApp.cpl<br />
2013-05-15 19:15:11	692104	----a-w-	C:\Windows\SysWow64\FlashPlayerApp.exe<br />
2013-05-09 08:59:07	72016	----a-w-	C:\Windows\System32\drivers\aswRdr2.sys<br />
2013-05-09 08:59:07	65336	----a-w-	C:\Windows\System32\drivers\aswRvrt.sys<br />
2013-05-09 08:59:07	189936	----a-w-	C:\Windows\System32\drivers\aswVmm.sys<br />
2013-05-09 08:59:07	1025808	----a-w-	C:\Windows\System32\drivers\aswSnx.sys<br />
2013-05-09 08:59:06	80816	----a-w-	C:\Windows\System32\drivers\aswMonFlt.sys<br />
2013-05-09 08:58:37	41664	----a-w-	C:\Windows\avastSS.scr<br />
2013-05-02 01:06:08	278800	------w-	C:\Windows\System32\MpSigStub.exe<br />
2013-05-01 16:52:39	971680	----a-w-	C:\Windows\System32\deployJava1.dll<br />
2013-05-01 16:52:39	1092512	----a-w-	C:\Windows\System32\npDeployJava1.dll<br />
2013-04-23 14:14:05	57	----a-w-	C:\ProgramData\ocejolb.bat<br />
2013-04-23 14:14:05	153	----a-w-	C:\ProgramData\ocejolb.reg<br />
2013-04-23 14:13:51	44544	----a-w-	C:\ProgramData\rundll32.exe<br />
2013-04-13 05:49:23	135168	----a-w-	C:\Windows\apppatch\AppPatch64\AcXtrnal.dll<br />
2013-04-13 05:49:19	350208	----a-w-	C:\Windows\apppatch\AppPatch64\AcLayers.dll<br />
2013-04-13 05:49:19	308736	----a-w-	C:\Windows\apppatch\AppPatch64\AcGenral.dll<br />
2013-04-13 05:49:19	111104	----a-w-	C:\Windows\apppatch\AppPatch64\acspecfc.dll<br />
2013-04-13 04:45:16	474624	----a-w-	C:\Windows\apppatch\AcSpecfc.dll<br />
2013-04-13 04:45:15	2176512	----a-w-	C:\Windows\apppatch\AcGenral.dll<br />
2013-04-10 06:01:54	265064	----a-w-	C:\Windows\System32\drivers\dxgmms1.sys<br />
2013-04-10 06:01:53	983400	----a-w-	C:\Windows\System32\drivers\dxgkrnl.sys<br />
2013-04-10 03:30:50	3153920	----a-w-	C:\Windows\System32\win32k.sys<br />
2013-04-06 06:51:22	9728	---ha-w-	C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll<br />
2013-04-05 06:52:14	2242048	----a-w-	C:\Windows\System32\wininet.dll<br />
2013-04-05 06:50:36	3958784	----a-w-	C:\Windows\System32\jscript9.dll<br />
2013-04-05 06:50:31	67072	----a-w-	C:\Windows\System32\iesetup.dll<br />
2013-04-05 06:50:31	136704	----a-w-	C:\Windows\System32\iesysprep.dll<br />
2013-04-05 05:28:24	1767424	----a-w-	C:\Windows\SysWow64\wininet.dll<br />
2013-04-05 05:26:26	2877440	----a-w-	C:\Windows\SysWow64\jscript9.dll<br />
2013-04-05 05:26:21	61440	----a-w-	C:\Windows\SysWow64\iesetup.dll<br />
2013-04-05 05:26:21	109056	----a-w-	C:\Windows\SysWow64\iesysprep.dll<br />
2013-04-05 04:43:00	2706432	----a-w-	C:\Windows\System32\mshtml.tlb<br />
2013-04-05 04:29:45	2706432	----a-w-	C:\Windows\SysWow64\mshtml.tlb<br />
2013-04-05 03:51:11	89600	----a-w-	C:\Windows\System32\RegisterIEPKEYs.exe<br />
2013-04-05 03:38:25	71680	----a-w-	C:\Windows\SysWow64\RegisterIEPKEYs.exe<br />
2013-03-19 06:04:06	5550424	----a-w-	C:\Windows\System32\ntoskrnl.exe<br />
2013-03-19 05:53:58	48640	----a-w-	C:\Windows\System32\wwanprotdim.dll<br />
2013-03-19 05:53:58	230400	----a-w-	C:\Windows\System32\wwansvc.dll<br />
2013-03-19 05:46:56	43520	----a-w-	C:\Windows\System32\csrsrv.dll<br />
2013-03-19 05:04:13	3968856	----a-w-	C:\Windows\SysWow64\ntkrnlpa.exe<br />
2013-03-19 05:04:10	3913560	----a-w-	C:\Windows\SysWow64\ntoskrnl.exe<br />
2013-03-19 04:47:50	6656	----a-w-	C:\Windows\SysWow64\apisetschema.dll<br />
2013-03-19 03:06:33	112640	----a-w-	C:\Windows\System32\smss.exe<br />
2013-02-27 06:02:44	111448	----a-w-	C:\Windows\System32\consent.exe<br />
2013-02-27 05:48:00	1930752	----a-w-	C:\Windows\System32\authui.dll<br />
2013-02-27 05:47:10	70144	----a-w-	C:\Windows\System32\appinfo.dll<br />
2013-02-27 04:49:24	1796096	----a-w-	C:\Windows\SysWow64\authui.dll<br />
.<br />
============= FINISH: 19:26:56.90 ===============<br />
<br />
<b>ATTACH</b><br />
.<br />
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.<br />
IF REQUESTED, ZIP IT UP &amp; ATTACH IT<br />
.<br />
DDS (Ver_2012-11-20.01)<br />
.<br />
Microsoft Windows 7 Home Premium <br />
Boot Device: \Device\HarddiskVolume1<br />
Install Date: 05/01/2012 17:32:22<br />
System Uptime: 23/05/2013 18:06:56 (1 hours ago)<br />
.<br />
Motherboard: TOSHIBA |  | PWWAE<br />
Processor: AMD Athlon(tm) II P360 Dual-Core Processor | Socket M2/S1G1 | 1679/200mhz<br />
.<br />
==== Disk Partitions =========================<br />
.<br />
C: is FIXED (NTFS) - 74 GiB total, 22.606 GiB free.<br />
D: is FIXED (NTFS) - 223 GiB total, 215.713 GiB free.<br />
E: is CDROM ()<br />
.<br />
==== Disabled Device Manager Items =============<br />
.<br />
==== System Restore Points ===================<br />
.<br />
RP142: 21/05/2013 08:37:06 - avast! Free Antivirus Setup<br />
RP143: 21/05/2013 10:22:30 - Windows Update<br />
RP144: 21/05/2013 10:27:41 - Installed iTunes<br />
RP145: 21/05/2013 10:42:09 - Installed Adobe Reader XI.<br />
RP146: 21/05/2013 10:49:53 - avast! Free Antivirus Setup<br />
RP147: 23/05/2013 18:03:56 - Installed Microsoft Visual C++ 2005 Redistributable<br />
.<br />
==== Installed Programs ======================<br />
.<br />
Adobe AIR<br />
Adobe Flash Player 11 ActiveX<br />
Adobe Flash Player 11 Plugin<br />
Adobe Reader XI (11.0.03)<br />
Advertising Center<br />
ALTools Update<br />
ALZip 8.51<br />
Apple Application Support<br />
Apple Mobile Device Support<br />
Apple Software Update<br />
Ask Toolbar<br />
ATI Catalyst Install Manager<br />
avast! Free Antivirus<br />
Bonjour<br />
Catalyst Control Center - Branding<br />
Catalyst Control Center Graphics Previews Common<br />
Catalyst Control Center Graphics Previews Vista<br />
Catalyst Control Center InstallProxy<br />
Catalyst Control Center Localization All<br />
ccc-core-static<br />
ccc-utility64<br />
CCC Help Chinese Standard<br />
CCC Help Chinese Traditional<br />
CCC Help Czech<br />
CCC Help Danish<br />
CCC Help Dutch<br />
CCC Help English<br />
CCC Help Finnish<br />
CCC Help French<br />
CCC Help German<br />
CCC Help Greek<br />
CCC Help Hungarian<br />
CCC Help Italian<br />
CCC Help Japanese<br />
CCC Help Korean<br />
CCC Help Norwegian<br />
CCC Help Polish<br />
CCC Help Portuguese<br />
CCC Help Russian<br />
CCC Help Spanish<br />
CCC Help Swedish<br />
CCC Help Thai<br />
CCC Help Turkish<br />
FastStone Image Viewer 4.7<br />
FileHippo.com Update Checker<br />
ImagXpress<br />
iTunes<br />
Java 7 Update 21 (64-bit)<br />
Java Auto Updater<br />
Java(TM) 6 Update 20<br />
Malwarebytes Anti-Malware version 1.75.0.1300<br />
Microsoft .NET Framework 4 Client Profile<br />
Microsoft Mouse and Keyboard Center<br />
Microsoft Office 2010<br />
Microsoft Office Click-to-Run 2010<br />
Microsoft Office Starter 2010 - English<br />
Microsoft Silverlight<br />
Microsoft Visual C++ 2005 Redistributable<br />
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17<br />
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148<br />
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161<br />
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319<br />
MSXML 4.0 SP2 (KB954430)<br />
MSXML 4.0 SP2 (KB973688)<br />
Nero 9 Essentials<br />
Nero BackItUp<br />
Nero BackItUp and Burn<br />
Nero BurnRights<br />
Nero BurnRights Help<br />
Nero ControlCenter<br />
Nero DiscSpeed<br />
Nero DiscSpeed Help<br />
Nero DriveSpeed<br />
Nero DriveSpeed Help<br />
Nero Express<br />
Nero Express Help<br />
Nero InfoTool<br />
Nero InfoTool Help<br />
Nero Installer<br />
Nero Online Upgrade<br />
Nero RescueAgent<br />
Nero StartSmart<br />
Nero StartSmart Help<br />
NeroExpress<br />
neroxml<br />
Opera 12.15<br />
Photo Service - powered by myphotobook<br />
PlayReady PC Runtime amd64<br />
Realtek Ethernet Controller Driver For Windows 7<br />
Realtek High Definition Audio Driver<br />
Realtek USB 2.0 Card Reader<br />
Realtek WLAN Driver<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)<br />
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)<br />
Skype Click to Call<br />
Skype™ 6.3<br />
Synaptics Pointing Device Driver<br />
TeamViewer 7<br />
TOSHIBA Assist<br />
TOSHIBA Bulletin Board<br />
TOSHIBA ConfigFree<br />
TOSHIBA Disc Creator<br />
TOSHIBA Face Recognition<br />
TOSHIBA Flash Cards Support Utility<br />
TOSHIBA Hardware Setup<br />
TOSHIBA HDD/SSD Alert<br />
Toshiba Manuals<br />
TOSHIBA Media Controller<br />
TOSHIBA Media Controller Plug-in<br />
TOSHIBA Online Product Information<br />
TOSHIBA Recovery Media Creator<br />
TOSHIBA Recovery Media Creator Reminder<br />
TOSHIBA ReelTime<br />
TOSHIBA Service Station<br />
TOSHIBA Supervisor Password<br />
Toshiba TEMPRO<br />
TOSHIBA Value Added Package<br />
TOSHIBA Web Camera Application<br />
TRORMCLauncher<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)<br />
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)<br />
Utility Common Driver<br />
Windows Live Sync<br />
Windows Live Upload Tool<br />
WinPatrol<br />
Yontoo 2.04.1<br />
.<br />
==== Event Viewer Messages From Past Week ========<br />
.<br />
21/05/2013 16:40:45, Error: ACPI [13]  - : The embedded controller (EC) did not respond within the specified timeout period. This may indicate that there is an error in the EC hardware or firmware or that the BIOS is accessing the EC incorrectly. You should check with your computer manufacturer for an upgraded BIOS. In some situations, this error may cause the computer to function incorrectly.<br />
21/05/2013 12:40:52, Error: Service Control Manager [7022]  - The Windows Update service hung on starting.<br />
21/05/2013 10:27:36, Error: Service Control Manager [7031]  - The Apple Mobile Device service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.<br />
19/05/2013 08:54:14, Error: Microsoft-Windows-Bits-Client [16398]  - A new BITS job could not be created. The current job count for the user Gubbins-TOSH\Gubbins (60) is equal to or greater than the job limit (60) specified through group policy.  To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error, and restart the BITS service. If this error recurs, contact your system administrator and increate the per-user and per-computer Group Policy job limits.<br />
.<br />
==== End Of File ===========================<br />
<br />
<b>ARK</b><br />
GMER 2.1.19163 - <a href="http://www.gmer.net" target="_blank">http://www.gmer.net</a><br />
Rootkit scan 2013-05-23 19:41:17<br />
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -&gt; \Device\0000005b TOSHIBA_ rev.GH10 298.09GB<br />
Running: oqjelw3l.exe; Driver: C:\Users\Gubbins\AppData\Local\Temp\pxliapog.sys<br />
<br />
<br />
---- Kernel code sections - GMER 2.1 ----<br />
<br />
INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 560                                                                                        fffff80002df5000 13 bytes [D2, 48, 8B, CB, E8, DF, C2, ...]<br />
INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 574                                                                                        fffff80002df500e 3 bytes [00, 00, 00]<br />
<br />
---- User code sections - GMER 2.1 ----<br />
<br />
.text     C:\Windows\system32\wininit.exe[516] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                000000007725eecd 1 byte [62]<br />
.text     C:\Windows\system32\services.exe[580] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                               000000007725eecd 1 byte [62]<br />
.text     C:\Windows\system32\winlogon.exe[688] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                               000000007725eecd 1 byte [62]<br />
.text     C:\Windows\system32\svchost.exe[752] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                000000007725eecd 1 byte [62]<br />
.text     C:\Windows\system32\atiesrxx.exe[896] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                               000000007725eecd 1 byte [62]<br />
.text     C:\Windows\System32\svchost.exe[968] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                000000007725eecd 1 byte [62]<br />
.text     C:\Windows\System32\svchost.exe[112] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                000000007725eecd 1 byte [62]<br />
.text     C:\Windows\system32\svchost.exe[368] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                000000007725eecd 1 byte [62]<br />
.text     C:\Windows\system32\svchost.exe[432] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                000000007725eecd 1 byte [62]<br />
.text     C:\Windows\system32\svchost.exe[1132] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                               000000007725eecd 1 byte [62]<br />
.text     C:\Windows\System32\spoolsv.exe[1504] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                               000000007725eecd 1 byte [62]<br />
.text     C:\Windows\system32\svchost.exe[1540] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                               000000007725eecd 1 byte [62]<br />
.text     C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1616] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                  00000000752ba30a 1 byte [62]<br />
.text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1648] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112  00000000752ba30a 1 byte [62]<br />
.text     C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe[1736] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                       00000000752ba30a 1 byte [62]<br />
.text     c:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe[1780] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                        00000000752ba30a 1 byte [62]<br />
.text     C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe[2032] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                 00000000752ba30a 1 byte [62]<br />
.text     C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe[1576] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                             00000000752ba30a 1 byte [62]<br />
.text     C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe[1060] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                             000000007725eecd 1 byte [62]<br />
.text     C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe[2148] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                                           00000000752ba30a 1 byte [62]<br />
.text     C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe[2624] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory                000000007751faa0 5 bytes JMP 0000000100030600<br />
.text     C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe[2624] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory                    000000007751fb38 5 bytes JMP 0000000100030804<br />
.text     C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe[2624] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                     000000007751fc90 5 bytes JMP 0000000100030c0c<br />
.text     C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe[2624] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                 0000000077520018 5 bytes JMP 0000000100030a08<br />
.text     C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe[2624] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                     0000000077521900 5 bytes JMP 0000000100030e10<br />
.text     C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe[2624] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                             000000007753c45a 5 bytes JMP 00000001000301f8<br />
.text     C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe[2624] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                           0000000077541217 5 bytes JMP 00000001000303fc<br />
.text     C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe[2624] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                00000000752ba30a 1 byte [62]<br />
.text     C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe[2624] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity             0000000075eb5181 5 bytes JMP 0000000100181014<br />
.text     C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe[2624] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA                 0000000075eb5254 5 bytes JMP 0000000100180804<br />
.text     C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe[2624] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW                 0000000075eb53d5 5 bytes JMP 0000000100180a08<br />
.text     C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe[2624] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A                0000000075eb54c2 5 bytes JMP 0000000100180c0c<br />
.text     C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe[2624] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W                0000000075eb55e2 5 bytes JMP 0000000100180e10<br />
.text     C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe[2624] C:\Windows\SysWOW64\sechost.dll!CreateServiceA                       0000000075eb567c 5 bytes JMP 00000001001801f8<br />
.text     C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe[2624] C:\Windows\SysWOW64\sechost.dll!CreateServiceW                       0000000075eb589f 5 bytes JMP 00000001001803fc<br />
.text     C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe[2624] C:\Windows\SysWOW64\sechost.dll!DeleteService                        0000000075eb5a22 5 bytes JMP 0000000100180600<br />
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2876] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory        000000007751faa0 5 bytes JMP 0000000100030600<br />
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2876] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory            000000007751fb38 5 bytes JMP 0000000100030804<br />
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2876] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess             000000007751fc90 5 bytes JMP 0000000100030c0c<br />
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2876] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory         0000000077520018 5 bytes JMP 0000000100030a08<br />
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2876] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread             0000000077521900 5 bytes JMP 0000000100030e10<br />
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2876] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                     000000007753c45a 5 bytes JMP 00000001000301f8<br />
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2876] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                   0000000077541217 5 bytes JMP 00000001000303fc<br />
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2876] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112        00000000752ba30a 1 byte [62]<br />
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2876] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity     0000000075eb5181 5 bytes JMP 00000001001c1014<br />
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2876] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA         0000000075eb5254 5 bytes JMP 00000001001c0804<br />
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2876] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW         0000000075eb53d5 5 bytes JMP 00000001001c0a08<br />
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2876] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A        0000000075eb54c2 3 bytes JMP 00000001001c0c0c<br />
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2876] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A + 4    0000000075eb54c6 1 byte [8A]<br />
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2876] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W        0000000075eb55e2 5 bytes JMP 00000001001c0e10<br />
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2876] C:\Windows\SysWOW64\sechost.dll!CreateServiceA               0000000075eb567c 5 bytes JMP 00000001001c01f8<br />
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2876] C:\Windows\SysWOW64\sechost.dll!CreateServiceW               0000000075eb589f 5 bytes JMP 00000001001c03fc<br />
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2876] C:\Windows\SysWOW64\sechost.dll!DeleteService                0000000075eb5a22 5 bytes JMP 00000001001c0600<br />
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2876] C:\Windows\syswow64\USER32.dll!SetWinEventHook               0000000075a2ee09 5 bytes JMP 00000001001d01f8<br />
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2876] C:\Windows\syswow64\USER32.dll!UnhookWinEvent                0000000075a33982 5 bytes JMP 00000001001d03fc<br />
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2876] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW             0000000075a37603 5 bytes JMP 00000001001d0804<br />
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2876] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA             0000000075a3835c 5 bytes JMP 00000001001d0600<br />
.text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[2876] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx           0000000075a4f52b 5 bytes JMP 00000001001d0a08<br />
.text     C:\Windows\system32\svchost.exe[3004] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                          0000000077343ae0 5 bytes JMP 000000010018075c<br />
.text     C:\Windows\system32\svchost.exe[3004] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                            0000000077347a90 5 bytes JMP 00000001001803a4<br />
.text     C:\Windows\system32\svchost.exe[3004] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                                               0000000077371490 5 bytes JMP 0000000100180b14<br />
.text     C:\Windows\system32\svchost.exe[3004] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                                                   00000000773714f0 5 bytes JMP 0000000100180ecc<br />
.text     C:\Windows\system32\svchost.exe[3004] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                    00000000773715d0 5 bytes JMP 000000010018163c<br />
.text     C:\Windows\system32\svchost.exe[3004] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                                                0000000077371810 5 bytes JMP 0000000100181284<br />
.text     C:\Windows\system32\svchost.exe[3004] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                    0000000077372840 5 bytes JMP 00000001001819f4<br />
.text     C:\Windows\system32\svchost.exe[3004] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                                               000000007725eecd 1 byte [62]<br />
