I am looking for some help with getting rid of a troublesome browser redirect problem. While using google results page IE often redirects the link when clicked on to Info.com and other similar sites.
I have tried numerous virus scanners..AVG, Mcafee, and also ad removers such as Adaware, Superspy, TDSS killer. I have tried cleaning registries with all sorts of cleaners but it keeps coming back.
I would appreciate if anybody out there can have a look at my logs and provide me with some help in getting rid of this.....
I have attached the logs as requested.
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-11-30 11:20:56
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 TOSHIBA_ rev.FG00
Running: gmer.exe; Driver: C:\Users\Willie\AppData\Local\Temp\pwdiqpod.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0x8A1DB79E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0x8A1DB738]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0x8A1DB74C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0x8A1DB7DC]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0x8A1DB710]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0x8A1DB724]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0x8A1DB7B2]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0x8A1DB78A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0x8A1DB776]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0x8A1DB80B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0x8A1DB7F2]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0x8A1DB7C8]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateUserProcess [0x8A1DB762]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwYieldExecution 82047982 5 Bytes JMP 8A1DB7CC \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateUserProcess 821E5C11 5 Bytes JMP 8A1DB766 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 8220D143 5 Bytes JMP 8A1DB80F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 8222C89A 7 Bytes JMP 8A1DB7E0 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 8222CB5D 5 Bytes JMP 8A1DB7F6 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetInformationProcess 822308C8 5 Bytes JMP 8A1DB77A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 822362DD 7 Bytes JMP 8A1DB7B6 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 822384FA 5 Bytes JMP 8A1DB728 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess 8223CFA8 5 Bytes JMP 8A1DB714 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtCreateFile 8225E33B 5 Bytes JMP 8A1DB7A2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcess 822ADD7F 5 Bytes JMP 8A1DB73C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 822ADDCA 7 Bytes JMP 8A1DB750 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetContextThread 822AE883 5 Bytes JMP 8A1DB78E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
.text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x8EA0A340, 0x3EE577, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\services.exe[760] kernel32.dll!GetStartupInfoW 76041929 5 Bytes JMP 001900B5
.text C:\Windows\system32\services.exe[760] kernel32.dll!GetStartupInfoA 760419C9 5 Bytes JMP 001900A4
.text C:\Windows\system32\services.exe[760] kernel32.dll!CreateProcessW 76041BF3 5 Bytes JMP 00190106
.text C:\Windows\system32\services.exe[760] kernel32.dll!CreateProcessA 76041C28 5 Bytes JMP 001900EB
.text C:\Windows\system32\services.exe[760] kernel32.dll!VirtualProtect 76041DC3 5 Bytes JMP 00190F8A
.text C:\Windows\system32\services.exe[760] kernel32.dll!CreateNamedPipeA 76042EF5 5 Bytes JMP 0019000A
.text C:\Windows\system32\services.exe[760] kernel32.dll!CreateNamedPipeW 76045C0C 5 Bytes JMP 00190025
.text C:\Windows\system32\services.exe[760] kernel32.dll!CreatePipe 76068E6E 5 Bytes JMP 00190093
.text C:\Windows\system32\services.exe[760] kernel32.dll!LoadLibraryExW 76069109 5 Bytes JMP 00190058
.text C:\Windows\system32\services.exe[760] kernel32.dll!LoadLibraryW 76069362 5 Bytes JMP 00190FAF
.text C:\Windows\system32\services.exe[760] kernel32.dll!LoadLibraryExA 760694B4 5 Bytes JMP 00190047
.text C:\Windows\system32\services.exe[760] kernel32.dll!LoadLibraryA 760694DC 5 Bytes JMP 00190036
.text C:\Windows\system32\services.exe[760] kernel32.dll!VirtualProtectEx 7606DBDA 5 Bytes JMP 00190F79
.text C:\Windows\system32\services.exe[760] kernel32.dll!GetProcAddress 7608903B 5 Bytes JMP 00190121
.text C:\Windows\system32\services.exe[760] kernel32.dll!CreateFileW 7608AECB 5 Bytes JMP 00190FD4
.text C:\Windows\system32\services.exe[760] kernel32.dll!CreateFileA 7608CE5F 5 Bytes JMP 00190FE5
.text C:\Windows\system32\services.exe[760] kernel32.dll!WinExec 760D5CF7 5 Bytes JMP 001900DA
.text C:\Windows\system32\services.exe[760] ADVAPI32.dll!RegCreateKeyExA 75DB39AB 5 Bytes JMP 0017005B
.text C:\Windows\system32\services.exe[760] ADVAPI32.dll!RegCreateKeyA 75DB3BA9 5 Bytes JMP 0017002F
.text C:\Windows\system32\services.exe[760] ADVAPI32.dll!RegOpenKeyA 75DB89C7 5 Bytes JMP 00170000
.text C:\Windows\system32\services.exe[760] ADVAPI32.dll!RegCreateKeyW 75DC391E 5 Bytes JMP 00170040
.text C:\Windows\system32\services.exe[760] ADVAPI32.dll!RegCreateKeyExW 75DC41F1 5 Bytes JMP 00170F9E
.text C:\Windows\system32\services.exe[760] ADVAPI32.dll!RegOpenKeyExA 75DC7C42 5 Bytes JMP 00170FD4
.text C:\Windows\system32\services.exe[760] ADVAPI32.dll!RegOpenKeyW 75DCE2B5 5 Bytes JMP 00170FE5
.text C:\Windows\system32\services.exe[760] ADVAPI32.dll!RegOpenKeyExW 75DD7BA1 5 Bytes JMP 00170FB9
.text C:\Windows\system32\services.exe[760] msvcrt.dll!_wsystem 76177F2F 5 Bytes JMP 001A0FBC
.text C:\Windows\system32\services.exe[760] msvcrt.dll!system 7617804B 5 Bytes JMP 001A0FCD
.text C:\Windows\system32\services.exe[760] msvcrt.dll!_creat 7617BBE1 5 Bytes JMP 001A0022
.text C:\Windows\system32\services.exe[760] msvcrt.dll!_open 7617D106 5 Bytes JMP 001A0000
.text C:\Windows\system32\services.exe[760] msvcrt.dll!_wcreat 7617D326 5 Bytes JMP 001A003D
.text C:\Windows\system32\services.exe[760] msvcrt.dll!_wopen 7617D501 5 Bytes JMP 001A0011
.text C:\Windows\system32\services.exe[760] WS2_32.dll!socket 773236D1 5 Bytes JMP 001B000A
.text C:\Windows\system32\services.exe[760] WININET.dll!InternetOpenA 771BD4AD 5 Bytes JMP 001D0FEF
.text C:\Windows\system32\services.exe[760] WININET.dll!InternetOpenW 771BD80A 5 Bytes JMP 001D0000
.text C:\Windows\system32\services.exe[760] WININET.dll!InternetOpenUrlA 771BFE7B 5 Bytes JMP 001D0FCA
.text C:\Windows\system32\services.exe[760] WININET.dll!InternetOpenUrlW 77209189 5 Bytes JMP 001D0FB9
.text C:\Windows\system32\lsass.exe[800] kernel32.dll!GetStartupInfoW 76041929 5 Bytes JMP 00130F3D
.text C:\Windows\system32\lsass.exe[800] kernel32.dll!GetStartupInfoA 760419C9 5 Bytes JMP 00130F4E
.text C:\Windows\system32\lsass.exe[800] kernel32.dll!CreateProcessW 76041BF3 5 Bytes JMP 00130EF6
.text C:\Windows\system32\lsass.exe[800] kernel32.dll!CreateProcessA 76041C28 5 Bytes JMP 00130F07
.text C:\Windows\system32\lsass.exe[800] kernel32.dll!VirtualProtect 76041DC3 5 Bytes JMP 00130F7A
.text C:\Windows\system32\lsass.exe[800] kernel32.dll!CreateNamedPipeA 76042EF5 5 Bytes JMP 0013001B
.text C:\Windows\system32\lsass.exe[800] kernel32.dll!CreateNamedPipeW 76045C0C 5 Bytes JMP 00130FD4
.text C:\Windows\system32\lsass.exe[800] kernel32.dll!CreatePipe 76068E6E 5 Bytes JMP 00130F5F
.text C:\Windows\system32\lsass.exe[800] kernel32.dll!LoadLibraryExW 76069109 5 Bytes JMP 00130F8B
.text C:\Windows\system32\lsass.exe[800] kernel32.dll!LoadLibraryW 76069362 5 Bytes JMP 00130FB9
.text C:\Windows\system32\lsass.exe[800] kernel32.dll!LoadLibraryExA 760694B4 5 Bytes JMP 00130FA8
.text C:\Windows\system32\lsass.exe[800] kernel32.dll!LoadLibraryA 760694DC 5 Bytes JMP 00130040
