i have the original dvd of my os. windows vista home premium sp2...no new occurances of the blue screen since original post. major redirects to websites that mcafee responds to "as suspicious". 2 full system scan show no threats, but computer is very slow at certain times.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by Fresh Almighty at 18:16:36 on 2011-12-30
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2302.1224 [GMT -6:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\Windows\system32\mfevtps.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\System32\wpcumi.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\System32\CtHelper.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\ehome\ehmsas.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Windows\System32\mobsync.exe
C:\Windows\System32\ping.exe
C:\Program Files\Common Files\McAfee\Core\mchost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://att.my.yahoo.com/
uSearch Bar =
uInternet Settings,ProxyOverride = *.local
mSearchAssistant =
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: SearchPerks! Perk Counter: {2787ea8e-8d87-48af-88ad-b30246c917ab} - c:\program files\searchperks! perk counter\Bmbho.dll
BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20111012204745.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: SearchPerks! Perk Counter: {2787ea8e-8d87-48af-88ad-b30246c917ab} - c:\program files\searchperks! perk counter\Bmbho.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - No File
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [DSS] c:\windows\DosOCXPOP32.exe
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [Steam] "e:\games\half life 2\steam.exe" -silent
uRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Weather] c:\program files\aws\weatherbug\Weather.exe 1
uRun: [CmTray] "c:\program files\content manager\launchCM.exe"
mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
mRun: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
dRun: [DevconDefaultDB] c:\windows\system32\READREG /SILENT /FAIL=1
dRunOnce: [DelayShred] "c:\program files\mcafee\mshr\shrcl.exe" /p1 /q c:\users\fresha~1\appdata\local\temp\low\hsperf~1.sh! c:\users\fresha~1\appdata\local\temp\HSPERF~1.SH!
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\office\office\OSA9.EXE
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
LSP: c:\windows\system32\wpclsp.dll
LSP: mswsock.dll
Trusted Zone: beatport.com\media
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - hxxp://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/WebfettiInitialSetup1.0.1.1.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{0D8C8065-F712-4C9D-BC82-262D6987D636} : DhcpNameServer = 192.168.1.254
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2011-3-13 459728]
R1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\drivers\mfenlfk.sys [2011-10-12 64584]
R1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2011-10-12 165032]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-5-22 21504]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-10-12 271480]
R2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-10-12 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-10-12 271480]
R2 McProxy;McAfee Proxy Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-10-12 271480]
R2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2011-10-12 171168]
R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2011-10-12 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2011-10-12 148520]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2009-7-14 239648]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2011-10-12 56064]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2011-10-12 153280]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2011-10-12 314088]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate1c9a06a2b98ceb0;Google Update Service (gupdate1c9a06a2b98ceb0);c:\program files\google\update\GoogleUpdate.exe [2009-3-8 133104]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2010-11-27 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-3-8 133104]
S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2011-10-12 52320]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-10-12 84488]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-12-24 21:38:11 -------- d-----w- c:\program files\Content Manager
2011-12-23 05:27:01 388096 ----a-r- c:\users\fresh almighty\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-12-23 05:26:57 -------- d-----w- c:\program files\Trend Micro
2011-12-15 21:46:01 4223008 ----a-w- c:\windows\system32\NVStWiz.exe
2011-12-14 18:09:22 61248 ----a-w- c:\windows\system32\OpenCL.dll
2011-12-14 18:09:19 919872 ----a-w- c:\windows\system32\nvdispco32.dll
2011-12-14 18:09:19 877376 ----a-w- c:\windows\system32\nvgenco32.dll
2011-12-14 18:09:16 17248576 ----a-w- c:\windows\system32\nvcompiler.dll
2011-12-14 17:55:30 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-14 17:55:08 49152 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-14 17:54:21 2043904 ----a-w- c:\windows\system32\win32k.sys
2011-12-14 17:54:18 429056 ----a-w- c:\windows\system32\EncDec.dll
2011-12-14 17:54:15 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-12-14 17:54:15 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-12-14 17:53:58 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
.
==================== Find3M ====================
.
2011-12-08 18:26:15 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-10 11:54:13 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-11-03 22:47:42 1798144 ----a-w- c:\windows\system32\jscript9.dll
2011-11-03 22:40:21 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-11-03 22:39:47 1127424 ----a-w- c:\windows\system32\wininet.dll
2011-11-03 22:31:57 2382848 ----a-w- c:\windows\system32\mshtml.tlb
.
============= FINISH: 18:17:36.16 ===============
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2011-12-30 19:15:19
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST3200822A rev.3.01
Running: 7xk5124o.exe; Driver: C:\Users\FRESHA~1\AppData\Local\Temp\fxtyapoc.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0x8384AD48]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0x8384AD72]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0x8384AD5E]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0x8384AD34]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwYieldExecution 82E34982 5 Bytes JMP 8384AD38 \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
? C:\Users\FRESHA~1\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\svchost.exe[300] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 008B0FEF
.text C:\Windows\system32\svchost.exe[300] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 008B0FDE
.text C:\Windows\system32\svchost.exe[300] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 008B0014
.text C:\Windows\system32\svchost.exe[300] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 00E2008A
.text C:\Windows\system32\svchost.exe[300] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 00E20F44
.text C:\Windows\system32\svchost.exe[300] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 00E20F04
.text C:\Windows\system32\svchost.exe[300] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 00E200A5
.text C:\Windows\system32\svchost.exe[300] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 00E20F7A
.text C:\Windows\system32\svchost.exe[300] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 00E20FE5
.text C:\Windows\system32\svchost.exe[300] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 00E20FD4
.text C:\Windows\system32\svchost.exe[300] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 00E20F55
.text C:\Windows\system32\svchost.exe[300] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 00E20F97
.text C:\Windows\system32\svchost.exe[300] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 00E20FC3
.text C:\Windows\system32\svchost.exe[300] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 00E20FA8
.text C:\Windows\system32\svchost.exe[300] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 00E20040
.text C:\Windows\system32\svchost.exe[300] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 00E2006F
.text C:\Windows\system32\svchost.exe[300] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 00E20EF3
