Scour redirect virus in Google via Internet Explorer
Redirects me to http://63.209.69.107/see.php?
I have tried lots of things to resolve this but it has been persistent
Using Norton 360/spybot all the time and have not had a serious problem in years until now.
Attached:
1. HijackThis log.
2. dds.txt
3. attach.txt
4. ark.txt (crashed blue screen of death twice, finally run in safe mode with networking).
5. sysinfo
==================
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:17:32 PM, on 1/10/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccSvcHst.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE
C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe
C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\Sendori\SendoriTray.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe
C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe
C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Calibre2\calibre.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Calibre2\calibre-parallel.exe
C:\Users\Shelli\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\IPS\IPSBHO.DLL
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\coIEPlg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [RemoteControl9] "c:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
O4 - HKLM\..\Run: [PDVD9LanguageShortcut] "c:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] c:\Program Files (x86)\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [AccuWeatherWidget] "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" --startup
O4 - HKLM\..\Run: [FATrayAlert] C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [Sendori Tray] "C:\Program Files (x86)\Sendori\SendoriTray.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Intel(R) Turbo Boost Technology Monitor 2.0.lnk = C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe
O4 - Global Startup: Install LastPass IE RunOnce.lnk = C:\Program Files (x86)\Common Files\lpuninstall.exe
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\LastPass\LPToolbar.dll
O9 - Extra 'Tools' menuitem: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\LastPass\LPToolbar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://ccfiles.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.11.0.cab
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} (JuniperSetupClientControl Class) - https://mygp.gp.com/dana-cached/sc/JuniperSetupClient.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareupdate/ocx/121022/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3B34BA86-2C39-415B-9F6F-541F0D2687CE}: NameServer = 0.0.0.0
O17 - HKLM\System\CCS\Services\Tcpip\..\{DFBA02F4-D8C8-47EA-9194-1DEABEF2671A}: NameServer = 216.146.35.240,216.146.36.240,192.168.1.1
O18 - Protocol: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - C:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
O20 - Winlogon Notify: FastAccess - C:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
O23 - Service: Application Sendori - Sendori, Inc. - C:\Program Files (x86)\Sendori\SendoriSvc.exe
O23 - Service: Bluetooth Device Monitor - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth Media Service - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
O23 - Service: Bluetooth OBEX Service - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
O23 - Service: CyberLink Product - 2011/11/17 22:34:14 (CLKMSVC10_9EC60124) - CyberLink - c:\Program Files (x86)\Cyberlink\PowerDVD9\NavFilter\kmsvc.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: Dell Digital Delivery Service (DellDigitalDelivery) - Dell Products, LP. - C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: FAService - Sensible Vision - C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccSvcHst.exe
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Dell DataSafe Online (NOBU) - Dell, Inc. - C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: RoxMediaDB12OEM - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: Service Sendori - sendori - C:\Program Files (x86)\Sendori\Sendori.Service.exe
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks SAS - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: sndappv2 - Sendori - C:\Program Files (x86)\Sendori\sndappv2.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Sound Blaster X-Fi MB Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Intel(R) Turbo Boost Technology Monitor 2.0 (TurboBoost) - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Wacom Professional Service (WTabletServicePro) - Wacom Technology, Corp. - C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
--
End of file - 18241 bytes
==============
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.9.2
Run by Shelli at 20:18:38 on 2013-01-10
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8086.4548 [GMT -5:00]
.
AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccSvcHst.exe
C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
C:\Program Files (x86)\Sendori\sndappv2.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Sendori\SendoriSvc.exe
C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Sendori\Sendori.Service.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Sendori\SendoriUp.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccSvcHst.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Google\Update\1.3.21.123\GoogleCrashHandler.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE
C:\Program Files (x86)\Google\Update\1.3.21.123\GoogleCrashHandler64.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
C:\Program Files\Tablet\Wacom\WacomHost.exe
C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe
C:\Windows\system32\AMBSpiE.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe
C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\Sendori\SendoriTray.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe
C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Intel\TurboBoost\TurboBoost.exe
C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files\Greenshot\Greenshot.exe
C:\Program Files (x86)\Calibre2\calibre.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
C:\Windows\system32\notepad.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Calibre2\calibre-parallel.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxps://www.google.com/
uSearch Bar = Preserve
mWinlogon: Userinit = userinit.exe
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
BHO: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\coieplg.dll
BHO: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ips\ipsbho.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\coieplg.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
mRun: [VolPanel] "C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe" /r
mRun: [UpdReg] C:\Windows\UpdReg.EXE
mRun: [RemoteControl9] "c:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
mRun: [PDVD9LanguageShortcut] "c:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"
mRun: [BDRegion] c:\Program Files (x86)\Cyberlink\Shared Files\brs.exe
mRun: [AccuWeatherWidget] "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" --startup
mRun: [FATrayAlert] C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
mRun: [FAStartup] <no file>
StartupFolder: C:\Users\Shelli\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\INTEL(~1.LNK - C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\INSTAL~1.LNK - C:\Program Files (x86)\Common Files\lpuninstall.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {36ECAF82-3300-8F84-092E-AFF36D6C7040} - {86529161-034E-4F8A-88D2-3C625E612E04} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
Trusted Zone: pinterest.com
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.11.0.cab
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://mygp.gp.com/dana-cached/sc/JuniperSetupClient.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/121022/CTPID.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{3B34BA86-2C39-415B-9F6F-541F0D2687CE} : NameServer = 0.0.0.0
TCP: Interfaces\{A025C8A1-6C0C-4BF7-B7C3-2062A071045B} : DHCPNameServer = 13.36.0.1 13.36.0.2
TCP: Interfaces\{DFBA02F4-D8C8-47EA-9194-1DEABEF2671A} : NameServer = 216.146.35.240,216.146.36.240,192.168.1.1
TCP: Interfaces\{DFBA02F4-D8C8-47EA-9194-1DEABEF2671A} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{DFBA02F4-D8C8-47EA-9194-1DEABEF2671A}\2416E6A6F656D27657563747 : DHCPNameServer = 192.168.33.1 75.75.75.75 75.75.76.76
Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - C:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: FastAccess - C:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll
Notify: SDWinLogon - SDWinLogon.dll
AppInit_DLLs= C:\Windows\SysWOW64\nvinit.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
LSA: Notification Packages = scecli FAPassSync
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /MAXX3
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
x64-Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
x64-Run: [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray
x64-Run: [QuickSet] c:\Program Files\Dell\QuickSet\QuickSet.exe
x64-Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
x64-Run: [CTMasterOnOffMonitor] Rundll32.exe CTMWatch.dll StartCTMasterOnOffWatch
x64-Run: [RunDLLEntry] C:\Windows\System32\RunDLL32.exe C:\Windows\System32\AmbRunE.dll,RunDLLEntry
x64-IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
x64-DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
x64-Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - <orphaned>
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\Windows\System32\ieudinit.exe
.
============= SERVICES / DRIVERS ===============
.
R0 nvpciflt;nvpciflt;C:\Windows\System32\drivers\nvpciflt.sys [2012-10-25 30056]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2011-11-17 55856]
R0 stdcfltn;Disk Class Filter Driver for Accelerometer;C:\Windows\System32\drivers\stdcfltn.sys [2011-11-18 21616]
R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\N360x64\0502020.003\symds64.sys [2012-11-3 450680]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\N360x64\0502020.003\symefa64.sys [2012-11-3 912504]
R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20130107.001\BHDrvx64.sys [2013-1-9 1384608]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2012-11-24 283200]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20130109.001\IDSviA64.sys [2013-1-10 513184]
R1 nvkflt;nvkflt;C:\Windows\System32\drivers\nvkflt.sys [2012-10-25 284008]
R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\N360x64\0502020.003\ironx64.sys [2012-11-3 171128]
R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\N360x64\0502020.003\symnets.sys [2012-11-3 386168]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2011-11-17 98208]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-8-8 1166848]
R2 Application Sendori;Application Sendori;C:\Program Files (x86)\Sendori\SendoriSvc.exe [2012-12-10 118632]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor;C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-5-19 921664]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2011-5-19 995392]
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-6-3 134928]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
R2 DellDigitalDelivery;Dell Digital Delivery Service;C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe [2012-10-9 173568]
R2 FAService;FAService;C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe [2012-2-14 2451440]
R2 N360;Norton 360;C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccsvchst.exe [2012-11-3 130008]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-11-25 687400]
R2 NOBU;Dell DataSafe Online;C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe [2010-8-25 2823000]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-1-9 1103392]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-1-9 1369624]
R2 Service Sendori;Service Sendori;C:\Program Files (x86)\Sendori\Sendori.Service.exe [2012-12-10 14696]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2011-11-17 1692480]
R2 sndappv2;sndappv2;C:\Program Files (x86)\Sendori\sndappv2.exe [2012-12-10 3569512]
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\System32\drivers\TurboB.sys [2010-11-29 16120]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-11-17 2656280]
R2 WTabletServicePro;Wacom Professional Service;C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [2012-12-19 613760]
R3 Acceler;Accelerometer Service;C:\Windows\System32\drivers\Accelern.sys [2011-11-17 27760]
R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;C:\Windows\System32\drivers\AmpPal.sys [2011-8-8 299008]
R3 Bluetooth Media Service;Bluetooth Media Service;C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [2011-5-19 1335360]
R3 btmaudio;Intel Bluetooth Audio Service;C:\Windows\System32\drivers\btmaud.sys [2011-5-19 51712]
R3 btmaux;Intel Bluetooth Auxiliary Service;C:\Windows\System32\drivers\btmaux.sys [2011-5-19 53248]
R3 btmhsf;btmhsf;C:\Windows\System32\drivers\btmhsf.sys [2011-11-15 327168]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\System32\drivers\CtClsFlt.sys [2012-11-3 176000]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-11-24 138912]
R3 iBtFltCoex;iBtFltCoex;C:\Windows\System32\drivers\iBtFltCoex.sys [2011-12-9 60416]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-11-17 317440]
R3 iwdbus;IWD Bus Enumerator;C:\Windows\System32\drivers\iwdbus.sys [2012-4-19 25528]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-7-27 340240]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2011-11-17 82432]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2011-11-17 181760]
R3 qicflt;upper Device Filter Driver;C:\Windows\System32\drivers\qicflt.sys [2011-11-17 29288]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-6-10 539240]
R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
S2 CLKMSVC10_9EC60124;CyberLink Product - 2011/11/17 22:34:14;C:\Program Files (x86)\Cyberlink\PowerDVD9\NavFilter\kmsvc.exe [2011-8-11 248304]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-1-9 168384]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-10-19 160944]
S3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;C:\Windows\System32\drivers\AmpPal.sys [2011-8-8 299008]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-11-17 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-11-17 79360]
S3 FACAP;facap, FastAccess Video Capture;C:\Windows\System32\drivers\facap.sys [2008-9-24 238848]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2012-11-3 57856]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-9-12 1512448]
S3 hidkmdf;KMDF Driver;C:\Windows\System32\drivers\hidkmdf.sys [2012-12-19 13728]
S3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2011-11-17 158976]
S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\Windows\System32\drivers\intelaud.sys [2012-4-19 35256]
S3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;C:\Windows\System32\drivers\nvstusb.sys [2011-11-17 121960]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-11-3 19456]
S3 RoxMediaDB12OEM;RoxMediaDB12OEM;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
S3 Sound Blaster X-Fi MB Licensing Service;Sound Blaster X-Fi MB Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe [2011-11-17 79360]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-11-3 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2012-11-3 30208]
S3 WacHidRouter;Wacom Hid Router;C:\Windows\System32\drivers\wachidrouter.sys [2012-12-19 81312]
S3 wacomrouterfilter;Wacom Router Filter Driver;C:\Windows\System32\drivers\wacomrouterfilter.sys [2012-12-19 15776]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-11-3 1255736]
.
