Hi Gringo, GMER report completed and here it is...I will still have to backup my files. I do need to get a little more sleep, lol. I will connect later this afternnon. Thanks for your help
GMER REPORT
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-05-04 06:24:06
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST9160412ASG rev.0004SDM1
Running: gmer.exe; Driver: C:\DOCUME~1\Connie's\LOCALS~1\Temp\pxldqpog.sys
---- System - GMER 1.0.15 ----
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwCreateKey [0xF76B52A0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteKey [0xF76B52B4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xF76B52E0]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xF76B5336]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenKey [0xF76B528C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xF76B5264]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xF76B5278]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwRenameKey [0xF76B52CA]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetSecurityObject [0xF76B530C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetValueKey [0xF76B52F6]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0xF76B5360]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xF76B534C]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0xF76B5320]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetSecurityObject
---- Kernel code sections - GMER 1.0.15 ----
init C:\WINDOWS\system32\drivers\tifm21.sys entry point in "init" section [0xB9D24EBF]
? C:\DOCUME~1\Connie's\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\System32\svchost.exe[140] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 026B0FEF
.text C:\WINDOWS\System32\svchost.exe[140] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 026B0FD4
.text C:\WINDOWS\System32\svchost.exe[140] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 026B000A
.text C:\WINDOWS\System32\svchost.exe[140] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 03B30000
.text C:\WINDOWS\System32\svchost.exe[140] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 03B300A1
.text C:\WINDOWS\System32\svchost.exe[140] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 03B30090
.text C:\WINDOWS\System32\svchost.exe[140] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 03B30073
.text C:\WINDOWS\System32\svchost.exe[140] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 03B30FB6
.text C:\WINDOWS\System32\svchost.exe[140] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 03B30047
.text C:\WINDOWS\System32\svchost.exe[140] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 03B30F80
.text C:\WINDOWS\System32\svchost.exe[140] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 03B300C8
.text C:\WINDOWS\System32\svchost.exe[140] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 03B30F54
.text C:\WINDOWS\System32\svchost.exe[140] kernel32.dll!CreateProcessA 7C80236B 1 Byte [E9]
.text C:\WINDOWS\System32\svchost.exe[140] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 03B30F6F
.text C:\WINDOWS\System32\svchost.exe[140] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 03B30F43
.text C:\WINDOWS\System32\svchost.exe[140] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 03B30058
.text C:\WINDOWS\System32\svchost.exe[140] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 03B30011
.text C:\WINDOWS\System32\svchost.exe[140] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 03B30F9B
.text C:\WINDOWS\System32\svchost.exe[140] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 03B30FE5
.text C:\WINDOWS\System32\svchost.exe[140] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 03B30036
.text C:\WINDOWS\System32\svchost.exe[140] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 03B300ED
.text C:\WINDOWS\System32\svchost.exe[140] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 03B2001B
.text C:\WINDOWS\System32\svchost.exe[140] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 03B20087
.text C:\WINDOWS\System32\svchost.exe[140] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 03B20FCA
.text C:\WINDOWS\System32\svchost.exe[140] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 03B20FDB
.text C:\WINDOWS\System32\svchost.exe[140] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 03B20076
.text C:\WINDOWS\System32\svchost.exe[140] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 03B20000
.text C:\WINDOWS\System32\svchost.exe[140] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 03B2005B
.text C:\WINDOWS\System32\svchost.exe[140] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 03B20036
.text C:\WINDOWS\System32\svchost.exe[140] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 03B10FA3
.text C:\WINDOWS\System32\svchost.exe[140] msvcrt.dll!system 77C293C7 5 Bytes JMP 03B10FBE
.text C:\WINDOWS\System32\svchost.exe[140] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 03B10038
.text C:\WINDOWS\System32\svchost.exe[140] msvcrt.dll!_open 77C2F566 5 Bytes JMP 03B10000
.text C:\WINDOWS\System32\svchost.exe[140] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 03B10FD9
.text C:\WINDOWS\System32\svchost.exe[140] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 03B1001D
.text C:\WINDOWS\System32\svchost.exe[140] WS2_32.dll!socket 71AB4211 5 Bytes JMP 03440FEF
.text C:\WINDOWS\System32\svchost.exe[140] WININET.dll!InternetOpenA 3D95D6A8 5 Bytes JMP 02EA0FEF
.text C:\WINDOWS\System32\svchost.exe[140] WININET.dll!InternetOpenW 3D95DB21 5 Bytes JMP 02EA0FCA
.text C:\WINDOWS\System32\svchost.exe[140] WININET.dll!InternetOpenUrlA 3D95F3BC 5 Bytes JMP 02EA0000
.text C:\WINDOWS\System32\svchost.exe[140] WININET.dll!InternetOpenUrlW 3D9A6DFF 5 Bytes JMP 02EA0FAF
.text C:\WINDOWS\system32\svchost.exe[636] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00750FEF
.text C:\WINDOWS\system32\svchost.exe[636] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00750011