.text C:\Windows\system32\svchost.exe[300] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 00E20025
.text C:\Windows\system32\svchost.exe[300] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 00E20000
.text C:\Windows\system32\svchost.exe[300] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 00E20F33
.text C:\Windows\system32\svchost.exe[300] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 00890FB7
.text C:\Windows\system32\svchost.exe[300] msvcrt.dll!system 760B804B 5 Bytes JMP 00890042
.text C:\Windows\system32\svchost.exe[300] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 00890FD2
.text C:\Windows\system32\svchost.exe[300] msvcrt.dll!_open 760BD106 5 Bytes JMP 00890FEF
.text C:\Windows\system32\svchost.exe[300] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 00890027
.text C:\Windows\system32\svchost.exe[300] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 0089000C
.text C:\Windows\system32\svchost.exe[300] ADVAPI32.dll!RegCreateKeyExA 776B39AB 5 Bytes JMP 008A0FA1
.text C:\Windows\system32\svchost.exe[300] ADVAPI32.dll!RegCreateKeyA 776B3BA9 5 Bytes JMP 008A0FC3
.text C:\Windows\system32\svchost.exe[300] ADVAPI32.dll!RegOpenKeyA 776B89C7 5 Bytes JMP 008A0FEF
.text C:\Windows\system32\svchost.exe[300] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 008A0FB2
.text C:\Windows\system32\svchost.exe[300] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 008A0F90
.text C:\Windows\system32\svchost.exe[300] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 008A0025
.text C:\Windows\system32\svchost.exe[300] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 008A0014
.text C:\Windows\system32\svchost.exe[300] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 008A0FD4
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[340] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 6F4E9AE2 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[340] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 6F4E9A20 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Windows\System32\svchost.exe[456] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 00870FEF
.text C:\Windows\System32\svchost.exe[456] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 0087001B
.text C:\Windows\System32\svchost.exe[456] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 0087000A
.text C:\Windows\System32\svchost.exe[456] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 00880F26
.text C:\Windows\System32\svchost.exe[456] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 00880F41
.text C:\Windows\System32\svchost.exe[456] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 008800A2
.text C:\Windows\System32\svchost.exe[456] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 00880091
.text C:\Windows\System32\svchost.exe[456] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 0088002C
.text C:\Windows\System32\svchost.exe[456] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 00880FDB
.text C:\Windows\System32\svchost.exe[456] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 00880FC0
.text C:\Windows\System32\svchost.exe[456] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 00880062
.text C:\Windows\System32\svchost.exe[456] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 00880F52
.text C:\Windows\System32\svchost.exe[456] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 00880F8A
.text C:\Windows\System32\svchost.exe[456] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 00880F79
.text C:\Windows\System32\svchost.exe[456] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 00880FAF
.text C:\Windows\System32\svchost.exe[456] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 00880047
.text C:\Windows\System32\svchost.exe[456] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 00880EE6
.text C:\Windows\System32\svchost.exe[456] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 00880011
.text C:\Windows\System32\svchost.exe[456] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 00880000
.text C:\Windows\System32\svchost.exe[456] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 00880F15
.text C:\Windows\System32\svchost.exe[456] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 00160F9A
.text C:\Windows\System32\svchost.exe[456] msvcrt.dll!system 760B804B 5 Bytes JMP 00160FB5
.text C:\Windows\System32\svchost.exe[456] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 0016001B
.text C:\Windows\System32\svchost.exe[456] msvcrt.dll!_open 760BD106 5 Bytes JMP 00160000
.text C:\Windows\System32\svchost.exe[456] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 00160FC6
.text C:\Windows\System32\svchost.exe[456] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 00160FE3
.text C:\Windows\System32\svchost.exe[456] ADVAPI32.dll!RegCreateKeyExA 776B39AB 1 Byte [E9]
.text C:\Windows\System32\svchost.exe[456] ADVAPI32.dll!RegCreateKeyExA 776B39AB 5 Bytes JMP 006D0FAF
.text C:\Windows\System32\svchost.exe[456] ADVAPI32.dll!RegCreateKeyA 776B3BA9 5 Bytes JMP 006D0051
.text C:\Windows\System32\svchost.exe[456] ADVAPI32.dll!RegOpenKeyA 776B89C7 5 Bytes JMP 006D0000
.text C:\Windows\System32\svchost.exe[456] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 006D0FCA
.text C:\Windows\System32\svchost.exe[456] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 006D006C
.text C:\Windows\System32\svchost.exe[456] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 006D0FE5
.text C:\Windows\System32\svchost.exe[456] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 006D001B
.text C:\Windows\System32\svchost.exe[456] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 006D0036
.text C:\Windows\System32\svchost.exe[456] WS2_32.dll!socket 761236D1 5 Bytes JMP 006C0FEF
.text C:\Windows\System32\svchost.exe[648] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 001C0000
.text C:\Windows\System32\svchost.exe[648] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 001C0FDB
.text C:\Windows\System32\svchost.exe[648] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 001C001B
.text C:\Windows\System32\svchost.exe[648] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 00210F3E
.text C:\Windows\System32\svchost.exe[648] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 00210F63
.text C:\Windows\System32\svchost.exe[648] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 002100B0
.text C:\Windows\System32\svchost.exe[648] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 00210F23
.text C:\Windows\System32\svchost.exe[648] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 00210062
.text C:\Windows\System32\svchost.exe[648] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 0021000A
.text C:\Windows\System32\svchost.exe[648] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 00210025
.text C:\Windows\System32\svchost.exe[648] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 00210084
.text C:\Windows\System32\svchost.exe[648] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 00210F94
.text C:\Windows\System32\svchost.exe[648] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 00210FAF
.text C:\Windows\System32\svchost.exe[648] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 00210051
.text C:\Windows\System32\svchost.exe[648] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 00210036
.text C:\Windows\System32\svchost.exe[648] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 00210073
.text C:\Windows\System32\svchost.exe[648] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 002100C1
.text C:\Windows\System32\svchost.exe[648] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 00210FD4
.text C:\Windows\System32\svchost.exe[648] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 00210FEF
.text C:\Windows\System32\svchost.exe[648] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 0021009F
.text C:\Windows\System32\svchost.exe[648] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 00090F9C
.text C:\Windows\System32\svchost.exe[648] msvcrt.dll!system 760B804B 5 Bytes JMP 00090FB7
.text C:\Windows\System32\svchost.exe[648] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 0009001D
.text C:\Windows\System32\svchost.exe[648] msvcrt.dll!_open 760BD106 5 Bytes JMP 00090FEF
.text C:\Windows\System32\svchost.exe[648] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 00090FC8