=============== Created Last 30 ================
.
2013-01-10 23:25:40 -------- d-----w- C:\Users\Shelli\AppData\Roaming\calibre
2013-01-10 23:25:31 -------- d-----w- C:\Program Files (x86)\Calibre2
2013-01-10 23:22:31 -------- d-----w- C:\Users\Shelli\AppData\Local\Apple Computer
2013-01-10 23:22:25 -------- d-----w- C:\Users\Shelli\AppData\Roaming\Barnes & Noble
2013-01-10 23:22:24 -------- d-----w- C:\Program Files (x86)\Barnes & Noble
2013-01-10 04:12:41 -------- d-----w- C:\Program Files (x86)\PC Tools
2013-01-10 04:07:47 253256 ----a-w- C:\Windows\System32\drivers\PCTSD64.sys
2013-01-10 04:07:47 -------- d-----w- C:\Program Files (x86)\Common Files\PC Tools
2013-01-10 04:05:49 -------- d-----w- C:\ProgramData\PC Tools
2013-01-10 04:05:48 -------- d-----w- C:\Users\Shelli\AppData\Roaming\TestApp
2013-01-10 03:39:32 -------- d-----w- C:\Program Files\Enigma Software Group
2013-01-10 03:39:20 -------- d-----w- C:\Windows\83B952C7F8F34CA3B4C533C85B24E478.TMP
2013-01-10 03:39:19 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2013-01-10 02:50:05 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2013-01-10 02:49:59 17272 ----a-w- C:\Windows\System32\sdnclean64.exe
2013-01-10 02:49:56 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-01-10 02:07:13 -------- d-----w- C:\Users\Shelli\GooredFix Backups
2013-01-09 19:25:35 143360 --sha-r- C:\Windows\SysWow64\dbghelpo.dll
2013-01-06 15:43:58 -------- d-----w- C:\Users\Shelli\AppData\Roaming\Juniper Networks
2012-12-22 17:17:41 -------- d-----w- C:\Program Files (x86)\Auslogics
2012-12-22 17:03:53 -------- d-----w- C:\Program Files (x86)\Cozi Express
2012-12-21 21:42:05 -------- d-----w- C:\Users\Shelli\AppData\Local\Amazon
2012-12-21 08:00:53 46080 ----a-w- C:\Windows\System32\atmlib.dll
2012-12-21 08:00:53 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2012-12-21 08:00:52 367616 ----a-w- C:\Windows\System32\atmfd.dll
2012-12-21 08:00:52 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll
2012-12-14 23:16:03 -------- d-----w- C:\ProgramData\Blumentals
2012-12-14 23:15:37 -------- d-----w- C:\Users\Shelli\AppData\Roaming\Blumentals
2012-12-14 23:15:37 -------- d-----w- C:\Program Files (x86)\WeBuilder 2011
2012-12-12 10:37:11 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2012-12-12 10:37:11 2048 ----a-w- C:\Windows\System32\tzres.dll
2012-12-12 10:36:50 478208 ----a-w- C:\Windows\System32\dpnet.dll
2012-12-12 10:36:50 376832 ----a-w- C:\Windows\SysWow64\dpnet.dll
.
==================== Find3M ====================
.
2013-01-09 16:48:16 74248 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-01-09 16:48:16 697864 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-01-09 16:47:32 15739912 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
2012-12-18 02:06:28 14794312 ----a-w- C:\Program Files (x86)\Common Files\lpuninstall.exe
2012-12-10 23:01:54 321384 ----a-w- C:\Windows\SysWow64\Sendori.dll
2012-12-07 13:20:16 441856 ----a-w- C:\Windows\System32\Wpc.dll
2012-12-07 13:15:31 2746368 ----a-w- C:\Windows\System32\gameux.dll
2012-12-07 12:26:17 308736 ----a-w- C:\Windows\SysWow64\Wpc.dll
2012-12-07 12:20:43 2576384 ----a-w- C:\Windows\SysWow64\gameux.dll
2012-12-07 11:20:04 30720 ----a-w- C:\Windows\System32\usk.rs
2012-12-07 11:20:03 43520 ----a-w- C:\Windows\System32\csrr.rs
2012-12-07 11:20:03 23552 ----a-w- C:\Windows\System32\oflc.rs
2012-12-07 11:20:01 45568 ----a-w- C:\Windows\System32\oflc-nz.rs
2012-12-07 11:20:01 44544 ----a-w- C:\Windows\System32\pegibbfc.rs
2012-12-07 11:20:01 20480 ----a-w- C:\Windows\System32\pegi-fi.rs
2012-12-07 11:20:00 20480 ----a-w- C:\Windows\System32\pegi-pt.rs
2012-12-07 11:19:59 20480 ----a-w- C:\Windows\System32\pegi.rs
2012-12-07 11:19:58 46592 ----a-w- C:\Windows\System32\fpb.rs
2012-12-07 11:19:57 40960 ----a-w- C:\Windows\System32\cob-au.rs
2012-12-07 11:19:57 21504 ----a-w- C:\Windows\System32\grb.rs
2012-12-07 11:19:57 15360 ----a-w- C:\Windows\System32\djctq.rs
2012-12-07 11:19:56 55296 ----a-w- C:\Windows\System32\cero.rs
2012-12-07 11:19:55 51712 ----a-w- C:\Windows\System32\esrb.rs
2012-11-30 05:45:35 362496 ----a-w- C:\Windows\System32\wow64win.dll
2012-11-30 05:45:35 243200 ----a-w- C:\Windows\System32\wow64.dll
2012-11-30 05:45:35 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2012-11-30 05:45:14 215040 ----a-w- C:\Windows\System32\winsrv.dll
2012-11-30 05:43:12 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2012-11-30 05:41:07 424448 ----a-w- C:\Windows\System32\KernelBase.dll
2012-11-30 04:54:00 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2012-11-30 04:53:59 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2012-11-30 03:23:48 338432 ----a-w- C:\Windows\System32\conhost.exe
2012-11-30 02:44:06 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2012-11-30 02:44:04 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2012-11-30 02:44:04 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2012-11-30 02:44:03 2048 ----a-w- C:\Windows\SysWow64\user.exe
2012-11-30 02:38:59 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2012-11-30 02:38:59 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2012-11-30 02:38:59 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2012-11-30 02:38:59 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2012-11-26 00:31:01 9728 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2012-11-25 02:51:37 283200 ----a-w- C:\Windows\System32\drivers\dtsoftbus01.sys
2012-11-23 03:26:31 3149824 ----a-w- C:\Windows\System32\win32k.sys
2012-11-23 03:13:57 68608 ----a-w- C:\Windows\System32\taskhost.exe
2012-11-22 05:44:23 800768 ----a-w- C:\Windows\System32\usp10.dll
2012-11-22 04:45:03 626688 ----a-w- C:\Windows\SysWow64\usp10.dll
2012-11-20 05:48:49 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-11-20 04:51:09 220160 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-11-14 06:11:44 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2012-11-14 06:04:11 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-11-14 06:02:49 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-11-14 05:57:46 599040 ----a-w- C:\Windows\System32\vbscript.dll
2012-11-14 05:57:35 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-11-14 05:52:40 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-11-14 02:09:22 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-11-14 01:58:15 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-11-14 01:57:37 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-11-14 01:49:25 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-11-14 01:48:27 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
2012-11-14 01:44:42 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-11-09 05:45:32 750592 ----a-w- C:\Windows\System32\win32spl.dll
2012-11-09 04:53:17 95208 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2012-11-09 04:53:16 821736 ----a-w- C:\Windows\SysWow64\npdeployJava1.dll
2012-11-09 04:43:04 492032 ----a-w- C:\Windows\SysWow64\win32spl.dll
2012-11-03 08:48:54 174200 ----a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2012-11-03 05:21:06 473072 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2012-11-01 05:43:42 2002432 ----a-w- C:\Windows\System32\msxml6.dll
2012-11-01 05:43:42 1882624 ----a-w- C:\Windows\System32\msxml3.dll
2012-11-01 04:47:54 1389568 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-11-01 04:47:54 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-10-29 13:14:20 1981312 ----a-w- C:\Windows\System32\Wacom_Tablet.dll
2012-10-29 13:14:20 1974144 ----a-w- C:\Windows\System32\Wacom_Touch_Tablet.dll
2012-10-29 13:14:20 1843072 ----a-w- C:\Windows\System32\Wintab32.dll
2012-10-29 13:14:18 1840000 ----a-w- C:\Windows\System32\WacomMT.dll
2012-10-29 13:14:16 1628032 ----a-w- C:\Windows\SysWow64\Wacom_Tablet.dll
2012-10-29 13:14:16 1621376 ----a-w- C:\Windows\SysWow64\Wacom_Touch_Tablet.dll
2012-10-29 13:14:16 1509248 ----a-w- C:\Windows\SysWow64\Wintab32.dll
2012-10-29 13:14:16 1505152 ----a-w- C:\Windows\SysWow64\WacomMT.dll
2012-10-16 21:34:57 3544134 ----a-w- C:\Windows\System32\nvcoproc.bin
2012-10-16 21:34:56 3293544 ----a-w- C:\Windows\System32\nvsvc64.dll
2012-10-16 21:34:42 6200680 ----a-w- C:\Windows\System32\nvcpl.dll
2012-10-16 21:34:33 891240 ----a-w- C:\Windows\System32\nvvsvc.exe
2012-10-16 21:34:32 866664 ----a-w- C:\Windows\System32\nv3dappshext.dll
2012-10-16 21:34:32 63336 ----a-w- C:\Windows\System32\nvshext.dll
2012-10-16 21:34:32 55144 ----a-w- C:\Windows\System32\nv3dappshextr.dll
2012-10-16 21:34:32 2557800 ----a-w- C:\Windows\System32\nvsvcr.dll
2012-10-16 21:34:32 118120 ----a-w- C:\Windows\System32\nvmctray.dll
2012-10-16 08:38:37 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2012-10-16 08:38:34 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2012-10-16 07:39:52 561664 ----a-w- C:\Windows\apppatch\AcLayers.dll
.
============= FINISH: 20:18:59.76 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 11/3/2012 10:37:38 PM
System Uptime: 1/10/2013 6:55:50 PM (2 hours ago)
.
Motherboard: Dell Inc. | | 0K4H3G
Processor: Intel(R) Core(TM) i7-2670QM CPU @ 2.20GHz | CPU | 2201/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 347 GiB total, 289.024 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 332 GiB total, 29.876 GiB free.