.text C:\WINDOWS\system32\svchost.exe[636] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00750000
.text C:\WINDOWS\system32\svchost.exe[636] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 0079000A
.text C:\WINDOWS\system32\svchost.exe[636] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 007900AB
.text C:\WINDOWS\system32\svchost.exe[636] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 0079009A
.text C:\WINDOWS\system32\svchost.exe[636] kernel32.dll!LoadLibraryExW 7C801AF5 3 Bytes JMP 0079007D
.text C:\WINDOWS\system32\svchost.exe[636] kernel32.dll!LoadLibraryExW + 4 7C801AF9 1 Byte [83]
.text C:\WINDOWS\system32\svchost.exe[636] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00790062
.text C:\WINDOWS\system32\svchost.exe[636] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00790051
.text C:\WINDOWS\system32\svchost.exe[636] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 007900C8
.text C:\WINDOWS\system32\svchost.exe[636] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00790F80
.text C:\WINDOWS\system32\svchost.exe[636] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00790F4A
.text C:\WINDOWS\system32\svchost.exe[636] kernel32.dll!CreateProcessA 7C80236B 1 Byte [E9]
.text C:\WINDOWS\system32\svchost.exe[636] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00790F6F
.text C:\WINDOWS\system32\svchost.exe[636] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00790F39
.text C:\WINDOWS\system32\svchost.exe[636] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00790FCA
.text C:\WINDOWS\system32\svchost.exe[636] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0079001B
.text C:\WINDOWS\system32\svchost.exe[636] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00790F9B
.text C:\WINDOWS\system32\svchost.exe[636] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00790040
.text C:\WINDOWS\system32\svchost.exe[636] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00790FEF
.text C:\WINDOWS\system32\svchost.exe[636] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 007900ED
.text C:\WINDOWS\system32\svchost.exe[636] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00780FE5
.text C:\WINDOWS\system32\svchost.exe[636] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00780F94
.text C:\WINDOWS\system32\svchost.exe[636] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00780036
.text C:\WINDOWS\system32\svchost.exe[636] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 0078001B
.text C:\WINDOWS\system32\svchost.exe[636] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00780FAF
.text C:\WINDOWS\system32\svchost.exe[636] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00780000
.text C:\WINDOWS\system32\svchost.exe[636] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 0078005B
.text C:\WINDOWS\system32\svchost.exe[636] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00780FD4
.text C:\WINDOWS\system32\svchost.exe[636] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00770F7F
.text C:\WINDOWS\system32\svchost.exe[636] msvcrt.dll!system 77C293C7 5 Bytes JMP 00770F9A
.text C:\WINDOWS\system32\svchost.exe[636] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00770FB5
.text C:\WINDOWS\system32\svchost.exe[636] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00770FE3
.text C:\WINDOWS\system32\svchost.exe[636] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0077000A
.text C:\WINDOWS\system32\svchost.exe[636] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00770FD2
.text C:\WINDOWS\system32\svchost.exe[636] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00760FEF
.text C:\WINDOWS\system32\svchost.exe[944] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00BA0000
.text C:\WINDOWS\system32\svchost.exe[944] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00BA0FD4
.text C:\WINDOWS\system32\svchost.exe[944] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00BA0FEF
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BE0FEF
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BE005B
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BE0F5C
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BE0F83
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BE0040
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BE0FB9
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BE0F2E
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BE0076
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BE00B6
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BE009B
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BE00C7
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BE0F9E
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BE0FCA
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BE0F4B
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BE0025
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BE0000
.text C:\WINDOWS\system32\svchost.exe[944] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BE0F1D
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00BD0FC0
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00BD0F83
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00BD0FDB
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00BD0011
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00BD0040
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00BD0000
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00BD0F94
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [DD, 88]
.text C:\WINDOWS\system32\svchost.exe[944] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00BD0FA5
.text C:\WINDOWS\system32\svchost.exe[944] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00BC004E
.text C:\WINDOWS\system32\svchost.exe[944] msvcrt.dll!system 77C293C7 5 Bytes JMP 00BC0FC3
.text C:\WINDOWS\system32\svchost.exe[944] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00BC0FDE
.text C:\WINDOWS\system32\svchost.exe[944] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00BC0FEF