.text C:\Windows\system32\lsass.exe[800] kernel32.dll!VirtualProtectEx 7606DBDA 5 Bytes JMP 0013006F
.text C:\Windows\system32\lsass.exe[800] kernel32.dll!GetProcAddress 7608903B 5 Bytes JMP 0013009E
.text C:\Windows\system32\lsass.exe[800] kernel32.dll!CreateFileW 7608AECB 5 Bytes JMP 0013000A
.text C:\Windows\system32\lsass.exe[800] kernel32.dll!CreateFileA 7608CE5F 5 Bytes JMP 00130FEF
.text C:\Windows\system32\lsass.exe[800] kernel32.dll!WinExec 760D5CF7 5 Bytes JMP 00130F2C
.text C:\Windows\system32\lsass.exe[800] ADVAPI32.dll!RegCreateKeyExA 75DB39AB 5 Bytes JMP 00120F91
.text C:\Windows\system32\lsass.exe[800] ADVAPI32.dll!RegCreateKeyA 75DB3BA9 5 Bytes JMP 00120FC7
.text C:\Windows\system32\lsass.exe[800] ADVAPI32.dll!RegOpenKeyA 75DB89C7 5 Bytes JMP 00120000
.text C:\Windows\system32\lsass.exe[800] ADVAPI32.dll!RegCreateKeyW 75DC391E 5 Bytes JMP 00120FAC
.text C:\Windows\system32\lsass.exe[800] ADVAPI32.dll!RegCreateKeyExW 75DC41F1 5 Bytes JMP 0012004E
.text C:\Windows\system32\lsass.exe[800] ADVAPI32.dll!RegOpenKeyExA 75DC7C42 5 Bytes JMP 0012002C
.text C:\Windows\system32\lsass.exe[800] ADVAPI32.dll!RegOpenKeyW 75DCE2B5 5 Bytes JMP 00120011
.text C:\Windows\system32\lsass.exe[800] ADVAPI32.dll!RegOpenKeyExW 75DD7BA1 5 Bytes JMP 0012003D
.text C:\Windows\system32\lsass.exe[800] msvcrt.dll!_wsystem 76177F2F 5 Bytes JMP 0014001B
.text C:\Windows\system32\lsass.exe[800] msvcrt.dll!system 7617804B 5 Bytes JMP 00140F90
.text C:\Windows\system32\lsass.exe[800] msvcrt.dll!_creat 7617BBE1 5 Bytes JMP 00140FBC
.text C:\Windows\system32\lsass.exe[800] msvcrt.dll!_open 7617D106 5 Bytes JMP 00140000
.text C:\Windows\system32\lsass.exe[800] msvcrt.dll!_wcreat 7617D326 5 Bytes JMP 00140FA1
.text C:\Windows\system32\lsass.exe[800] msvcrt.dll!_wopen 7617D501 5 Bytes JMP 00140FE3
.text C:\Windows\system32\lsass.exe[800] WS2_32.dll!socket 773236D1 5 Bytes JMP 00920FEF
.text C:\Windows\system32\lsass.exe[800] WININET.dll!InternetOpenA 771BD4AD 5 Bytes JMP 0091000A
.text C:\Windows\system32\lsass.exe[800] WININET.dll!InternetOpenW 771BD80A 5 Bytes JMP 0091001B
.text C:\Windows\system32\lsass.exe[800] WININET.dll!InternetOpenUrlA 771BFE7B 5 Bytes JMP 00910FE5
.text C:\Windows\system32\lsass.exe[800] WININET.dll!InternetOpenUrlW 77209189 5 Bytes JMP 00910FC0
.text C:\Windows\system32\svchost.exe[832] kernel32.dll!GetStartupInfoW 76041929 5 Bytes JMP 001A0F7C
.text C:\Windows\system32\svchost.exe[832] kernel32.dll!GetStartupInfoA 760419C9 5 Bytes JMP 001A0F8D
.text C:\Windows\system32\svchost.exe[832] kernel32.dll!CreateProcessW 76041BF3 5 Bytes JMP 001A0F46
.text C:\Windows\system32\svchost.exe[832] kernel32.dll!CreateProcessA 76041C28 5 Bytes JMP 001A00DD
.text C:\Windows\system32\svchost.exe[832] kernel32.dll!VirtualProtect 76041DC3 5 Bytes JMP 001A0093
.text C:\Windows\system32\svchost.exe[832] kernel32.dll!CreateNamedPipeA 76042EF5 5 Bytes JMP 001A0FCA
.text C:\Windows\system32\svchost.exe[832] kernel32.dll!CreateNamedPipeW 76045C0C 5 Bytes JMP 001A0FB9
.text C:\Windows\system32\svchost.exe[832] kernel32.dll!CreatePipe 76068E6E 5 Bytes JMP 001A0F9E
.text C:\Windows\system32\svchost.exe[832] kernel32.dll!LoadLibraryExW 76069109 5 Bytes JMP 001A0076
.text C:\Windows\system32\svchost.exe[832] kernel32.dll!LoadLibraryW 76069362 5 Bytes JMP 001A004A
.text C:\Windows\system32\svchost.exe[832] kernel32.dll!LoadLibraryExA 760694B4 5 Bytes JMP 001A005B
.text C:\Windows\system32\svchost.exe[832] kernel32.dll!LoadLibraryA 760694DC 5 Bytes JMP 001A0025
.text C:\Windows\system32\svchost.exe[832] kernel32.dll!VirtualProtectEx 7606DBDA 5 Bytes JMP 001A00AE
.text C:\Windows\system32\svchost.exe[832] kernel32.dll!GetProcAddress 7608903B 5 Bytes JMP 001A00F8
.text C:\Windows\system32\svchost.exe[832] kernel32.dll!CreateFileW 7608AECB 5 Bytes JMP 001A0FDB
.text C:\Windows\system32\svchost.exe[832] kernel32.dll!CreateFileA 7608CE5F 5 Bytes JMP 001A0000
.text C:\Windows\system32\svchost.exe[832] kernel32.dll!WinExec 760D5CF7 5 Bytes JMP 001A0F6B
.text C:\Windows\system32\svchost.exe[832] msvcrt.dll!_wsystem 76177F2F 5 Bytes JMP 001C003D
.text C:\Windows\system32\svchost.exe[832] msvcrt.dll!system 7617804B 5 Bytes JMP 001C0FB2
.text C:\Windows\system32\svchost.exe[832] msvcrt.dll!_creat 7617BBE1 5 Bytes JMP 001C0FD7
.text C:\Windows\system32\svchost.exe[832] msvcrt.dll!_open 7617D106 5 Bytes JMP 001C0000
.text C:\Windows\system32\svchost.exe[832] msvcrt.dll!_wcreat 7617D326 5 Bytes JMP 001C0022
.text C:\Windows\system32\svchost.exe[832] msvcrt.dll!_wopen 7617D501 5 Bytes JMP 001C0011
.text C:\Windows\system32\svchost.exe[832] ADVAPI32.dll!RegCreateKeyExA 75DB39AB 5 Bytes JMP 00190FA5
.text C:\Windows\system32\svchost.exe[832] ADVAPI32.dll!RegCreateKeyA 75DB3BA9 5 Bytes JMP 00190FC0
.text C:\Windows\system32\svchost.exe[832] ADVAPI32.dll!RegOpenKeyA 75DB89C7 5 Bytes JMP 00190FE5
.text C:\Windows\system32\svchost.exe[832] ADVAPI32.dll!RegCreateKeyW 75DC391E 5 Bytes JMP 00190047
.text C:\Windows\system32\svchost.exe[832] ADVAPI32.dll!RegCreateKeyExW 75DC41F1 5 Bytes JMP 00190F94
.text C:\Windows\system32\svchost.exe[832] ADVAPI32.dll!RegOpenKeyExA 75DC7C42 5 Bytes JMP 0019001B
.text C:\Windows\system32\svchost.exe[832] ADVAPI32.dll!RegOpenKeyW 75DCE2B5 5 Bytes JMP 00190000
.text C:\Windows\system32\svchost.exe[832] ADVAPI32.dll!RegOpenKeyExW 75DD7BA1 5 Bytes JMP 0019002C
.text C:\Windows\system32\svchost.exe[832] WS2_32.dll!socket 773236D1 5 Bytes JMP 001D0FEF
.text C:\Windows\system32\svchost.exe[952] kernel32.dll!GetStartupInfoW 76041929 5 Bytes JMP 00850F66
.text C:\Windows\system32\svchost.exe[952] kernel32.dll!GetStartupInfoA 760419C9 5 Bytes JMP 008500AC
.text C:\Windows\system32\svchost.exe[952] kernel32.dll!CreateProcessW 76041BF3 5 Bytes JMP 00850F41
.text C:\Windows\system32\svchost.exe[952] kernel32.dll!CreateProcessA 76041C28 5 Bytes JMP 008500D8
.text C:\Windows\system32\svchost.exe[952] kernel32.dll!VirtualProtect 76041DC3 5 Bytes JMP 00850065
.text C:\Windows\system32\svchost.exe[952] kernel32.dll!CreateNamedPipeA 76042EF5 5 Bytes JMP 00850FCD
.text C:\Windows\system32\svchost.exe[952] kernel32.dll!CreateNamedPipeW 76045C0C 5 Bytes JMP 0085001E
.text C:\Windows\system32\svchost.exe[952] kernel32.dll!CreatePipe 76068E6E 5 Bytes JMP 00850091
.text C:\Windows\system32\svchost.exe[952] kernel32.dll!LoadLibraryExW 76069109 5 Bytes JMP 00850054
.text C:\Windows\system32\svchost.exe[952] kernel32.dll!LoadLibraryW 76069362 5 Bytes JMP 00850FB2
.text C:\Windows\system32\svchost.exe[952] kernel32.dll!LoadLibraryExA 760694B4 5 Bytes JMP 00850F97
.text C:\Windows\system32\svchost.exe[952] kernel32.dll!LoadLibraryA 760694DC 5 Bytes JMP 00850039
.text C:\Windows\system32\svchost.exe[952] kernel32.dll!VirtualProtectEx 7606DBDA 5 Bytes JMP 00850080
.text C:\Windows\system32\svchost.exe[952] kernel32.dll!GetProcAddress 7608903B 5 Bytes JMP 00850F30
.text C:\Windows\system32\svchost.exe[952] kernel32.dll!CreateFileW 7608AECB 5 Bytes JMP 00850FDE
.text C:\Windows\system32\svchost.exe[952] kernel32.dll!CreateFileA 7608CE5F 5 Bytes JMP 00850FEF
.text C:\Windows\system32\svchost.exe[952] kernel32.dll!WinExec 760D5CF7 5 Bytes JMP 008500BD
.text C:\Windows\system32\svchost.exe[952] msvcrt.dll!_wsystem 76177F2F 5 Bytes JMP 008A0036
.text C:\Windows\system32\svchost.exe[952] msvcrt.dll!system 7617804B 5 Bytes JMP 008A0011
.text C:\Windows\system32\svchost.exe[952] msvcrt.dll!_creat 7617BBE1 5 Bytes JMP 008A0FB5
.text C:\Windows\system32\svchost.exe[952] msvcrt.dll!_open 7617D106 5 Bytes JMP 008A0FEF
.text C:\Windows\system32\svchost.exe[952] msvcrt.dll!_wcreat 7617D326 5 Bytes JMP 008A0000
.text C:\Windows\system32\svchost.exe[952] msvcrt.dll!_wopen 7617D501 5 Bytes JMP 008A0FD2
.text C:\Windows\system32\svchost.exe[952] ADVAPI32.dll!RegCreateKeyExA 75DB39AB 5 Bytes JMP 00840F97