.text     C:\Windows\system32\svchost.exe[3004] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                                            000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Windows\system32\svchost.exe[3004] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                                                000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Windows\system32\svchost.exe[3004] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                                                000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Windows\system32\svchost.exe[3004] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                                               000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Windows\system32\svchost.exe[3004] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                                               000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Windows\system32\svchost.exe[3004] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                                      000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Windows\system32\svchost.exe[3004] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                                      000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Windows\system32\svchost.exe[3004] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                                       000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                               0000000077343ae0 5 bytes JMP 000000010042075c<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                 0000000077347a90 5 bytes JMP 00000001004203a4<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                    0000000077371490 5 bytes JMP 0000000100420b14<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                        00000000773714f0 5 bytes JMP 0000000100420ecc<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                         00000000773715d0 5 bytes JMP 000000010042163c<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                     0000000077371810 5 bytes JMP 0000000100421284<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                         0000000077372840 5 bytes JMP 00000001004219f4<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe[3400] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                 000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe[3400] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                     000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe[3400] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                     000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe[3400] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                    000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe[3400] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                    000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe[3400] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                           000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe[3400] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                           000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe[3400] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                            000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe[3484] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory                                          000000007751faa0 5 bytes JMP 0000000100240600<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe[3484] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory                                              000000007751fb38 5 bytes JMP 0000000100240804<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe[3484] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                               000000007751fc90 5 bytes JMP 0000000100240c0c<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe[3484] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                                           0000000077520018 5 bytes JMP 0000000100240a08<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe[3484] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                                               0000000077521900 5 bytes JMP 0000000100240e10<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe[3484] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                                       000000007753c45a 5 bytes JMP 00000001002401f8<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe[3484] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                                     0000000077541217 5 bytes JMP 00000001002403fc<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe[3484] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                                          00000000752ba30a 1 byte [62]<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe[3484] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                                 0000000075a2ee09 5 bytes JMP 00000001002501f8<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe[3484] C:\Windows\syswow64\USER32.dll!UnhookWinEvent                                                  0000000075a33982 5 bytes JMP 00000001002503fc<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe[3484] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                               0000000075a37603 5 bytes JMP 0000000100250804<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe[3484] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                               0000000075a3835c 5 bytes JMP 0000000100250600<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe[3484] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx                                             0000000075a4f52b 5 bytes JMP 0000000100250a08<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe[3484] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity                                       0000000075eb5181 5 bytes JMP 0000000100261014<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe[3484] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA                                           0000000075eb5254 5 bytes JMP 0000000100260804<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe[3484] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW                                           0000000075eb53d5 5 bytes JMP 0000000100260a08<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe[3484] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A                                          0000000075eb54c2 5 bytes JMP 0000000100260c0c<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe[3484] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W                                          0000000075eb55e2 5 bytes JMP 0000000100260e10<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe[3484] C:\Windows\SysWOW64\sechost.dll!CreateServiceA                                                 0000000075eb567c 5 bytes JMP 00000001002601f8<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe[3484] C:\Windows\SysWOW64\sechost.dll!CreateServiceW                                                 0000000075eb589f 5 bytes JMP 00000001002603fc<br />
.text     C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe[3484] C:\Windows\SysWOW64\sechost.dll!DeleteService                                                  0000000075eb5a22 5 bytes JMP 0000000100260600<br />
.text     C:\Windows\System32\svchost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                          0000000077343ae0 5 bytes JMP 000000010021075c<br />
.text     C:\Windows\System32\svchost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                            0000000077347a90 5 bytes JMP 00000001002103a4<br />
.text     C:\Windows\System32\svchost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                                               0000000077371490 5 bytes JMP 0000000100210b14<br />
.text     C:\Windows\System32\svchost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                                                   00000000773714f0 5 bytes JMP 0000000100210ecc<br />
.text     C:\Windows\System32\svchost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                    00000000773715d0 5 bytes JMP 000000010021163c<br />
.text     C:\Windows\System32\svchost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                                                0000000077371810 5 bytes JMP 0000000100211284<br />
.text     C:\Windows\System32\svchost.exe[3548] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                    0000000077372840 5 bytes JMP 00000001002119f4<br />
.text     C:\Windows\System32\svchost.exe[3548] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                                            000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Windows\System32\svchost.exe[3548] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                                                000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Windows\System32\svchost.exe[3548] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                                                000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Windows\System32\svchost.exe[3548] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                                               000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Windows\System32\svchost.exe[3548] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                                               000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Windows\System32\svchost.exe[3548] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                                      000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Windows\System32\svchost.exe[3548] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                                      000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Windows\System32\svchost.exe[3548] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                                       000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Program Files\Windows Media Player\wmpnetwk.exe[3604] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                            000000007725eecd 1 byte [62]<br />
.text     C:\Windows\system32\SearchIndexer.exe[3764] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                    0000000077343ae0 5 bytes JMP 000000010029075c<br />
.text     C:\Windows\system32\SearchIndexer.exe[3764] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                      0000000077347a90 5 bytes JMP 00000001002903a4<br />
.text     C:\Windows\system32\SearchIndexer.exe[3764] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                                         0000000077371490 5 bytes JMP 0000000100290b14<br />
.text     C:\Windows\system32\SearchIndexer.exe[3764] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                                             00000000773714f0 5 bytes JMP 0000000100290ecc<br />
.text     C:\Windows\system32\SearchIndexer.exe[3764] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                              00000000773715d0 5 bytes JMP 000000010029163c<br />
.text     C:\Windows\system32\SearchIndexer.exe[3764] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                                          0000000077371810 5 bytes JMP 0000000100291284<br />
.text     C:\Windows\system32\SearchIndexer.exe[3764] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                              0000000077372840 5 bytes JMP 00000001002919f4<br />
.text     C:\Windows\system32\SearchIndexer.exe[3764] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                                         000000007725eecd 1 byte [62]<br />
.text     C:\Windows\system32\SearchIndexer.exe[3764] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                                      000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Windows\system32\SearchIndexer.exe[3764] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                                          000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Windows\system32\SearchIndexer.exe[3764] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                                          000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Windows\system32\SearchIndexer.exe[3764] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                                         000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Windows\system32\SearchIndexer.exe[3764] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                                         000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Windows\system32\SearchIndexer.exe[3764] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                                000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Windows\system32\SearchIndexer.exe[3764] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                                000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Windows\system32\SearchIndexer.exe[3764] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                                 000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Windows\system32\wbem\wmiprvse.exe[4048] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                    0000000077343ae0 5 bytes JMP 000000010030075c<br />
.text     C:\Windows\system32\wbem\wmiprvse.exe[4048] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                      0000000077347a90 5 bytes JMP 00000001003003a4<br />
.text     C:\Windows\system32\wbem\wmiprvse.exe[4048] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                                         0000000077371490 5 bytes JMP 0000000100300b14<br />
.text     C:\Windows\system32\wbem\wmiprvse.exe[4048] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                                             00000000773714f0 5 bytes JMP 0000000100300ecc<br />
.text     C:\Windows\system32\wbem\wmiprvse.exe[4048] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                              00000000773715d0 5 bytes JMP 000000010030163c<br />
.text     C:\Windows\system32\wbem\wmiprvse.exe[4048] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                                          0000000077371810 5 bytes JMP 0000000100301284<br />
.text     C:\Windows\system32\wbem\wmiprvse.exe[4048] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                              0000000077372840 5 bytes JMP 00000001003019f4<br />
.text     C:\Windows\system32\wbem\wmiprvse.exe[4048] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                                         000000007725eecd 1 byte [62]<br />
.text     C:\Windows\system32\wbem\wmiprvse.exe[4048] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                                      000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Windows\system32\wbem\wmiprvse.exe[4048] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                                          000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Windows\system32\wbem\wmiprvse.exe[4048] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                                          000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Windows\system32\wbem\wmiprvse.exe[4048] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                                         000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Windows\system32\wbem\wmiprvse.exe[4048] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                                         000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Windows\system32\wbem\wmiprvse.exe[4048] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                                000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Windows\system32\wbem\wmiprvse.exe[4048] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                                000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Windows\system32\wbem\wmiprvse.exe[4048] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                                 000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Windows\system32\taskhost.exe[1972] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                         0000000077343ae0 5 bytes JMP 000000010016075c<br />
.text     C:\Windows\system32\taskhost.exe[1972] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                           0000000077347a90 5 bytes JMP 00000001001603a4<br />
.text     C:\Windows\system32\taskhost.exe[1972] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                                              0000000077371490 5 bytes JMP 0000000100160b14<br />
.text     C:\Windows\system32\taskhost.exe[1972] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                                                  00000000773714f0 5 bytes JMP 0000000100160ecc<br />
.text     C:\Windows\system32\taskhost.exe[1972] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                   00000000773715d0 5 bytes JMP 000000010016163c<br />
.text     C:\Windows\system32\taskhost.exe[1972] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                                               0000000077371810 5 bytes JMP 0000000100161284<br />
.text     C:\Windows\system32\taskhost.exe[1972] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                   0000000077372840 5 bytes JMP 00000001001619f4<br />
.text     C:\Windows\system32\taskhost.exe[1972] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                                              000000007725eecd 1 byte [62]<br />
.text     C:\Windows\system32\taskhost.exe[1972] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                                           000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Windows\system32\taskhost.exe[1972] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                                               000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Windows\system32\taskhost.exe[1972] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                                               000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Windows\system32\taskhost.exe[1972] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                                              000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Windows\system32\taskhost.exe[1972] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                                              000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Windows\system32\taskhost.exe[1972] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                                     000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Windows\system32\taskhost.exe[1972] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                                     000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Windows\system32\taskhost.exe[1972] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                                      000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Windows\system32\Dwm.exe[2924] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                              0000000077343ae0 5 bytes JMP 000000010028075c<br />
.text     C:\Windows\system32\Dwm.exe[2924] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                                0000000077347a90 5 bytes JMP 00000001002803a4<br />
.text     C:\Windows\system32\Dwm.exe[2924] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                                                   0000000077371490 5 bytes JMP 0000000100280b14<br />
.text     C:\Windows\system32\Dwm.exe[2924] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                                                       00000000773714f0 5 bytes JMP 0000000100280ecc<br />
.text     C:\Windows\system32\Dwm.exe[2924] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                        00000000773715d0 5 bytes JMP 000000010028163c<br />
.text     C:\Windows\system32\Dwm.exe[2924] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                                                    0000000077371810 5 bytes JMP 0000000100281284<br />
.text     C:\Windows\system32\Dwm.exe[2924] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                        0000000077372840 5 bytes JMP 00000001002819f4<br />
.text     C:\Windows\system32\Dwm.exe[2924] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                                                000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Windows\system32\Dwm.exe[2924] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                                                    000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Windows\system32\Dwm.exe[2924] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                                                    000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Windows\system32\Dwm.exe[2924] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                                                   000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Windows\system32\Dwm.exe[2924] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                                                   000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Windows\system32\Dwm.exe[2924] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                                          000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Windows\system32\Dwm.exe[2924] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                                          000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Windows\system32\Dwm.exe[2924] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                                           000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Windows\Explorer.EXE[2788] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                                  0000000077343ae0 5 bytes JMP 000000010025075c<br />
.text     C:\Windows\Explorer.EXE[2788] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                                    0000000077347a90 5 bytes JMP 00000001002503a4<br />
.text     C:\Windows\Explorer.EXE[2788] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                                                       0000000077371490 5 bytes JMP 0000000100250b14<br />
.text     C:\Windows\Explorer.EXE[2788] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                                                           00000000773714f0 5 bytes JMP 0000000100250ecc<br />