.text C:\WINDOWS\system32\svchost.exe[944] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00BC0033
.text C:\WINDOWS\system32\svchost.exe[944] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00BC000C
.text C:\WINDOWS\system32\svchost.exe[944] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00BB0FEF
.text C:\WINDOWS\Explorer.EXE[1044] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 01490000
.text C:\WINDOWS\Explorer.EXE[1044] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 01490FE5
.text C:\WINDOWS\Explorer.EXE[1044] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0149001B
.text C:\WINDOWS\Explorer.EXE[1044] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01790000
.text C:\WINDOWS\Explorer.EXE[1044] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 0179008E
.text C:\WINDOWS\Explorer.EXE[1044] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01790F99
.text C:\WINDOWS\Explorer.EXE[1044] kernel32.dll!LoadLibraryExW 7C801AF5 3 Bytes JMP 01790073
.text C:\WINDOWS\Explorer.EXE[1044] kernel32.dll!LoadLibraryExW + 4 7C801AF9 1 Byte [84]
.text C:\WINDOWS\Explorer.EXE[1044] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01790FB6
.text C:\WINDOWS\Explorer.EXE[1044] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01790051
.text C:\WINDOWS\Explorer.EXE[1044] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 017900D5
.text C:\WINDOWS\Explorer.EXE[1044] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 017900C4
.text C:\WINDOWS\Explorer.EXE[1044] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01790F68
.text C:\WINDOWS\Explorer.EXE[1044] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01790101
.text C:\WINDOWS\Explorer.EXE[1044] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01790F4D
.text C:\WINDOWS\Explorer.EXE[1044] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01790062
.text C:\WINDOWS\Explorer.EXE[1044] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01790011
.text C:\WINDOWS\Explorer.EXE[1044] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 017900A9
.text C:\WINDOWS\Explorer.EXE[1044] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01790FDB
.text C:\WINDOWS\Explorer.EXE[1044] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01790022
.text C:\WINDOWS\Explorer.EXE[1044] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 017900F0
.text C:\WINDOWS\Explorer.EXE[1044] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01770FB9
.text C:\WINDOWS\Explorer.EXE[1044] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 0177004A
.text C:\WINDOWS\Explorer.EXE[1044] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01770FCA
.text C:\WINDOWS\Explorer.EXE[1044] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01770FDB
.text C:\WINDOWS\Explorer.EXE[1044] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01770F8D
.text C:\WINDOWS\Explorer.EXE[1044] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01770000
.text C:\WINDOWS\Explorer.EXE[1044] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 01770025
.text C:\WINDOWS\Explorer.EXE[1044] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01770FA8
.text C:\WINDOWS\Explorer.EXE[1044] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 014C0F86
.text C:\WINDOWS\Explorer.EXE[1044] msvcrt.dll!system 77C293C7 5 Bytes JMP 014C0F97
.text C:\WINDOWS\Explorer.EXE[1044] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 014C0000
.text C:\WINDOWS\Explorer.EXE[1044] msvcrt.dll!_open 77C2F566 5 Bytes JMP 014C0FEF
.text C:\WINDOWS\Explorer.EXE[1044] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 014C0011
.text C:\WINDOWS\Explorer.EXE[1044] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 014C0FD2
.text C:\WINDOWS\Explorer.EXE[1044] WININET.dll!InternetOpenA 3D95D6A8 5 Bytes JMP 014A0FE5
.text C:\WINDOWS\Explorer.EXE[1044] WININET.dll!InternetOpenW 3D95DB21 5 Bytes JMP 014A0000
.text C:\WINDOWS\Explorer.EXE[1044] WININET.dll!InternetOpenUrlA 3D95F3BC 5 Bytes JMP 014A0011
.text C:\WINDOWS\Explorer.EXE[1044] WININET.dll!InternetOpenUrlW 3D9A6DFF 5 Bytes JMP 014A0022
.text C:\WINDOWS\Explorer.EXE[1044] WS2_32.dll!socket 71AB4211 5 Bytes JMP 014B000A
.text C:\WINDOWS\system32\services.exe[1588] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00040000
.text C:\WINDOWS\system32\services.exe[1588] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00040FDE
.text C:\WINDOWS\system32\services.exe[1588] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00040FEF
.text C:\WINDOWS\system32\services.exe[1588] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00740FEF
.text C:\WINDOWS\system32\services.exe[1588] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00740F68
.text C:\WINDOWS\system32\services.exe[1588] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00740F83
.text C:\WINDOWS\system32\services.exe[1588] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00740051
.text C:\WINDOWS\system32\services.exe[1588] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00740F94
.text C:\WINDOWS\system32\services.exe[1588] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00740025
.text C:\WINDOWS\system32\services.exe[1588] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 0074009D
.text C:\WINDOWS\system32\services.exe[1588] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00740082
.text C:\WINDOWS\system32\services.exe[1588] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 007400DD
.text C:\WINDOWS\system32\services.exe[1588] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00740F3A
.text C:\WINDOWS\system32\services.exe[1588] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 007400EE
.text C:\WINDOWS\system32\services.exe[1588] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00740036
.text C:\WINDOWS\system32\services.exe[1588] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00740FD4
.text C:\WINDOWS\system32\services.exe[1588] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00740F57
.text C:\WINDOWS\system32\services.exe[1588] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00740014