F: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Description: facap, FastAccess Video Capture
Device ID: ROOT\IMAGE\0000
Manufacturer: Sensible Vision
Name: facap, FastAccess Video Capture
PNP Device ID: ROOT\IMAGE\0000
Service: FACAP
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
AccelerometerP11
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Reader XI (11.0.01)
Advanced Audio FX Engine
Allmyapps
Amazon Kindle
Audacity 2.0.2
Auslogics Duplicate File Finder
Big Solitaires 3D 1.4
calibre
CCleaner
Consumer In-Home Service Agreement
Cozi
CutePDF Writer 3.0
CyberLink PowerDVD 9.6
D3DX10
DAEMON Tools Lite
Dell DataSafe Local Backup
Dell DataSafe Local Backup - Support Software
Dell DataSafe Online
Dell Digital Delivery
Dell Edoc Viewer
Dell Getting Started Guide
Dell MusicStage
Dell PhotoStage
Dell Stage
Dell Support Center
Dell VideoStage
Dell Webcam Central
DirectX 9 Runtime
Face Recognition
Facebook Messenger 2.1.4651.0
FastStone Photo Resizer 3.1
Free YouTube Download version 3.1.40.1031
Google Chrome
Google Drive
Google Toolbar for Internet Explorer
Google Update Helper
Greenshot 1.0.6.2228
Intel PROSet Wireless
Intel(R) Control Center
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology
Intel(R) PROSet/Wireless WiFi Software
Intel(R) Turbo Boost Technology Monitor 2.0
Intel(R) WiDi
Intel(R) Wireless Display
Internet Explorer
iSEEK AnswerWorks English Runtime
Java 7 Update 9
Java(TM) 6 Update 27 (64-bit)
Java(TM) 6 Update 37
Jing
Junk Mail filter update
K-Lite Codec Pack 9.4.6 (Standard)
LAME v3.99.3 (for Windows)
LastPass(uninstall only)
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Office 64-bit Components 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared 64-bit MUI (English) 2007
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Ultimate 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft SkyDrive
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Movie Maker
MSVCRT
MSVCRT_amd64
MSVCRT110
MSVCRT110_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nero 10 Movie ThemePack Basic
Nero Blu-ray Player
Nero Control Center 10
Nero ControlCenter 10 Help (CHM)
Nero Core Components 10
Nero Update
NOOK for PC
Norton 360
NVIDIA Control Panel 307.21
NVIDIA Graphics Driver 307.21
NVIDIA Install Application
NVIDIA Optimus 1.10.8
NVIDIA Update 1.10.8
NVIDIA Update Components
Photo Common
Photo Gallery
PhotoShowExpress
PlayReady PC Runtime x86
Quicken 2012
Quickset64
RBVirtualFolder64Inst
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
Realtek High Definition Audio Driver
RealUpgrade 1.1
Roxio Activation Module
Roxio BackOnTrack
Roxio Burn
Roxio Creator Starter
Roxio Express Labeler 3
Roxio File Backup
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687441) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition
Sendori
Skype 6.0
SmartTRAK
Sonic CinePlayer Decoder Pack
Sound Blaster X-Fi MB
SpeedFan (remove only)
Spybot - Search & Destroy
Synaptics Pointing Device Driver
SyncUP
System Requirements Lab for Intel
TrustedID
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2760586) 32-Bit Edition
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
VLC media player 2.0.5
Wacom Tablet
WebQuiz XP
WebTablet FB Plugin 64 bit
WeBuilder 2011 v11.4
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Movie Maker 2.6
WinHTTrack Website Copier 3.46-1 (x64)
WinSCP 5.1.3
.
==== Event Viewer Messages From Past Week ========
.
1/9/2013 8:54:38 PM, Error: Service Control Manager [7022] - The Service Sendori service hung on starting.
1/9/2013 11:14:09 PM, Error: PCTCore [280] -
1/10/2013 7:00:22 PM, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
1/10/2013 7:00:22 PM, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
1/10/2013 6:59:12 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
1/10/2013 6:57:16 PM, Error: Service Control Manager [7001] - The Spybot-S&D 2 Security Center Service service depends on the Security Center service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
1/10/2013 6:16:45 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
1/10/2013 6:16:45 PM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
.
==== End Of File ===========================
GMER 2.0.18444 - http://www.gmer.net
Rootkit scan 2013-01-10 21:30:17
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 rev. 698.64GB
Running: gut16kj6.exe; Driver: C:\Users\Shelli\AppData\Local\Temp\pxldrpow.sys
---- User code sections - GMER 2.0 ----
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000765b1401 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000765b1419 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000765b1431 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000765b144a 2 bytes [5B, 76]
.text ... * 9
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000765b14dd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000765b14f5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000765b150d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000765b1525 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000765b153d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000765b1555 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000765b156d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000765b1585 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000765b159d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000765b15b5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000765b15cd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000765b16b2 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000765b16bd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\ksuser.dll!KsCreatePin + 35 00000000709a11a8 2 bytes [9A, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\ksuser.dll!KsCreatePin + 248 00000000709a127d 2 bytes [9A, 70]
.text ... * 6
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\ksuser.dll!KsCreateAllocator + 21 00000000709a13a8 2 bytes [9A, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\ksuser.dll!KsCreateClock + 21 00000000709a1422 2 bytes [9A, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\ksuser.dll!KsCreateTopologyNode + 19 00000000709a1498 2 bytes [9A, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkD3dContextCreate + 4 00000000707c1825 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkD3dContextDestroy + 4 00000000707c1830 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkD3dContextDestroyAll + 4 00000000707c183b 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkD3dDrawPrimitives2 + 4 00000000707c1846 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkD3dValidateTextureStageState + 4 00000000707c1851 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdAddAttachedSurface + 4 00000000707c185c 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdAlphaBlt + 4 00000000707c1867 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdAttachSurface + 4 00000000707c1872 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdBeginMoCompFrame + 4 00000000707c187d 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdBlt + 4 00000000707c1888 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdCanCreateD3DBuffer + 4 00000000707c1893 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdCanCreateSurface + 4 00000000707c189e 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdColorControl + 4 00000000707c18a9 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdCreateD3DBuffer + 4 00000000707c18b4 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdCreateDirectDrawObject + 4 00000000707c18bf 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdCreateMoComp + 4 00000000707c18ca 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdCreateSurface + 4 00000000707c18d5 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdCreateSurfaceEx + 4 00000000707c18e0 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdCreateSurfaceObject + 4 00000000707c18eb 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdDeleteDirectDrawObject + 4 00000000707c18f6 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdDeleteSurfaceObject + 4 00000000707c1901 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdDestroyD3DBuffer + 4 00000000707c190c 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdDestroyMoComp + 4 00000000707c1917 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdDestroySurface + 4 00000000707c1922 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdEndMoCompFrame + 4 00000000707c192d 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdFlip + 4 00000000707c1938 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdFlipToGDISurface + 4 00000000707c1943 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetAvailDriverMemory + 4 00000000707c194e 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetBltStatus + 4 00000000707c1959 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetDC + 4 00000000707c1964 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetDriverInfo + 4 00000000707c196f 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetDriverState + 4 00000000707c197a 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetDxHandle + 4 00000000707c1985 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetFlipStatus + 4 00000000707c1990 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetInternalMoCompInfo + 4 00000000707c199b 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetMoCompBuffInfo + 4 00000000707c19a6 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetMoCompFormats + 4 00000000707c19b1 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetMoCompGuids + 4 00000000707c19bc 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetScanLine + 4 00000000707c19c7 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdLock + 4 00000000707c19d2 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdLockD3D + 4 00000000707c19dd 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdQueryDirectDrawObject + 4 00000000707c19e8 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdQueryMoCompStatus + 4 00000000707c19f3 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdReenableDirectDrawObject + 4 00000000707c19fe 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdReleaseDC + 4 00000000707c1a09 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdRenderMoComp + 4 00000000707c1a14 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdResetVisrgn + 4 00000000707c1a1f 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdSetColorKey + 4 00000000707c1a2a 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdSetExclusiveMode + 4 00000000707c1a35 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdSetGammaRamp + 4 00000000707c1a40 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdSetOverlayPosition + 4 00000000707c1a4b 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdUnattachSurface + 4 00000000707c1a56 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdUnlock + 4 00000000707c1a61 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdUnlockD3D + 4 00000000707c1a6c 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdUpdateOverlay + 4 00000000707c1a77 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 4 00000000707c1a82 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 52 00000000707c1ab2 2 bytes [7C, 70]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetModuleFileNameExW + 17 00000000765b1401 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!EnumProcessModules + 17 00000000765b1419 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 17 00000000765b1431 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 42 00000000765b144a 2 bytes [5B, 76]
.text ... * 9
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!EnumDeviceDrivers + 17 00000000765b14dd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameA + 17 00000000765b14f5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!QueryWorkingSetEx + 17 00000000765b150d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameW + 17 00000000765b1525 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetModuleBaseNameW + 17 00000000765b153d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!EnumProcesses + 17 00000000765b1555 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetProcessMemoryInfo + 17 00000000765b156d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetPerformanceInfo + 17 00000000765b1585 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!QueryWorkingSet + 17 00000000765b159d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetModuleBaseNameA + 17 00000000765b15b5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetModuleFileNameExA + 17 00000000765b15cd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 20 00000000765b16b2 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 31 00000000765b16bd 2 bytes [5B, 76]
.text C:\Windows\system32\taskeng.exe[1680] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Windows\system32\taskeng.exe[1680] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Windows\system32\taskeng.exe[1680] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Windows\system32\taskeng.exe[1680] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Windows\system32\taskeng.exe[1680] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Windows\system32\taskeng.exe[1680] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Windows\system32\taskeng.exe[1680] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Windows\system32\taskeng.exe[1680] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Windows\system32\Dwm.exe[3276] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Windows\system32\Dwm.exe[3276] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Windows\system32\Dwm.exe[3276] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Windows\system32\Dwm.exe[3276] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Windows\system32\Dwm.exe[3276] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Windows\system32\Dwm.exe[3276] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Windows\system32\Dwm.exe[3276] C:\Windows\system32\dxgi.dll!CreateDXGIFactory 000007fefa02dc88 5 bytes JMP 000007fffa0000d8
.text C:\Windows\system32\Dwm.exe[3276] C:\Windows\system32\dxgi.dll!CreateDXGIFactory1 000007fefa02de10 5 bytes JMP 000007fffa000110
.text C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[3284] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[3284] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[3284] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[3284] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[3284] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[3284] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076fe1d1b 5 bytes JMP 00000001729611d1
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076fe1dc9 5 bytes JMP 0000000172961019
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076fe2aa4 5 bytes JMP 000000017296154b
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076fe2d0a 5 bytes JMP 0000000172961276
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076f6e9a2 5 bytes JMP 00000001729615b4
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076f6ebdc 5 bytes JMP 000000017296119a
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075585ea5 5 bytes JMP 00000001729615e6
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000755b9d0b 5 bytes JMP 000000017296122b
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[3356] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[3356] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[3356] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[3356] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[3356] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[3356] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[3356] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[3356] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[3356] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[3356] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[3356] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\WINDOWS\System32\WerFault.exe[3852] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\WINDOWS\System32\WerFault.exe[3852] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\WINDOWS\System32\WerFault.exe[3852] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\WINDOWS\System32\WerFault.exe[3852] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\WINDOWS\System32\WerFault.exe[3852] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\WINDOWS\System32\WerFault.exe[3852] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\WINDOWS\System32\WerFault.exe[3852] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\WINDOWS\System32\WerFault.exe[3852] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\WINDOWS\System32\WerFault.exe[3852] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\WINDOWS\System32\WerFault.exe[3852] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\WINDOWS\System32\WerFault.exe[3852] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000765b1401 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000765b1419 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000765b1431 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000765b144a 2 bytes [5B, 76]