.text     C:\Windows\Explorer.EXE[2788] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                            00000000773715d0 5 bytes JMP 000000010025163c<br />
.text     C:\Windows\Explorer.EXE[2788] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                                                        0000000077371810 5 bytes JMP 0000000100251284<br />
.text     C:\Windows\Explorer.EXE[2788] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                            0000000077372840 5 bytes JMP 00000001002519f4<br />
.text     C:\Windows\Explorer.EXE[2788] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                                                       000000007725eecd 1 byte [62]<br />
.text     C:\Windows\Explorer.EXE[2788] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                                                    000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Windows\Explorer.EXE[2788] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                                                        000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Windows\Explorer.EXE[2788] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                                                        000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Windows\Explorer.EXE[2788] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                                                       000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Windows\Explorer.EXE[2788] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                                                       000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Windows\Explorer.EXE[2788] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                                              000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Windows\Explorer.EXE[2788] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                                              000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Windows\Explorer.EXE[2788] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                                               000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe[2704] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                     0000000077343ae0 5 bytes JMP 00000001002b075c<br />
.text     C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe[2704] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                       0000000077347a90 5 bytes JMP 00000001002b03a4<br />
.text     C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe[2704] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                          0000000077371490 5 bytes JMP 00000001002b0b14<br />
.text     C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe[2704] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                              00000000773714f0 5 bytes JMP 00000001002b0ecc<br />
.text     C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe[2704] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                               00000000773715d0 5 bytes JMP 00000001002b163c<br />
.text     C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe[2704] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                           0000000077371810 5 bytes JMP 00000001002b1284<br />
.text     C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe[2704] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                               0000000077372840 5 bytes JMP 00000001002b19f4<br />
.text     C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe[2704] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                          000000007725eecd 1 byte [62]<br />
.text     C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe[2704] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                       000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe[2704] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                           000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe[2704] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                           000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe[2704] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                          000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe[2704] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                          000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe[2704] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                 000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe[2704] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                 000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe[2704] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                  000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe[3176] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                 0000000077343ae0 5 bytes JMP 00000001002c075c<br />
.text     C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe[3176] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                   0000000077347a90 5 bytes JMP 00000001002c03a4<br />
.text     C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe[3176] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                      0000000077371490 5 bytes JMP 00000001002c0b14<br />
.text     C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe[3176] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                          00000000773714f0 5 bytes JMP 00000001002c0ecc<br />
.text     C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe[3176] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                           00000000773715d0 5 bytes JMP 00000001002c163c<br />
.text     C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe[3176] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                       0000000077371810 5 bytes JMP 00000001002c1284<br />
.text     C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe[3176] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                           0000000077372840 5 bytes JMP 00000001002c19f4<br />
.text     C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe[3176] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                      000000007725eecd 1 byte [62]<br />
.text     C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe[3176] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                   000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe[3176] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                       000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe[3176] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                       000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe[3176] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                      000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe[3176] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                      000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe[3176] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                             000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe[3176] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                             000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe[3176] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                              000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe[2604] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                     0000000077343ae0 5 bytes JMP 000000010032075c<br />
.text     C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe[2604] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                       0000000077347a90 5 bytes JMP 00000001003203a4<br />
.text     C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe[2604] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                          0000000077371490 5 bytes JMP 0000000100320b14<br />
.text     C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe[2604] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                              00000000773714f0 5 bytes JMP 0000000100320ecc<br />
.text     C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe[2604] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                               00000000773715d0 5 bytes JMP 000000010032163c<br />
.text     C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe[2604] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                           0000000077371810 5 bytes JMP 0000000100321284<br />
.text     C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe[2604] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                               0000000077372840 5 bytes JMP 00000001003219f4<br />
.text     C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe[2604] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                          000000007725eecd 1 byte [62]<br />
.text     C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe[2604] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                       000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe[2604] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                           000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe[2604] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                           000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe[2604] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                          000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe[2604] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                          000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe[2604] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                 000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe[2604] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                 000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe[2604] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                  000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[988] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                           0000000077343ae0 5 bytes JMP 000000010025075c<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[988] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                             0000000077347a90 5 bytes JMP 00000001002503a4<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[988] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                                0000000077371490 5 bytes JMP 0000000100250b14<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[988] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                                    00000000773714f0 5 bytes JMP 0000000100250ecc<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[988] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                     00000000773715d0 5 bytes JMP 000000010025163c<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[988] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                                 0000000077371810 5 bytes JMP 0000000100251284<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[988] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                     0000000077372840 5 bytes JMP 00000001002519f4<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[988] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                                000000007725eecd 1 byte [62]<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[988] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                             000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[988] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                                 000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[988] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                                 000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[988] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                                000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[988] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                                000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[988] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                       000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[988] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                       000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[988] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                        000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3432] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                           0000000077343ae0 5 bytes JMP 00000001003c075c<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3432] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                             0000000077347a90 5 bytes JMP 00000001003c03a4<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3432] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                                0000000077371490 5 bytes JMP 00000001003c0b14<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3432] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                                    00000000773714f0 5 bytes JMP 00000001003c0ecc<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3432] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                     00000000773715d0 5 bytes JMP 00000001003c163c<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3432] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                                 0000000077371810 5 bytes JMP 00000001003c1284<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3432] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                     0000000077372840 5 bytes JMP 00000001003c19f4<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3432] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                                000000007725eecd 1 byte [62]<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3432] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                             000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3432] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                                 000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3432] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                                 000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3432] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                                000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3432] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                                000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3432] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                       000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3432] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                       000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3432] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                        000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2380] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                        0000000077343ae0 5 bytes JMP 00000001003b075c<br />
.text     C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2380] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                          0000000077347a90 5 bytes JMP 00000001003b03a4<br />
.text     C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2380] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                             0000000077371490 5 bytes JMP 00000001003b0b14<br />
.text     C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2380] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                                 00000000773714f0 5 bytes JMP 00000001003b0ecc<br />
.text     C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2380] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                  00000000773715d0 5 bytes JMP 00000001003b163c<br />
.text     C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2380] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                              0000000077371810 5 bytes JMP 00000001003b1284<br />
.text     C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2380] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                  0000000077372840 5 bytes JMP 00000001003b19f4<br />
.text     C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2380] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                             000000007725eecd 1 byte [62]<br />
.text     C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2380] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                          000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2380] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                              000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2380] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                              000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2380] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                             000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2380] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                             000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2380] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                    000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2380] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                    000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[2380] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                     000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1396] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                         000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1396] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                             000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1396] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                             000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1396] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                            000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1396] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                            000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1396] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                   000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1396] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                   000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[1396] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                    000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3820] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                         0000000077343ae0 5 bytes JMP 00000001005f075c<br />
.text     C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3820] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                           0000000077347a90 5 bytes JMP 00000001005f03a4<br />
.text     C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3820] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                              0000000077371490 5 bytes JMP 00000001005f0b14<br />
.text     C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3820] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                                  00000000773714f0 5 bytes JMP 00000001005f0ecc<br />
.text     C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3820] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                   00000000773715d0 5 bytes JMP 00000001005f163c<br />
.text     C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3820] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                               0000000077371810 5 bytes JMP 00000001005f1284<br />
.text     C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3820] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                   0000000077372840 5 bytes JMP 00000001005f19f4<br />
.text     C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3820] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                              000000007725eecd 1 byte [62]<br />
.text     C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3820] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                           000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3820] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                               000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3820] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                               000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3820] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                              000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3820] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                              000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3820] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                     000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3820] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                     000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe[3820] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                      000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3692] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                            0000000077343ae0 5 bytes JMP 00000001003c075c<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3692] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                              0000000077347a90 5 bytes JMP 00000001003c03a4<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3692] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                                 0000000077371490 5 bytes JMP 00000001003c0b14<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3692] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                                     00000000773714f0 5 bytes JMP 00000001003c0ecc<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3692] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                      00000000773715d0 5 bytes JMP 00000001003c163c<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3692] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                                  0000000077371810 5 bytes JMP 00000001003c1284<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3692] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                      0000000077372840 5 bytes JMP 00000001003c19f4<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3692] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                                 000000007725eecd 1 byte [62]<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3692] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                              000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3692] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                                  000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3692] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                                  000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3692] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                                 000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3692] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                                 000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3692] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                        000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3692] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                        000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3692] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                         000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Windows\System32\svchost.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                          0000000077343ae0 5 bytes JMP 000000010046075c<br />