.text C:\Windows\system32\svchost.exe[952] ADVAPI32.dll!RegCreateKeyA 75DB3BA9 5 Bytes JMP 00840FBC
.text C:\Windows\system32\svchost.exe[952] ADVAPI32.dll!RegOpenKeyA 75DB89C7 5 Bytes JMP 00840FEF
.text C:\Windows\system32\svchost.exe[952] ADVAPI32.dll!RegCreateKeyW 75DC391E 5 Bytes JMP 00840039
.text C:\Windows\system32\svchost.exe[952] ADVAPI32.dll!RegCreateKeyExW 75DC41F1 5 Bytes JMP 0084004A
.text C:\Windows\system32\svchost.exe[952] ADVAPI32.dll!RegOpenKeyExA 75DC7C42 5 Bytes JMP 00840014
.text C:\Windows\system32\svchost.exe[952] ADVAPI32.dll!RegOpenKeyW 75DCE2B5 5 Bytes JMP 00840FDE
.text C:\Windows\system32\svchost.exe[952] ADVAPI32.dll!RegOpenKeyExW 75DD7BA1 5 Bytes JMP 00840FCD
.text C:\Windows\system32\svchost.exe[952] WS2_32.dll!socket 773236D1 5 Bytes JMP 008B0FEF
.text C:\Windows\system32\svchost.exe[1032] kernel32.dll!GetStartupInfoW 76041929 5 Bytes JMP 006C00A5
.text C:\Windows\system32\svchost.exe[1032] kernel32.dll!GetStartupInfoA 760419C9 5 Bytes JMP 006C0F55
.text C:\Windows\system32\svchost.exe[1032] kernel32.dll!CreateProcessW 76041BF3 5 Bytes JMP 006C00CA
.text C:\Windows\system32\svchost.exe[1032] kernel32.dll!CreateProcessA 76041C28 5 Bytes JMP 006C0F33
.text C:\Windows\system32\svchost.exe[1032] kernel32.dll!VirtualProtect 76041DC3 5 Bytes JMP 006C0F84
.text C:\Windows\system32\svchost.exe[1032] kernel32.dll!CreateNamedPipeA 76042EF5 5 Bytes JMP 006C001E
.text C:\Windows\system32\svchost.exe[1032] kernel32.dll!CreateNamedPipeW 76045C0C 5 Bytes JMP 006C0FCD
.text C:\Windows\system32\svchost.exe[1032] kernel32.dll!CreatePipe 76068E6E 5 Bytes JMP 006C008A
.text C:\Windows\system32\svchost.exe[1032] kernel32.dll!LoadLibraryExW 76069109 5 Bytes JMP 006C005E
.text C:\Windows\system32\svchost.exe[1032] kernel32.dll!LoadLibraryW 76069362 5 Bytes JMP 006C0FA1
.text C:\Windows\system32\svchost.exe[1032] kernel32.dll!LoadLibraryExA 760694B4 5 Bytes JMP 006C0043
.text C:\Windows\system32\svchost.exe[1032] kernel32.dll!LoadLibraryA 760694DC 5 Bytes JMP 006C0FBC
.text C:\Windows\system32\svchost.exe[1032] kernel32.dll!VirtualProtectEx 7606DBDA 5 Bytes JMP 006C0079
.text C:\Windows\system32\svchost.exe[1032] kernel32.dll!GetProcAddress 7608903B 5 Bytes JMP 006C00E5
.text C:\Windows\system32\svchost.exe[1032] kernel32.dll!CreateFileW 7608AECB 5 Bytes JMP 006C0FDE
.text C:\Windows\system32\svchost.exe[1032] kernel32.dll!CreateFileA 7608CE5F 5 Bytes JMP 006C0FEF
.text C:\Windows\system32\svchost.exe[1032] kernel32.dll!WinExec 760D5CF7 5 Bytes JMP 006C0F44
.text C:\Windows\system32\svchost.exe[1032] msvcrt.dll!_wsystem 76177F2F 5 Bytes JMP 006D0FB2
.text C:\Windows\system32\svchost.exe[1032] msvcrt.dll!system 7617804B 5 Bytes JMP 006D003D
.text C:\Windows\system32\svchost.exe[1032] msvcrt.dll!_creat 7617BBE1 5 Bytes JMP 006D0FDE
.text C:\Windows\system32\svchost.exe[1032] msvcrt.dll!_open 7617D106 5 Bytes JMP 006D000C
.text C:\Windows\system32\svchost.exe[1032] msvcrt.dll!_wcreat 7617D326 5 Bytes JMP 006D0FCD
.text C:\Windows\system32\svchost.exe[1032] msvcrt.dll!_wopen 7617D501 5 Bytes JMP 006D0FEF
.text C:\Windows\system32\svchost.exe[1032] ADVAPI32.dll!RegCreateKeyExA 75DB39AB 5 Bytes JMP 006B002F
.text C:\Windows\system32\svchost.exe[1032] ADVAPI32.dll!RegCreateKeyA 75DB3BA9 5 Bytes JMP 006B0014
.text C:\Windows\system32\svchost.exe[1032] ADVAPI32.dll!RegOpenKeyA 75DB89C7 5 Bytes JMP 006B0FE5
.text C:\Windows\system32\svchost.exe[1032] ADVAPI32.dll!RegCreateKeyW 75DC391E 5 Bytes JMP 006B0F97
.text C:\Windows\system32\svchost.exe[1032] ADVAPI32.dll!RegCreateKeyExW 75DC41F1 5 Bytes JMP 006B0040
.text C:\Windows\system32\svchost.exe[1032] ADVAPI32.dll!RegOpenKeyExA 75DC7C42 5 Bytes JMP 006B0FB9
.text C:\Windows\system32\svchost.exe[1032] ADVAPI32.dll!RegOpenKeyW 75DCE2B5 5 Bytes JMP 006B0FD4
.text C:\Windows\system32\svchost.exe[1032] ADVAPI32.dll!RegOpenKeyExW 75DD7BA1 5 Bytes JMP 006B0FA8
.text C:\Windows\system32\svchost.exe[1032] WS2_32.dll!socket 773236D1 5 Bytes JMP 00730000
.text C:\Windows\system32\svchost.exe[1032] WININET.dll!InternetOpenA 771BD4AD 5 Bytes JMP 006E0FEF
.text C:\Windows\system32\svchost.exe[1032] WININET.dll!InternetOpenW 771BD80A 5 Bytes JMP 006E000A
.text C:\Windows\system32\svchost.exe[1032] WININET.dll!InternetOpenUrlA 771BFE7B 5 Bytes JMP 006E0FD4
.text C:\Windows\system32\svchost.exe[1032] WININET.dll!InternetOpenUrlW 77209189 5 Bytes JMP 006E0FC3
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!GetStartupInfoW 76041929 5 Bytes JMP 00750098
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!GetStartupInfoA 760419C9 5 Bytes JMP 00750087
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateProcessW 76041BF3 5 Bytes JMP 007500C4
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateProcessA 76041C28 5 Bytes JMP 007500B3
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!VirtualProtect 76041DC3 5 Bytes JMP 00750F92
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateNamedPipeA 76042EF5 5 Bytes JMP 00750FE5
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateNamedPipeW 76045C0C 5 Bytes JMP 00750036
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreatePipe 76068E6E 5 Bytes JMP 00750F66
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!LoadLibraryExW 76069109 5 Bytes JMP 00750076
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!LoadLibraryW 76069362 5 Bytes JMP 00750FD4
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!LoadLibraryExA 760694B4 5 Bytes JMP 00750FC3
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!LoadLibraryA 760694DC 5 Bytes JMP 0075005B
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!VirtualProtectEx 7606DBDA 5 Bytes JMP 00750F77
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!GetProcAddress 7608903B 5 Bytes JMP 007500DF
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateFileW 7608AECB 5 Bytes JMP 0075001B
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!CreateFileA 7608CE5F 5 Bytes JMP 00750000
.text C:\Windows\System32\svchost.exe[1084] kernel32.dll!WinExec 760D5CF7 5 Bytes JMP 00750F37
.text C:\Windows\System32\svchost.exe[1084] msvcrt.dll!_wsystem 76177F2F 5 Bytes JMP 00760F90
.text C:\Windows\System32\svchost.exe[1084] msvcrt.dll!system 7617804B 5 Bytes JMP 00760025
.text C:\Windows\System32\svchost.exe[1084] msvcrt.dll!_creat 7617BBE1 5 Bytes JMP 00760FC6
.text C:\Windows\System32\svchost.exe[1084] msvcrt.dll!_open 7617D106 5 Bytes JMP 00760FE3
.text C:\Windows\System32\svchost.exe[1084] msvcrt.dll!_wcreat 7617D326 5 Bytes JMP 00760FB5
.text C:\Windows\System32\svchost.exe[1084] msvcrt.dll!_wopen 7617D501 5 Bytes JMP 00760000
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegCreateKeyExA 75DB39AB 5 Bytes JMP 00730FB2
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegCreateKeyA 75DB3BA9 5 Bytes JMP 0073002F
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegOpenKeyA 75DB89C7 5 Bytes JMP 00730FEF
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegCreateKeyW 75DC391E 5 Bytes JMP 0073004A
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegCreateKeyExW 75DC41F1 5 Bytes JMP 0073006F
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegOpenKeyExA 75DC7C42 5 Bytes JMP 00730014
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegOpenKeyW 75DCE2B5 5 Bytes JMP 00730FDE
.text C:\Windows\System32\svchost.exe[1084] ADVAPI32.dll!RegOpenKeyExW 75DD7BA1 5 Bytes JMP 00730FC3
.text C:\Windows\System32\svchost.exe[1084] WS2_32.dll!socket 773236D1 5 Bytes JMP 009C0000
.text C:\Windows\System32\svchost.exe[1084] WININET.dll!InternetOpenA 771BD4AD 5 Bytes JMP 008F0FE5
.text C:\Windows\System32\svchost.exe[1084] WININET.dll!InternetOpenW 771BD80A 5 Bytes JMP 008F000A