.text ... * 9
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000765b14dd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000765b14f5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000765b150d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000765b1525 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000765b153d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000765b1555 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000765b156d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000765b1585 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000765b159d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000765b15b5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000765b15cd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000765b16b2 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000765b16bd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000765b1401 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000765b1419 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000765b1431 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000765b144a 2 bytes [5B, 76]
.text ... * 9
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000765b14dd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000765b14f5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000765b150d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000765b1525 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000765b153d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000765b1555 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000765b156d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000765b1585 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000765b159d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000765b15b5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000765b15cd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000765b16b2 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000765b16bd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\KERNEL32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\KERNEL32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076fe1d1b 5 bytes JMP 00000001729611d1
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076fe1dc9 5 bytes JMP 0000000172961019
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076fe2aa4 5 bytes JMP 000000017296154b
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076fe2d0a 5 bytes JMP 0000000172961276
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076f6e9a2 5 bytes JMP 00000001729615b4
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076f6ebdc 5 bytes JMP 000000017296119a
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075585ea5 5 bytes JMP 00000001729615e6
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000755b9d0b 5 bytes JMP 000000017296122b
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076fe1d1b 5 bytes JMP 00000001729611d1
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076fe1dc9 5 bytes JMP 0000000172961019
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076fe2aa4 5 bytes JMP 000000017296154b
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076fe2d0a 5 bytes JMP 0000000172961276
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076f6e9a2 5 bytes JMP 00000001729615b4
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076f6ebdc 5 bytes JMP 000000017296119a
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075585ea5 5 bytes JMP 00000001729615e6
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000755b9d0b 5 bytes JMP 000000017296122b
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\KERNEL32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\KERNEL32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076fe1d1b 5 bytes JMP 00000001729611d1
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076fe1dc9 5 bytes JMP 0000000172961019
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076fe2aa4 5 bytes JMP 000000017296154b
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076fe2d0a 5 bytes JMP 0000000172961276
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076f6e9a2 5 bytes JMP 00000001729615b4
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076f6ebdc 5 bytes JMP 000000017296119a
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075585ea5 5 bytes JMP 00000001729615e6
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000755b9d0b 5 bytes JMP 000000017296122b
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076fe1d1b 5 bytes JMP 00000001729611d1
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076fe1dc9 5 bytes JMP 0000000172961019
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076fe2aa4 5 bytes JMP 000000017296154b
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076fe2d0a 5 bytes JMP 0000000172961276
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076f6e9a2 5 bytes JMP 00000001729615b4
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076f6ebdc 5 bytes JMP 000000017296119a
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075585ea5 5 bytes JMP 00000001729615e6
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000755b9d0b 5 bytes JMP 000000017296122b
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4832] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4832] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4832] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4832] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4832] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4832] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\KERNEL32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\KERNEL32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076fe1d1b 5 bytes JMP 00000001729611d1
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076fe1dc9 5 bytes JMP 0000000172961019
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076fe2aa4 5 bytes JMP 000000017296154b
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076fe2d0a 5 bytes JMP 0000000172961276
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076f6e9a2 5 bytes JMP 00000001729615b4
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076f6ebdc 5 bytes JMP 000000017296119a
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075585ea5 5 bytes JMP 00000001729615e6
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000755b9d0b 5 bytes JMP 000000017296122b
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076fe1d1b 5 bytes JMP 00000001729611d1
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076fe1dc9 5 bytes JMP 0000000172961019
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076fe2aa4 5 bytes JMP 000000017296154b
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076fe2d0a 5 bytes JMP 0000000172961276
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000765b1401 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000765b1419 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000765b1431 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000765b144a 2 bytes [5B, 76]
.text ... * 9
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000765b14dd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000765b14f5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000765b150d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000765b1525 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000765b153d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000765b1555 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000765b156d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000765b1585 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000765b159d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000765b15b5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000765b15cd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000765b16b2 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000765b16bd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076f6e9a2 5 bytes JMP 00000001729615b4
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076f6ebdc 5 bytes JMP 000000017296119a
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075585ea5 5 bytes JMP 00000001729615e6
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000755b9d0b 5 bytes JMP 000000017296122b
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076fe1d1b 5 bytes JMP 00000001729611d1
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076fe1dc9 5 bytes JMP 0000000172961019
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076fe2aa4 5 bytes JMP 000000017296154b
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076fe2d0a 5 bytes JMP 0000000172961276
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076f6e9a2 5 bytes JMP 00000001729615b4
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076f6ebdc 5 bytes JMP 000000017296119a
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075585ea5 5 bytes JMP 00000001729615e6
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000755b9d0b 5 bytes JMP 000000017296122b
.text C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe[5680] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 00000000764b87b1 5 bytes [33, C0, C2, 04, 00]
.text C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe[5680] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe[5680] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe[5680] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe[5680] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe[5680] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files (x86)\Sendori\SendoriTray.exe[5744] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files (x86)\Sendori\SendoriTray.exe[5744] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files (x86)\Sendori\SendoriTray.exe[5744] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files (x86)\Sendori\SendoriTray.exe[5744] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files (x86)\Sendori\SendoriTray.exe[5744] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076fe1d1b 5 bytes JMP 00000001729611d1
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076fe1dc9 5 bytes JMP 0000000172961019
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076fe2aa4 5 bytes JMP 000000017296154b
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076fe2d0a 5 bytes JMP 0000000172961276
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000765b1401 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000765b1419 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000765b1431 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000765b144a 2 bytes [5B, 76]
.text ... * 9
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000765b14dd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000765b14f5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000765b150d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000765b1525 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000765b153d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000765b1555 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000765b156d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000765b1585 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000765b159d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000765b15b5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000765b15cd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000765b16b2 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000765b16bd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076f6e9a2 5 bytes JMP 00000001729615b4
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076f6ebdc 5 bytes JMP 000000017296119a
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075585ea5 5 bytes JMP 00000001729615e6
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000755b9d0b 5 bytes JMP 000000017296122b
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\KERNEL32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\KERNEL32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5928] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5928] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5928] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5928] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5928] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5928] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5928] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5928] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5928] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5928] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5928] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076fe1d1b 5 bytes JMP 00000001729611d1
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076fe1dc9 5 bytes JMP 0000000172961019
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076fe2aa4 5 bytes JMP 000000017296154b
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076fe2d0a 5 bytes JMP 0000000172961276
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076f6e9a2 5 bytes JMP 00000001729615b4
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076f6ebdc 5 bytes JMP 000000017296119a
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075585ea5 5 bytes JMP 00000001729615e6
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000755b9d0b 5 bytes JMP 000000017296122b
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076fe1d1b 5 bytes JMP 00000001729611d1
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076fe1dc9 5 bytes JMP 0000000172961019
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076fe2aa4 5 bytes JMP 000000017296154b
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076fe2d0a 5 bytes JMP 0000000172961276
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076f6e9a2 5 bytes JMP 00000001729615b4
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076f6ebdc 5 bytes JMP 000000017296119a
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075585ea5 5 bytes JMP 00000001729615e6
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000755b9d0b 5 bytes JMP 000000017296122b
---- Devices - GMER 2.0 ----
Device \FileSystem\fastfat \Fat m32\Drivers\Ntfs.sys
Device \Driver\qicflt \Device\ToasterFilter ws\system32\DRIVERS\kbdclass.sys
Device \FileSystem\SRTSP \Device\NAVAP ws\system32\DRIVERS\kbdclass.sys
Device \Driver\NAVENG \Device\NAVENG ws\system32\DRIVERS\kbdclass.sys
Device \Driver\NAVEX15 \Device\NAVEX15 ws\system32\DRIVERS\kbdclass.sys
Device \Driver\usbccgp \Device\0000009c ws\system32\DRIVERS\kbdclass.sys
Device \FileSystem\SRTSP \Device\SAVRT
Device \FileSystem\SRTSP \Device\SRTSP
---- Threads - GMER 2.0 ----
Thread C:\Windows\SysWOW64\rundll32.exe [1944:1304] 000000000043f040
Thread C:\Windows\SysWOW64\rundll32.exe [1944:1328] 00000000001d3a80
Thread C:\Windows\SysWOW64\rundll32.exe [1944:1732] 00000000001d3a10
Thread C:\Windows\SysWOW64\rundll32.exe [1944:5764] 0000000000515cfe
Thread C:\Windows\SysWOW64\rundll32.exe [1944:5612] 0000000000512ea6
Thread C:\Windows\SysWOW64\rundll32.exe [1944:6008] 00000000005133de
Thread [1636:5236] 0000000077952e25
Thread [1636:5304] 0000000076dc820d
Thread [1636:5308] 0000000077953e45
Thread [1636:5312] 0000000077953e45
Thread [1636:5316] 000000007559d864
Thread [1636:5344] 0000000071e7a6e3
Thread [1636:5616] 0000000071e75548
---- Processes - GMER 2.0 ----
Library ? (*** suspicious ***) @ [1636] 0000000000400000
Library ? (*** suspicious ***) @ C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [5680] 0000000075510000
---- Registry - GMER 2.0 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Teredo\PreviousState\[email protected] 51123
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Teredo\PreviousState\[email protected] 2001:0:4137:9e76:24c6:384c:b838:4ff9
Reg HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\[email protected] 1882
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3B34BA86-2C39-415B-9F6F-541F0D2687CE}@EnableDHCP 0
---- Files - GMER 2.0 ----
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS010CA.log 1048576 bytes
---- EOF - GMER 2.0 ----
=============
Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows 7 Home Premium, Service Pack 1, 64 bit
Processor: Intel(R) Core(TM) i7-2670QM CPU @ 2.20GHz, Intel64 Family 6 Model 42 Stepping 7
Processor Count: 8
RAM: 8086 Mb
Graphics Card: NVIDIA GeForce GT 550M, 1023 Mb
Hard Drives: C: Total - 355551 MB, Free - 295303 MB; E: Total - 339745 MB, Free - 30591 MB;
Motherboard: Dell Inc., 0K4H3G
Antivirus: Norton 360, Updated and Enabled
Redirects me to http://63.209.69.107/see.php?
I have tried lots of things to resolve this but it has been persistent
Using Norton 360/spybot all the time and have not had a serious problem in years until now.
Attached:
1. HijackThis log.
2. dds.txt
3. attach.txt
4. ark.txt (crashed blue screen of death twice, finally run in safe mode with networking).