.text     C:\Windows\System32\svchost.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                            0000000077347a90 5 bytes JMP 00000001004603a4<br />
.text     C:\Windows\System32\svchost.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                                               0000000077371490 5 bytes JMP 0000000100460b14<br />
.text     C:\Windows\System32\svchost.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                                                   00000000773714f0 5 bytes JMP 0000000100460ecc<br />
.text     C:\Windows\System32\svchost.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                    00000000773715d0 5 bytes JMP 000000010046163c<br />
.text     C:\Windows\System32\svchost.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                                                0000000077371810 5 bytes JMP 0000000100461284<br />
.text     C:\Windows\System32\svchost.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                    0000000077372840 5 bytes JMP 00000001004619f4<br />
.text     C:\Windows\System32\svchost.exe[3780] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                                            000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Windows\System32\svchost.exe[3780] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                                                000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Windows\System32\svchost.exe[3780] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                                                000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Windows\System32\svchost.exe[3780] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                                               000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Windows\System32\svchost.exe[3780] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                                               000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Windows\System32\svchost.exe[3780] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                                      000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Windows\System32\svchost.exe[3780] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                                      000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Windows\System32\svchost.exe[3780] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                                       000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe[3204] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                0000000077343ae0 5 bytes JMP 00000001001a075c<br />
.text     C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe[3204] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                  0000000077347a90 5 bytes JMP 00000001001a03a4<br />
.text     C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe[3204] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                     0000000077371490 5 bytes JMP 00000001001a0b14<br />
.text     C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe[3204] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                         00000000773714f0 5 bytes JMP 00000001001a0ecc<br />
.text     C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe[3204] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                          00000000773715d0 5 bytes JMP 00000001001a163c<br />
.text     C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe[3204] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                      0000000077371810 5 bytes JMP 00000001001a1284<br />
.text     C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe[3204] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                          0000000077372840 5 bytes JMP 00000001001a19f4<br />
.text     C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe[3204] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                     000000007725eecd 1 byte [62]<br />
.text     C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe[3204] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                  000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe[3204] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                      000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe[3204] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                      000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe[3204] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                     000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe[3204] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                     000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe[3204] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                            000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe[3204] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                            000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe[3204] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                             000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe[2596] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                           0000000077343ae0 5 bytes JMP 000000010044075c<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe[2596] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                             0000000077347a90 5 bytes JMP 00000001004403a4<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe[2596] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                0000000077371490 5 bytes JMP 0000000100440b14<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe[2596] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                    00000000773714f0 5 bytes JMP 0000000100440ecc<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe[2596] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                     00000000773715d0 5 bytes JMP 000000010044163c<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe[2596] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                 0000000077371810 5 bytes JMP 0000000100441284<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe[2596] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                     0000000077372840 5 bytes JMP 00000001004419f4<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe[2596] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                             000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe[2596] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                 000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe[2596] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                 000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe[2596] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe[2596] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe[2596] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                       000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe[2596] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                       000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe[2596] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                        000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe[3268] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                          0000000077343ae0 5 bytes JMP 000000010020075c<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe[3268] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                            0000000077347a90 5 bytes JMP 00000001002003a4<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe[3268] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                               0000000077371490 5 bytes JMP 0000000100200b14<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe[3268] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                   00000000773714f0 5 bytes JMP 0000000100200ecc<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe[3268] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                    00000000773715d0 5 bytes JMP 000000010020163c<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe[3268] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                0000000077371810 5 bytes JMP 0000000100201284<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe[3268] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                    0000000077372840 5 bytes JMP 00000001002019f4<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe[3268] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                            000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe[3268] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe[3268] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe[3268] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                               000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe[3268] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                               000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe[3268] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                      000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe[3268] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                      000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe[3268] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                       000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory                                  000000007751faa0 5 bytes JMP 0000000100030600<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory                                      000000007751fb38 5 bytes JMP 0000000100030804<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                       000000007751fc90 5 bytes JMP 0000000100030c0c<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                                   0000000077520018 5 bytes JMP 0000000100030a08<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                                       0000000077521900 5 bytes JMP 0000000100030e10<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                               000000007753c45a 5 bytes JMP 00000001000301f8<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                             0000000077541217 5 bytes JMP 00000001000303fc<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                                  00000000752ba30a 1 byte [62]<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                00000000760f1465 2 bytes [0F, 76]<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                               00000000760f14bb 2 bytes [0F, 76]<br />
.text     ...                                                                                                                                                       * 2<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                         0000000075a2ee09 5 bytes JMP 00000001001401f8<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\syswow64\USER32.dll!UnhookWinEvent                                          0000000075a33982 5 bytes JMP 00000001001403fc<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                       0000000075a37603 5 bytes JMP 0000000100140804<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                       0000000075a3835c 5 bytes JMP 0000000100140600<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx                                     0000000075a4f52b 5 bytes JMP 0000000100140a08<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity                               0000000075eb5181 5 bytes JMP 0000000100151014<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA                                   0000000075eb5254 5 bytes JMP 0000000100150804<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW                                   0000000075eb53d5 5 bytes JMP 0000000100150a08<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A                                  0000000075eb54c2 5 bytes JMP 0000000100150c0c<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W                                  0000000075eb55e2 5 bytes JMP 0000000100150e10<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\SysWOW64\sechost.dll!CreateServiceA                                         0000000075eb567c 5 bytes JMP 00000001001501f8<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\SysWOW64\sechost.dll!CreateServiceW                                         0000000075eb589f 5 bytes JMP 00000001001503fc<br />
.text     C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3088] C:\Windows\SysWOW64\sechost.dll!DeleteService                                          0000000075eb5a22 5 bytes JMP 0000000100150600<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3140] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                           000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3140] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                               000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3140] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                               000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3140] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                              000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3140] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                              000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3140] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                     000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3140] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                     000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3140] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                      000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe[3960] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                   0000000077343ae0 5 bytes JMP 00000001003c075c<br />
.text     C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe[3960] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                     0000000077347a90 5 bytes JMP 00000001003c03a4<br />
.text     C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe[3960] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                        0000000077371490 5 bytes JMP 00000001003c0b14<br />
.text     C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe[3960] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                            00000000773714f0 5 bytes JMP 00000001003c0ecc<br />
.text     C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe[3960] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                             00000000773715d0 5 bytes JMP 00000001003c163c<br />
.text     C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe[3960] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                         0000000077371810 5 bytes JMP 00000001003c1284<br />
.text     C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe[3960] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                             0000000077372840 5 bytes JMP 00000001003c19f4<br />
.text     C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe[3960] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                        000000007725eecd 1 byte [62]<br />
.text     C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe[3960] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                     000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe[3960] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                         000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe[3960] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                         000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe[3960] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                        000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe[3960] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                        000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe[3960] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                               000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe[3960] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                               000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe[3960] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe[1232] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory                    000000007751faa0 5 bytes JMP 0000000100030600<br />
.text     C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe[1232] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory                        000000007751fb38 5 bytes JMP 0000000100030804<br />
.text     C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe[1232] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                         000000007751fc90 5 bytes JMP 0000000100030c0c<br />
.text     C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe[1232] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                     0000000077520018 5 bytes JMP 0000000100030a08<br />
.text     C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe[1232] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                         0000000077521900 5 bytes JMP 0000000100030e10<br />
.text     C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe[1232] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                 000000007753c45a 5 bytes JMP 00000001000301f8<br />
.text     C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe[1232] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                               0000000077541217 5 bytes JMP 00000001000303fc<br />
.text     C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe[1232] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                    00000000752ba30a 1 byte [62]<br />
.text     C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe[1232] C:\Windows\syswow64\USER32.dll!SetWinEventHook                           0000000075a2ee09 5 bytes JMP 00000001002401f8<br />
.text     C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe[1232] C:\Windows\syswow64\USER32.dll!UnhookWinEvent                            0000000075a33982 5 bytes JMP 00000001002403fc<br />
.text     C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe[1232] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                         0000000075a37603 5 bytes JMP 0000000100240804<br />
.text     C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe[1232] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                         0000000075a3835c 5 bytes JMP 0000000100240600<br />
.text     C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe[1232] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx                       0000000075a4f52b 5 bytes JMP 0000000100240a08<br />
.text     C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe[1232] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity                 0000000075eb5181 5 bytes JMP 0000000100251014<br />
.text     C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe[1232] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA                     0000000075eb5254 5 bytes JMP 0000000100250804<br />
.text     C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe[1232] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW                     0000000075eb53d5 5 bytes JMP 0000000100250a08<br />
.text     C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe[1232] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A                    0000000075eb54c2 5 bytes JMP 0000000100250c0c<br />
.text     C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe[1232] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W                    0000000075eb55e2 5 bytes JMP 0000000100250e10<br />
.text     C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe[1232] C:\Windows\SysWOW64\sechost.dll!CreateServiceA                           0000000075eb567c 5 bytes JMP 00000001002501f8<br />
.text     C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe[1232] C:\Windows\SysWOW64\sechost.dll!CreateServiceW                           0000000075eb589f 5 bytes JMP 00000001002503fc<br />
.text     C:\Program Files (x86)\Nero\Nero BackItUp &amp; Burn\Nero BackItUp\NBAgent.exe[1232] C:\Windows\SysWOW64\sechost.dll!DeleteService                            0000000075eb5a22 5 bytes JMP 0000000100250600<br />