.text C:\Windows\System32\svchost.exe[1084] WININET.dll!InternetOpenUrlA 771BFE7B 5 Bytes JMP 008F0025
.text C:\Windows\System32\svchost.exe[1084] WININET.dll!InternetOpenUrlW 77209189 5 Bytes JMP 008F0FD4
.text C:\Windows\System32\svchost.exe[1120] kernel32.dll!GetStartupInfoW 76041929 5 Bytes JMP 00EA00A2
.text C:\Windows\System32\svchost.exe[1120] kernel32.dll!GetStartupInfoA 760419C9 5 Bytes JMP 00EA0087
.text C:\Windows\System32\svchost.exe[1120] kernel32.dll!CreateProcessW 76041BF3 5 Bytes JMP 00EA0F15
.text C:\Windows\System32\svchost.exe[1120] kernel32.dll!CreateProcessA 76041C28 5 Bytes JMP 00EA0F26
.text C:\Windows\System32\svchost.exe[1120] kernel32.dll!VirtualProtect 76041DC3 5 Bytes JMP 00EA0F77
.text C:\Windows\System32\svchost.exe[1120] kernel32.dll!CreateNamedPipeA 76042EF5 5 Bytes JMP 00EA0FDB
.text C:\Windows\System32\svchost.exe[1120] kernel32.dll!CreateNamedPipeW 76045C0C 5 Bytes JMP 00EA0FCA
.text C:\Windows\System32\svchost.exe[1120] kernel32.dll!CreatePipe 76068E6E 5 Bytes JMP 00EA0076
.text C:\Windows\System32\svchost.exe[1120] kernel32.dll!LoadLibraryExW 76069109 5 Bytes JMP 00EA0051
.text C:\Windows\System32\svchost.exe[1120] kernel32.dll!LoadLibraryW 76069362 5 Bytes JMP 00EA0F9E
.text C:\Windows\System32\svchost.exe[1120] kernel32.dll!LoadLibraryExA 760694B4 5 Bytes JMP 00EA0040
.text C:\Windows\System32\svchost.exe[1120] kernel32.dll!LoadLibraryA 760694DC 5 Bytes JMP 00EA0FB9
.text C:\Windows\System32\svchost.exe[1120] kernel32.dll!VirtualProtectEx 7606DBDA 5 Bytes JMP 00EA0F66
.text C:\Windows\System32\svchost.exe[1120] kernel32.dll!GetProcAddress 7608903B 5 Bytes JMP 00EA00C7
.text C:\Windows\System32\svchost.exe[1120] kernel32.dll!CreateFileW 7608AECB 5 Bytes JMP 00EA0011
.text C:\Windows\System32\svchost.exe[1120] kernel32.dll!CreateFileA 7608CE5F 5 Bytes JMP 00EA0000
.text C:\Windows\System32\svchost.exe[1120] kernel32.dll!WinExec 760D5CF7 5 Bytes JMP 00EA0F41
.text C:\Windows\System32\svchost.exe[1120] msvcrt.dll!_wsystem 76177F2F 5 Bytes JMP 00EF0077
.text C:\Windows\System32\svchost.exe[1120] msvcrt.dll!system 7617804B 5 Bytes JMP 00EF0066
.text C:\Windows\System32\svchost.exe[1120] msvcrt.dll!_creat 7617BBE1 5 Bytes JMP 00EF0044
.text C:\Windows\System32\svchost.exe[1120] msvcrt.dll!_open 7617D106 5 Bytes JMP 00EF000C
.text C:\Windows\System32\svchost.exe[1120] msvcrt.dll!_wcreat 7617D326 5 Bytes JMP 00EF0055
.text C:\Windows\System32\svchost.exe[1120] msvcrt.dll!_wopen 7617D501 5 Bytes JMP 00EF001D
.text C:\Windows\System32\svchost.exe[1120] ADVAPI32.dll!RegCreateKeyExA 75DB39AB 5 Bytes JMP 00E80F8D
.text C:\Windows\System32\svchost.exe[1120] ADVAPI32.dll!RegCreateKeyA 75DB3BA9 5 Bytes JMP 00E80FA8
.text C:\Windows\System32\svchost.exe[1120] ADVAPI32.dll!RegOpenKeyA 75DB89C7 5 Bytes JMP 00E80FEF
.text C:\Windows\System32\svchost.exe[1120] ADVAPI32.dll!RegCreateKeyW 75DC391E 5 Bytes JMP 00E8002F
.text C:\Windows\System32\svchost.exe[1120] ADVAPI32.dll!RegCreateKeyExW 75DC41F1 5 Bytes JMP 00E8004A
.text C:\Windows\System32\svchost.exe[1120] ADVAPI32.dll!RegOpenKeyExA 75DC7C42 5 Bytes JMP 00E80014
.text C:\Windows\System32\svchost.exe[1120] ADVAPI32.dll!RegOpenKeyW 75DCE2B5 5 Bytes JMP 00E80FD4
.text C:\Windows\System32\svchost.exe[1120] ADVAPI32.dll!RegOpenKeyExW 75DD7BA1 5 Bytes JMP 00E80FB9
.text C:\Windows\System32\svchost.exe[1120] WS2_32.dll!socket 773236D1 5 Bytes JMP 00F00FEF
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!GetStartupInfoW 76041929 5 Bytes JMP 012B00BD
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!GetStartupInfoA 760419C9 5 Bytes JMP 012B0F77
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!CreateProcessW 76041BF3 5 Bytes JMP 012B0F52
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!CreateProcessA 76041C28 5 Bytes JMP 012B00E9
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!VirtualProtect 76041DC3 5 Bytes JMP 012B0F99
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!CreateNamedPipeA 76042EF5 5 Bytes JMP 012B0FE5
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!CreateNamedPipeW 76045C0C 5 Bytes JMP 012B0FD4
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!CreatePipe 76068E6E 5 Bytes JMP 012B00A2
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!LoadLibraryExW 76069109 5 Bytes JMP 012B0073
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!LoadLibraryW 76069362 5 Bytes JMP 012B0051
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!LoadLibraryExA 760694B4 5 Bytes JMP 012B0062
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!LoadLibraryA 760694DC 5 Bytes JMP 012B0040
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!VirtualProtectEx 7606DBDA 5 Bytes JMP 012B0F88
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!GetProcAddress 7608903B 5 Bytes JMP 012B0F37
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!CreateFileW 7608AECB 5 Bytes JMP 012B001B
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!CreateFileA 7608CE5F 5 Bytes JMP 012B0000
.text C:\Windows\System32\svchost.exe[1132] kernel32.dll!WinExec 760D5CF7 5 Bytes JMP 012B00D8
.text C:\Windows\System32\svchost.exe[1132] msvcrt.dll!_wsystem 76177F2F 5 Bytes JMP 01340FCF
.text C:\Windows\System32\svchost.exe[1132] msvcrt.dll!system 7617804B 5 Bytes JMP 0134005A
.text C:\Windows\System32\svchost.exe[1132] msvcrt.dll!_creat 7617BBE1 5 Bytes JMP 0134002E
.text C:\Windows\System32\svchost.exe[1132] msvcrt.dll!_open 7617D106 5 Bytes JMP 01340000
.text C:\Windows\System32\svchost.exe[1132] msvcrt.dll!_wcreat 7617D326 5 Bytes JMP 01340049
.text C:\Windows\System32\svchost.exe[1132] msvcrt.dll!_wopen 7617D501 5 Bytes JMP 0134001D
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!RegCreateKeyExA 75DB39AB 5 Bytes JMP 012A0062
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!RegCreateKeyA 75DB3BA9 5 Bytes JMP 012A0FCA
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!RegOpenKeyA 75DB89C7 5 Bytes JMP 012A0FE5
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!RegCreateKeyW 75DC391E 5 Bytes JMP 012A0047
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!RegCreateKeyExW 75DC41F1 5 Bytes JMP 012A0FA5
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!RegOpenKeyExA 75DC7C42 5 Bytes JMP 012A001B
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!RegOpenKeyW 75DCE2B5 5 Bytes JMP 012A0000
.text C:\Windows\System32\svchost.exe[1132] ADVAPI32.dll!RegOpenKeyExW 75DD7BA1 5 Bytes JMP 012A0036
.text C:\Windows\system32\svchost.exe[1136] ntdll.dll!NtProtectVirtualMemory 77514B84 5 Bytes JMP 0098000A
.text C:\Windows\system32\svchost.exe[1136] ntdll.dll!NtWriteVirtualMemory 775154C4 5 Bytes JMP 00A1000A
.text C:\Windows\system32\svchost.exe[1136] ntdll.dll!KiUserExceptionDispatcher 77515BF8 5 Bytes JMP 0096000A
.text C:\Windows\system32\svchost.exe[1136] kernel32.dll!GetStartupInfoW 76041929 5 Bytes JMP 00A80F5E
.text C:\Windows\system32\svchost.exe[1136] kernel32.dll!GetStartupInfoA 760419C9 5 Bytes JMP 00A80F6F
.text C:\Windows\system32\svchost.exe[1136] kernel32.dll!CreateProcessW 76041BF3 5 Bytes JMP 00A800EB
.text C:\Windows\system32\svchost.exe[1136] kernel32.dll!CreateProcessA 76041C28 5 Bytes JMP 00A800DA
.text C:\Windows\system32\svchost.exe[1136] kernel32.dll!VirtualProtect 76041DC3 5 Bytes JMP 00A80089
.text C:\Windows\system32\svchost.exe[1136] kernel32.dll!CreateNamedPipeA 76042EF5 5 Bytes JMP 00A80FEF
.text C:\Windows\system32\svchost.exe[1136] kernel32.dll!CreateNamedPipeW 76045C0C 5 Bytes JMP 00A80FDE
.text C:\Windows\system32\svchost.exe[1136] kernel32.dll!CreatePipe 76068E6E 5 Bytes JMP 00A800A4
.text C:\Windows\system32\svchost.exe[1136] kernel32.dll!LoadLibraryExW 76069109 5 Bytes JMP 00A80078
.text C:\Windows\system32\svchost.exe[1136] kernel32.dll!LoadLibraryW 76069362 5 Bytes JMP 00A8005B