5. sysinfo
==================
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:17:32 PM, on 1/10/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccSvcHst.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE
C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe
C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\Sendori\SendoriTray.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe
C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe
C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Calibre2\calibre.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Calibre2\calibre-parallel.exe
C:\Users\Shelli\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\IPS\IPSBHO.DLL
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\coIEPlg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [RemoteControl9] "c:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
O4 - HKLM\..\Run: [PDVD9LanguageShortcut] "c:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] c:\Program Files (x86)\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [AccuWeatherWidget] "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" --startup
O4 - HKLM\..\Run: [FATrayAlert] C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [Sendori Tray] "C:\Program Files (x86)\Sendori\SendoriTray.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Intel(R) Turbo Boost Technology Monitor 2.0.lnk = C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe
O4 - Global Startup: Install LastPass IE RunOnce.lnk = C:\Program Files (x86)\Common Files\lpuninstall.exe
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\LastPass\LPToolbar.dll
O9 - Extra 'Tools' menuitem: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\LastPass\LPToolbar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://ccfiles.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab
O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.11.0.cab
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} (JuniperSetupClientControl Class) - https://mygp.gp.com/dana-cached/sc/JuniperSetupClient.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareupdate/ocx/121022/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3B34BA86-2C39-415B-9F6F-541F0D2687CE}: NameServer = 0.0.0.0
O17 - HKLM\System\CCS\Services\Tcpip\..\{DFBA02F4-D8C8-47EA-9194-1DEABEF2671A}: NameServer = 216.146.35.240,216.146.36.240,192.168.1.1
O18 - Protocol: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - C:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
O20 - Winlogon Notify: FastAccess - C:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
O23 - Service: Application Sendori - Sendori, Inc. - C:\Program Files (x86)\Sendori\SendoriSvc.exe
O23 - Service: Bluetooth Device Monitor - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth Media Service - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
O23 - Service: Bluetooth OBEX Service - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
O23 - Service: CyberLink Product - 2011/11/17 22:34:14 (CLKMSVC10_9EC60124) - CyberLink - c:\Program Files (x86)\Cyberlink\PowerDVD9\NavFilter\kmsvc.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: Dell Digital Delivery Service (DellDigitalDelivery) - Dell Products, LP. - C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: FAService - Sensible Vision - C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccSvcHst.exe
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Dell DataSafe Online (NOBU) - Dell, Inc. - C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: RoxMediaDB12OEM - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: Service Sendori - sendori - C:\Program Files (x86)\Sendori\Sendori.Service.exe
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks SAS - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: sndappv2 - Sendori - C:\Program Files (x86)\Sendori\sndappv2.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Sound Blaster X-Fi MB Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Intel(R) Turbo Boost Technology Monitor 2.0 (TurboBoost) - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Wacom Professional Service (WTabletServicePro) - Wacom Technology, Corp. - C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
--
End of file - 18241 bytes
==============
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.9.2
Run by Shelli at 20:18:38 on 2013-01-10
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8086.4548 [GMT -5:00]
.
AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccSvcHst.exe
C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
C:\Program Files (x86)\Sendori\sndappv2.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Sendori\SendoriSvc.exe
C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Sendori\Sendori.Service.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Sendori\SendoriUp.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccSvcHst.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Google\Update\1.3.21.123\GoogleCrashHandler.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE
C:\Program Files (x86)\Google\Update\1.3.21.123\GoogleCrashHandler64.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
C:\Program Files\Tablet\Wacom\WacomHost.exe
C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe
C:\Windows\system32\AMBSpiE.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe
C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\Sendori\SendoriTray.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe
C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Intel\TurboBoost\TurboBoost.exe
C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files\Greenshot\Greenshot.exe
C:\Program Files (x86)\Calibre2\calibre.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
C:\Windows\system32\notepad.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Calibre2\calibre-parallel.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxps://www.google.com/
uSearch Bar = Preserve
mWinlogon: Userinit = userinit.exe
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
BHO: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\coieplg.dll
BHO: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ips\ipsbho.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\coieplg.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
mRun: [VolPanel] "C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe" /r
mRun: [UpdReg] C:\Windows\UpdReg.EXE
mRun: [RemoteControl9] "c:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
mRun: [PDVD9LanguageShortcut] "c:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"
mRun: [BDRegion] c:\Program Files (x86)\Cyberlink\Shared Files\brs.exe
mRun: [AccuWeatherWidget] "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" --startup
mRun: [FATrayAlert] C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
mRun: [FAStartup] <no file>
StartupFolder: C:\Users\Shelli\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\INTEL(~1.LNK - C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\INSTAL~1.LNK - C:\Program Files (x86)\Common Files\lpuninstall.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll
IE: {36ECAF82-3300-8F84-092E-AFF36D6C7040} - {86529161-034E-4F8A-88D2-3C625E612E04} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
Trusted Zone: pinterest.com
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.11.0.cab
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://mygp.gp.com/dana-cached/sc/JuniperSetupClient.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/121022/CTPID.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{3B34BA86-2C39-415B-9F6F-541F0D2687CE} : NameServer = 0.0.0.0
TCP: Interfaces\{A025C8A1-6C0C-4BF7-B7C3-2062A071045B} : DHCPNameServer = 13.36.0.1 13.36.0.2
TCP: Interfaces\{DFBA02F4-D8C8-47EA-9194-1DEABEF2671A} : NameServer = 216.146.35.240,216.146.36.240,192.168.1.1
TCP: Interfaces\{DFBA02F4-D8C8-47EA-9194-1DEABEF2671A} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{DFBA02F4-D8C8-47EA-9194-1DEABEF2671A}\2416E6A6F656D27657563747 : DHCPNameServer = 192.168.33.1 75.75.75.75 75.75.76.76
Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - C:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: FastAccess - C:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll
Notify: SDWinLogon - SDWinLogon.dll
AppInit_DLLs= C:\Windows\SysWOW64\nvinit.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
LSA: Notification Packages = scecli FAPassSync
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /MAXX3
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
x64-Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
x64-Run: [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray
x64-Run: [QuickSet] c:\Program Files\Dell\QuickSet\QuickSet.exe
x64-Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
x64-Run: [CTMasterOnOffMonitor] Rundll32.exe CTMWatch.dll StartCTMasterOnOffWatch
x64-Run: [RunDLLEntry] C:\Windows\System32\RunDLL32.exe C:\Windows\System32\AmbRunE.dll,RunDLLEntry
x64-IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
x64-DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
x64-Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - <orphaned>
x64-Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - <orphaned>
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\Windows\System32\ieudinit.exe
.
============= SERVICES / DRIVERS ===============
.
R0 nvpciflt;nvpciflt;C:\Windows\System32\drivers\nvpciflt.sys [2012-10-25 30056]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2011-11-17 55856]
R0 stdcfltn;Disk Class Filter Driver for Accelerometer;C:\Windows\System32\drivers\stdcfltn.sys [2011-11-18 21616]
R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\N360x64\0502020.003\symds64.sys [2012-11-3 450680]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\N360x64\0502020.003\symefa64.sys [2012-11-3 912504]
R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20130107.001\BHDrvx64.sys [2013-1-9 1384608]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2012-11-24 283200]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20130109.001\IDSviA64.sys [2013-1-10 513184]
R1 nvkflt;nvkflt;C:\Windows\System32\drivers\nvkflt.sys [2012-10-25 284008]
R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\N360x64\0502020.003\ironx64.sys [2012-11-3 171128]
R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\N360x64\0502020.003\symnets.sys [2012-11-3 386168]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2011-11-17 98208]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2011-8-8 1166848]
R2 Application Sendori;Application Sendori;C:\Program Files (x86)\Sendori\SendoriSvc.exe [2012-12-10 118632]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor;C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-5-19 921664]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2011-5-19 995392]
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2011-6-3 134928]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
R2 DellDigitalDelivery;Dell Digital Delivery Service;C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe [2012-10-9 173568]
R2 FAService;FAService;C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe [2012-2-14 2451440]
R2 N360;Norton 360;C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\ccsvchst.exe [2012-11-3 130008]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-11-25 687400]
R2 NOBU;Dell DataSafe Online;C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe [2010-8-25 2823000]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2013-1-9 1103392]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2013-1-9 1369624]
R2 Service Sendori;Service Sendori;C:\Program Files (x86)\Sendori\Sendori.Service.exe [2012-12-10 14696]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2011-11-17 1692480]
R2 sndappv2;sndappv2;C:\Program Files (x86)\Sendori\sndappv2.exe [2012-12-10 3569512]
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\System32\drivers\TurboB.sys [2010-11-29 16120]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-11-17 2656280]
R2 WTabletServicePro;Wacom Professional Service;C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [2012-12-19 613760]
R3 Acceler;Accelerometer Service;C:\Windows\System32\drivers\Accelern.sys [2011-11-17 27760]
R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;C:\Windows\System32\drivers\AmpPal.sys [2011-8-8 299008]
R3 Bluetooth Media Service;Bluetooth Media Service;C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [2011-5-19 1335360]
R3 btmaudio;Intel Bluetooth Audio Service;C:\Windows\System32\drivers\btmaud.sys [2011-5-19 51712]
R3 btmaux;Intel Bluetooth Auxiliary Service;C:\Windows\System32\drivers\btmaux.sys [2011-5-19 53248]
R3 btmhsf;btmhsf;C:\Windows\System32\drivers\btmhsf.sys [2011-11-15 327168]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\System32\drivers\CtClsFlt.sys [2012-11-3 176000]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-11-24 138912]
R3 iBtFltCoex;iBtFltCoex;C:\Windows\System32\drivers\iBtFltCoex.sys [2011-12-9 60416]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-11-17 317440]
R3 iwdbus;IWD Bus Enumerator;C:\Windows\System32\drivers\iwdbus.sys [2012-4-19 25528]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-7-27 340240]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2011-11-17 82432]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2011-11-17 181760]
R3 qicflt;upper Device Filter Driver;C:\Windows\System32\drivers\qicflt.sys [2011-11-17 29288]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-6-10 539240]
R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
S2 CLKMSVC10_9EC60124;CyberLink Product - 2011/11/17 22:34:14;C:\Program Files (x86)\Cyberlink\PowerDVD9\NavFilter\kmsvc.exe [2011-8-11 248304]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2013-1-9 168384]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-10-19 160944]
S3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;C:\Windows\System32\drivers\AmpPal.sys [2011-8-8 299008]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-11-17 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-11-17 79360]
S3 FACAP;facap, FastAccess Video Capture;C:\Windows\System32\drivers\facap.sys [2008-9-24 238848]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2012-11-3 57856]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-9-12 1512448]
S3 hidkmdf;KMDF Driver;C:\Windows\System32\drivers\hidkmdf.sys [2012-12-19 13728]
S3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2011-11-17 158976]
S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\Windows\System32\drivers\intelaud.sys [2012-4-19 35256]
S3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;C:\Windows\System32\drivers\nvstusb.sys [2011-11-17 121960]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-11-3 19456]
S3 RoxMediaDB12OEM;RoxMediaDB12OEM;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
S3 Sound Blaster X-Fi MB Licensing Service;Sound Blaster X-Fi MB Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe [2011-11-17 79360]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-11-3 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2012-11-3 30208]
S3 WacHidRouter;Wacom Hid Router;C:\Windows\System32\drivers\wachidrouter.sys [2012-12-19 81312]
S3 wacomrouterfilter;Wacom Router Filter Driver;C:\Windows\System32\drivers\wacomrouterfilter.sys [2012-12-19 15776]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-11-3 1255736]
.
=============== Created Last 30 ================
.