.text C:\Windows\System32\svchost.exe[648] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 0009000C
.text C:\Windows\System32\svchost.exe[648] ADVAPI32.dll!RegCreateKeyExA 776B39AB 5 Bytes JMP 000B0054
.text C:\Windows\System32\svchost.exe[648] ADVAPI32.dll!RegCreateKeyA 776B3BA9 5 Bytes JMP 000B002F
.text C:\Windows\System32\svchost.exe[648] ADVAPI32.dll!RegOpenKeyA 776B89C7 5 Bytes JMP 000B0FEF
.text C:\Windows\System32\svchost.exe[648] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 000B0FA8
.text C:\Windows\System32\svchost.exe[648] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 000B0065
.text C:\Windows\System32\svchost.exe[648] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 000B0FCA
.text C:\Windows\System32\svchost.exe[648] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 000B0000
.text C:\Windows\System32\svchost.exe[648] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 000B0FB9
.text C:\Windows\System32\svchost.exe[648] WS2_32.dll!socket 761236D1 5 Bytes JMP 000A0FE5
.text C:\Windows\system32\services.exe[656] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 000C0000
.text C:\Windows\system32\services.exe[656] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 000C001B
.text C:\Windows\system32\services.exe[656] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 000C0FE5
.text C:\Windows\system32\services.exe[656] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 000D00C6
.text C:\Windows\system32\services.exe[656] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 000D00B5
.text C:\Windows\system32\services.exe[656] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 000D00F2
.text C:\Windows\system32\services.exe[656] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 000D00E1
.text C:\Windows\system32\services.exe[656] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 000D009A
.text C:\Windows\system32\services.exe[656] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 000D002C
.text C:\Windows\system32\services.exe[656] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 000D0047
.text C:\Windows\system32\services.exe[656] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 000D0F8A
.text C:\Windows\system32\services.exe[656] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 000D0FC0
.text C:\Windows\system32\services.exe[656] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 000D007D
.text C:\Windows\system32\services.exe[656] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 000D0FDB
.text C:\Windows\system32\services.exe[656] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 000D006C
.text C:\Windows\system32\services.exe[656] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 000D0F9B
.text C:\Windows\system32\services.exe[656] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 000D0F4A
.text C:\Windows\system32\services.exe[656] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 000D001B
.text C:\Windows\system32\services.exe[656] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 000D0000
.text C:\Windows\system32\services.exe[656] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 000D0F65
.text C:\Windows\system32\services.exe[656] ADVAPI32.dll!RegCreateKeyExA 776B39AB 1 Byte [E9]
.text C:\Windows\system32\services.exe[656] ADVAPI32.dll!RegCreateKeyExA 776B39AB 5 Bytes JMP 00670FAF
.text C:\Windows\system32\services.exe[656] ADVAPI32.dll!RegCreateKeyA 776B3BA9 5 Bytes JMP 00670051
.text C:\Windows\system32\services.exe[656] ADVAPI32.dll!RegOpenKeyA 776B89C7 5 Bytes JMP 0067000A
.text C:\Windows\system32\services.exe[656] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 00670FC0
.text C:\Windows\system32\services.exe[656] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 00670F9E
.text C:\Windows\system32\services.exe[656] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 00670FE5
.text C:\Windows\system32\services.exe[656] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 0067001B
.text C:\Windows\system32\services.exe[656] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 00670040
.text C:\Windows\system32\services.exe[656] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 000E0053
.text C:\Windows\system32\services.exe[656] msvcrt.dll!system 760B804B 5 Bytes JMP 000E0042
.text C:\Windows\system32\services.exe[656] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 000E0FE3
.text C:\Windows\system32\services.exe[656] msvcrt.dll!_open 760BD106 5 Bytes JMP 000E0000
.text C:\Windows\system32\services.exe[656] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 000E0FD2
.text C:\Windows\system32\services.exe[656] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 000E0011
.text C:\Windows\system32\services.exe[656] WS2_32.dll!socket 761236D1 5 Bytes JMP 000F0000
.text C:\Windows\system32\services.exe[656] WININET.dll!InternetOpenA 77864E3C 5 Bytes JMP 00680FEF
.text C:\Windows\system32\services.exe[656] WININET.dll!InternetOpenUrlA 7786BFDE 5 Bytes JMP 0068000A
.text C:\Windows\system32\services.exe[656] WININET.dll!InternetOpenW 7789C126 5 Bytes JMP 00680FD4
.text C:\Windows\system32\services.exe[656] WININET.dll!InternetOpenUrlW 778CD8D2 5 Bytes JMP 00680025
.text C:\Windows\system32\lsass.exe[672] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 000B0FEF
.text C:\Windows\system32\lsass.exe[672] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 000B0025
.text C:\Windows\system32\lsass.exe[672] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 000B0014
.text C:\Windows\system32\lsass.exe[672] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 000C0F40
.text C:\Windows\system32\lsass.exe[672] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 000C0F51
.text C:\Windows\system32\lsass.exe[672] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 000C00B2
.text C:\Windows\system32\lsass.exe[672] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 000C00A1
.text C:\Windows\system32\lsass.exe[672] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 000C0F84
.text C:\Windows\system32\lsass.exe[672] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 000C0FDE
.text C:\Windows\system32\lsass.exe[672] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 000C0FCD
.text C:\Windows\system32\lsass.exe[672] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 000C0F62
.text C:\Windows\system32\lsass.exe[672] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 000C0FAB
.text C:\Windows\system32\lsass.exe[672] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 000C005E
.text C:\Windows\system32\lsass.exe[672] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 000C0FBC
.text C:\Windows\system32\lsass.exe[672] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 000C0039
.text C:\Windows\system32\lsass.exe[672] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 000C0F73
.text C:\Windows\system32\lsass.exe[672] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 000C0F00
.text C:\Windows\system32\lsass.exe[672] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 000C0014
.text C:\Windows\system32\lsass.exe[672] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 000C0FEF
.text C:\Windows\system32\lsass.exe[672] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 000C0F25
.text C:\Windows\system32\lsass.exe[672] ADVAPI32.dll!RegCreateKeyExA 776B39AB 5 Bytes JMP 00900F7C
.text C:\Windows\system32\lsass.exe[672] ADVAPI32.dll!RegCreateKeyA 776B3BA9 5 Bytes JMP 00900F97
.text C:\Windows\system32\lsass.exe[672] ADVAPI32.dll!RegOpenKeyA 776B89C7 5 Bytes JMP 00900FEF
.text C:\Windows\system32\lsass.exe[672] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 0090001E
.text C:\Windows\system32\lsass.exe[672] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 00900F6B
.text C:\Windows\system32\lsass.exe[672] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 00900FC3
.text C:\Windows\system32\lsass.exe[672] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 00900FD4
.text C:\Windows\system32\lsass.exe[672] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 00900FB2
.text C:\Windows\system32\lsass.exe[672] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 000D0FB2
.text C:\Windows\system32\lsass.exe[672] msvcrt.dll!system 760B804B 5 Bytes JMP 000D003D
.text C:\Windows\system32\lsass.exe[672] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 000D0022