.text C:\Windows\system32\svchost.exe[1136] kernel32.dll!LoadLibraryExA 760694B4 5 Bytes JMP 00A80FB9
.text C:\Windows\system32\svchost.exe[1136] kernel32.dll!LoadLibraryA 760694DC 5 Bytes JMP 00A80040
.text C:\Windows\system32\svchost.exe[1136] kernel32.dll!VirtualProtectEx 7606DBDA 5 Bytes JMP 00A80F8A
.text C:\Windows\system32\svchost.exe[1136] kernel32.dll!GetProcAddress 7608903B 5 Bytes JMP 00A80106
.text C:\Windows\system32\svchost.exe[1136] kernel32.dll!CreateFileW 7608AECB 5 Bytes JMP 00A80025
.text C:\Windows\system32\svchost.exe[1136] kernel32.dll!CreateFileA 7608CE5F 5 Bytes JMP 00A8000A
.text C:\Windows\system32\svchost.exe[1136] kernel32.dll!WinExec 760D5CF7 5 Bytes JMP 00A800C9
.text C:\Windows\system32\svchost.exe[1136] msvcrt.dll!_wsystem 76177F2F 5 Bytes JMP 00A9005F
.text C:\Windows\system32\svchost.exe[1136] msvcrt.dll!system 7617804B 5 Bytes JMP 00A90FD4
.text C:\Windows\system32\svchost.exe[1136] msvcrt.dll!_creat 7617BBE1 5 Bytes JMP 00A90033
.text C:\Windows\system32\svchost.exe[1136] msvcrt.dll!_open 7617D106 5 Bytes JMP 00A90FEF
.text C:\Windows\system32\svchost.exe[1136] msvcrt.dll!_wcreat 7617D326 5 Bytes JMP 00A90044
.text C:\Windows\system32\svchost.exe[1136] msvcrt.dll!_wopen 7617D501 5 Bytes JMP 00A9000C
.text C:\Windows\system32\svchost.exe[1136] ADVAPI32.dll!RegCreateKeyExA 75DB39AB 5 Bytes JMP 00A70F9E
.text C:\Windows\system32\svchost.exe[1136] ADVAPI32.dll!RegCreateKeyA 75DB3BA9 5 Bytes JMP 00A70FCA
.text C:\Windows\system32\svchost.exe[1136] ADVAPI32.dll!RegOpenKeyA 75DB89C7 5 Bytes JMP 00A70000
.text C:\Windows\system32\svchost.exe[1136] ADVAPI32.dll!RegCreateKeyW 75DC391E 5 Bytes JMP 00A70FB9
.text C:\Windows\system32\svchost.exe[1136] ADVAPI32.dll!RegCreateKeyExW 75DC41F1 5 Bytes JMP 00A70F8D
.text C:\Windows\system32\svchost.exe[1136] ADVAPI32.dll!RegOpenKeyExA 75DC7C42 5 Bytes JMP 00A7001B
.text C:\Windows\system32\svchost.exe[1136] ADVAPI32.dll!RegOpenKeyW 75DCE2B5 5 Bytes JMP 00A70FDB
.text C:\Windows\system32\svchost.exe[1136] ADVAPI32.dll!RegOpenKeyExW 75DD7BA1 5 Bytes JMP 00A70036
.text C:\Windows\system32\svchost.exe[1136] WS2_32.dll!socket 773236D1 5 Bytes JMP 01310FEF
.text C:\Windows\system32\svchost.exe[1136] WININET.dll!InternetOpenA 771BD4AD 5 Bytes JMP 00AA000A
.text C:\Windows\system32\svchost.exe[1136] WININET.dll!InternetOpenW 771BD80A 5 Bytes JMP 00AA001B
.text C:\Windows\system32\svchost.exe[1136] WININET.dll!InternetOpenUrlA 771BFE7B 5 Bytes JMP 00AA0036
.text C:\Windows\system32\svchost.exe[1136] WININET.dll!InternetOpenUrlW 77209189 5 Bytes JMP 00AA0051
.text C:\Windows\system32\svchost.exe[1268] kernel32.dll!GetStartupInfoW 76041929 5 Bytes JMP 00950087
.text C:\Windows\system32\svchost.exe[1268] kernel32.dll!GetStartupInfoA 760419C9 5 Bytes JMP 00950F41
.text C:\Windows\system32\svchost.exe[1268] kernel32.dll!CreateProcessW 76041BF3 5 Bytes JMP 00950EFA
.text C:\Windows\system32\svchost.exe[1268] kernel32.dll!CreateProcessA 76041C28 5 Bytes JMP 00950F15
.text C:\Windows\system32\svchost.exe[1268] kernel32.dll!VirtualProtect 76041DC3 5 Bytes JMP 0095006C
.text C:\Windows\system32\svchost.exe[1268] kernel32.dll!CreateNamedPipeA 76042EF5 5 Bytes JMP 00950FD4
.text C:\Windows\system32\svchost.exe[1268] kernel32.dll!CreateNamedPipeW 76045C0C 5 Bytes JMP 00950025
.text C:\Windows\system32\svchost.exe[1268] kernel32.dll!CreatePipe 76068E6E 5 Bytes JMP 00950F5C
.text C:\Windows\system32\svchost.exe[1268] kernel32.dll!LoadLibraryExW 76069109 5 Bytes JMP 00950F92
.text C:\Windows\system32\svchost.exe[1268] kernel32.dll!LoadLibraryW 76069362 5 Bytes JMP 00950040
.text C:\Windows\system32\svchost.exe[1268] kernel32.dll!LoadLibraryExA 760694B4 5 Bytes JMP 0095005B
.text C:\Windows\system32\svchost.exe[1268] kernel32.dll!LoadLibraryA 760694DC 5 Bytes JMP 00950FB9
.text C:\Windows\system32\svchost.exe[1268] kernel32.dll!VirtualProtectEx 7606DBDA 5 Bytes JMP 00950F6D
.text C:\Windows\system32\svchost.exe[1268] kernel32.dll!GetProcAddress 7608903B 5 Bytes JMP 00950EDF
.text C:\Windows\system32\svchost.exe[1268] kernel32.dll!CreateFileW 7608AECB 5 Bytes JMP 0095000A
.text C:\Windows\system32\svchost.exe[1268] kernel32.dll!CreateFileA 7608CE5F 5 Bytes JMP 00950FEF
.text C:\Windows\system32\svchost.exe[1268] kernel32.dll!WinExec 760D5CF7 5 Bytes JMP 00950F26
.text C:\Windows\system32\svchost.exe[1268] msvcrt.dll!_wsystem 76177F2F 5 Bytes JMP 00960F86
.text C:\Windows\system32\svchost.exe[1268] msvcrt.dll!system 7617804B 5 Bytes JMP 00960FAB
.text C:\Windows\system32\svchost.exe[1268] msvcrt.dll!_creat 7617BBE1 5 Bytes JMP 00960FCD
.text C:\Windows\system32\svchost.exe[1268] msvcrt.dll!_open 7617D106 5 Bytes JMP 00960FEF
.text C:\Windows\system32\svchost.exe[1268] msvcrt.dll!_wcreat 7617D326 5 Bytes JMP 00960FBC
.text C:\Windows\system32\svchost.exe[1268] msvcrt.dll!_wopen 7617D501 5 Bytes JMP 00960FDE
.text C:\Windows\system32\svchost.exe[1268] ADVAPI32.dll!RegCreateKeyExA 75DB39AB 5 Bytes JMP 0018005B
.text C:\Windows\system32\svchost.exe[1268] ADVAPI32.dll!RegCreateKeyA 75DB3BA9 5 Bytes JMP 00180040
.text C:\Windows\system32\svchost.exe[1268] ADVAPI32.dll!RegOpenKeyA 75DB89C7 5 Bytes JMP 00180FEF
.text C:\Windows\system32\svchost.exe[1268] ADVAPI32.dll!RegCreateKeyW 75DC391E 5 Bytes JMP 00180FAF
.text C:\Windows\system32\svchost.exe[1268] ADVAPI32.dll!RegCreateKeyExW 75DC41F1 5 Bytes JMP 0018006C
.text C:\Windows\system32\svchost.exe[1268] ADVAPI32.dll!RegOpenKeyExA 75DC7C42 5 Bytes JMP 00180FD4
.text C:\Windows\system32\svchost.exe[1268] ADVAPI32.dll!RegOpenKeyW 75DCE2B5 5 Bytes JMP 00180014
.text C:\Windows\system32\svchost.exe[1268] ADVAPI32.dll!RegOpenKeyExW 75DD7BA1 5 Bytes JMP 00180025
.text C:\Windows\system32\svchost.exe[1268] WS2_32.dll!socket 773236D1 5 Bytes JMP 0098000A
.text C:\Windows\system32\svchost.exe[1268] WinInet.dll!InternetOpenA 771BD4AD 5 Bytes JMP 00970FE5
.text C:\Windows\system32\svchost.exe[1268] WinInet.dll!InternetOpenW 771BD80A 5 Bytes JMP 00970000
.text C:\Windows\system32\svchost.exe[1268] WinInet.dll!InternetOpenUrlA 771BFE7B 5 Bytes JMP 00970011
.text C:\Windows\system32\svchost.exe[1268] WinInet.dll!InternetOpenUrlW 77209189 5 Bytes JMP 0097002C
.text C:\Windows\system32\svchost.exe[1452] kernel32.dll!GetStartupInfoW 76041929 5 Bytes JMP 009100EB
.text C:\Windows\system32\svchost.exe[1452] kernel32.dll!GetStartupInfoA 760419C9 5 Bytes JMP 009100D0
.text C:\Windows\system32\svchost.exe[1452] kernel32.dll!CreateProcessW 76041BF3 5 Bytes JMP 00910F5E
.text C:\Windows\system32\svchost.exe[1452] kernel32.dll!CreateProcessA 76041C28 5 Bytes JMP 00910F6F
.text C:\Windows\system32\svchost.exe[1452] kernel32.dll!VirtualProtect 76041DC3 5 Bytes JMP 0091009A
.text C:\Windows\system32\svchost.exe[1452] kernel32.dll!CreateNamedPipeA 76042EF5 5 Bytes JMP 00910025
.text C:\Windows\system32\svchost.exe[1452] kernel32.dll!CreateNamedPipeW 76045C0C 5 Bytes JMP 00910040
.text C:\Windows\system32\svchost.exe[1452] kernel32.dll!CreatePipe 76068E6E 5 Bytes JMP 009100BF
.text C:\Windows\system32\svchost.exe[1452] kernel32.dll!LoadLibraryExW 76069109 5 Bytes JMP 00910FC0
.text C:\Windows\system32\svchost.exe[1452] kernel32.dll!LoadLibraryW 76069362 5 Bytes JMP 00910062
.text C:\Windows\system32\svchost.exe[1452] kernel32.dll!LoadLibraryExA 760694B4 5 Bytes JMP 0091007D
.text C:\Windows\system32\svchost.exe[1452] kernel32.dll!LoadLibraryA 760694DC 5 Bytes JMP 00910051
.text C:\Windows\system32\svchost.exe[1452] kernel32.dll!VirtualProtectEx 7606DBDA 5 Bytes JMP 00910FAF
.text C:\Windows\system32\svchost.exe[1452] kernel32.dll!GetProcAddress 7608903B 5 Bytes JMP 00910F4D
.text C:\Windows\system32\svchost.exe[1452] kernel32.dll!CreateFileW 7608AECB 5 Bytes JMP 00910FEF
.text C:\Windows\system32\svchost.exe[1452] kernel32.dll!CreateFileA 7608CE5F 5 Bytes JMP 00910000