2013-01-10 23:25:40 -------- d-----w- C:\Users\Shelli\AppData\Roaming\calibre
2013-01-10 23:25:31 -------- d-----w- C:\Program Files (x86)\Calibre2
2013-01-10 23:22:31 -------- d-----w- C:\Users\Shelli\AppData\Local\Apple Computer
2013-01-10 23:22:25 -------- d-----w- C:\Users\Shelli\AppData\Roaming\Barnes & Noble
2013-01-10 23:22:24 -------- d-----w- C:\Program Files (x86)\Barnes & Noble
2013-01-10 04:12:41 -------- d-----w- C:\Program Files (x86)\PC Tools
2013-01-10 04:07:47 253256 ----a-w- C:\Windows\System32\drivers\PCTSD64.sys
2013-01-10 04:07:47 -------- d-----w- C:\Program Files (x86)\Common Files\PC Tools
2013-01-10 04:05:49 -------- d-----w- C:\ProgramData\PC Tools
2013-01-10 04:05:48 -------- d-----w- C:\Users\Shelli\AppData\Roaming\TestApp
2013-01-10 03:39:32 -------- d-----w- C:\Program Files\Enigma Software Group
2013-01-10 03:39:20 -------- d-----w- C:\Windows\83B952C7F8F34CA3B4C533C85B24E478.TMP
2013-01-10 03:39:19 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2013-01-10 02:50:05 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2013-01-10 02:49:59 17272 ----a-w- C:\Windows\System32\sdnclean64.exe
2013-01-10 02:49:56 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-01-10 02:07:13 -------- d-----w- C:\Users\Shelli\GooredFix Backups
2013-01-09 19:25:35 143360 --sha-r- C:\Windows\SysWow64\dbghelpo.dll
2013-01-06 15:43:58 -------- d-----w- C:\Users\Shelli\AppData\Roaming\Juniper Networks
2012-12-22 17:17:41 -------- d-----w- C:\Program Files (x86)\Auslogics
2012-12-22 17:03:53 -------- d-----w- C:\Program Files (x86)\Cozi Express
2012-12-21 21:42:05 -------- d-----w- C:\Users\Shelli\AppData\Local\Amazon
2012-12-21 08:00:53 46080 ----a-w- C:\Windows\System32\atmlib.dll
2012-12-21 08:00:53 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2012-12-21 08:00:52 367616 ----a-w- C:\Windows\System32\atmfd.dll
2012-12-21 08:00:52 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll
2012-12-14 23:16:03 -------- d-----w- C:\ProgramData\Blumentals
2012-12-14 23:15:37 -------- d-----w- C:\Users\Shelli\AppData\Roaming\Blumentals
2012-12-14 23:15:37 -------- d-----w- C:\Program Files (x86)\WeBuilder 2011
2012-12-12 10:37:11 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2012-12-12 10:37:11 2048 ----a-w- C:\Windows\System32\tzres.dll
2012-12-12 10:36:50 478208 ----a-w- C:\Windows\System32\dpnet.dll
2012-12-12 10:36:50 376832 ----a-w- C:\Windows\SysWow64\dpnet.dll
.
==================== Find3M ====================
.
2013-01-09 16:48:16 74248 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-01-09 16:48:16 697864 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-01-09 16:47:32 15739912 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
2012-12-18 02:06:28 14794312 ----a-w- C:\Program Files (x86)\Common Files\lpuninstall.exe
2012-12-10 23:01:54 321384 ----a-w- C:\Windows\SysWow64\Sendori.dll
2012-12-07 13:20:16 441856 ----a-w- C:\Windows\System32\Wpc.dll
2012-12-07 13:15:31 2746368 ----a-w- C:\Windows\System32\gameux.dll
2012-12-07 12:26:17 308736 ----a-w- C:\Windows\SysWow64\Wpc.dll
2012-12-07 12:20:43 2576384 ----a-w- C:\Windows\SysWow64\gameux.dll
2012-12-07 11:20:04 30720 ----a-w- C:\Windows\System32\usk.rs
2012-12-07 11:20:03 43520 ----a-w- C:\Windows\System32\csrr.rs
2012-12-07 11:20:03 23552 ----a-w- C:\Windows\System32\oflc.rs
2012-12-07 11:20:01 45568 ----a-w- C:\Windows\System32\oflc-nz.rs
2012-12-07 11:20:01 44544 ----a-w- C:\Windows\System32\pegibbfc.rs
2012-12-07 11:20:01 20480 ----a-w- C:\Windows\System32\pegi-fi.rs
2012-12-07 11:20:00 20480 ----a-w- C:\Windows\System32\pegi-pt.rs
2012-12-07 11:19:59 20480 ----a-w- C:\Windows\System32\pegi.rs
2012-12-07 11:19:58 46592 ----a-w- C:\Windows\System32\fpb.rs
2012-12-07 11:19:57 40960 ----a-w- C:\Windows\System32\cob-au.rs
2012-12-07 11:19:57 21504 ----a-w- C:\Windows\System32\grb.rs
2012-12-07 11:19:57 15360 ----a-w- C:\Windows\System32\djctq.rs
2012-12-07 11:19:56 55296 ----a-w- C:\Windows\System32\cero.rs
2012-12-07 11:19:55 51712 ----a-w- C:\Windows\System32\esrb.rs
2012-11-30 05:45:35 362496 ----a-w- C:\Windows\System32\wow64win.dll
2012-11-30 05:45:35 243200 ----a-w- C:\Windows\System32\wow64.dll
2012-11-30 05:45:35 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2012-11-30 05:45:14 215040 ----a-w- C:\Windows\System32\winsrv.dll
2012-11-30 05:43:12 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2012-11-30 05:41:07 424448 ----a-w- C:\Windows\System32\KernelBase.dll
2012-11-30 04:54:00 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2012-11-30 04:53:59 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2012-11-30 03:23:48 338432 ----a-w- C:\Windows\System32\conhost.exe
2012-11-30 02:44:06 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2012-11-30 02:44:04 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2012-11-30 02:44:04 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2012-11-30 02:44:03 2048 ----a-w- C:\Windows\SysWow64\user.exe
2012-11-30 02:38:59 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2012-11-30 02:38:59 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2012-11-30 02:38:59 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2012-11-30 02:38:59 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2012-11-26 00:31:01 9728 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2012-11-25 02:51:37 283200 ----a-w- C:\Windows\System32\drivers\dtsoftbus01.sys
2012-11-23 03:26:31 3149824 ----a-w- C:\Windows\System32\win32k.sys
2012-11-23 03:13:57 68608 ----a-w- C:\Windows\System32\taskhost.exe
2012-11-22 05:44:23 800768 ----a-w- C:\Windows\System32\usp10.dll
2012-11-22 04:45:03 626688 ----a-w- C:\Windows\SysWow64\usp10.dll
2012-11-20 05:48:49 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-11-20 04:51:09 220160 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-11-14 06:11:44 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2012-11-14 06:04:11 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-11-14 06:02:49 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-11-14 05:57:46 599040 ----a-w- C:\Windows\System32\vbscript.dll
2012-11-14 05:57:35 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-11-14 05:52:40 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-11-14 02:09:22 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-11-14 01:58:15 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-11-14 01:57:37 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-11-14 01:49:25 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-11-14 01:48:27 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
2012-11-14 01:44:42 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-11-09 05:45:32 750592 ----a-w- C:\Windows\System32\win32spl.dll
2012-11-09 04:53:17 95208 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2012-11-09 04:53:16 821736 ----a-w- C:\Windows\SysWow64\npdeployJava1.dll
2012-11-09 04:43:04 492032 ----a-w- C:\Windows\SysWow64\win32spl.dll
2012-11-03 08:48:54 174200 ----a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2012-11-03 05:21:06 473072 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2012-11-01 05:43:42 2002432 ----a-w- C:\Windows\System32\msxml6.dll
2012-11-01 05:43:42 1882624 ----a-w- C:\Windows\System32\msxml3.dll
2012-11-01 04:47:54 1389568 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-11-01 04:47:54 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-10-29 13:14:20 1981312 ----a-w- C:\Windows\System32\Wacom_Tablet.dll
2012-10-29 13:14:20 1974144 ----a-w- C:\Windows\System32\Wacom_Touch_Tablet.dll
2012-10-29 13:14:20 1843072 ----a-w- C:\Windows\System32\Wintab32.dll
2012-10-29 13:14:18 1840000 ----a-w- C:\Windows\System32\WacomMT.dll
2012-10-29 13:14:16 1628032 ----a-w- C:\Windows\SysWow64\Wacom_Tablet.dll
2012-10-29 13:14:16 1621376 ----a-w- C:\Windows\SysWow64\Wacom_Touch_Tablet.dll
2012-10-29 13:14:16 1509248 ----a-w- C:\Windows\SysWow64\Wintab32.dll
2012-10-29 13:14:16 1505152 ----a-w- C:\Windows\SysWow64\WacomMT.dll
2012-10-16 21:34:57 3544134 ----a-w- C:\Windows\System32\nvcoproc.bin
2012-10-16 21:34:56 3293544 ----a-w- C:\Windows\System32\nvsvc64.dll
2012-10-16 21:34:42 6200680 ----a-w- C:\Windows\System32\nvcpl.dll
2012-10-16 21:34:33 891240 ----a-w- C:\Windows\System32\nvvsvc.exe
2012-10-16 21:34:32 866664 ----a-w- C:\Windows\System32\nv3dappshext.dll
2012-10-16 21:34:32 63336 ----a-w- C:\Windows\System32\nvshext.dll
2012-10-16 21:34:32 55144 ----a-w- C:\Windows\System32\nv3dappshextr.dll
2012-10-16 21:34:32 2557800 ----a-w- C:\Windows\System32\nvsvcr.dll
2012-10-16 21:34:32 118120 ----a-w- C:\Windows\System32\nvmctray.dll
2012-10-16 08:38:37 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2012-10-16 08:38:34 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2012-10-16 07:39:52 561664 ----a-w- C:\Windows\apppatch\AcLayers.dll
.
============= FINISH: 20:18:59.76 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 11/3/2012 10:37:38 PM
System Uptime: 1/10/2013 6:55:50 PM (2 hours ago)
.
Motherboard: Dell Inc. | | 0K4H3G
Processor: Intel(R) Core(TM) i7-2670QM CPU @ 2.20GHz | CPU | 2201/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 347 GiB total, 289.024 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 332 GiB total, 29.876 GiB free.