.text C:\WINDOWS\system32\services.exe[1588] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00740FC3
.text C:\WINDOWS\system32\services.exe[1588] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 007400AE
.text C:\WINDOWS\system32\services.exe[1588] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00070FC0
.text C:\WINDOWS\system32\services.exe[1588] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00070F6F
.text C:\WINDOWS\system32\services.exe[1588] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00070FD1
.text C:\WINDOWS\system32\services.exe[1588] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00070011
.text C:\WINDOWS\system32\services.exe[1588] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00070F8A
.text C:\WINDOWS\system32\services.exe[1588] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00070000
.text C:\WINDOWS\system32\services.exe[1588] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00070036
.text C:\WINDOWS\system32\services.exe[1588] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00070FAF
.text C:\WINDOWS\system32\services.exe[1588] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00060F64
.text C:\WINDOWS\system32\services.exe[1588] msvcrt.dll!system 77C293C7 5 Bytes JMP 00060F7F
.text C:\WINDOWS\system32\services.exe[1588] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00060FB5
.text C:\WINDOWS\system32\services.exe[1588] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00060FE3
.text C:\WINDOWS\system32\services.exe[1588] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00060F90
.text C:\WINDOWS\system32\services.exe[1588] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00060FC6
.text C:\WINDOWS\system32\services.exe[1588] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00050000
.text C:\WINDOWS\system32\lsass.exe[1600] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00CC0000
.text C:\WINDOWS\system32\lsass.exe[1600] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00CC0FCA
.text C:\WINDOWS\system32\lsass.exe[1600] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00CC0FDB
.text C:\WINDOWS\system32\lsass.exe[1600] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00E90FEF
.text C:\WINDOWS\system32\lsass.exe[1600] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00E90F6B
.text C:\WINDOWS\system32\lsass.exe[1600] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00E90F86
.text C:\WINDOWS\system32\lsass.exe[1600] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00E90F97
.text C:\WINDOWS\system32\lsass.exe[1600] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00E90FA8
.text C:\WINDOWS\system32\lsass.exe[1600] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00E9002F
.text C:\WINDOWS\system32\lsass.exe[1600] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00E90F3D
.text C:\WINDOWS\system32\lsass.exe[1600] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00E90F5A
.text C:\WINDOWS\system32\lsass.exe[1600] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E900C5
.text C:\WINDOWS\system32\lsass.exe[1600] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E90F2C
.text C:\WINDOWS\system32\lsass.exe[1600] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00E90F11
.text C:\WINDOWS\system32\lsass.exe[1600] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00E9004A
.text C:\WINDOWS\system32\lsass.exe[1600] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00E9000A
.text C:\WINDOWS\system32\lsass.exe[1600] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00E90085
.text C:\WINDOWS\system32\lsass.exe[1600] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00E90FC3
.text C:\WINDOWS\system32\lsass.exe[1600] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00E90FD4
.text C:\WINDOWS\system32\lsass.exe[1600] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00E900A0
.text C:\WINDOWS\system32\lsass.exe[1600] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00CF0FCA
.text C:\WINDOWS\system32\lsass.exe[1600] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00CF0F8A
.text C:\WINDOWS\system32\lsass.exe[1600] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00CF0011
.text C:\WINDOWS\system32\lsass.exe[1600] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00CF0FE5
.text C:\WINDOWS\system32\lsass.exe[1600] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00CF0047
.text C:\WINDOWS\system32\lsass.exe[1600] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00CF0000
.text C:\WINDOWS\system32\lsass.exe[1600] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00CF0FA5
.text C:\WINDOWS\system32\lsass.exe[1600] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [EF, 88]
.text C:\WINDOWS\system32\lsass.exe[1600] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00CF0036
.text C:\WINDOWS\system32\lsass.exe[1600] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00CE0042
.text C:\WINDOWS\system32\lsass.exe[1600] msvcrt.dll!system 77C293C7 5 Bytes JMP 00CE0027
.text C:\WINDOWS\system32\lsass.exe[1600] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00CE0FC8
.text C:\WINDOWS\system32\lsass.exe[1600] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00CE0FEF
.text C:\WINDOWS\system32\lsass.exe[1600] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00CE0FB7
.text C:\WINDOWS\system32\lsass.exe[1600] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00CE0000
.text C:\WINDOWS\system32\lsass.exe[1600] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00CD0FEF
.text C:\Program Files\Messenger\msmsgs.exe[1604] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00EF0000
.text C:\Program Files\Messenger\msmsgs.exe[1604] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00EF0FCA
.text C:\Program Files\Messenger\msmsgs.exe[1604] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00EF0FDB
.text C:\Program Files\Messenger\msmsgs.exe[1604] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F90FE5