.text C:\Windows\system32\svchost.exe[1452] kernel32.dll!WinExec 760D5CF7 5 Bytes JMP 00910F8A
.text C:\Windows\system32\svchost.exe[1452] msvcrt.dll!_wsystem 76177F2F 5 Bytes JMP 00920053
.text C:\Windows\system32\svchost.exe[1452] msvcrt.dll!system 7617804B 5 Bytes JMP 00920038
.text C:\Windows\system32\svchost.exe[1452] msvcrt.dll!_creat 7617BBE1 5 Bytes JMP 0092001D
.text C:\Windows\system32\svchost.exe[1452] msvcrt.dll!_open 7617D106 5 Bytes JMP 0092000C
.text C:\Windows\system32\svchost.exe[1452] msvcrt.dll!_wcreat 7617D326 5 Bytes JMP 00920FC8
.text C:\Windows\system32\svchost.exe[1452] msvcrt.dll!_wopen 7617D501 5 Bytes JMP 00920FEF
.text C:\Windows\system32\svchost.exe[1452] ADVAPI32.dll!RegCreateKeyExA 75DB39AB 5 Bytes JMP 008C0F68
.text C:\Windows\system32\svchost.exe[1452] ADVAPI32.dll!RegCreateKeyA 75DB3BA9 5 Bytes JMP 008C0F94
.text C:\Windows\system32\svchost.exe[1452] ADVAPI32.dll!RegOpenKeyA 75DB89C7 5 Bytes JMP 008C0FE5
.text C:\Windows\system32\svchost.exe[1452] ADVAPI32.dll!RegCreateKeyW 75DC391E 5 Bytes JMP 008C0F83
.text C:\Windows\system32\svchost.exe[1452] ADVAPI32.dll!RegCreateKeyExW 75DC41F1 5 Bytes JMP 008C0F57
.text C:\Windows\system32\svchost.exe[1452] ADVAPI32.dll!RegOpenKeyExA 75DC7C42 5 Bytes JMP 008C0FB9
.text C:\Windows\system32\svchost.exe[1452] ADVAPI32.dll!RegOpenKeyW 75DCE2B5 5 Bytes JMP 008C0FD4
.text C:\Windows\system32\svchost.exe[1452] ADVAPI32.dll!RegOpenKeyExW 75DD7BA1 5 Bytes JMP 008C0000
.text C:\Windows\system32\svchost.exe[1452] WS2_32.dll!socket 773236D1 5 Bytes JMP 00980000
.text C:\Windows\system32\svchost.exe[1452] WININET.dll!InternetOpenA 771BD4AD 5 Bytes JMP 00970FEF
.text C:\Windows\system32\svchost.exe[1452] WININET.dll!InternetOpenW 771BD80A 5 Bytes JMP 00970FD4
.text C:\Windows\system32\svchost.exe[1452] WININET.dll!InternetOpenUrlA 771BFE7B 5 Bytes JMP 00970FB9
.text C:\Windows\system32\svchost.exe[1452] WININET.dll!InternetOpenUrlW 77209189 5 Bytes JMP 00970FA8
.text C:\Windows\System32\svchost.exe[1480] kernel32.dll!GetStartupInfoW 76041929 5 Bytes JMP 00AD0098
.text C:\Windows\System32\svchost.exe[1480] kernel32.dll!GetStartupInfoA 760419C9 5 Bytes JMP 00AD0073
.text C:\Windows\System32\svchost.exe[1480] kernel32.dll!CreateProcessW 76041BF3 5 Bytes JMP 00AD0F15
.text C:\Windows\System32\svchost.exe[1480] kernel32.dll!CreateProcessA 76041C28 5 Bytes JMP 00AD0F26
.text C:\Windows\System32\svchost.exe[1480] kernel32.dll!VirtualProtect 76041DC3 5 Bytes JMP 00AD0051
.text C:\Windows\System32\svchost.exe[1480] kernel32.dll!CreateNamedPipeA 76042EF5 5 Bytes JMP 00AD0025
.text C:\Windows\System32\svchost.exe[1480] kernel32.dll!CreateNamedPipeW 76045C0C 5 Bytes JMP 00AD0FD4
.text C:\Windows\System32\svchost.exe[1480] kernel32.dll!CreatePipe 76068E6E 5 Bytes JMP 00AD0F52
.text C:\Windows\System32\svchost.exe[1480] kernel32.dll!LoadLibraryExW 76069109 5 Bytes JMP 00AD0F83
.text C:\Windows\System32\svchost.exe[1480] kernel32.dll!LoadLibraryW 76069362 5 Bytes JMP 00AD0FA8
.text C:\Windows\System32\svchost.exe[1480] kernel32.dll!LoadLibraryExA 760694B4 5 Bytes JMP 00AD0040
.text C:\Windows\System32\svchost.exe[1480] kernel32.dll!LoadLibraryA 760694DC 5 Bytes JMP 00AD0FC3
.text C:\Windows\System32\svchost.exe[1480] kernel32.dll!VirtualProtectEx 7606DBDA 5 Bytes JMP 00AD0062
.text C:\Windows\System32\svchost.exe[1480] kernel32.dll!GetProcAddress 7608903B 5 Bytes JMP 00AD00C7
.text C:\Windows\System32\svchost.exe[1480] kernel32.dll!CreateFileW 7608AECB 5 Bytes JMP 00AD0014
.text C:\Windows\System32\svchost.exe[1480] kernel32.dll!CreateFileA 7608CE5F 5 Bytes JMP 00AD0FEF
.text C:\Windows\System32\svchost.exe[1480] kernel32.dll!WinExec 760D5CF7 5 Bytes JMP 00AD0F37
.text C:\Windows\System32\svchost.exe[1480] msvcrt.dll!_wsystem 76177F2F 5 Bytes JMP 00AE0031
.text C:\Windows\System32\svchost.exe[1480] msvcrt.dll!system 7617804B 5 Bytes JMP 00AE0FA6
.text C:\Windows\System32\svchost.exe[1480] msvcrt.dll!_creat 7617BBE1 5 Bytes JMP 00AE0FC1
.text C:\Windows\System32\svchost.exe[1480] msvcrt.dll!_open 7617D106 5 Bytes JMP 00AE0FEF
.text C:\Windows\System32\svchost.exe[1480] msvcrt.dll!_wcreat 7617D326 5 Bytes JMP 00AE0016
.text C:\Windows\System32\svchost.exe[1480] msvcrt.dll!_wopen 7617D501 5 Bytes JMP 00AE0FD2
.text C:\Windows\System32\svchost.exe[1480] ADVAPI32.dll!RegCreateKeyExA 75DB39AB 5 Bytes JMP 00AB0F8D
.text C:\Windows\System32\svchost.exe[1480] ADVAPI32.dll!RegCreateKeyA 75DB3BA9 5 Bytes JMP 00AB0FA8
.text C:\Windows\System32\svchost.exe[1480] ADVAPI32.dll!RegOpenKeyA 75DB89C7 5 Bytes JMP 00AB0000
.text C:\Windows\System32\svchost.exe[1480] ADVAPI32.dll!RegCreateKeyW 75DC391E 5 Bytes JMP 00AB002F
.text C:\Windows\System32\svchost.exe[1480] ADVAPI32.dll!RegCreateKeyExW 75DC41F1 5 Bytes JMP 00AB0040
.text C:\Windows\System32\svchost.exe[1480] ADVAPI32.dll!RegOpenKeyExA 75DC7C42 5 Bytes JMP 00AB0FD4
.text C:\Windows\System32\svchost.exe[1480] ADVAPI32.dll!RegOpenKeyW 75DCE2B5 5 Bytes JMP 00AB0FEF
.text C:\Windows\System32\svchost.exe[1480] ADVAPI32.dll!RegOpenKeyExW 75DD7BA1 5 Bytes JMP 00AB0FB9
.text C:\Windows\System32\svchost.exe[1480] WS2_32.dll!socket 773236D1 5 Bytes JMP 00C10000
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] kernel32.dll!GetStartupInfoW 76041929 5 Bytes JMP 000100BB
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] kernel32.dll!GetStartupInfoA 760419C9 5 Bytes JMP 00010F6B
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] kernel32.dll!CreateProcessW 76041BF3 5 Bytes JMP 00010F50
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] kernel32.dll!CreateProcessA 76041C28 5 Bytes JMP 000100E7
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] kernel32.dll!VirtualProtect 76041DC3 5 Bytes JMP 00010FA8
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] kernel32.dll!CreateNamedPipeA 76042EF5 5 Bytes JMP 00010025
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] kernel32.dll!CreateNamedPipeW 76045C0C 5 Bytes JMP 00010040
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] kernel32.dll!CreatePipe 76068E6E 5 Bytes JMP 00010F7C
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] kernel32.dll!LoadLibraryExW 76069109 5 Bytes JMP 00010076
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] kernel32.dll!LoadLibraryW 76069362 5 Bytes JMP 00010FB9
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] kernel32.dll!LoadLibraryExA 760694B4 5 Bytes JMP 00010065
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] kernel32.dll!LoadLibraryA 760694DC 5 Bytes JMP 00010FD4
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] kernel32.dll!VirtualProtectEx 7606DBDA 5 Bytes JMP 00010F97
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] kernel32.dll!GetProcAddress 7608903B 5 Bytes JMP 000100F8
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] kernel32.dll!CreateFileW 7608AECB 5 Bytes JMP 00010FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] kernel32.dll!CreateFileA 7608CE5F 5 Bytes JMP 0001000A
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] kernel32.dll!WinExec 760D5CF7 5 Bytes JMP 000100CC
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] ADVAPI32.dll!RegCreateKeyExA 75DB39AB 5 Bytes JMP 00050FB2
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] ADVAPI32.dll!RegCreateKeyA 75DB3BA9 5 Bytes JMP 00050FCD
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] ADVAPI32.dll!RegOpenKeyA 75DB89C7 5 Bytes JMP 00050FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] ADVAPI32.dll!RegCreateKeyW 75DC391E 5 Bytes JMP 00050054
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] ADVAPI32.dll!RegCreateKeyExW 75DC41F1 5 Bytes JMP 00050065
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] ADVAPI32.dll!RegOpenKeyExA 75DC7C42 5 Bytes JMP 00050FDE