.text     C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3356] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                      0000000077343ae0 5 bytes JMP 00000001001e075c<br />
.text     C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3356] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                        0000000077347a90 5 bytes JMP 00000001001e03a4<br />
.text     C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3356] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                           0000000077371490 5 bytes JMP 00000001001e0b14<br />
.text     C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3356] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                               00000000773714f0 5 bytes JMP 00000001001e0ecc<br />
.text     C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3356] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                00000000773715d0 5 bytes JMP 00000001001e163c<br />
.text     C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3356] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                            0000000077371810 5 bytes JMP 00000001001e1284<br />
.text     C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3356] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                0000000077372840 5 bytes JMP 00000001001e19f4<br />
.text     C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe[2040] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory                                         000000007751faa0 5 bytes JMP 0000000100030600<br />
.text     C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe[2040] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory                                             000000007751fb38 5 bytes JMP 0000000100030804<br />
.text     C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe[2040] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                              000000007751fc90 5 bytes JMP 0000000100030c0c<br />
.text     C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe[2040] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                                          0000000077520018 5 bytes JMP 0000000100030a08<br />
.text     C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe[2040] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                                              0000000077521900 5 bytes JMP 0000000100030e10<br />
.text     C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe[2040] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                                      000000007753c45a 5 bytes JMP 00000001000301f8<br />
.text     C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe[2040] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                                    0000000077541217 5 bytes JMP 00000001000303fc<br />
.text     C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe[2040] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                                         00000000752ba30a 1 byte [62]<br />
.text     C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe[2040] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                                0000000075a2ee09 5 bytes JMP 00000001002401f8<br />
.text     C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe[2040] C:\Windows\syswow64\USER32.dll!UnhookWinEvent                                                 0000000075a33982 5 bytes JMP 00000001002403fc<br />
.text     C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe[2040] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                              0000000075a37603 5 bytes JMP 0000000100240804<br />
.text     C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe[2040] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                              0000000075a3835c 5 bytes JMP 0000000100240600<br />
.text     C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe[2040] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx                                            0000000075a4f52b 5 bytes JMP 0000000100240a08<br />
.text     C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe[2040] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity                                      0000000075eb5181 5 bytes JMP 0000000100251014<br />
.text     C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe[2040] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA                                          0000000075eb5254 5 bytes JMP 0000000100250804<br />
.text     C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe[2040] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW                                          0000000075eb53d5 5 bytes JMP 0000000100250a08<br />
.text     C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe[2040] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A                                         0000000075eb54c2 5 bytes JMP 0000000100250c0c<br />
.text     C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe[2040] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W                                         0000000075eb55e2 5 bytes JMP 0000000100250e10<br />
.text     C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe[2040] C:\Windows\SysWOW64\sechost.dll!CreateServiceA                                                0000000075eb567c 5 bytes JMP 00000001002501f8<br />
.text     C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe[2040] C:\Windows\SysWOW64\sechost.dll!CreateServiceW                                                0000000075eb589f 5 bytes JMP 00000001002503fc<br />
.text     C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe[2040] C:\Windows\SysWOW64\sechost.dll!DeleteService                                                 0000000075eb5a22 5 bytes JMP 0000000100250600<br />
.text     C:\Windows\system32\taskeng.exe[4108] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                          0000000077343ae0 5 bytes JMP 00000001003a075c<br />
.text     C:\Windows\system32\taskeng.exe[4108] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                            0000000077347a90 5 bytes JMP 00000001003a03a4<br />
.text     C:\Windows\system32\taskeng.exe[4108] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                                               0000000077371490 5 bytes JMP 00000001003a0b14<br />
.text     C:\Windows\system32\taskeng.exe[4108] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                                                   00000000773714f0 5 bytes JMP 00000001003a0ecc<br />
.text     C:\Windows\system32\taskeng.exe[4108] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                    00000000773715d0 5 bytes JMP 00000001003a163c<br />
.text     C:\Windows\system32\taskeng.exe[4108] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                                                0000000077371810 5 bytes JMP 00000001003a1284<br />
.text     C:\Windows\system32\taskeng.exe[4108] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                    0000000077372840 5 bytes JMP 00000001003a19f4<br />
.text     C:\Windows\system32\taskeng.exe[4108] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                                            000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Windows\system32\taskeng.exe[4108] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                                                000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Windows\system32\taskeng.exe[4108] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                                                000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Windows\system32\taskeng.exe[4108] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                                               000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Windows\system32\taskeng.exe[4108] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                                               000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Windows\system32\taskeng.exe[4108] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                                      000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Windows\system32\taskeng.exe[4108] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                                      000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Windows\system32\taskeng.exe[4108] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                                       000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Program Files\AVAST Software\Avast\AvastUI.exe[4448] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                             00000000752ba30a 1 byte [62]<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4992] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                           0000000077343ae0 5 bytes JMP 000000010033075c<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4992] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                             0000000077347a90 5 bytes JMP 00000001003303a4<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4992] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                0000000077371490 5 bytes JMP 0000000100330b14<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4992] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                    00000000773714f0 5 bytes JMP 0000000100330ecc<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4992] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                     00000000773715d0 5 bytes JMP 000000010033163c<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4992] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                 0000000077371810 5 bytes JMP 0000000100331284<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4992] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                     0000000077372840 5 bytes JMP 00000001003319f4<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4992] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                000000007725eecd 1 byte [62]<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4992] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                             000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4992] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                 000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4992] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                 000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4992] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4992] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4992] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                       000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4992] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                       000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe[4992] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                        000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[4856] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                           0000000077343ae0 5 bytes JMP 000000010026075c<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[4856] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                             0000000077347a90 5 bytes JMP 00000001002603a4<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[4856] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                0000000077371490 5 bytes JMP 0000000100260b14<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[4856] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                    00000000773714f0 5 bytes JMP 0000000100260ecc<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[4856] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                     00000000773715d0 5 bytes JMP 000000010026163c<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[4856] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                 0000000077371810 5 bytes JMP 0000000100261284<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[4856] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                     0000000077372840 5 bytes JMP 00000001002619f4<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[4856] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                000000007725eecd 1 byte [62]<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[4856] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                             000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[4856] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                 000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[4856] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                 000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[4856] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[4856] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[4856] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                       000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[4856] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                       000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe[4856] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                        000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Windows\system32\taskhost.exe[3128] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                         0000000077343ae0 5 bytes JMP 000000010017075c<br />
.text     C:\Windows\system32\taskhost.exe[3128] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                           0000000077347a90 5 bytes JMP 00000001001703a4<br />
.text     C:\Windows\system32\taskhost.exe[3128] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                                              0000000077371490 5 bytes JMP 0000000100170b14<br />
.text     C:\Windows\system32\taskhost.exe[3128] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                                                  00000000773714f0 5 bytes JMP 0000000100170ecc<br />
.text     C:\Windows\system32\taskhost.exe[3128] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                                   00000000773715d0 5 bytes JMP 000000010017163c<br />
.text     C:\Windows\system32\taskhost.exe[3128] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                                               0000000077371810 5 bytes JMP 0000000100171284<br />
.text     C:\Windows\system32\taskhost.exe[3128] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                   0000000077372840 5 bytes JMP 00000001001719f4<br />
.text     C:\Windows\system32\taskhost.exe[3128] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                                              000000007725eecd 1 byte [62]<br />
.text     C:\Windows\system32\taskhost.exe[3128] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                                           000007fefee76e00 5 bytes JMP 000007ff7ee91dac<br />
.text     C:\Windows\system32\taskhost.exe[3128] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                                               000007fefee76f2c 5 bytes JMP 000007ff7ee90ecc<br />
.text     C:\Windows\system32\taskhost.exe[3128] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                                               000007fefee77220 5 bytes JMP 000007ff7ee91284<br />
.text     C:\Windows\system32\taskhost.exe[3128] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                                              000007fefee7739c 5 bytes JMP 000007ff7ee9163c<br />
.text     C:\Windows\system32\taskhost.exe[3128] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                                              000007fefee77538 5 bytes JMP 000007ff7ee919f4<br />
.text     C:\Windows\system32\taskhost.exe[3128] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                                                     000007fefee775e8 5 bytes JMP 000007ff7ee903a4<br />
.text     C:\Windows\system32\taskhost.exe[3128] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                                                     000007fefee7790c 5 bytes JMP 000007ff7ee9075c<br />
.text     C:\Windows\system32\taskhost.exe[3128] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                                                      000007fefee77ab4 5 bytes JMP 000007ff7ee90b14<br />
.text     C:\Users\Gubbins\Desktop\oqjelw3l.exe[4188] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory                                                         000000007751faa0 5 bytes JMP 0000000100030600<br />
.text     C:\Users\Gubbins\Desktop\oqjelw3l.exe[4188] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory                                                             000000007751fb38 5 bytes JMP 0000000100030804<br />
.text     C:\Users\Gubbins\Desktop\oqjelw3l.exe[4188] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                                              000000007751fc90 5 bytes JMP 0000000100030c0c<br />
.text     C:\Users\Gubbins\Desktop\oqjelw3l.exe[4188] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                                                          0000000077520018 5 bytes JMP 0000000100030a08<br />
.text     C:\Users\Gubbins\Desktop\oqjelw3l.exe[4188] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                                                              0000000077521900 5 bytes JMP 0000000100030e10<br />
.text     C:\Users\Gubbins\Desktop\oqjelw3l.exe[4188] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                                                      000000007753c45a 5 bytes JMP 00000001000301f8<br />
.text     C:\Users\Gubbins\Desktop\oqjelw3l.exe[4188] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                                                    0000000077541217 5 bytes JMP 00000001000303fc<br />
.text     C:\Users\Gubbins\Desktop\oqjelw3l.exe[4188] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                                                         00000000752ba30a 1 byte [62]<br />
.text     C:\Users\Gubbins\Desktop\oqjelw3l.exe[4188] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity                                                      0000000075eb5181 5 bytes JMP 0000000100241014<br />
.text     C:\Users\Gubbins\Desktop\oqjelw3l.exe[4188] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA                                                          0000000075eb5254 5 bytes JMP 0000000100240804<br />
.text     C:\Users\Gubbins\Desktop\oqjelw3l.exe[4188] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW                                                          0000000075eb53d5 5 bytes JMP 0000000100240a08<br />
.text     C:\Users\Gubbins\Desktop\oqjelw3l.exe[4188] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A                                                         0000000075eb54c2 5 bytes JMP 0000000100240c0c<br />
.text     C:\Users\Gubbins\Desktop\oqjelw3l.exe[4188] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W                                                         0000000075eb55e2 5 bytes JMP 0000000100240e10<br />
.text     C:\Users\Gubbins\Desktop\oqjelw3l.exe[4188] C:\Windows\SysWOW64\sechost.dll!CreateServiceA                                                                0000000075eb567c 5 bytes JMP 00000001002401f8<br />
.text     C:\Users\Gubbins\Desktop\oqjelw3l.exe[4188] C:\Windows\SysWOW64\sechost.dll!CreateServiceW                                                                0000000075eb589f 5 bytes JMP 00000001002403fc<br />
.text     C:\Users\Gubbins\Desktop\oqjelw3l.exe[4188] C:\Windows\SysWOW64\sechost.dll!DeleteService                                                                 0000000075eb5a22 5 bytes JMP 0000000100240600<br />
.text     C:\Users\Gubbins\Desktop\oqjelw3l.exe[4188] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                                                0000000075a2ee09 5 bytes JMP 00000001002601f8<br />
.text     C:\Users\Gubbins\Desktop\oqjelw3l.exe[4188] C:\Windows\syswow64\USER32.dll!UnhookWinEvent                                                                 0000000075a33982 5 bytes JMP 00000001002603fc<br />
.text     C:\Users\Gubbins\Desktop\oqjelw3l.exe[4188] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                                              0000000075a37603 5 bytes JMP 0000000100260804<br />
.text     C:\Users\Gubbins\Desktop\oqjelw3l.exe[4188] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                                              0000000075a3835c 5 bytes JMP 0000000100260600<br />
.text     C:\Users\Gubbins\Desktop\oqjelw3l.exe[4188] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx                                                            0000000075a4f52b 5 bytes JMP 0000000100260a08<br />
<br />
---- Threads - GMER 2.1 ----<br />
<br />
Thread    C:\Windows\system32\svchost.exe [1540:1712]                                                                                                               000007fef30b2888<br />
Thread    C:\Windows\system32\svchost.exe [1540:2636]                                                                                                               000007fef30b2a40<br />
Thread    C:\Windows\System32\svchost.exe [3548:3980]                                                                                                               000007fef5b79688<br />
Thread    C:\Program Files\Windows Media Player\wmpnetwk.exe [3604:3648]                                                                                            000007fefd9a0168<br />
Thread    C:\Program Files\Windows Media Player\wmpnetwk.exe [3604:3680]                                                                                            000007fefb7f2a7c<br />
Thread    C:\Program Files\Windows Media Player\wmpnetwk.exe [3604:3688]                                                                                            000007fef621d618<br />
Thread    C:\Program Files\Windows Media Player\wmpnetwk.exe [3604:3956]                                                                                            000007fef9555124<br />
Thread    C:\Program Files\Windows Media Player\wmpnetwk.exe [3604:4032]                                                                                            000007fef61b9730<br />
Thread    C:\Program Files\Windows Media Player\wmpnetwk.exe [3604:4036]                                                                                            000007fef621d618<br />
<br />
---- Registry - GMER 2.1 ----<br />