.text C:\Windows\system32\lsass.exe[672] msvcrt.dll!_open 760BD106 5 Bytes JMP 000D0FEF
.text C:\Windows\system32\lsass.exe[672] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 000D0FCD
.text C:\Windows\system32\lsass.exe[672] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 000D0FDE
.text C:\Windows\system32\lsass.exe[672] WS2_32.dll!socket 761236D1 5 Bytes JMP 008B0000
.text C:\Windows\system32\lsass.exe[672] WININET.dll!InternetOpenA 77864E3C 5 Bytes JMP 0091000A
.text C:\Windows\system32\lsass.exe[672] WININET.dll!InternetOpenUrlA 7786BFDE 5 Bytes JMP 0091002F
.text C:\Windows\system32\lsass.exe[672] WININET.dll!InternetOpenW 7789C126 5 Bytes JMP 00910FEF
.text C:\Windows\system32\lsass.exe[672] WININET.dll!InternetOpenUrlW 778CD8D2 5 Bytes JMP 00910FDE
.text C:\Windows\System32\ping.exe[780] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 0094000A
.text C:\Windows\System32\ping.exe[780] ntdll.dll!NtCreateProcessEx 779C42F4 5 Bytes JMP 0095000A
.text C:\Windows\System32\ping.exe[780] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 0072000A
.text C:\Windows\System32\ping.exe[780] ntdll.dll!NtWriteVirtualMemory 779C54C4 5 Bytes JMP 0077000A
.text C:\Windows\System32\ping.exe[780] ntdll.dll!NtCreateUserProcess 779C5654 5 Bytes JMP 0096000A
.text C:\Windows\System32\ping.exe[780] ntdll.dll!KiUserExceptionDispatcher 779C5BF8 5 Bytes JMP 001E000A
.text C:\Windows\System32\ping.exe[780] USER32.dll!WindowFromPoint 7620884F 5 Bytes JMP 00EA000A
.text C:\Windows\System32\ping.exe[780] USER32.dll!GetForegroundWindow 762132C4 5 Bytes JMP 00EB000A
.text C:\Windows\System32\ping.exe[780] USER32.dll!GetCursorPos 76220B88 5 Bytes JMP 00E7000A
.text C:\Windows\System32\ping.exe[780] ole32.dll!CoCreateInstance 76579F3E 5 Bytes JMP 00D2000A
.text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 00160FEF
.text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 00160025
.text C:\Windows\system32\svchost.exe[868] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 0016000A
.text C:\Windows\system32\svchost.exe[868] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 00170F28
.text C:\Windows\system32\svchost.exe[868] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 00170F4D
.text C:\Windows\system32\svchost.exe[868] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 00170EF5
.text C:\Windows\system32\svchost.exe[868] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 00170F06
.text C:\Windows\system32\svchost.exe[868] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 00170067
.text C:\Windows\system32\svchost.exe[868] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 00170FE5
.text C:\Windows\system32\svchost.exe[868] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 00170036
.text C:\Windows\system32\svchost.exe[868] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 00170F5E
.text C:\Windows\system32\svchost.exe[868] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 00170F8D
.text C:\Windows\system32\svchost.exe[868] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 00170FAF
.text C:\Windows\system32\svchost.exe[868] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 00170F9E
.text C:\Windows\system32\svchost.exe[868] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 00170FC0
.text C:\Windows\system32\svchost.exe[868] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 00170078
.text C:\Windows\system32\svchost.exe[868] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 00170EE4
.text C:\Windows\system32\svchost.exe[868] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 0017001B
.text C:\Windows\system32\svchost.exe[868] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 00170000
.text C:\Windows\system32\svchost.exe[868] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 00170F17
.text C:\Windows\system32\svchost.exe[868] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 00180FC8
.text C:\Windows\system32\svchost.exe[868] msvcrt.dll!system 760B804B 5 Bytes JMP 00180FD9
.text C:\Windows\system32\svchost.exe[868] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 0018002E
.text C:\Windows\system32\svchost.exe[868] msvcrt.dll!_open 760BD106 5 Bytes JMP 00180000
.text C:\Windows\system32\svchost.exe[868] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 00180053
.text C:\Windows\system32\svchost.exe[868] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 00180011
.text C:\Windows\system32\svchost.exe[868] ADVAPI32.dll!RegCreateKeyExA 776B39AB 5 Bytes JMP 001A006F
.text C:\Windows\system32\svchost.exe[868] ADVAPI32.dll!RegCreateKeyA 776B3BA9 5 Bytes JMP 001A004A
.text C:\Windows\system32\svchost.exe[868] ADVAPI32.dll!RegOpenKeyA 776B89C7 5 Bytes JMP 001A0FEF
.text C:\Windows\system32\svchost.exe[868] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 001A0FC3
.text C:\Windows\system32\svchost.exe[868] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 001A0FA8
.text C:\Windows\system32\svchost.exe[868] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 001A002F
.text C:\Windows\system32\svchost.exe[868] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 001A0014
.text C:\Windows\system32\svchost.exe[868] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 001A0FDE
.text C:\Windows\system32\svchost.exe[868] WS2_32.dll!socket 761236D1 5 Bytes JMP 0019000A
.text C:\Windows\system32\svchost.exe[940] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 00870FEF
.text C:\Windows\system32\svchost.exe[940] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 00870FB9
.text C:\Windows\system32\svchost.exe[940] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 00870FD4
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 00880F4E
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 00880094
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 00880F0E
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 00880F29
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 00880079
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 00880FC3
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 0088001E
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 00880F69
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 00880F95
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 0088004A
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 00880FB2
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 0088002F
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 00880F84
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 008800C0
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 00880FDE
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 00880FEF
.text C:\Windows\system32\svchost.exe[940] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 008800A5
.text C:\Windows\system32\svchost.exe[940] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 0089004E
.text C:\Windows\system32\svchost.exe[940] msvcrt.dll!system 760B804B 5 Bytes JMP 00890FC3
.text C:\Windows\system32\svchost.exe[940] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 00890029
.text C:\Windows\system32\svchost.exe[940] msvcrt.dll!_open 760BD106 5 Bytes JMP 00890FEF
.text C:\Windows\system32\svchost.exe[940] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 00890FDE
.text C:\Windows\system32\svchost.exe[940] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 0089000C
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!RegCreateKeyExA 776B39AB 5 Bytes JMP 0091005B
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!RegCreateKeyA 776B3BA9 5 Bytes JMP 00910040
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!RegOpenKeyA 776B89C7 5 Bytes JMP 00910FEF
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 00910FB9
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 0091006C
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 00910FDE
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 0091000A
.text C:\Windows\system32\svchost.exe[940] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 00910025
.text C:\Windows\system32\svchost.exe[940] WS2_32.dll!socket 761236D1 5 Bytes JMP 008A0FE5
.text C:\Windows\system32\svchost.exe[940] WININET.dll!InternetOpenA 77864E3C 5 Bytes JMP 00920FEF
.text C:\Windows\system32\svchost.exe[940] WININET.dll!InternetOpenUrlA 7786BFDE 5 Bytes JMP 0092001B