.text C:\Program Files\Messenger\msmsgs.exe[1604] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F90F3A
.text C:\Program Files\Messenger\msmsgs.exe[1604] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F90F4B
.text C:\Program Files\Messenger\msmsgs.exe[1604] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F90F72
.text C:\Program Files\Messenger\msmsgs.exe[1604] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F90F8D
.text C:\Program Files\Messenger\msmsgs.exe[1604] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F9001B
.text C:\Program Files\Messenger\msmsgs.exe[1604] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F90F18
.text C:\Program Files\Messenger\msmsgs.exe[1604] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F90054
.text C:\Program Files\Messenger\msmsgs.exe[1604] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F90EEC
.text C:\Program Files\Messenger\msmsgs.exe[1604] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F9007B
.text C:\Program Files\Messenger\msmsgs.exe[1604] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F90096
.text C:\Program Files\Messenger\msmsgs.exe[1604] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F90F9E
.text C:\Program Files\Messenger\msmsgs.exe[1604] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F90FD4
.text C:\Program Files\Messenger\msmsgs.exe[1604] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F90F29
.text C:\Program Files\Messenger\msmsgs.exe[1604] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F9000A
.text C:\Program Files\Messenger\msmsgs.exe[1604] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F90FC3
.text C:\Program Files\Messenger\msmsgs.exe[1604] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F90F07
.text C:\Program Files\Messenger\msmsgs.exe[1604] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00F70F8B
.text C:\Program Files\Messenger\msmsgs.exe[1604] msvcrt.dll!system 77C293C7 5 Bytes JMP 00F70F9C
.text C:\Program Files\Messenger\msmsgs.exe[1604] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00F70FC1
.text C:\Program Files\Messenger\msmsgs.exe[1604] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00F70FEF
.text C:\Program Files\Messenger\msmsgs.exe[1604] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00F7000C
.text C:\Program Files\Messenger\msmsgs.exe[1604] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00F70FD2
.text C:\Program Files\Messenger\msmsgs.exe[1604] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00F80FC3
.text C:\Program Files\Messenger\msmsgs.exe[1604] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00F8004A
.text C:\Program Files\Messenger\msmsgs.exe[1604] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00F80FD4
.text C:\Program Files\Messenger\msmsgs.exe[1604] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00F80000
.text C:\Program Files\Messenger\msmsgs.exe[1604] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00F80F8D
.text C:\Program Files\Messenger\msmsgs.exe[1604] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00F80FEF
.text C:\Program Files\Messenger\msmsgs.exe[1604] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00F80FA8
.text C:\Program Files\Messenger\msmsgs.exe[1604] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [18, 89]
.text C:\Program Files\Messenger\msmsgs.exe[1604] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00F8002F
.text C:\Program Files\Messenger\msmsgs.exe[1604] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00F60FE5
.text C:\Program Files\Messenger\msmsgs.exe[1604] WININET.dll!InternetOpenA 3D95D6A8 5 Bytes JMP 00F50FEF
.text C:\Program Files\Messenger\msmsgs.exe[1604] WININET.dll!InternetOpenW 3D95DB21 5 Bytes JMP 00F50000
.text C:\Program Files\Messenger\msmsgs.exe[1604] WININET.dll!InternetOpenUrlA 3D95F3BC 5 Bytes JMP 00F50FCA
.text C:\Program Files\Messenger\msmsgs.exe[1604] WININET.dll!InternetOpenUrlW 3D9A6DFF 5 Bytes JMP 00F50FB9
.text C:\WINDOWS\system32\svchost.exe[1768] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00AC000A
.text C:\WINDOWS\system32\svchost.exe[1768] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00AC0FD4
.text C:\WINDOWS\system32\svchost.exe[1768] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00AC0FE5
.text C:\WINDOWS\system32\svchost.exe[1768] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F90000
.text C:\WINDOWS\system32\svchost.exe[1768] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F90FA5
.text C:\WINDOWS\system32\svchost.exe[1768] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F90FB6
.text C:\WINDOWS\system32\svchost.exe[1768] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F9009A
.text C:\WINDOWS\system32\svchost.exe[1768] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F90073
.text C:\WINDOWS\system32\svchost.exe[1768] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F90047
.text C:\WINDOWS\system32\svchost.exe[1768] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F90F6A
.text C:\WINDOWS\system32\svchost.exe[1768] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F900BC
.text C:\WINDOWS\system32\svchost.exe[1768] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F90F4F
.text C:\WINDOWS\system32\svchost.exe[1768] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F900E8
.text C:\WINDOWS\system32\svchost.exe[1768] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F90F3E
.text C:\WINDOWS\system32\svchost.exe[1768] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F90062
.text C:\WINDOWS\system32\svchost.exe[1768] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F9001B
.text C:\WINDOWS\system32\svchost.exe[1768] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F900AB
.text C:\WINDOWS\system32\svchost.exe[1768] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F90FE5
.text C:\WINDOWS\system32\svchost.exe[1768] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F9002C
.text C:\WINDOWS\system32\svchost.exe[1768] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F900D7