F: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Description: facap, FastAccess Video Capture
Device ID: ROOT\IMAGE\0000
Manufacturer: Sensible Vision
Name: facap, FastAccess Video Capture
PNP Device ID: ROOT\IMAGE\0000
Service: FACAP
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
AccelerometerP11
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Reader XI (11.0.01)
Advanced Audio FX Engine
Allmyapps
Amazon Kindle
Audacity 2.0.2
Auslogics Duplicate File Finder
Big Solitaires 3D 1.4
calibre
CCleaner
Consumer In-Home Service Agreement
Cozi
CutePDF Writer 3.0
CyberLink PowerDVD 9.6
D3DX10
DAEMON Tools Lite
Dell DataSafe Local Backup
Dell DataSafe Local Backup - Support Software
Dell DataSafe Online
Dell Digital Delivery
Dell Edoc Viewer
Dell Getting Started Guide
Dell MusicStage
Dell PhotoStage
Dell Stage
Dell Support Center
Dell VideoStage
Dell Webcam Central
DirectX 9 Runtime
Face Recognition
Facebook Messenger 2.1.4651.0
FastStone Photo Resizer 3.1
Free YouTube Download version 3.1.40.1031
Google Chrome
Google Drive
Google Toolbar for Internet Explorer
Google Update Helper
Greenshot 1.0.6.2228
Intel PROSet Wireless
Intel(R) Control Center
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology
Intel(R) PROSet/Wireless WiFi Software
Intel(R) Turbo Boost Technology Monitor 2.0
Intel(R) WiDi
Intel(R) Wireless Display
Internet Explorer
iSEEK AnswerWorks English Runtime
Java 7 Update 9
Java(TM) 6 Update 27 (64-bit)
Java(TM) 6 Update 37
Jing
Junk Mail filter update
K-Lite Codec Pack 9.4.6 (Standard)
LAME v3.99.3 (for Windows)
LastPass(uninstall only)
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Office 64-bit Components 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared 64-bit MUI (English) 2007
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Ultimate 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft SkyDrive
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Movie Maker
MSVCRT
MSVCRT_amd64
MSVCRT110
MSVCRT110_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nero 10 Movie ThemePack Basic
Nero Blu-ray Player
Nero Control Center 10
Nero ControlCenter 10 Help (CHM)
Nero Core Components 10
Nero Update
NOOK for PC
Norton 360
NVIDIA Control Panel 307.21
NVIDIA Graphics Driver 307.21
NVIDIA Install Application
NVIDIA Optimus 1.10.8
NVIDIA Update 1.10.8
NVIDIA Update Components
Photo Common
Photo Gallery
PhotoShowExpress
PlayReady PC Runtime x86
Quicken 2012
Quickset64
RBVirtualFolder64Inst
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
Realtek High Definition Audio Driver
RealUpgrade 1.1
Roxio Activation Module
Roxio BackOnTrack
Roxio Burn
Roxio Creator Starter
Roxio Express Labeler 3
Roxio File Backup
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687441) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition
Sendori
Skype 6.0
SmartTRAK
Sonic CinePlayer Decoder Pack
Sound Blaster X-Fi MB
SpeedFan (remove only)
Spybot - Search & Destroy
Synaptics Pointing Device Driver
SyncUP
System Requirements Lab for Intel
TrustedID
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2760586) 32-Bit Edition
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
VLC media player 2.0.5
Wacom Tablet
WebQuiz XP
WebTablet FB Plugin 64 bit
WeBuilder 2011 v11.4
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Movie Maker 2.6
WinHTTrack Website Copier 3.46-1 (x64)
WinSCP 5.1.3
.
==== Event Viewer Messages From Past Week ========
.
1/9/2013 8:54:38 PM, Error: Service Control Manager [7022] - The Service Sendori service hung on starting.
1/9/2013 11:14:09 PM, Error: PCTCore [280] -
1/10/2013 7:00:22 PM, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
1/10/2013 7:00:22 PM, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
1/10/2013 6:59:12 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.
1/10/2013 6:57:16 PM, Error: Service Control Manager [7001] - The Spybot-S&D 2 Security Center Service service depends on the Security Center service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
1/10/2013 6:16:45 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
1/10/2013 6:16:45 PM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
.
==== End Of File ===========================
GMER 2.0.18444 - http://www.gmer.net
Rootkit scan 2013-01-10 21:30:17
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 rev. 698.64GB
Running: gut16kj6.exe; Driver: C:\Users\Shelli\AppData\Local\Temp\pxldrpow.sys
---- User code sections - GMER 2.0 ----
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000765b1401 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000765b1419 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000765b1431 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000765b144a 2 bytes [5B, 76]
.text ... * 9
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000765b14dd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000765b14f5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000765b150d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000765b1525 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000765b153d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000765b1555 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000765b156d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000765b1585 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000765b159d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000765b15b5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000765b15cd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000765b16b2 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000765b16bd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\ksuser.dll!KsCreatePin + 35 00000000709a11a8 2 bytes [9A, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\ksuser.dll!KsCreatePin + 248 00000000709a127d 2 bytes [9A, 70]
.text ... * 6
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\ksuser.dll!KsCreateAllocator + 21 00000000709a13a8 2 bytes [9A, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\ksuser.dll!KsCreateClock + 21 00000000709a1422 2 bytes [9A, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\ksuser.dll!KsCreateTopologyNode + 19 00000000709a1498 2 bytes [9A, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkD3dContextCreate + 4 00000000707c1825 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkD3dContextDestroy + 4 00000000707c1830 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkD3dContextDestroyAll + 4 00000000707c183b 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkD3dDrawPrimitives2 + 4 00000000707c1846 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkD3dValidateTextureStageState + 4 00000000707c1851 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdAddAttachedSurface + 4 00000000707c185c 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdAlphaBlt + 4 00000000707c1867 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdAttachSurface + 4 00000000707c1872 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdBeginMoCompFrame + 4 00000000707c187d 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdBlt + 4 00000000707c1888 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdCanCreateD3DBuffer + 4 00000000707c1893 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdCanCreateSurface + 4 00000000707c189e 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdColorControl + 4 00000000707c18a9 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdCreateD3DBuffer + 4 00000000707c18b4 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdCreateDirectDrawObject + 4 00000000707c18bf 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdCreateMoComp + 4 00000000707c18ca 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdCreateSurface + 4 00000000707c18d5 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdCreateSurfaceEx + 4 00000000707c18e0 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdCreateSurfaceObject + 4 00000000707c18eb 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdDeleteDirectDrawObject + 4 00000000707c18f6 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdDeleteSurfaceObject + 4 00000000707c1901 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdDestroyD3DBuffer + 4 00000000707c190c 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdDestroyMoComp + 4 00000000707c1917 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdDestroySurface + 4 00000000707c1922 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdEndMoCompFrame + 4 00000000707c192d 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdFlip + 4 00000000707c1938 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdFlipToGDISurface + 4 00000000707c1943 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetAvailDriverMemory + 4 00000000707c194e 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetBltStatus + 4 00000000707c1959 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetDC + 4 00000000707c1964 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetDriverInfo + 4 00000000707c196f 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetDriverState + 4 00000000707c197a 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetDxHandle + 4 00000000707c1985 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetFlipStatus + 4 00000000707c1990 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetInternalMoCompInfo + 4 00000000707c199b 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetMoCompBuffInfo + 4 00000000707c19a6 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetMoCompFormats + 4 00000000707c19b1 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetMoCompGuids + 4 00000000707c19bc 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdGetScanLine + 4 00000000707c19c7 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdLock + 4 00000000707c19d2 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdLockD3D + 4 00000000707c19dd 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdQueryDirectDrawObject + 4 00000000707c19e8 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdQueryMoCompStatus + 4 00000000707c19f3 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdReenableDirectDrawObject + 4 00000000707c19fe 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdReleaseDC + 4 00000000707c1a09 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdRenderMoComp + 4 00000000707c1a14 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdResetVisrgn + 4 00000000707c1a1f 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdSetColorKey + 4 00000000707c1a2a 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdSetExclusiveMode + 4 00000000707c1a35 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdSetGammaRamp + 4 00000000707c1a40 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdSetOverlayPosition + 4 00000000707c1a4b 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdUnattachSurface + 4 00000000707c1a56 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdUnlock + 4 00000000707c1a61 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdUnlockD3D + 4 00000000707c1a6c 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdUpdateOverlay + 4 00000000707c1a77 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 4 00000000707c1a82 2 bytes [7C, 70]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe[636] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 52 00000000707c1ab2 2 bytes [7C, 70]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1272] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetModuleFileNameExW + 17 00000000765b1401 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!EnumProcessModules + 17 00000000765b1419 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 17 00000000765b1431 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 42 00000000765b144a 2 bytes [5B, 76]
.text ... * 9
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!EnumDeviceDrivers + 17 00000000765b14dd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameA + 17 00000000765b14f5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!QueryWorkingSetEx + 17 00000000765b150d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameW + 17 00000000765b1525 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetModuleBaseNameW + 17 00000000765b153d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!EnumProcesses + 17 00000000765b1555 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetProcessMemoryInfo + 17 00000000765b156d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetPerformanceInfo + 17 00000000765b1585 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!QueryWorkingSet + 17 00000000765b159d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetModuleBaseNameA + 17 00000000765b15b5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetModuleFileNameExA + 17 00000000765b15cd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 20 00000000765b16b2 2 bytes [5B, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2948] C:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 31 00000000765b16bd 2 bytes [5B, 76]
.text C:\Windows\system32\taskeng.exe[1680] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Windows\system32\taskeng.exe[1680] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Windows\system32\taskeng.exe[1680] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Windows\system32\taskeng.exe[1680] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Windows\system32\taskeng.exe[1680] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Windows\system32\taskeng.exe[1680] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Windows\system32\taskeng.exe[1680] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Windows\system32\taskeng.exe[1680] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Windows\system32\Dwm.exe[3276] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Windows\system32\Dwm.exe[3276] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Windows\system32\Dwm.exe[3276] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Windows\system32\Dwm.exe[3276] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Windows\system32\Dwm.exe[3276] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Windows\system32\Dwm.exe[3276] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Windows\system32\Dwm.exe[3276] C:\Windows\system32\dxgi.dll!CreateDXGIFactory 000007fefa02dc88 5 bytes JMP 000007fffa0000d8
.text C:\Windows\system32\Dwm.exe[3276] C:\Windows\system32\dxgi.dll!CreateDXGIFactory1 000007fefa02de10 5 bytes JMP 000007fffa000110
.text C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[3284] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[3284] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[3284] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[3284] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[3284] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe[3284] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076fe1d1b 5 bytes JMP 00000001729611d1
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076fe1dc9 5 bytes JMP 0000000172961019
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076fe2aa4 5 bytes JMP 000000017296154b
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076fe2d0a 5 bytes JMP 0000000172961276
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076f6e9a2 5 bytes JMP 00000001729615b4
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076f6ebdc 5 bytes JMP 000000017296119a
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075585ea5 5 bytes JMP 00000001729615e6
.text C:\Program Files\Tablet\Wacom\WacomHost.exe[3292] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000755b9d0b 5 bytes JMP 000000017296122b
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe[3312] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[3356] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[3356] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[3356] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[3356] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[3356] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[3356] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[3356] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[3356] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[3356] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[3356] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe[3356] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\WINDOWS\System32\WerFault.exe[3852] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\WINDOWS\System32\WerFault.exe[3852] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\WINDOWS\System32\WerFault.exe[3852] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\WINDOWS\System32\WerFault.exe[3852] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\WINDOWS\System32\WerFault.exe[3852] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\WINDOWS\System32\WerFault.exe[3852] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\WINDOWS\System32\WerFault.exe[3852] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\WINDOWS\System32\WerFault.exe[3852] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\WINDOWS\System32\WerFault.exe[3852] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\WINDOWS\System32\WerFault.exe[3852] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\WINDOWS\System32\WerFault.exe[3852] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000765b1401 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000765b1419 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000765b1431 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000765b144a 2 bytes [5B, 76]
.text ... * 9
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000765b14dd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000765b14f5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000765b150d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000765b1525 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000765b153d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000765b1555 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000765b156d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000765b1585 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000765b159d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000765b15b5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000765b15cd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000765b16b2 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[3868] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000765b16bd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000765b1401 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000765b1419 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000765b1431 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000765b144a 2 bytes [5B, 76]