.text C:\Windows\system32\svchost.exe[940] WININET.dll!InternetOpenW 7789C126 5 Bytes JMP 0092000A
.text C:\Windows\system32\svchost.exe[940] WININET.dll!InternetOpenUrlW 778CD8D2 5 Bytes JMP 00920FCA
.text C:\Windows\System32\svchost.exe[972] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 01040FEF
.text C:\Windows\System32\svchost.exe[972] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 01040FC3
.text C:\Windows\System32\svchost.exe[972] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 01040FD4
.text C:\Windows\System32\svchost.exe[972] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 010500E1
.text C:\Windows\System32\svchost.exe[972] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 010500D0
.text C:\Windows\System32\svchost.exe[972] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 01050117
.text C:\Windows\System32\svchost.exe[972] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 01050F80
.text C:\Windows\System32\svchost.exe[972] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 010500A4
.text C:\Windows\System32\svchost.exe[972] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 01050036
.text C:\Windows\System32\svchost.exe[972] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 01050FEF
.text C:\Windows\System32\svchost.exe[972] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 01050FA5
.text C:\Windows\System32\svchost.exe[972] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 01050087
.text C:\Windows\System32\svchost.exe[972] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 01050076
.text C:\Windows\System32\svchost.exe[972] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 01050FCA
.text C:\Windows\System32\svchost.exe[972] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 0105005B
.text C:\Windows\System32\svchost.exe[972] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 010500B5
.text C:\Windows\System32\svchost.exe[972] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 01050128
.text C:\Windows\System32\svchost.exe[972] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 01050025
.text C:\Windows\System32\svchost.exe[972] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 0105000A
.text C:\Windows\System32\svchost.exe[972] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 010500FC
.text C:\Windows\System32\svchost.exe[972] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 00DC0F9C
.text C:\Windows\System32\svchost.exe[972] msvcrt.dll!system 760B804B 5 Bytes JMP 00DC0027
.text C:\Windows\System32\svchost.exe[972] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 00DC0FD2
.text C:\Windows\System32\svchost.exe[972] msvcrt.dll!_open 760BD106 5 Bytes JMP 00DC0FEF
.text C:\Windows\System32\svchost.exe[972] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 00DC0FB7
.text C:\Windows\System32\svchost.exe[972] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 00DC000C
.text C:\Windows\System32\svchost.exe[972] ADVAPI32.dll!RegCreateKeyExA 776B39AB 5 Bytes JMP 00DD0F8A
.text C:\Windows\System32\svchost.exe[972] ADVAPI32.dll!RegCreateKeyA 776B3BA9 5 Bytes JMP 00DD002C
.text C:\Windows\System32\svchost.exe[972] ADVAPI32.dll!RegOpenKeyA 776B89C7 5 Bytes JMP 00DD0000
.text C:\Windows\System32\svchost.exe[972] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 00DD0FAF
.text C:\Windows\System32\svchost.exe[972] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 00DD0F6F
.text C:\Windows\System32\svchost.exe[972] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 00DD001B
.text C:\Windows\System32\svchost.exe[972] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 00DD0FE5
.text C:\Windows\System32\svchost.exe[972] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 00DD0FC0
.text C:\Windows\System32\svchost.exe[972] WS2_32.dll!socket 761236D1 5 Bytes JMP 01070FE5
.text C:\Windows\System32\svchost.exe[972] WININET.dll!InternetOpenA 77864E3C 5 Bytes JMP 01F70FE5
.text C:\Windows\System32\svchost.exe[972] WININET.dll!InternetOpenUrlA 7786BFDE 5 Bytes JMP 01F70014
.text C:\Windows\System32\svchost.exe[972] WININET.dll!InternetOpenW 7789C126 5 Bytes JMP 01F70FD4
.text C:\Windows\System32\svchost.exe[972] WININET.dll!InternetOpenUrlW 778CD8D2 5 Bytes JMP 01F70FC3
.text C:\Windows\System32\svchost.exe[1056] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 00D10000
.text C:\Windows\System32\svchost.exe[1056] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 00D10FD4
.text C:\Windows\System32\svchost.exe[1056] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 00D10FEF
.text C:\Windows\System32\svchost.exe[1056] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 00D60F52
.text C:\Windows\System32\svchost.exe[1056] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 00D60F6D
.text C:\Windows\System32\svchost.exe[1056] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 00D600C4
.text C:\Windows\System32\svchost.exe[1056] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 00D60F37
.text C:\Windows\System32\svchost.exe[1056] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 00D6006C
.text C:\Windows\System32\svchost.exe[1056] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 00D60025
.text C:\Windows\System32\svchost.exe[1056] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 00D60040
.text C:\Windows\System32\svchost.exe[1056] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 00D600A2
.text C:\Windows\System32\svchost.exe[1056] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 00D6005B
.text C:\Windows\System32\svchost.exe[1056] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 00D60FB9
.text C:\Windows\System32\svchost.exe[1056] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 00D60FA8
.text C:\Windows\System32\svchost.exe[1056] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 00D60FD4
.text C:\Windows\System32\svchost.exe[1056] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 00D60087
.text C:\Windows\System32\svchost.exe[1056] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 00D600D5
.text C:\Windows\System32\svchost.exe[1056] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 00D6000A
.text C:\Windows\System32\svchost.exe[1056] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 00D60FEF
.text C:\Windows\System32\svchost.exe[1056] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 00D600B3
.text C:\Windows\System32\svchost.exe[1056] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 00D80FAD
.text C:\Windows\System32\svchost.exe[1056] msvcrt.dll!system 760B804B 5 Bytes JMP 00D80FBE
.text C:\Windows\System32\svchost.exe[1056] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 00D80FD9
.text C:\Windows\System32\svchost.exe[1056] msvcrt.dll!_open 760BD106 5 Bytes JMP 00D80000
.text C:\Windows\System32\svchost.exe[1056] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 00D8002E
.text C:\Windows\System32\svchost.exe[1056] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 00D8001D
.text C:\Windows\System32\svchost.exe[1056] ADVAPI32.dll!RegCreateKeyExA 776B39AB 5 Bytes JMP 00970036
.text C:\Windows\System32\svchost.exe[1056] ADVAPI32.dll!RegCreateKeyA 776B3BA9 5 Bytes JMP 00970FAF
.text C:\Windows\System32\svchost.exe[1056] ADVAPI32.dll!RegOpenKeyA 776B89C7 5 Bytes JMP 00970000
.text C:\Windows\System32\svchost.exe[1056] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 00970F94
.text C:\Windows\System32\svchost.exe[1056] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 00970F6F
.text C:\Windows\System32\svchost.exe[1056] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 00970011
.text C:\Windows\System32\svchost.exe[1056] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 00970FE5
.text C:\Windows\System32\svchost.exe[1056] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 00970FC0
.text C:\Windows\System32\svchost.exe[1056] WS2_32.dll!socket 761236D1 5 Bytes JMP 00DD0000
.text C:\Windows\System32\svchost.exe[1056] WININET.dll!InternetOpenA 77864E3C 5 Bytes JMP 01590000
.text C:\Windows\System32\svchost.exe[1056] WININET.dll!InternetOpenUrlA 7786BFDE 5 Bytes JMP 01590025
.text C:\Windows\System32\svchost.exe[1056] WININET.dll!InternetOpenW 7789C126 5 Bytes JMP 01590FE5
.text C:\Windows\System32\svchost.exe[1056] WININET.dll!InternetOpenUrlW 778CD8D2 5 Bytes JMP 01590FCA
.text C:\Windows\system32\svchost.exe[1084] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 00F90000