.text C:\WINDOWS\system32\svchost.exe[1768] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00AF0036
.text C:\WINDOWS\system32\svchost.exe[1768] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00AF0FA8
.text C:\WINDOWS\system32\svchost.exe[1768] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00AF0FEF
.text C:\WINDOWS\system32\svchost.exe[1768] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00AF0025
.text C:\WINDOWS\system32\svchost.exe[1768] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00AF0FB9
.text C:\WINDOWS\system32\svchost.exe[1768] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00AF000A
.text C:\WINDOWS\system32\svchost.exe[1768] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00AF0FCA
.text C:\WINDOWS\system32\svchost.exe[1768] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [CF, 88]
.text C:\WINDOWS\system32\svchost.exe[1768] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00AF005B
.text C:\WINDOWS\system32\svchost.exe[1768] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00AE0042
.text C:\WINDOWS\system32\svchost.exe[1768] msvcrt.dll!system 77C293C7 5 Bytes JMP 00AE0FB7
.text C:\WINDOWS\system32\svchost.exe[1768] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00AE0FD9
.text C:\WINDOWS\system32\svchost.exe[1768] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00AE0000
.text C:\WINDOWS\system32\svchost.exe[1768] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00AE0FC8
.text C:\WINDOWS\system32\svchost.exe[1768] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00AE001D
.text C:\WINDOWS\system32\svchost.exe[1768] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00AD0FEF
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 02920FEF
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 02920FB9
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 02920FD4
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 037C0FE5
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 037C0054
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 037C0F5F
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 037C0039
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 037C0F7C
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 037C0F9E
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 037C0080
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 037C0F38
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 037C00BD
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 037C00AC
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 037C0F09
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 037C0F8D
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 037C0000
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 037C006F
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 037C0FAF
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 037C0FCA
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 037C009B
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 037B000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 037B0051
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 037B0FB9
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 037B0FD4
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 037B0036
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 037B0FEF
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 037B0F94
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [9B, 8B]
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 037B001B
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215505 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB14 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E53AF C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E52E1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E534C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E51B2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E5214 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E5412 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E5276 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 037A0FA4
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] msvcrt.dll!system 77C293C7 5 Bytes JMP 037A0FB5
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 037A000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] msvcrt.dll!_open 77C2F566 5 Bytes JMP 037A0FE3
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 037A001B
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 037A0FC6
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] ole32.dll!OleLoadFromStream 7752983B 5 Bytes JMP 3E3E5717 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] WININET.dll!InternetOpenA 3D95D6A8 5 Bytes JMP 03780000
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] WININET.dll!InternetOpenW 3D95DB21 5 Bytes JMP 03780011
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] WININET.dll!InternetOpenUrlA 3D95F3BC 5 Bytes JMP 03780022
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] WININET.dll!InternetOpenUrlW 3D9A6DFF 5 Bytes JMP 03780FD1
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1784] ws2_32.dll!socket 71AB4211 5 Bytes JMP 03790000
.text C:\WINDOWS\system32\svchost.exe[1864] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00A00000
.text C:\WINDOWS\system32\svchost.exe[1864] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00A00036
.text C:\WINDOWS\system32\svchost.exe[1864] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00A0001B
.text C:\WINDOWS\system32\svchost.exe[1864] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00B70FEF
.text C:\WINDOWS\system32\svchost.exe[1864] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00B7005E
.text C:\WINDOWS\system32\svchost.exe[1864] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00B70F69
.text C:\WINDOWS\system32\svchost.exe[1864] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00B70F86
.text C:\WINDOWS\system32\svchost.exe[1864] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00B70F97