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] ADVAPI32.dll!RegOpenKeyW 75DCE2B5 5 Bytes JMP 0005000A
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] ADVAPI32.dll!RegOpenKeyExW 75DD7BA1 5 Bytes JMP 0005002F
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] USER32.dll!DialogBoxParamW 772B10B0 5 Bytes JMP 6991C00F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] USER32.dll!DialogBoxIndirectParamW 772B2EF5 5 Bytes JMP 69A5BC22 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] USER32.dll!DialogBoxParamA 772C8152 5 Bytes JMP 69A5BBE7 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] USER32.dll!DialogBoxIndirectParamA 772C847D 5 Bytes JMP 69A5BC5D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] USER32.dll!MessageBoxIndirectA 772DD4D9 5 Bytes JMP 69A5BBA3 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] USER32.dll!MessageBoxIndirectW 772DD5D3 5 Bytes JMP 69A5BB5F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] USER32.dll!MessageBoxExA 772DD639 5 Bytes JMP 69A5BB25 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] USER32.dll!MessageBoxExW 772DD65D 5 Bytes JMP 69A5BAEB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] msvcrt.dll!_wsystem 76177F2F 5 Bytes JMP 00060025
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] msvcrt.dll!system 7617804B 5 Bytes JMP 00060F9A
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] msvcrt.dll!_creat 7617BBE1 5 Bytes JMP 00060FBC
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] msvcrt.dll!_open 7617D106 5 Bytes JMP 00060000
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] msvcrt.dll!_wcreat 7617D326 5 Bytes JMP 00060FAB
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] msvcrt.dll!_wopen 7617D501 5 Bytes JMP 00060FE3
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] SHELL32.dll!SHRestricted + D95 767089A8 4 Bytes [99, 0B, F3, 69]
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] SHELL32.dll!SHRestricted + D9D 767089B0 8 Bytes [A7, 0A, F3, 69, A4, 32, F2, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] ole32.dll!OleLoadFromStream 76271E80 5 Bytes JMP 69A5BE1F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] WS2_32.dll!socket 773236D1 5 Bytes JMP 0008000A
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] WININET.dll!HttpOpenRequestA 771AFBBC 5 Bytes JMP 67BF4690 c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] WININET.dll!InternetConnectA 771B0692 5 Bytes JMP 67BF4790 c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] WININET.dll!InternetCloseHandle 771B2DB8 5 Bytes JMP 67BF43D0 c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] WININET.dll!InternetReadFile 771B74B9 5 Bytes JMP 67BF44F0 c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] WININET.dll!InternetOpenA 771BD4AD 5 Bytes JMP 00210000
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] WININET.dll!InternetOpenW 771BD80A 5 Bytes JMP 00210011
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] WININET.dll!InternetOpenUrlA 771BFE7B 5 Bytes JMP 00210FDB
.text C:\Program Files\Internet Explorer\iexplore.exe[1988] WININET.dll!InternetOpenUrlW 77209189 5 Bytes JMP 0021002C
.text C:\Windows\system32\svchost.exe[2308] kernel32.dll!GetStartupInfoW 76041929 5 Bytes JMP 009C0F29
.text C:\Windows\system32\svchost.exe[2308] kernel32.dll!GetStartupInfoA 760419C9 5 Bytes JMP 009C0F44
.text C:\Windows\system32\svchost.exe[2308] kernel32.dll!CreateProcessW 76041BF3 5 Bytes JMP 009C00B6
.text C:\Windows\system32\svchost.exe[2308] kernel32.dll!CreateProcessA 76041C28 5 Bytes JMP 009C009B
.text C:\Windows\system32\svchost.exe[2308] kernel32.dll!VirtualProtect 76041DC3 5 Bytes JMP 009C004A
.text C:\Windows\system32\svchost.exe[2308] kernel32.dll!CreateNamedPipeA 76042EF5 5 Bytes JMP 009C0FD4
.text C:\Windows\system32\svchost.exe[2308] kernel32.dll!CreateNamedPipeW 76045C0C 5 Bytes JMP 009C0FC3
.text C:\Windows\system32\svchost.exe[2308] kernel32.dll!CreatePipe 76068E6E 5 Bytes JMP 009C0F55
.text C:\Windows\system32\svchost.exe[2308] kernel32.dll!LoadLibraryExW 76069109 5 Bytes JMP 009C0F7C
.text C:\Windows\system32\svchost.exe[2308] kernel32.dll!LoadLibraryW 76069362 5 Bytes JMP 009C0F8D
.text C:\Windows\system32\svchost.exe[2308] kernel32.dll!LoadLibraryExA 760694B4 5 Bytes JMP 009C002F
.text C:\Windows\system32\svchost.exe[2308] kernel32.dll!LoadLibraryA 760694DC 5 Bytes JMP 009C0FA8
.text C:\Windows\system32\svchost.exe[2308] kernel32.dll!VirtualProtectEx 7606DBDA 5 Bytes JMP 009C0065
.text C:\Windows\system32\svchost.exe[2308] kernel32.dll!GetProcAddress 7608903B 5 Bytes JMP 009C0F04
.text C:\Windows\system32\svchost.exe[2308] kernel32.dll!CreateFileW 7608AECB 5 Bytes JMP 009C0FEF
.text C:\Windows\system32\svchost.exe[2308] kernel32.dll!CreateFileA 7608CE5F 5 Bytes JMP 009C000A
.text C:\Windows\system32\svchost.exe[2308] kernel32.dll!WinExec 760D5CF7 5 Bytes JMP 009C008A
.text C:\Windows\system32\svchost.exe[2308] msvcrt.dll!_wsystem 76177F2F 5 Bytes JMP 009D0F9C
.text C:\Windows\system32\svchost.exe[2308] msvcrt.dll!system 7617804B 5 Bytes JMP 009D0FAD
.text C:\Windows\system32\svchost.exe[2308] msvcrt.dll!_creat 7617BBE1 5 Bytes JMP 009D0FD2
.text C:\Windows\system32\svchost.exe[2308] msvcrt.dll!_open 7617D106 5 Bytes JMP 009D0000
.text C:\Windows\system32\svchost.exe[2308] msvcrt.dll!_wcreat 7617D326 5 Bytes JMP 009D0027
.text C:\Windows\system32\svchost.exe[2308] msvcrt.dll!_wopen 7617D501 5 Bytes JMP 009D0FEF
.text C:\Windows\system32\svchost.exe[2308] ADVAPI32.dll!RegCreateKeyExA 75DB39AB 5 Bytes JMP 009B0036
.text C:\Windows\system32\svchost.exe[2308] ADVAPI32.dll!RegCreateKeyA 75DB3BA9 5 Bytes JMP 009B0FA5
.text C:\Windows\system32\svchost.exe[2308] ADVAPI32.dll!RegOpenKeyA 75DB89C7 5 Bytes JMP 009B0FEF
.text C:\Windows\system32\svchost.exe[2308] ADVAPI32.dll!RegCreateKeyW 75DC391E 5 Bytes JMP 009B0F94
.text C:\Windows\system32\svchost.exe[2308] ADVAPI32.dll!RegCreateKeyExW 75DC41F1 5 Bytes JMP 009B0F6F
.text C:\Windows\system32\svchost.exe[2308] ADVAPI32.dll!RegOpenKeyExA 75DC7C42 5 Bytes JMP 009B0FCA
.text C:\Windows\system32\svchost.exe[2308] ADVAPI32.dll!RegOpenKeyW 75DCE2B5 5 Bytes JMP 009B0000
.text C:\Windows\system32\svchost.exe[2308] ADVAPI32.dll!RegOpenKeyExW 75DD7BA1 5 Bytes JMP 009B0011
.text C:\Windows\system32\svchost.exe[2308] WS2_32.dll!socket 773236D1 5 Bytes JMP 009E000A
.text C:\Windows\system32\DllHost.exe[2492] kernel32.dll!GetStartupInfoW 76041929 5 Bytes JMP 00840F41
.text C:\Windows\system32\DllHost.exe[2492] kernel32.dll!GetStartupInfoA 760419C9 5 Bytes JMP 00840087
.text C:\Windows\system32\DllHost.exe[2492] kernel32.dll!CreateProcessW 76041BF3 5 Bytes JMP 008400AC
.text C:\Windows\system32\DllHost.exe[2492] kernel32.dll!CreateProcessA 76041C28 5 Bytes JMP 00840F15
.text C:\Windows\system32\DllHost.exe[2492] kernel32.dll!VirtualProtect 76041DC3 5 Bytes JMP 00840F77
.text C:\Windows\system32\DllHost.exe[2492] kernel32.dll!CreateNamedPipeA 76042EF5 5 Bytes JMP 00840011
.text C:\Windows\system32\DllHost.exe[2492] kernel32.dll!CreateNamedPipeW 76045C0C 5 Bytes JMP 00840022
.text C:\Windows\system32\DllHost.exe[2492] kernel32.dll!CreatePipe 76068E6E 5 Bytes JMP 00840076
.text C:\Windows\system32\DllHost.exe[2492] kernel32.dll!LoadLibraryExW 76069109 5 Bytes JMP 00840F94
.text C:\Windows\system32\DllHost.exe[2492] kernel32.dll!LoadLibraryW 76069362 5 Bytes JMP 00840FC0
.text C:\Windows\system32\DllHost.exe[2492] kernel32.dll!LoadLibraryExA 760694B4 5 Bytes JMP 00840FA5
.text C:\Windows\system32\DllHost.exe[2492] kernel32.dll!LoadLibraryA 760694DC 5 Bytes JMP 00840047
.text C:\Windows\system32\DllHost.exe[2492] kernel32.dll!VirtualProtectEx 7606DBDA 5 Bytes JMP 00840F66
.text C:\Windows\system32\DllHost.exe[2492] kernel32.dll!GetProcAddress 7608903B 5 Bytes JMP 00840EFA