.text C:\Windows\system32\svchost.exe[1084] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 00F9001B
.text C:\Windows\system32\svchost.exe[1084] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 00F90FE5
.text C:\Windows\system32\svchost.exe[1084] ntdll.dll!NtWriteVirtualMemory 779C54C4 5 Bytes JMP 00AB000A
.text C:\Windows\system32\svchost.exe[1084] ntdll.dll!KiUserExceptionDispatcher 779C5BF8 5 Bytes JMP 00A5000A
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 00FA00A2
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 00FA0F5C
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 00FA00CE
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 00FA00BD
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 00FA0F77
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 00FA0FDB
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 00FA0FCA
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 00FA0087
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 00FA0F94
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 00FA0047
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 00FA0FA5
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 00FA0036
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 00FA006C
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 00FA00E9
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 00FA0011
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 00FA0000
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 00FA0F41
.text C:\Windows\system32\svchost.exe[1084] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 00FF0058
.text C:\Windows\system32\svchost.exe[1084] msvcrt.dll!system 760B804B 5 Bytes JMP 00FF003D
.text C:\Windows\system32\svchost.exe[1084] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 00FF0022
.text C:\Windows\system32\svchost.exe[1084] msvcrt.dll!_open 760BD106 5 Bytes JMP 00FF0FEF
.text C:\Windows\system32\svchost.exe[1084] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 00FF0FCD
.text C:\Windows\system32\svchost.exe[1084] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 00FF0FDE
.text C:\Windows\system32\svchost.exe[1084] ADVAPI32.dll!RegCreateKeyExA 776B39AB 3 Bytes JMP 00F70FD4
.text C:\Windows\system32\svchost.exe[1084] ADVAPI32.dll!RegCreateKeyExA + 4 776B39AF 1 Byte [89]
.text C:\Windows\system32\svchost.exe[1084] ADVAPI32.dll!RegCreateKeyA 776B3BA9 3 Bytes JMP 00F7005B
.text C:\Windows\system32\svchost.exe[1084] ADVAPI32.dll!RegCreateKeyA + 4 776B3BAD 1 Byte [89]
.text C:\Windows\system32\svchost.exe[1084] ADVAPI32.dll!RegOpenKeyA 776B89C7 3 Bytes JMP 00F70000
.text C:\Windows\system32\svchost.exe[1084] ADVAPI32.dll!RegOpenKeyA + 4 776B89CB 1 Byte [89]
.text C:\Windows\system32\svchost.exe[1084] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 00F70076
.text C:\Windows\system32\svchost.exe[1084] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 00F7009B
.text C:\Windows\system32\svchost.exe[1084] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 00F70FEF
.text C:\Windows\system32\svchost.exe[1084] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 00F7001B
.text C:\Windows\system32\svchost.exe[1084] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 00F70040
.text C:\Windows\system32\svchost.exe[1084] WS2_32.dll!socket 761236D1 5 Bytes JMP 0134000A
.text C:\Windows\system32\svchost.exe[1084] WININET.dll!InternetOpenA 77864E3C 5 Bytes JMP 00F80000
.text C:\Windows\system32\svchost.exe[1084] WININET.dll!InternetOpenUrlA 7786BFDE 5 Bytes JMP 00F80FDE
.text C:\Windows\system32\svchost.exe[1084] WININET.dll!InternetOpenW 7789C126 5 Bytes JMP 00F80FEF
.text C:\Windows\system32\svchost.exe[1084] WININET.dll!InternetOpenUrlW 778CD8D2 5 Bytes JMP 00F80FC3
.text C:\Windows\system32\svchost.exe[1240] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 00220FE5
.text C:\Windows\system32\svchost.exe[1240] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 00220014
.text C:\Windows\system32\svchost.exe[1240] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 00220FD4
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 002300B8
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 00230F68
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 002300C9
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 00230F32
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 0023005D
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 00230FEF
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 00230FDE
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 00230093
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 00230F83
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 00230040
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 00230F94
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 00230FB9
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 00230082
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 00230F17
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 0023001B
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 0023000A
.text C:\Windows\system32\svchost.exe[1240] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 00230F57
.text C:\Windows\system32\svchost.exe[1240] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 00240FA6
.text C:\Windows\system32\svchost.exe[1240] msvcrt.dll!system 760B804B 5 Bytes JMP 00240FB7
.text C:\Windows\system32\svchost.exe[1240] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 00240016
.text C:\Windows\system32\svchost.exe[1240] msvcrt.dll!_open 760BD106 5 Bytes JMP 00240FEF
.text C:\Windows\system32\svchost.exe[1240] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 00240027
.text C:\Windows\system32\svchost.exe[1240] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 00240FD2
.text C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!RegCreateKeyExA 776B39AB 5 Bytes JMP 00210069
.text C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!RegCreateKeyA 776B3BA9 5 Bytes JMP 00210058
.text C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!RegOpenKeyA 776B89C7 5 Bytes JMP 0021000A
.text C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 00210FD1
.text C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 00210FAC
.text C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 00210036
.text C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 0021001B
.text C:\Windows\system32\svchost.exe[1240] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 00210047
.text C:\Windows\system32\svchost.exe[1240] WS2_32.dll!socket 761236D1 5 Bytes JMP 00290FE5
.text C:\Windows\system32\svchost.exe[1256] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 008D0FEF
.text C:\Windows\system32\svchost.exe[1256] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 008D0FCD
.text C:\Windows\system32\svchost.exe[1256] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 008D0FDE
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 008E00A4
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 008E0F5E
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 008E0F21
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 008E0F3C
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 008E007F
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 008E0036
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 008E0FE5
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 008E0F79
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 008E0062
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 008E0051
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 008E0FA5
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 008E0FCA
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 008E0F8A
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 008E0F06
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 008E001B
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 008E0000
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 008E0F4D
.text C:\Windows\system32\svchost.exe[1256] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 008A0FA6
.text C:\Windows\system32\svchost.exe[1256] msvcrt.dll!system 760B804B 5 Bytes JMP 008A0FB7
.text C:\Windows\system32\svchost.exe[1256] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 008A001D
.text C:\Windows\system32\svchost.exe[1256] msvcrt.dll!_open 760BD106 5 Bytes JMP 008A0FE3