.text C:\WINDOWS\system32\svchost.exe[1864] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00B70FB2
.text C:\WINDOWS\system32\svchost.exe[1864] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00B70F2C
.text C:\WINDOWS\system32\svchost.exe[1864] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00B70F3D
.text C:\WINDOWS\system32\svchost.exe[1864] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00B700BE
.text C:\WINDOWS\system32\svchost.exe[1864] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00B70099
.text C:\WINDOWS\system32\svchost.exe[1864] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00B700D9
.text C:\WINDOWS\system32\svchost.exe[1864] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00B70039
.text C:\WINDOWS\system32\svchost.exe[1864] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00B70FDE
.text C:\WINDOWS\system32\svchost.exe[1864] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00B70F4E
.text C:\WINDOWS\system32\svchost.exe[1864] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00B70014
.text C:\WINDOWS\system32\svchost.exe[1864] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00B70FCD
.text C:\WINDOWS\system32\svchost.exe[1864] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00B70F1B
.text C:\WINDOWS\system32\svchost.exe[1864] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00A30025
.text C:\WINDOWS\system32\svchost.exe[1864] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00A30047
.text C:\WINDOWS\system32\svchost.exe[1864] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00A30014
.text C:\WINDOWS\system32\svchost.exe[1864] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00A30FDE
.text C:\WINDOWS\system32\svchost.exe[1864] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00A30036
.text C:\WINDOWS\system32\svchost.exe[1864] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00A30FEF
.text C:\WINDOWS\system32\svchost.exe[1864] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00A30F9E
.text C:\WINDOWS\system32\svchost.exe[1864] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [C3, 88]
.text C:\WINDOWS\system32\svchost.exe[1864] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00A30FAF
.text C:\WINDOWS\system32\svchost.exe[1864] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00A20056
.text C:\WINDOWS\system32\svchost.exe[1864] msvcrt.dll!system 77C293C7 5 Bytes JMP 00A20031
.text C:\WINDOWS\system32\svchost.exe[1864] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00A20FD2
.text C:\WINDOWS\system32\svchost.exe[1864] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00A20FE3
.text C:\WINDOWS\system32\svchost.exe[1864] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00A20FC1
.text C:\WINDOWS\system32\svchost.exe[1864] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00A2000C
.text C:\WINDOWS\system32\svchost.exe[1864] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00A10FEF
.text C:\WINDOWS\system32\svchost.exe[2280] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00900FE5
.text C:\WINDOWS\system32\svchost.exe[2280] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 0090001B
.text C:\WINDOWS\system32\svchost.exe[2280] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0090000A
.text C:\WINDOWS\system32\svchost.exe[2280] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BF0000
.text C:\WINDOWS\system32\svchost.exe[2280] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BF0F74
.text C:\WINDOWS\system32\svchost.exe[2280] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BF0069
.text C:\WINDOWS\system32\svchost.exe[2280] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BF0058
.text C:\WINDOWS\system32\svchost.exe[2280] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BF0047
.text C:\WINDOWS\system32\svchost.exe[2280] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BF0036
.text C:\WINDOWS\system32\svchost.exe[2280] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BF009A
.text C:\WINDOWS\system32\svchost.exe[2280] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BF0F52
.text C:\WINDOWS\system32\svchost.exe[2280] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BF0F2D
.text C:\WINDOWS\system32\svchost.exe[2280] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BF00C6
.text C:\WINDOWS\system32\svchost.exe[2280] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BF00EB
.text C:\WINDOWS\system32\svchost.exe[2280] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BF0FAF
.text C:\WINDOWS\system32\svchost.exe[2280] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BF0FDB
.text C:\WINDOWS\system32\svchost.exe[2280] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BF0F63
.text C:\WINDOWS\system32\svchost.exe[2280] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BF001B
.text C:\WINDOWS\system32\svchost.exe[2280] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BF0FCA
.text C:\WINDOWS\system32\svchost.exe[2280] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BF00AB
.text C:\WINDOWS\system32\svchost.exe[2280] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00BE001B
.text C:\WINDOWS\system32\svchost.exe[2280] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00BE0F79
.text C:\WINDOWS\system32\svchost.exe[2280] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00BE0FCA
.text C:\WINDOWS\system32\svchost.exe[2280] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00BE0000
.text C:\WINDOWS\system32\svchost.exe[2280] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00BE0F8A
.text C:\WINDOWS\system32\svchost.exe[2280] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00BE0FEF
.text C:\WINDOWS\system32\svchost.exe[2280] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00BE0FA5
.text C:\WINDOWS\system32\svchost.exe[2280] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [DE, 88]
.text C:\WINDOWS\system32\svchost.exe[2280] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00BE002C
.text C:\WINDOWS\system32\svchost.exe[2280] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00930040