<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Type                                                                                                      2<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Start                                                                                                     2<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@ErrorControl                                                                                              1<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@DisplayName                                                                                               aswFsBlk<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Group                                                                                                     FSFilter Activity Monitor<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@DependOnService                                                                                           FltMgr?<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Description                                                                                               avast! mini-filter driver (aswFsBlk)<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Tag                                                                                                       2<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances                                                                                                 <br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances@DefaultInstance                                                                                 aswFsBlk Instance<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances\aswFsBlk Instance                                                                               <br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances\aswFsBlk Instance@Altitude                                                                      388400<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances\aswFsBlk Instance@Flags                                                                         0<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk                                                                                                           <br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Type                                                                                                     2<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Start                                                                                                    2<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@ErrorControl                                                                                             1<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@ImagePath                                                                                                \??\C:\Windows\system32\drivers\aswMonFlt.sys<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@DisplayName                                                                                              aswMonFlt<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Group                                                                                                    FSFilter Anti-Virus<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@DependOnService                                                                                          FltMgr?<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Description                                                                                              avast! mini-filter driver (aswMonFlt)<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances                                                                                                <br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances@DefaultInstance                                                                                aswMonFlt Instance<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances\aswMonFlt Instance                                                                             <br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances\aswMonFlt Instance@Altitude                                                                    320700<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances\aswMonFlt Instance@Flags                                                                       0<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt                                                                                                          <br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Type                                                                                                        1<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Start                                                                                                       1<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr@ErrorControl                                                                                                1<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr@DisplayName                                                                                                 aswRdr<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Group                                                                                                       PNP_TDI<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr@DependOnService                                                                                             tcpip?<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Description                                                                                                 avast! WFP Redirect driver<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr@ImagePath                                                                                                   \SystemRoot\System32\Drivers\aswrdr2.sys<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr\Parameters                                                                                                  <br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr\Parameters@MSIgnoreLSPDefault                                                                               <br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr\Parameters@WSIgnoreLSPDefault                                                                               nl_lsp.dll,imon.dll,xfire_lsp.dll,mslsp.dll,mssplsp.dll,cwhook.dll,spi.dll,  bmnet.dll,winsflt.dll<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr                                                                                                             <br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@Type                                                                                                       1<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@Start                                                                                                      0<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@ErrorControl                                                                                               1<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@DisplayName                                                                                                aswRvrt<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@Description                                                                                                avast! Revert<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters                                                                                                 <br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@BootCounter                                                                                     9<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@TickCounter                                                                                     108477<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@SystemRoot                                                                                      \Device\Harddisk0\Partition2\Windows<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@ImproperShutdown                                                                                1<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRvrt                                                                                                            <br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Type                                                                                                        2<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Start                                                                                                       1<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx@ErrorControl                                                                                                1<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx@DisplayName                                                                                                 aswSnx<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Group                                                                                                       FSFilter Virtualization<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx@DependOnService                                                                                             FltMgr?<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Description                                                                                                 avast! virtualization driver (aswSnx)<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Tag                                                                                                         2<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances                                                                                                   <br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances@DefaultInstance                                                                                   aswSnx Instance<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances\aswSnx Instance                                                                                   <br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances\aswSnx Instance@Altitude                                                                          137600<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances\aswSnx Instance@Flags                                                                             0<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Parameters                                                                                                  <br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Parameters@ProgramFolder                                                                                    \DosDevices\C:\Program Files\AVAST Software\Avast<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Parameters@DataFolder                                                                                       \DosDevices\C:\ProgramData\AVAST Software\Avast<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx                                                                                                             <br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP@Type                                                                                                         1<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP@Start                                                                                                        1<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP@ErrorControl                                                                                                 1<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP@DisplayName                                                                                                  aswSP<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP@Description                                                                                                  avast! Self Protection<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters                                                                                                   <br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@BehavShield                                                                                       1<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@ProgramFolder                                                                                     \DosDevices\C:\Program Files\AVAST Software\Avast<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@DataFolder                                                                                        \DosDevices\C:\ProgramData\AVAST Software\Avast<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@ProgramFilesFolder                                                                                \DosDevices\C:\Program Files<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@GadgetFolder                                                                                      \DosDevices\C:\Program Files\Windows Sidebar\Shared Gadgets\aswSidebar.gadget<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP                                                                                                              <br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Type                                                                                                        1<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Start                                                                                                       1<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswTdi@ErrorControl                                                                                                1<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswTdi@DisplayName                                                                                                 avast! Network Shield Support<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Group                                                                                                       PNP_TDI<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswTdi@DependOnService                                                                                             tcpip?<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Description                                                                                                 avast! Network Shield TDI driver<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Tag                                                                                                         10<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswTdi                                                                                                             <br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswVmm@Type                                                                                                        1<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswVmm@Start                                                                                                       0<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswVmm@ErrorControl                                                                                                1<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswVmm@DisplayName                                                                                                 aswVmm<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswVmm@Description                                                                                                 avast! VM Monitor<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswVmm\Parameters                                                                                                  <br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswVmm                                                                                                             <br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Type                                                                                              32<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Start                                                                                             2<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ErrorControl                                                                                      1<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ImagePath                                                                                         &quot;C:\Program Files\AVAST Software\Avast\AvastSvc.exe&quot;<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@DisplayName                                                                                       avast! Antivirus<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Group                                                                                             ShellSvcGroup<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@DependOnService                                                                                   aswMonFlt?RpcSS?<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@WOW64                                                                                             1<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ObjectName                                                                                        LocalSystem<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ServiceSidType                                                                                    1<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Description                                                                                       Manages and implements avast! antivirus services for this computer. This includes the resident protection, the virus chest and the scheduler.<br />
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus                                                                                                   <br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Type                                                                                                          2<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Start                                                                                                         2<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk@ErrorControl                                                                                                  1<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk@DisplayName                                                                                                   aswFsBlk<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Group                                                                                                         FSFilter Activity Monitor<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk@DependOnService                                                                                               FltMgr?<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Description                                                                                                   avast! mini-filter driver (aswFsBlk)<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Tag                                                                                                           2<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances (not active ControlSet)                                                                             <br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances@DefaultInstance                                                                                     aswFsBlk Instance<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances\aswFsBlk Instance (not active ControlSet)                                                           <br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances\aswFsBlk Instance@Altitude                                                                          388400<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances\aswFsBlk Instance@Flags                                                                             0<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Type                                                                                                         2<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Start                                                                                                        2<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt@ErrorControl                                                                                                 1<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt@ImagePath                                                                                                    \??\C:\Windows\system32\drivers\aswMonFlt.sys<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt@DisplayName                                                                                                  aswMonFlt<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Group                                                                                                        FSFilter Anti-Virus<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt@DependOnService                                                                                              FltMgr?