.text C:\Windows\system32\svchost.exe[1256] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 008A0FD2
.text C:\Windows\system32\svchost.exe[1256] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 008A0000
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegCreateKeyExA 776B39AB 5 Bytes JMP 008C005B
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegCreateKeyA 776B3BA9 5 Bytes JMP 008C004A
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegOpenKeyA 776B89C7 5 Bytes JMP 008C0000
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 008C0FC3
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 008C006C
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 008C0FDE
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 008C0FEF
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 008C002F
.text C:\Windows\system32\svchost.exe[1256] WS2_32.dll!socket 761236D1 5 Bytes JMP 008B0FEF
.text C:\Windows\system32\svchost.exe[1292] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 008A0FEF
.text C:\Windows\system32\svchost.exe[1292] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 008A0FC3
.text C:\Windows\system32\svchost.exe[1292] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 008A0FDE
.text C:\Windows\system32\svchost.exe[1292] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 008B00AC
.text C:\Windows\system32\svchost.exe[1292] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 008B0091
.text C:\Windows\system32\svchost.exe[1292] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 008B0F26
.text C:\Windows\system32\svchost.exe[1292] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 008B0F41
.text C:\Windows\system32\svchost.exe[1292] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 008B0F81
.text C:\Windows\system32\svchost.exe[1292] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 008B0FCA
.text C:\Windows\system32\svchost.exe[1292] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 008B0FB9
.text C:\Windows\system32\svchost.exe[1292] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 008B0080
.text C:\Windows\system32\svchost.exe[1292] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 008B005B
.text C:\Windows\system32\svchost.exe[1292] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 008B0040
.text C:\Windows\system32\svchost.exe[1292] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 008B0F9E
.text C:\Windows\system32\svchost.exe[1292] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 008B002F
.text C:\Windows\system32\svchost.exe[1292] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 008B0F66
.text C:\Windows\system32\svchost.exe[1292] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 008B00D8
.text C:\Windows\system32\svchost.exe[1292] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 008B0000
.text C:\Windows\system32\svchost.exe[1292] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 008B0FE5
.text C:\Windows\system32\svchost.exe[1292] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 008B00BD
.text C:\Windows\system32\svchost.exe[1292] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 00A50042
.text C:\Windows\system32\svchost.exe[1292] msvcrt.dll!system 760B804B 5 Bytes JMP 00A50FAD
.text C:\Windows\system32\svchost.exe[1292] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 00A50FD2
.text C:\Windows\system32\svchost.exe[1292] msvcrt.dll!_open 760BD106 5 Bytes JMP 00A50000
.text C:\Windows\system32\svchost.exe[1292] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 00A50027
.text C:\Windows\system32\svchost.exe[1292] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 00A50FE3
.text C:\Windows\system32\svchost.exe[1292] ADVAPI32.dll!RegCreateKeyExA 776B39AB 5 Bytes JMP 00880051
.text C:\Windows\system32\svchost.exe[1292] ADVAPI32.dll!RegCreateKeyA 776B3BA9 5 Bytes JMP 00880FB9
.text C:\Windows\system32\svchost.exe[1292] ADVAPI32.dll!RegOpenKeyA 776B89C7 5 Bytes JMP 00880000
.text C:\Windows\system32\svchost.exe[1292] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 00880040
.text C:\Windows\system32\svchost.exe[1292] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 0088006C
.text C:\Windows\system32\svchost.exe[1292] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 00880FE5
.text C:\Windows\system32\svchost.exe[1292] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 0088001B
.text C:\Windows\system32\svchost.exe[1292] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 00880FCA
.text C:\Windows\system32\svchost.exe[1292] WS2_32.dll!socket 761236D1 5 Bytes JMP 00A60000
.text C:\Windows\system32\svchost.exe[1292] WININET.dll!InternetOpenA 77864E3C 5 Bytes JMP 0089000A
.text C:\Windows\system32\svchost.exe[1292] WININET.dll!InternetOpenUrlA 7786BFDE 5 Bytes JMP 00890FE5
.text C:\Windows\system32\svchost.exe[1292] WININET.dll!InternetOpenW 7789C126 5 Bytes JMP 0089001B
.text C:\Windows\system32\svchost.exe[1292] WININET.dll!InternetOpenUrlW 778CD8D2 5 Bytes JMP 00890FD4
.text C:\Windows\system32\svchost.exe[1468] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 00AD0FEF
.text C:\Windows\system32\svchost.exe[1468] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 00AD000A
.text C:\Windows\system32\svchost.exe[1468] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 00AD0FD4
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 00AF00DA
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 00AF0F8A
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 00AF0F65
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 00AF0106
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 00AF00A4
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 00AF0FDB
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 00AF0036
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 00AF00BF
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 00AF0FC0
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 00AF0062
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 00AF007D
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 00AF0051
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 00AF0FAF
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 00AF0F54
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 00AF001B
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 00AF0000
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 00AF00EB
.text C:\Windows\system32\svchost.exe[1468] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 00B00F95
.text C:\Windows\system32\svchost.exe[1468] msvcrt.dll!system 760B804B 5 Bytes JMP 00B00FB0
.text C:\Windows\system32\svchost.exe[1468] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 00B00FC1
.text C:\Windows\system32\svchost.exe[1468] msvcrt.dll!_open 760BD106 5 Bytes JMP 00B00FEF
.text C:\Windows\system32\svchost.exe[1468] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 00B00016
.text C:\Windows\system32\svchost.exe[1468] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 00B00FDE
.text C:\Windows\system32\svchost.exe[1468] ADVAPI32.dll!RegCreateKeyExA 776B39AB 5 Bytes JMP 00AB0076
.text C:\Windows\system32\svchost.exe[1468] ADVAPI32.dll!RegCreateKeyA 776B3BA9 5 Bytes JMP 00AB0FD4
.text C:\Windows\system32\svchost.exe[1468] ADVAPI32.dll!RegOpenKeyA 776B89C7 5 Bytes JMP 00AB0000
.text C:\Windows\system32\svchost.exe[1468] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 00AB0065
.text C:\Windows\system32\svchost.exe[1468] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 00AB0FB9
.text C:\Windows\system32\svchost.exe[1468] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 00AB0036
.text C:\Windows\system32\svchost.exe[1468] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 00AB001B
.text C:\Windows\system32\svchost.exe[1468] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 00AB0FE5
.text C:\Windows\system32\svchost.exe[1468] WS2_32.dll!socket 761236D1 5 Bytes JMP 00AA000A
.text C:\Windows\system32\svchost.exe[1468] WININET.dll!InternetOpenA 77864E3C 5 Bytes JMP 00AC0FEF
.text C:\Windows\system32\svchost.exe[1468] WININET.dll!InternetOpenUrlA 7786BFDE 5 Bytes JMP 00AC0025
.text C:\Windows\system32\svchost.exe[1468] WININET.dll!InternetOpenW 7789C126 5 Bytes JMP 00AC0014
.text C:\Windows\system32\svchost.exe[1468] WININET.dll!InternetOpenUrlW 778CD8D2 5 Bytes JMP 00AC0036