.text C:\WINDOWS\system32\svchost.exe[2280] msvcrt.dll!system 77C293C7 5 Bytes JMP 00930FB5
.text C:\WINDOWS\system32\svchost.exe[2280] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00930FD7
.text C:\WINDOWS\system32\svchost.exe[2280] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00930000
.text C:\WINDOWS\system32\svchost.exe[2280] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00930FC6
.text C:\WINDOWS\system32\svchost.exe[2280] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00930011
.text C:\WINDOWS\system32\svchost.exe[2280] WININET.dll!InternetOpenA 3D95D6A8 5 Bytes JMP 00910000
.text C:\WINDOWS\system32\svchost.exe[2280] WININET.dll!InternetOpenW 3D95DB21 5 Bytes JMP 00910FDB
.text C:\WINDOWS\system32\svchost.exe[2280] WININET.dll!InternetOpenUrlA 3D95F3BC 5 Bytes JMP 00910FCA
.text C:\WINDOWS\system32\svchost.exe[2280] WININET.dll!InternetOpenUrlW 3D9A6DFF 5 Bytes JMP 00910FA5
.text C:\WINDOWS\system32\svchost.exe[2280] WS2_32.dll!socket 71AB4211 5 Bytes JMP 0092000A
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[2604] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 624199A1 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[2604] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 62419A63 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\system32\svchost.exe[3236] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00C20FEF
.text C:\WINDOWS\system32\svchost.exe[3236] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00C20014
.text C:\WINDOWS\system32\svchost.exe[3236] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00C20FDE
.text C:\WINDOWS\system32\svchost.exe[3236] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C50FEF
.text C:\WINDOWS\system32\svchost.exe[3236] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C5007A
.text C:\WINDOWS\system32\svchost.exe[3236] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C50069
.text C:\WINDOWS\system32\svchost.exe[3236] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C50058
.text C:\WINDOWS\system32\svchost.exe[3236] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C50047
.text C:\WINDOWS\system32\svchost.exe[3236] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C50025
.text C:\WINDOWS\system32\svchost.exe[3236] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C50F59
.text C:\WINDOWS\system32\svchost.exe[3236] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C500AB
.text C:\WINDOWS\system32\svchost.exe[3236] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C500BC
.text C:\WINDOWS\system32\svchost.exe[3236] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C50F23
.text C:\WINDOWS\system32\svchost.exe[3236] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00C500D7
.text C:\WINDOWS\system32\svchost.exe[3236] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00C50036
.text C:\WINDOWS\system32\svchost.exe[3236] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00C50FD4
.text C:\WINDOWS\system32\svchost.exe[3236] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00C50F74
.text C:\WINDOWS\system32\svchost.exe[3236] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00C50FB9
.text C:\WINDOWS\system32\svchost.exe[3236] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00C5000A
.text C:\WINDOWS\system32\svchost.exe[3236] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00C50F48
.text C:\WINDOWS\system32\svchost.exe[3236] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00C40FD4
.text C:\WINDOWS\system32\svchost.exe[3236] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00C40076
.text C:\WINDOWS\system32\svchost.exe[3236] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00C40FE5
.text C:\WINDOWS\system32\svchost.exe[3236] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00C40011
.text C:\WINDOWS\system32\svchost.exe[3236] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00C40FAF
.text C:\WINDOWS\system32\svchost.exe[3236] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00C40000
.text C:\WINDOWS\system32\svchost.exe[3236] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00C40051
.text C:\WINDOWS\system32\svchost.exe[3236] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00C40040
.text C:\WINDOWS\system32\svchost.exe[3236] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00C30064
.text C:\WINDOWS\system32\svchost.exe[3236] msvcrt.dll!system 77C293C7 5 Bytes JMP 00C30053
.text C:\WINDOWS\system32\svchost.exe[3236] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00C3001D
.text C:\WINDOWS\system32\svchost.exe[3236] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00C30FEF
.text C:\WINDOWS\system32\svchost.exe[3236] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00C30038
.text C:\WINDOWS\system32\svchost.exe[3236] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00C3000C
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\$NtUninstallKB39658$\150114840 0 bytes
File C:\WINDOWS\$NtUninstallKB39658$\150114840\@ 2048 bytes
File C:\WINDOWS\$NtUninstallKB39658$\150114840\cfg.ini 300 bytes
File C:\WINDOWS\$NtUninstallKB39658$\150114840\Desktop.ini 4608 bytes
File C:\WINDOWS\$NtUninstallKB39658$\150114840\L 0 bytes
File C:\WINDOWS\$NtUninstallKB39658$\150114840\L\akpnrerf 456320 bytes
File C:\WINDOWS\$NtUninstallKB39658$\150114840\oemid 50 bytes
File C:\WINDOWS\$NtUninstallKB39658$\150114840\U 0 bytes
File C:\WINDOWS\$NtUninstallKB39658$\150114840\U\00000001.@ 2048 bytes
File C:\WINDOWS\$NtUninstallKB39658$\150114840\U\00000002.@ 224768 bytes
File C:\WINDOWS\$NtUninstallKB39658$\150114840\U\00000004.@ 1024 bytes
File C:\WINDOWS\$NtUninstallKB39658$\150114840\U\80000000.@ 66560 bytes
File C:\WINDOWS\$NtUninstallKB39658$\150114840\U\80000004.@ 1024 bytes
File C:\WINDOWS\$NtUninstallKB39658$\150114840\U\80000032.@ 115712 bytes
File C:\WINDOWS\$NtUninstallKB39658$\150114840\version 1271 bytes
File C:\WINDOWS\$NtUninstallKB39658$\4262713361 0 bytes
---- EOF - GMER 1.0.15 ----