.text C:\Windows\system32\DllHost.exe[2492] kernel32.dll!CreateFileW 7608AECB 5 Bytes JMP 00840FDB
.text C:\Windows\system32\DllHost.exe[2492] kernel32.dll!CreateFileA 7608CE5F 5 Bytes JMP 00840000
.text C:\Windows\system32\DllHost.exe[2492] kernel32.dll!WinExec 760D5CF7 5 Bytes JMP 00840F30
.text C:\Windows\system32\DllHost.exe[2492] msvcrt.dll!_wsystem 76177F2F 5 Bytes JMP 00860031
.text C:\Windows\system32\DllHost.exe[2492] msvcrt.dll!system 7617804B 5 Bytes JMP 00860FA6
.text C:\Windows\system32\DllHost.exe[2492] msvcrt.dll!_creat 7617BBE1 5 Bytes JMP 00860FD2
.text C:\Windows\system32\DllHost.exe[2492] msvcrt.dll!_open 7617D106 5 Bytes JMP 00860000
.text C:\Windows\system32\DllHost.exe[2492] msvcrt.dll!_wcreat 7617D326 5 Bytes JMP 00860FC1
.text C:\Windows\system32\DllHost.exe[2492] msvcrt.dll!_wopen 7617D501 5 Bytes JMP 00860FE3
.text C:\Windows\system32\DllHost.exe[2492] ADVAPI32.dll!RegCreateKeyExA 75DB39AB 5 Bytes JMP 001E0047
.text C:\Windows\system32\DllHost.exe[2492] ADVAPI32.dll!RegCreateKeyA 75DB3BA9 5 Bytes JMP 001E001B
.text C:\Windows\system32\DllHost.exe[2492] ADVAPI32.dll!RegOpenKeyA 75DB89C7 5 Bytes JMP 001E0FEF
.text C:\Windows\system32\DllHost.exe[2492] ADVAPI32.dll!RegCreateKeyW 75DC391E 5 Bytes JMP 001E0036
.text C:\Windows\system32\DllHost.exe[2492] ADVAPI32.dll!RegCreateKeyExW 75DC41F1 5 Bytes JMP 001E0058
.text C:\Windows\system32\DllHost.exe[2492] ADVAPI32.dll!RegOpenKeyExA 75DC7C42 5 Bytes JMP 001E0FC3
.text C:\Windows\system32\DllHost.exe[2492] ADVAPI32.dll!RegOpenKeyW 75DCE2B5 5 Bytes JMP 001E0FDE
.text C:\Windows\system32\DllHost.exe[2492] ADVAPI32.dll!RegOpenKeyExW 75DD7BA1 5 Bytes JMP 001E000A
.text C:\Windows\System32\svchost.exe[2716] kernel32.dll!GetStartupInfoW 76041929 5 Bytes JMP 000A00B5
.text C:\Windows\System32\svchost.exe[2716] kernel32.dll!GetStartupInfoA 760419C9 5 Bytes JMP 000A0F79
.text C:\Windows\System32\svchost.exe[2716] kernel32.dll!CreateProcessW 76041BF3 5 Bytes JMP 000A00F2
.text C:\Windows\System32\svchost.exe[2716] kernel32.dll!CreateProcessA 76041C28 5 Bytes JMP 000A00E1
.text C:\Windows\System32\svchost.exe[2716] kernel32.dll!VirtualProtect 76041DC3 5 Bytes JMP 000A0064
.text C:\Windows\System32\svchost.exe[2716] kernel32.dll!CreateNamedPipeA 76042EF5 5 Bytes JMP 000A001B
.text C:\Windows\System32\svchost.exe[2716] kernel32.dll!CreateNamedPipeW 76045C0C 5 Bytes JMP 000A0FCA
.text C:\Windows\System32\svchost.exe[2716] kernel32.dll!CreatePipe 76068E6E 5 Bytes JMP 000A00A4
.text C:\Windows\System32\svchost.exe[2716] kernel32.dll!LoadLibraryExW 76069109 5 Bytes JMP 000A0F8A
.text C:\Windows\System32\svchost.exe[2716] kernel32.dll!LoadLibraryW 76069362 5 Bytes JMP 000A0036
.text C:\Windows\System32\svchost.exe[2716] kernel32.dll!LoadLibraryExA 760694B4 5 Bytes JMP 000A0047
.text C:\Windows\System32\svchost.exe[2716] kernel32.dll!LoadLibraryA 760694DC 5 Bytes JMP 000A0FB9
.text C:\Windows\System32\svchost.exe[2716] kernel32.dll!VirtualProtectEx 7606DBDA 5 Bytes JMP 000A007F
.text C:\Windows\System32\svchost.exe[2716] kernel32.dll!GetProcAddress 7608903B 5 Bytes JMP 000A0103
.text C:\Windows\System32\svchost.exe[2716] kernel32.dll!CreateFileW 7608AECB 5 Bytes JMP 000A000A
.text C:\Windows\System32\svchost.exe[2716] kernel32.dll!CreateFileA 7608CE5F 5 Bytes JMP 000A0FEF
.text C:\Windows\System32\svchost.exe[2716] kernel32.dll!WinExec 760D5CF7 5 Bytes JMP 000A00D0
.text C:\Windows\System32\svchost.exe[2716] msvcrt.dll!_wsystem 76177F2F 5 Bytes JMP 000B0FA6
.text C:\Windows\System32\svchost.exe[2716] msvcrt.dll!system 7617804B 5 Bytes JMP 000B0FB7
.text C:\Windows\System32\svchost.exe[2716] msvcrt.dll!_creat 7617BBE1 5 Bytes JMP 000B0FD2
.text C:\Windows\System32\svchost.exe[2716] msvcrt.dll!_open 7617D106 5 Bytes JMP 000B000C
.text C:\Windows\System32\svchost.exe[2716] msvcrt.dll!_wcreat 7617D326 5 Bytes JMP 000B0027
.text C:\Windows\System32\svchost.exe[2716] msvcrt.dll!_wopen 7617D501 5 Bytes JMP 000B0FE3
.text C:\Windows\System32\svchost.exe[2716] ADVAPI32.dll!RegCreateKeyExA 75DB39AB 5 Bytes JMP 0009007D
.text C:\Windows\System32\svchost.exe[2716] ADVAPI32.dll!RegCreateKeyA 75DB3BA9 5 Bytes JMP 00090051
.text C:\Windows\System32\svchost.exe[2716] ADVAPI32.dll!RegOpenKeyA 75DB89C7 5 Bytes JMP 0009000A
.text C:\Windows\System32\svchost.exe[2716] ADVAPI32.dll!RegCreateKeyW 75DC391E 5 Bytes JMP 00090062
.text C:\Windows\System32\svchost.exe[2716] ADVAPI32.dll!RegCreateKeyExW 75DC41F1 5 Bytes JMP 00090FC0
.text C:\Windows\System32\svchost.exe[2716] ADVAPI32.dll!RegOpenKeyExA 75DC7C42 5 Bytes JMP 0009002C
.text C:\Windows\System32\svchost.exe[2716] ADVAPI32.dll!RegOpenKeyW 75DCE2B5 5 Bytes JMP 0009001B
.text C:\Windows\System32\svchost.exe[2716] ADVAPI32.dll!RegOpenKeyExW 75DD7BA1 5 Bytes JMP 00090FE5
.text C:\Windows\Explorer.EXE[4040] kernel32.dll!GetStartupInfoW 76041929 5 Bytes JMP 000100A7
.text C:\Windows\Explorer.EXE[4040] kernel32.dll!GetStartupInfoA 760419C9 5 Bytes JMP 00010F61
.text C:\Windows\Explorer.EXE[4040] kernel32.dll!CreateProcessW 76041BF3 5 Bytes JMP 00010F3F
.text C:\Windows\Explorer.EXE[4040] kernel32.dll!CreateProcessA 76041C28 5 Bytes JMP 000100CC
.text C:\Windows\Explorer.EXE[4040] kernel32.dll!VirtualProtect 76041DC3 5 Bytes JMP 00010F83
.text C:\Windows\Explorer.EXE[4040] kernel32.dll!CreateNamedPipeA 76042EF5 5 Bytes JMP 00010FD4
.text C:\Windows\Explorer.EXE[4040] kernel32.dll!CreateNamedPipeW 76045C0C 5 Bytes JMP 00010025
.text C:\Windows\Explorer.EXE[4040] kernel32.dll!CreatePipe 76068E6E 1 Byte [E9]
.text C:\Windows\Explorer.EXE[4040] kernel32.dll!CreatePipe 76068E6E 5 Bytes JMP 00010F72
.text C:\Windows\Explorer.EXE[4040] kernel32.dll!LoadLibraryExW 76069109 5 Bytes JMP 0001005D
.text C:\Windows\Explorer.EXE[4040] kernel32.dll!LoadLibraryW 76069362 5 Bytes JMP 00010FB9
.text C:\Windows\Explorer.EXE[4040] kernel32.dll!LoadLibraryExA 760694B4 5 Bytes JMP 00010F94
.text C:\Windows\Explorer.EXE[4040] kernel32.dll!LoadLibraryA 760694DC 5 Bytes JMP 00010040
.text C:\Windows\Explorer.EXE[4040] kernel32.dll!VirtualProtectEx 7606DBDA 5 Bytes JMP 00010082
.text C:\Windows\Explorer.EXE[4040] kernel32.dll!GetProcAddress 7608903B 5 Bytes JMP 00010F2E
.text C:\Windows\Explorer.EXE[4040] kernel32.dll!CreateFileW 7608AECB 5 Bytes JMP 00010FEF
.text C:\Windows\Explorer.EXE[4040] kernel32.dll!CreateFileA 7608CE5F 5 Bytes JMP 00010000
.text C:\Windows\Explorer.EXE[4040] kernel32.dll!WinExec 760D5CF7 5 Bytes JMP 00010F50
.text C:\Windows\Explorer.EXE[4040] ADVAPI32.dll!RegCreateKeyExA 75DB39AB 5 Bytes JMP 00320F83
.text C:\Windows\Explorer.EXE[4040] ADVAPI32.dll!RegCreateKeyA 75DB3BA9 5 Bytes JMP 00320FAF
.text C:\Windows\Explorer.EXE[4040] ADVAPI32.dll!RegOpenKeyA 75DB89C7 5 Bytes JMP 00320000
.text C:\Windows\Explorer.EXE[4040] ADVAPI32.dll!RegCreateKeyW 75DC391E 5 Bytes JMP 00320F94
.text C:\Windows\Explorer.EXE[4040] ADVAPI32.dll!RegCreateKeyExW 75DC41F1 5 Bytes JMP 00320F72
.text C:\Windows\Explorer.EXE[4040] ADVAPI32.dll!RegOpenKeyExA 75DC7C42 5 Bytes JMP 0032001B
.text C:\Windows\Explorer.EXE[4040] ADVAPI32.dll!RegOpenKeyW 75DCE2B5 5 Bytes JMP 00320FE5
.text C:\Windows\Explorer.EXE[4040] ADVAPI32.dll!RegOpenKeyExW 75DD7BA1 5 Bytes JMP 00320FCA
.text C:\Windows\Explorer.EXE[4040] msvcrt.dll!_wsystem 76177F2F 5 Bytes JMP 00330016
.text C:\Windows\Explorer.EXE[4040] msvcrt.dll!system 7617804B 5 Bytes JMP 00330F95
.text C:\Windows\Explorer.EXE[4040] msvcrt.dll!_creat 7617BBE1 5 Bytes JMP 00330FB7
.text C:\Windows\Explorer.EXE[4040] msvcrt.dll!_open %2
Attached File(s)
-
Attach.txt (11.58K)
Number of downloads: 1 -
DDS.txt (14.59K)
Number of downloads: 3 -
MBRCheck_11.29.11_20.07.38.txt (15.56K)
Number of downloads: 2
This post has been edited by willie1690: 30 November 2011 - 04:05 PM

Help
This topic is locked

Back to top