<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Description                                                                                                  avast! mini-filter driver (aswMonFlt)<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances (not active ControlSet)                                                                            <br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances@DefaultInstance                                                                                    aswMonFlt Instance<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances\aswMonFlt Instance (not active ControlSet)                                                         <br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances\aswMonFlt Instance@Altitude                                                                        320700<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances\aswMonFlt Instance@Flags                                                                           0<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswRdr@Type                                                                                                            1<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswRdr@Start                                                                                                           1<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswRdr@ErrorControl                                                                                                    1<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswRdr@DisplayName                                                                                                     aswRdr<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswRdr@Group                                                                                                           PNP_TDI<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswRdr@DependOnService                                                                                                 tcpip?<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswRdr@Description                                                                                                     avast! WFP Redirect driver<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswRdr@ImagePath                                                                                                       \SystemRoot\System32\Drivers\aswrdr2.sys<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswRdr\Parameters (not active ControlSet)                                                                              <br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswRdr\Parameters@MSIgnoreLSPDefault                                                                                   <br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswRdr\Parameters@WSIgnoreLSPDefault                                                                                   nl_lsp.dll,imon.dll,xfire_lsp.dll,mslsp.dll,mssplsp.dll,cwhook.dll,spi.dll,  bmnet.dll,winsflt.dll<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswRvrt@Type                                                                                                           1<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswRvrt@Start                                                                                                          0<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswRvrt@ErrorControl                                                                                                   1<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswRvrt@DisplayName                                                                                                    aswRvrt<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswRvrt@Description                                                                                                    avast! Revert<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters (not active ControlSet)                                                                             <br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@BootCounter                                                                                         9<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@TickCounter                                                                                         108477<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@SystemRoot                                                                                          \Device\Harddisk0\Partition2\Windows<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@ImproperShutdown                                                                                    1<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx@Type                                                                                                            2<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx@Start                                                                                                           1<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx@ErrorControl                                                                                                    1<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx@DisplayName                                                                                                     aswSnx<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx@Group                                                                                                           FSFilter Virtualization<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx@DependOnService                                                                                                 FltMgr?<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx@Description                                                                                                     avast! virtualization driver (aswSnx)<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx@Tag                                                                                                             2<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances (not active ControlSet)                                                                               <br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances@DefaultInstance                                                                                       aswSnx Instance<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances\aswSnx Instance (not active ControlSet)                                                               <br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances\aswSnx Instance@Altitude                                                                              137600<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances\aswSnx Instance@Flags                                                                                 0<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx\Parameters (not active ControlSet)                                                                              <br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx\Parameters@ProgramFolder                                                                                        \DosDevices\C:\Program Files\AVAST Software\Avast<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx\Parameters@DataFolder                                                                                           \DosDevices\C:\ProgramData\AVAST Software\Avast<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP@Type                                                                                                             1<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP@Start                                                                                                            1<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP@ErrorControl                                                                                                     1<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP@DisplayName                                                                                                      aswSP<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP@Description                                                                                                      avast! Self Protection<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters (not active ControlSet)                                                                               <br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@BehavShield                                                                                           1<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@ProgramFolder                                                                                         \DosDevices\C:\Program Files\AVAST Software\Avast<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@DataFolder                                                                                            \DosDevices\C:\ProgramData\AVAST Software\Avast<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@ProgramFilesFolder                                                                                    \DosDevices\C:\Program Files<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@GadgetFolder                                                                                          \DosDevices\C:\Program Files\Windows Sidebar\Shared Gadgets\aswSidebar.gadget<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswTdi@Type                                                                                                            1<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswTdi@Start                                                                                                           1<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswTdi@ErrorControl                                                                                                    1<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswTdi@DisplayName                                                                                                     avast! Network Shield Support<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswTdi@Group                                                                                                           PNP_TDI<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswTdi@DependOnService                                                                                                 tcpip?<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswTdi@Description                                                                                                     avast! Network Shield TDI driver<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswTdi@Tag                                                                                                             10<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswVmm@Type                                                                                                            1<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswVmm@Start                                                                                                           0<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswVmm@ErrorControl                                                                                                    1<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswVmm@DisplayName                                                                                                     aswVmm<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswVmm@Description                                                                                                     avast! VM Monitor<br />
Reg       HKLM\SYSTEM\ControlSet002\services\aswVmm\Parameters (not active ControlSet)                                                                              <br />
Reg       HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Type                                                                                                  32<br />
Reg       HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Start                                                                                                 2<br />
Reg       HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ErrorControl                                                                                          1<br />
Reg       HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ImagePath                                                                                             &quot;C:\Program Files\AVAST Software\Avast\AvastSvc.exe&quot;<br />
Reg       HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@DisplayName                                                                                           avast! Antivirus<br />
Reg       HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Group                                                                                                 ShellSvcGroup<br />
Reg       HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@DependOnService                                                                                       aswMonFlt?RpcSS?<br />
Reg       HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@WOW64                                                                                                 1<br />
Reg       HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ObjectName                                                                                            LocalSystem<br />
Reg       HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ServiceSidType                                                                                        1<br />
Reg       HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Description                                                                                           Manages and implements avast! antivirus services for this computer. This includes the resident protection, the virus chest and the scheduler.<br />
<br />
---- EOF - GMER 2.1 ----<br />
<br />
Many thanks,<br />
Gubbo</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-virus-other-malware-removal/"><![CDATA[Virus & Other Malware Removal]]></category>
			<dc:creator>Gubbo</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/virus-other-malware-removal/1099536-virus-scanners-not-working.html</guid>
		</item>
		<item>
			<title><![CDATA[[file name]contained a virus and was deleted"]]></title>
			<link>http://forums.techguy.org/virus-other-malware-removal/1099535-file-name-contained-virus-deleted.html</link>
			<pubDate>Thu, 23 May 2013 18:44:47 GMT</pubDate>
			<description>I have a two computer network protected by a Sonicwall firewall. About a week ago I was on the internet and a virus warning popped up from my then installed security software Zone Alarm. Afterwards, my connection to the internet was lost but on one...</description>
			<content:encoded><![CDATA[<div>I have a two computer network protected by a Sonicwall firewall. About a week ago I was on the internet and a virus warning popped up from my then installed security software Zone Alarm. Afterwards, my connection to the internet was lost but on one machine only. After much work, I restored internet access but had to delete Zone Alarm. From the time I restored internet access I have not been able to download ANY file without getting the message: <b>&quot;[file name] contained a virus and was deleted&quot;.</b> In addition to IE9 that I normally use, I tried Firefox and Chrome with the same results. I've explored the options for security settings and have tried them all, but since ALL browsers are affected, I suspect a virus. I tried to reinstall Zone Alarm, but it immediately stopped my internet access again, so I uninstalled it. Note TSG still thinks it's installed.<br />
 <br />
<br />
OS Version: Microsoft Windows 7 Professional, Service Pack 1, 32 bit<br />
Processor: Pentium(R) Dual-Core CPU E6700 @ 3.20GHz, x64 Family 6 Model 23 Stepping 10<br />
Processor Count: 2<br />
RAM: 3293 Mb<br />
Graphics Card: Intel(R) G41 Express Chipset, 1422 Mb<br />
Hard Drives: C: Total - 476837 MB, Free - 442073 MB;<br />
Motherboard: MSI, G41M4 (MS-7592)<br />
Antivirus: ZoneAlarm Antivirus, Updated and Enabled</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/54-virus-other-malware-removal/"><![CDATA[Virus & Other Malware Removal]]></category>
			<dc:creator>dfloyd_chef</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/virus-other-malware-removal/1099535-file-name-contained-virus-deleted.html</guid>
		</item>
		<item>
			<title>Outlook 2007 message: offline folder file cannot be configured</title>
			<link>http://forums.techguy.org/business-applications/1099534-outlook-2007-message-offline-folder.html</link>
			<pubDate>Thu, 23 May 2013 18:29:06 GMT</pubDate>
			<description>The day after my latest Win 7 Update, I suddenly started getting the error message: 
 
MICROSOFT OFFICE OUTLOOK OFFLINE FOLDERS: 
Your offline folder file cannot be configured. 
 
c:\Users\Scott\AppData\Local\Microsoft\Outlook\outlook.ost 
 
Besides...</description>
			<content:encoded><![CDATA[<div>The day after my latest Win 7 Update, I suddenly started getting the error message:<br />
<br />
MICROSOFT OFFICE OUTLOOK OFFLINE FOLDERS:<br />
Your offline folder file cannot be configured.<br />
<br />
c:\Users\Scott\AppData\Local\Microsoft\Outlook\outlook.ost<br />
<br />
Besides this message, my emails struggle to open, I cannot attach files to outgoing emails, etc.  I tried the Recovery function, to take my laptop to a date prior to the Windows Update I did on 5/21, but it couldn't execute for that date, or for prior dates (which may be another separate problem to deal with). I don't know what to do, other than possibly reinstall Office. Advice?</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/16-business-applications/">Business Applications</category>
			<dc:creator>SmallBizBoss</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/business-applications/1099534-outlook-2007-message-offline-folder.html</guid>
		</item>
		<item>
			<title>Windows startup failure</title>
			<link>http://forums.techguy.org/windows-7/1099532-windows-startup-failure.html</link>
			<pubDate>Thu, 23 May 2013 18:08:45 GMT</pubDate>
			<description>I have an ASUS K60IJ laptop in which Windows 7 will start on battery, but not with the charger plugged in.  If the charger is plugged in, it will cause the computer to reboot continously.  I have tried a new charger with the same results so it is...</description>
			<content:encoded><![CDATA[<div>I have an ASUS K60IJ laptop in which Windows 7 will start on battery, but not with the charger plugged in.  If the charger is plugged in, it will cause the computer to reboot continously.  I have tried a new charger with the same results so it is not the charger.  The computer will run in BIOS boot with battery and charger connected.  But if the charger remains connected during windows startup, it will reboot.  I have tried with the battery removed from the computer with the same results.  I have run PC cleaner software and Norton 360 without solving the problem.  Since the computer will run in BIOS with the charger connected, I am thinking it is a startup virus.  I would like to know if others have similar problems with possible solutions.</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/86-windows-7/">Windows 7</category>
			<dc:creator>J3deff</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/windows-7/1099532-windows-startup-failure.html</guid>
		</item>
		<item>
			<title><![CDATA[Program Won't Install]]></title>
			<link>http://forums.techguy.org/all-other-software/1099531-program-wont-install.html</link>
			<pubDate>Thu, 23 May 2013 18:06:36 GMT</pubDate>
			<description><![CDATA[I'm trying to install a program. I go to 'My Documents' then 'Downloads' which is the name of the folder where the set-up icon is. I click on the icon and then click 'Run' as you normally would. But after I select the language (English) a message...]]></description>
			<content:encoded><![CDATA[<div>I'm trying to install a program. I go to 'My Documents' then 'Downloads' which is the name of the folder where the set-up icon is. I click on the icon and then click 'Run' as you normally would. But after I select the language (English) a message window appears which says 'Set-Up has detected that this program is already running, Please close all applications and continue.' I don't understand, how can this program be running if I haven't even installed it ? Although I do have a program from the same Software Company which had been 'locking' earlier. But as far as I can see, it's not running. So why would I get this message, if it's not running ?</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/18-all-other-software/">All Other Software</category>
			<dc:creator>Robert the Bruce</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/all-other-software/1099531-program-wont-install.html</guid>
		</item>
		<item>
			<title>Inherited speakers compatible?</title>
			<link>http://forums.techguy.org/hardware/1099530-inherited-speakers-compatible.html</link>
			<pubDate>Thu, 23 May 2013 17:50:34 GMT</pubDate>
			<description>I recently came by a pair of what I now know to be very decent speakers. 
They are part of this unit: 
http://www.amazon.com/Panasonic-SC-AK500-Compact-Stereo-System/dp/B0000655Y2/ref=cm_cr_pr_product_top 
Only the speakers, however. 
They are...</description>
			<content:encoded><![CDATA[<div>I recently came by a pair of what I now know to be very decent speakers.<br />
They are part of this unit:<br />
<a href="http://www.amazon.com/Panasonic-SC-AK500-Compact-Stereo-System/dp/B0000655Y2/ref=cm_cr_pr_product_top" target="_blank">http://www.amazon.com/Panasonic-SC-A...pr_product_top</a><br />
Only the speakers, however.<br />
They are bi-wired, with both wirings rated at 140W @ 6 ohm.<br />
<br />
Now I also have a decent system already.<br />
<a href="http://www.overstock.com/Electronics/TEAC-DVD-CD-Mini-Stereo-System-Refurbished/249282/product.html" target="_blank">http://www.overstock.com/Electronics...2/product.html</a><br />
They are only 15W, mono-wired, and<b> 8 ohm.</b>.  I'm quite happy with it already but now that I have these much larger speakers I'd like to know if I'd get any benefit from plugging them into this unit.<br />
<br />
From what I've read, the Bi-wiring is a joke.  Will merging the two '+' and the two '-' cables together cause any harm? (they already are on the unit, can undo if recommended)<br />
<br />
Next, do I have any real cause for concern with my output being 8ohm and speakers being much higher wattage @ only 6 ohm?<br />
<br />
Finally, would it help at all anyway?  There doesn't seem to be a market for amplifier units like this.  I'm either dumb or there aren't replacement units or anything that could take it's place?</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/19-hardware/">Hardware</category>
			<dc:creator>Psycher</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/hardware/1099530-inherited-speakers-compatible.html</guid>
		</item>
		<item>
			<title>Security Centre</title>
			<link>http://forums.techguy.org/windows-xp/1099529-security-centre.html</link>
			<pubDate>Thu, 23 May 2013 17:42:20 GMT</pubDate>
			<description><![CDATA[We're Sorry, The Security Centre could not change your Automatic Updates Centre. 