.text ... * 9
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000765b14dd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000765b14f5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000765b150d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000765b1525 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000765b153d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000765b1555 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000765b156d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000765b1585 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000765b159d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000765b15b5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000765b15cd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000765b16b2 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sendori\sndappv2.exe[3948] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000765b16bd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\KERNEL32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\KERNEL32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076fe1d1b 5 bytes JMP 00000001729611d1
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076fe1dc9 5 bytes JMP 0000000172961019
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076fe2aa4 5 bytes JMP 000000017296154b
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076fe2d0a 5 bytes JMP 0000000172961276
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076f6e9a2 5 bytes JMP 00000001729615b4
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076f6ebdc 5 bytes JMP 000000017296119a
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075585ea5 5 bytes JMP 00000001729615e6
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4364] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000755b9d0b 5 bytes JMP 000000017296122b
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076fe1d1b 5 bytes JMP 00000001729611d1
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076fe1dc9 5 bytes JMP 0000000172961019
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076fe2aa4 5 bytes JMP 000000017296154b
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076fe2d0a 5 bytes JMP 0000000172961276
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076f6e9a2 5 bytes JMP 00000001729615b4
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076f6ebdc 5 bytes JMP 000000017296119a
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075585ea5 5 bytes JMP 00000001729615e6
.text C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE[4492] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000755b9d0b 5 bytes JMP 000000017296122b
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\KERNEL32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\KERNEL32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076fe1d1b 5 bytes JMP 00000001729611d1
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076fe1dc9 5 bytes JMP 0000000172961019
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076fe2aa4 5 bytes JMP 000000017296154b
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076fe2d0a 5 bytes JMP 0000000172961276
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076f6e9a2 5 bytes JMP 00000001729615b4
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076f6ebdc 5 bytes JMP 000000017296119a
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075585ea5 5 bytes JMP 00000001729615e6
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe[4592] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000755b9d0b 5 bytes JMP 000000017296122b
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4624] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4632] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4640] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\WINDOWS\System32\igfxpers.exe[4684] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076fe1d1b 5 bytes JMP 00000001729611d1
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076fe1dc9 5 bytes JMP 0000000172961019
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076fe2aa4 5 bytes JMP 000000017296154b
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076fe2d0a 5 bytes JMP 0000000172961276
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076f6e9a2 5 bytes JMP 00000001729615b4
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076f6ebdc 5 bytes JMP 000000017296119a
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075585ea5 5 bytes JMP 00000001729615e6
.text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[4708] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000755b9d0b 5 bytes JMP 000000017296122b
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4772] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4832] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4832] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4832] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4832] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4832] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4832] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Program Files\Dell\QuickSet\quickset.exe[5052] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4588] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\KERNEL32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\KERNEL32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe[5240] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Windows\system32\AMBSpiE.exe[5324] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076fe1d1b 5 bytes JMP 00000001729611d1
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076fe1dc9 5 bytes JMP 0000000172961019
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076fe2aa4 5 bytes JMP 000000017296154b
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076fe2d0a 5 bytes JMP 0000000172961276
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076f6e9a2 5 bytes JMP 00000001729615b4
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076f6ebdc 5 bytes JMP 000000017296119a
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075585ea5 5 bytes JMP 00000001729615e6
.text C:\Program Files (x86)\Cyberlink\Shared files\brs.exe[5504] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000755b9d0b 5 bytes JMP 000000017296122b
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076fe1d1b 5 bytes JMP 00000001729611d1
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076fe1dc9 5 bytes JMP 0000000172961019
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076fe2aa4 5 bytes JMP 000000017296154b
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076fe2d0a 5 bytes JMP 0000000172961276
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000765b1401 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000765b1419 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000765b1431 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000765b144a 2 bytes [5B, 76]
.text ... * 9
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000765b14dd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000765b14f5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000765b150d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000765b1525 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000765b153d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000765b1555 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000765b156d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000765b1585 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000765b159d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000765b15b5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000765b15cd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000765b16b2 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000765b16bd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076f6e9a2 5 bytes JMP 00000001729615b4
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076f6ebdc 5 bytes JMP 000000017296119a
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075585ea5 5 bytes JMP 00000001729615e6
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe[5620] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000755b9d0b 5 bytes JMP 000000017296122b
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076fe1d1b 5 bytes JMP 00000001729611d1
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076fe1dc9 5 bytes JMP 0000000172961019
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076fe2aa4 5 bytes JMP 000000017296154b
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076fe2d0a 5 bytes JMP 0000000172961276
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076f6e9a2 5 bytes JMP 00000001729615b4
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076f6ebdc 5 bytes JMP 000000017296119a
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075585ea5 5 bytes JMP 00000001729615e6
.text C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe[5660] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000755b9d0b 5 bytes JMP 000000017296122b
.text C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe[5680] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 00000000764b87b1 5 bytes [33, C0, C2, 04, 00]
.text C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe[5680] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe[5680] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe[5680] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe[5680] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe[5680] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files (x86)\Sendori\SendoriTray.exe[5744] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files (x86)\Sendori\SendoriTray.exe[5744] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files (x86)\Sendori\SendoriTray.exe[5744] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files (x86)\Sendori\SendoriTray.exe[5744] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files (x86)\Sendori\SendoriTray.exe[5744] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076fe1d1b 5 bytes JMP 00000001729611d1
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076fe1dc9 5 bytes JMP 0000000172961019
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076fe2aa4 5 bytes JMP 000000017296154b
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076fe2d0a 5 bytes JMP 0000000172961276
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000765b1401 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000765b1419 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000765b1431 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000765b144a 2 bytes [5B, 76]
.text ... * 9
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000765b14dd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000765b14f5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000765b150d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000765b1525 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000765b153d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000765b1555 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000765b156d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000765b1585 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000765b159d 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000765b15b5 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000765b15cd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000765b16b2 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000765b16bd 2 bytes [5B, 76]
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076f6e9a2 5 bytes JMP 00000001729615b4
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076f6ebdc 5 bytes JMP 000000017296119a
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075585ea5 5 bytes JMP 00000001729615e6
.text C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe[5824] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000755b9d0b 5 bytes JMP 000000017296122b
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\KERNEL32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\KERNEL32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefeda7490 11 bytes JMP 000007fffde50228
.text C:\Program Files (x86)\Sensible Vision\Fast Access\Vendor\FastAccessChatAssist.exe[5920] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefedbbf00 7 bytes JMP 000007fffde50260
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5928] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5928] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000776699b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5928] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000776794d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5928] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077679640 5 bytes JMP 000000016fff0110
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5928] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007769a500 7 bytes JMP 000000016fff01b8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5928] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefde63460 7 bytes JMP 000007fffde500d8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5928] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefde69940 6 bytes JMP 000007fffde50148
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5928] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefde69fb0 5 bytes JMP 000007fffde50180
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5928] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefde6a150 5 bytes JMP 000007fffde50110
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5928] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff6189e0 8 bytes JMP 000007fffde501f0
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[5928] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff61be40 8 bytes JMP 000007fffde501b8
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076fe1d1b 5 bytes JMP 00000001729611d1
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076fe1dc9 5 bytes JMP 0000000172961019
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076fe2aa4 5 bytes JMP 000000017296154b
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076fe2d0a 5 bytes JMP 0000000172961276
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076f6e9a2 5 bytes JMP 00000001729615b4
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076f6ebdc 5 bytes JMP 000000017296119a
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075585ea5 5 bytes JMP 00000001729615e6
.text C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe[996] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000755b9d0b 5 bytes JMP 000000017296122b
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000764c1429 7 bytes JMP 000000017296128f
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000764db223 5 bytes JMP 000000017296159b
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000765588f4 7 bytes JMP 0000000172961339
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076558979 5 bytes JMP 00000001729616b8
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076558ccf 5 bytes JMP 000000017296101e
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076fe1d1b 5 bytes JMP 00000001729611d1
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076fe1dc9 5 bytes JMP 0000000172961019
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076fe2aa4 5 bytes JMP 000000017296154b
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076fe2d0a 5 bytes JMP 0000000172961276
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076f6e9a2 5 bytes JMP 00000001729615b4
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076f6ebdc 5 bytes JMP 000000017296119a
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075585ea5 5 bytes JMP 00000001729615e6
.text C:\Users\Shelli\Desktop\gut16kj6.exe[5436] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000755b9d0b 5 bytes JMP 000000017296122b
---- Devices - GMER 2.0 ----
Device \FileSystem\fastfat \Fat m32\Drivers\Ntfs.sys
Device \Driver\qicflt \Device\ToasterFilter ws\system32\DRIVERS\kbdclass.sys
Device \FileSystem\SRTSP \Device\NAVAP ws\system32\DRIVERS\kbdclass.sys
Device \Driver\NAVENG \Device\NAVENG ws\system32\DRIVERS\kbdclass.sys
Device \Driver\NAVEX15 \Device\NAVEX15 ws\system32\DRIVERS\kbdclass.sys
Device \Driver\usbccgp \Device\0000009c ws\system32\DRIVERS\kbdclass.sys
Device \FileSystem\SRTSP \Device\SAVRT
Device \FileSystem\SRTSP \Device\SRTSP
---- Threads - GMER 2.0 ----
Thread C:\Windows\SysWOW64\rundll32.exe [1944:1304] 000000000043f040
Thread C:\Windows\SysWOW64\rundll32.exe [1944:1328] 00000000001d3a80
Thread C:\Windows\SysWOW64\rundll32.exe [1944:1732] 00000000001d3a10
Thread C:\Windows\SysWOW64\rundll32.exe [1944:5764] 0000000000515cfe
Thread C:\Windows\SysWOW64\rundll32.exe [1944:5612] 0000000000512ea6
Thread C:\Windows\SysWOW64\rundll32.exe [1944:6008] 00000000005133de
Thread [1636:5236] 0000000077952e25
Thread [1636:5304] 0000000076dc820d
Thread [1636:5308] 0000000077953e45
Thread [1636:5312] 0000000077953e45
Thread [1636:5316] 000000007559d864
Thread [1636:5344] 0000000071e7a6e3
Thread [1636:5616] 0000000071e75548
---- Processes - GMER 2.0 ----
Library ? (*** suspicious ***) @ [1636] 0000000000400000
Library ? (*** suspicious ***) @ C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [5680] 0000000075510000
---- Registry - GMER 2.0 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Teredo\PreviousState\[email protected] 51123
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Teredo\PreviousState\[email protected] 2001:0:4137:9e76:24c6:384c:b838:4ff9
Reg HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\[email protected] 1882
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3B34BA86-2C39-415B-9F6F-541F0D2687CE}@EnableDHCP 0
---- Files - GMER 2.0 ----
File C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS010CA.log 1048576 bytes
---- EOF - GMER 2.0 ----
=============
Tech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows 7 Home Premium, Service Pack 1, 64 bit
Processor: Intel(R) Core(TM) i7-2670QM CPU @ 2.20GHz, Intel64 Family 6 Model 42 Stepping 7
Processor Count: 8
RAM: 8086 Mb
Graphics Card: NVIDIA GeForce GT 550M, 1023 Mb
Hard Drives: C: Total - 355551 MB, Free - 295303 MB; E: Total - 339745 MB, Free - 30591 MB;
Motherboard: Dell Inc., 0K4H3G
Antivirus: Norton 360, Updated and Enabled