 
This is the error message that I receive.  My automatic updates is turned on, but the balloon is red in my icon tray. 
Does this mean I am not secured for updates,...]]></description>
			<content:encoded><![CDATA[<div>We're Sorry, The Security Centre could not change your Automatic Updates Centre.<br />
<br />
This is the error message that I receive.  My automatic updates is turned on, but the balloon is red in my icon tray.<br />
Does this mean I am not secured for updates, or should I just ignore it.<br />
<br />
Any and all help is greatly appreciated.</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/21-windows-xp/">Windows XP</category>
			<dc:creator>Climewoman</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/windows-xp/1099529-security-centre.html</guid>
		</item>
		<item>
			<title>i have dell (inspiron m5030) laptop</title>
			<link>http://forums.techguy.org/windows-7/1099528-i-have-dell-inspiron-m5030.html</link>
			<pubDate>Thu, 23 May 2013 17:34:25 GMT</pubDate>
			<description><![CDATA[hi all  
i have dell (inspiron M5030) laptop and i have a built-in camera and i want it driver  
 
however i  went to dell website looking for the driver but i didn't know what's my camera's driver they gave me this list: 
Application (3) 
Audio (1)...]]></description>
			<content:encoded><![CDATA[<div>hi all <br />
i have dell (inspiron M5030) laptop and i have a built-in camera and i want it driver <br />
<br />
however i  went to dell website looking for the driver but i didn't know what's my camera's driver they gave me this list:<br />
Application (3)<br />
Audio (1)<br />
BIOS (1)<br />
Chipset (2)<br />
Communications (4)<br />
Diagnostics (1)<br />
Drivers for OS Deployment (2)<br />
Input (1)<br />
Network (4)<br />
Removable Storage (2)<br />
Serial ATA (3)<br />
System Utilities (1)<br />
Video (1)<br />
<br />
and i didn't know which one is for the camera :( i know it is funny but i couldn't know <br />
<br />
so i need your help guys <br />
<br />
thank you</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/86-windows-7/">Windows 7</category>
			<dc:creator>thelionn</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/windows-7/1099528-i-have-dell-inspiron-m5030.html</guid>
		</item>
		<item>
			<title>GPS Tracking App for Android Phone</title>
			<link>http://forums.techguy.org/android-phones-tablets/1099527-gps-tracking-app-android-phone.html</link>
			<pubDate>Thu, 23 May 2013 17:32:19 GMT</pubDate>
			<description><![CDATA[Is there a better app out there than Google's Latitude program for keeping track of where you have been on your Android phone.  My company pays me mileage but they want fairly precise information on the distances between stops.  I have a lot of...]]></description>
			<content:encoded><![CDATA[<div>Is there a better app out there than Google's Latitude program for keeping track of where you have been on your Android phone.  My company pays me mileage but they want fairly precise information on the distances between stops.  I have a lot of short trips between clients and would like to find something that keeps something of a log.  I feel like i am losing out on a lot of reimbursement dollars because Latitude is not only imprecise but about twice a day puts me somewhere miles from where I actually was.  There is no secrecy involved here (my wife doesn't really care where I'm at) so accuracy is the most important aspect.<br />
<br />
I'd really appreciate any help.<br />
<br />
Thanks...</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/97-android-phones-tablets/">Android Phones and Tablets</category>
			<dc:creator>tnt717</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/android-phones-tablets/1099527-gps-tracking-app-android-phone.html</guid>
		</item>
		<item>
			<title>.exe is not a valid win32 application</title>
			<link>http://forums.techguy.org/windows-xp/1099526-exe-not-valid-win32-application.html</link>
			<pubDate>Thu, 23 May 2013 17:31:38 GMT</pubDate>
			<description>Tech Support Guy System Info Utility version 1.0.0.2 
OS Version: Microsoft Windows XP Professional, Service Pack 2, 32 bit 
Processor: Intel(R) Pentium(R) M processor 1500MHz, x86 Family 6 Model 9 Stepping 5 
Processor Count: 1 
RAM: 511 Mb...</description>
			<content:encoded><![CDATA[<div>Tech Support Guy System Info Utility version 1.0.0.2<br />
OS Version: Microsoft Windows XP Professional, Service Pack 2, 32 bit<br />
Processor: Intel(R) Pentium(R) M processor 1500MHz, x86 Family 6 Model 9 Stepping 5<br />
Processor Count: 1<br />
RAM: 511 Mb<br />
Graphics Card: MOBILITY RADEON 9200, 64 Mb<br />
Hard Drives: C: Total - 38146 MB, Free - 19704 MB;<br />
Motherboard: COMPAL, 0860<br />
Antivirus: avast! Antivirus, Updated: Yes, On-Demand Scanner: Enabled<br />
<br />
The error message '.exe is not a valid win32 application' keeps popping up when ever I try to run a download for example like itunes or when I try to download windows components. I do not have any service packs or compression clients as it won't allow me either. I have recently had it's hard drive wiped due to hard drive corruption. I think it may be that I may have missing components but I am not sure which.</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/21-windows-xp/">Windows XP</category>
			<dc:creator>shamalama</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/windows-xp/1099526-exe-not-valid-win32-application.html</guid>
		</item>
		<item>
			<title>juno</title>
			<link>http://forums.techguy.org/web-email/1099524-juno.html</link>
			<pubDate>Thu, 23 May 2013 17:24:51 GMT</pubDate>
			<description><![CDATA[using windows 7 
when i'm sending mail the default setting is "to" 
I want to change it so that the default setting is "bcc" 
also the default setting for the font is "12" 
I want to change it to "14" 
 
HELP!!!!!!!!!!!!!!!!!!! 
 
 
herb]]></description>
			<content:encoded><![CDATA[<div>using windows 7<br />
when i'm sending mail the default setting is &quot;to&quot;<br />
I want to change it so that the default setting is &quot;bcc&quot;<br />
also the default setting for the font is &quot;12&quot;<br />
I want to change it to &quot;14&quot;<br />
<br />
HELP!!!!!!!!!!!!!!!!!!!<br />
<br />
<br />
herb</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/17-web-email/"><![CDATA[Web & Email]]></category>
			<dc:creator>lilaco</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/web-email/1099524-juno.html</guid>
		</item>
		<item>
			<title>Water Drops on Flowers</title>
			<link>http://forums.techguy.org/photo-album/1099523-water-drops-flowers.html</link>
			<pubDate>Thu, 23 May 2013 17:23:09 GMT</pubDate>
			<description>We had a hard rain last night so I decided to fire off a few early this morning just for the heck of it. 
 
Image: http://i907.photobucket.com/albums/ac279/Guyzerr/IMG_1714_zps73cd33fe.jpg  
 
Image:...</description>
			<content:encoded><![CDATA[<div>We had a hard rain last night so I decided to fire off a few early this morning just for the heck of it.<br />
<br />
<img src="http://i907.photobucket.com/albums/ac279/Guyzerr/IMG_1714_zps73cd33fe.jpg" border="0" alt="" onload="NcodeImageResizer.createOn(this);" /><br />
<br />
<img src="http://i907.photobucket.com/albums/ac279/Guyzerr/IMG_1712_zpsc4449f70.jpg" border="0" alt="" onload="NcodeImageResizer.createOn(this);" /><br />
<br />
<img src="http://i907.photobucket.com/albums/ac279/Guyzerr/IMG_1711_zpsb25abafe.jpg" border="0" alt="" onload="NcodeImageResizer.createOn(this);" /><br />
<br />
<img src="http://i907.photobucket.com/albums/ac279/Guyzerr/IMG_1710_zps07e8d52c.jpg" border="0" alt="" onload="NcodeImageResizer.createOn(this);" /><br />
<br />
<img src="http://i907.photobucket.com/albums/ac279/Guyzerr/IMG_1702_zps268da602.jpg" border="0" alt="" onload="NcodeImageResizer.createOn(this);" /><br />
<br />
Thanks for looking...</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/64-photo-album/">Photo Album</category>
			<dc:creator>Guyzer</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/photo-album/1099523-water-drops-flowers.html</guid>
		</item>
		<item>
			<title>HP Pavilion a6110n Desktop</title>
			<link>http://forums.techguy.org/hardware/1099522-hp-pavilion-a6110n-desktop.html</link>
			<pubDate>Thu, 23 May 2013 17:21:13 GMT</pubDate>
			<description>ASUS M2N68-LA (Narra2) motherboard 
Anyone familiar with this model and know the best way to reset the bios? I have moved the jumper, taken out the battery and unplugged it many times. It works, but I have to wait a while. The reset button looks...</description>
			<content:encoded><![CDATA[<div>ASUS M2N68-LA (Narra2) motherboard<br />
Anyone familiar with this model and know the best way to reset the bios? I have moved the jumper, taken out the battery and unplugged it many times. It works, but I have to wait a while. The reset button looks bent, and Im scared it will break off(from experience). The problem is, I get it reset, and make my changes in the bios, and it only boots into (what i call)standby mode. The fan runs, but no video. I have taken out the new vid card. This happened when the power cut off. Its happened before to this machine and others with Asus boards that Ive had here. Its just always a major pain to get everything back on and get video back up. It has a good power supply, and not the Bestec one that came with it. Is there a trick here I dont know?  Thanks in advance</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/19-hardware/">Hardware</category>
			<dc:creator>roosterwes</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/hardware/1099522-hp-pavilion-a6110n-desktop.html</guid>
		</item>
		<item>
			<title>no sound</title>
			<link>http://forums.techguy.org/hardware/1099520-no-sound.html</link>
			<pubDate>Thu, 23 May 2013 17:07:33 GMT</pubDate>
			<description>why am i not getting sound on my computer</description>
			<content:encoded><![CDATA[<div>why am i not getting sound on my computer</div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/19-hardware/">Hardware</category>
			<dc:creator>dbruner66</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/hardware/1099520-no-sound.html</guid>
		</item>
		<item>
			<title>fan running with lid closed, but blank screen when lid opened</title>
			<link>http://forums.techguy.org/hardware/1099519-fan-running-lid-closed-but.html</link>
			<pubDate>Thu, 23 May 2013 16:52:54 GMT</pubDate>
			<description><![CDATA[I have a Toshiba Satellite P745. When I close the lid the fan stays on and so does the light for the power button, then when I open the lid the screen stays blank and the computer doesn't start. I have to then manually power it down and it then...]]></description>
			<content:encoded><![CDATA[<div><i>I have a Toshiba Satellite P745. When I close the lid the fan stays on and so does the light for the power button, then when I open the lid the screen stays blank and the computer doesn't start. I have to then manually power it down and it then works fine. Some other information when the laptop first starts it asks me if i want to use windows 7 or perform a system restore, then the screen that tells you your computer didn't shut down right (the screen that gives you the option to run in safe mode) and then it starts fine. It also once in awhile makes a weird clicking noise in the bottom right corner. I have tried taking out the battery and that didn't work.<br />
Thanks for the help<br />
</i></div>

]]></content:encoded>
			<category domain="http://forums.techguy.org/19-hardware/">Hardware</category>
			<dc:creator>cjotjr25</dc:creator>
			<guid isPermaLink="true">http://forums.techguy.org/hardware/1099519-fan-running-lid-closed-but.html</guid>
		</item>
	</channel>
</rss>