.text C:\Windows\System32\svchost.exe[1788] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 00070000
.text C:\Windows\System32\svchost.exe[1788] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 00070FE5
.text C:\Windows\System32\svchost.exe[1788] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 0007001B
.text C:\Windows\System32\svchost.exe[1788] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 00080087
.text C:\Windows\System32\svchost.exe[1788] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 00080F37
.text C:\Windows\System32\svchost.exe[1788] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 000800BD
.text C:\Windows\System32\svchost.exe[1788] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 00080F26
.text C:\Windows\System32\svchost.exe[1788] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 0008002C
.text C:\Windows\System32\svchost.exe[1788] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 00080FC0
.text C:\Windows\System32\svchost.exe[1788] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 00080011
.text C:\Windows\System32\svchost.exe[1788] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 00080062
.text C:\Windows\System32\svchost.exe[1788] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 00080F52
.text C:\Windows\System32\svchost.exe[1788] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 00080F94
.text C:\Windows\System32\svchost.exe[1788] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 00080F6F
.text C:\Windows\System32\svchost.exe[1788] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 00080FA5
.text C:\Windows\System32\svchost.exe[1788] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 00080047
.text C:\Windows\System32\svchost.exe[1788] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 000800D8
.text C:\Windows\System32\svchost.exe[1788] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 00080FE5
.text C:\Windows\System32\svchost.exe[1788] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 00080000
.text C:\Windows\System32\svchost.exe[1788] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 00080098
.text C:\Windows\System32\svchost.exe[1788] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 00050FAB
.text C:\Windows\System32\svchost.exe[1788] msvcrt.dll!system 760B804B 5 Bytes JMP 00050FC6
.text C:\Windows\System32\svchost.exe[1788] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 00050011
.text C:\Windows\System32\svchost.exe[1788] msvcrt.dll!_open 760BD106 5 Bytes JMP 00050000
.text C:\Windows\System32\svchost.exe[1788] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 00050036
.text C:\Windows\System32\svchost.exe[1788] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 00050FD7
.text C:\Windows\System32\svchost.exe[1788] ADVAPI32.dll!RegCreateKeyExA 776B39AB 5 Bytes JMP 0006008E
.text C:\Windows\System32\svchost.exe[1788] ADVAPI32.dll!RegCreateKeyA 776B3BA9 5 Bytes JMP 00060062
.text C:\Windows\System32\svchost.exe[1788] ADVAPI32.dll!RegOpenKeyA 776B89C7 5 Bytes JMP 0006000A
.text C:\Windows\System32\svchost.exe[1788] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 00060073
.text C:\Windows\System32\svchost.exe[1788] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 000600A9
.text C:\Windows\System32\svchost.exe[1788] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 00060036
.text C:\Windows\System32\svchost.exe[1788] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 0006001B
.text C:\Windows\System32\svchost.exe[1788] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 00060047
.text C:\Windows\System32\svchost.exe[1788] WS2_32.dll!socket 761236D1 5 Bytes JMP 001F0FE5
.text C:\Windows\system32\svchost.exe[1924] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 00070000
.text C:\Windows\system32\svchost.exe[1924] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 00070FE5
.text C:\Windows\system32\svchost.exe[1924] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 0007001B
.text C:\Windows\system32\svchost.exe[1924] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 000800AE
.text C:\Windows\system32\svchost.exe[1924] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 00080F68
.text C:\Windows\system32\svchost.exe[1924] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 000800E1
.text C:\Windows\system32\svchost.exe[1924] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 000800D0
.text C:\Windows\system32\svchost.exe[1924] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 00080F8D
.text C:\Windows\system32\svchost.exe[1924] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 00080FDE
.text C:\Windows\system32\svchost.exe[1924] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 0008002F
.text C:\Windows\system32\svchost.exe[1924] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 0008009D
.text C:\Windows\system32\svchost.exe[1924] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 00080065
.text C:\Windows\system32\svchost.exe[1924] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 00080FB9
.text C:\Windows\system32\svchost.exe[1924] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 00080FA8
.text C:\Windows\system32\svchost.exe[1924] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 00080040
.text C:\Windows\system32\svchost.exe[1924] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 00080082
.text C:\Windows\system32\svchost.exe[1924] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 00080F39
.text C:\Windows\system32\svchost.exe[1924] kernel32.dll!CreateFileW 77ADB0EB 1 Byte [E9]
.text C:\Windows\system32\svchost.exe[1924] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 00080FEF
.text C:\Windows\system32\svchost.exe[1924] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 00080000
.text C:\Windows\system32\svchost.exe[1924] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 000800BF
.text C:\Windows\system32\svchost.exe[1924] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 00370044
.text C:\Windows\system32\svchost.exe[1924] msvcrt.dll!system 760B804B 5 Bytes JMP 00370FC3
.text C:\Windows\system32\svchost.exe[1924] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 00370FDE
.text C:\Windows\system32\svchost.exe[1924] msvcrt.dll!_open 760BD106 5 Bytes JMP 00370FEF
.text C:\Windows\system32\svchost.exe[1924] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 00370033
.text C:\Windows\system32\svchost.exe[1924] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 00370018
.text C:\Windows\system32\svchost.exe[1924] ADVAPI32.dll!RegCreateKeyExA 776B39AB 5 Bytes JMP 00060062
.text C:\Windows\system32\svchost.exe[1924] ADVAPI32.dll!RegCreateKeyA 776B3BA9 5 Bytes JMP 00060047
.text C:\Windows\system32\svchost.exe[1924] ADVAPI32.dll!RegOpenKeyA 776B89C7 5 Bytes JMP 00060FE5
.text C:\Windows\system32\svchost.exe[1924] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 00060FC0
.text C:\Windows\system32\svchost.exe[1924] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 00060FA5
.text C:\Windows\system32\svchost.exe[1924] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 0006001B
.text C:\Windows\system32\svchost.exe[1924] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 00060000
.text C:\Windows\system32\svchost.exe[1924] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 0006002C
.text C:\Windows\system32\svchost.exe[1924] WS2_32.dll!socket 761236D1 5 Bytes JMP 00050000
.text C:\Windows\System32\svchost.exe[1940] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 00960000
.text C:\Windows\System32\svchost.exe[1940] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 00960FDE
.text C:\Windows\System32\svchost.exe[1940] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 00960FEF
.text C:\Windows\System32\svchost.exe[1940] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 00970067
.text C:\Windows\System32\svchost.exe[1940] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 00970F21
.text C:\Windows\System32\svchost.exe[1940] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 00970EF5
.text C:\Windows\System32\svchost.exe[1940] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 00970F10
.text C:\Windows\System32\svchost.exe[1940] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 00970F3C
.text C:\Windows\System32\svchost.exe[1940] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 00970FCA
.text C:\Windows\System32\svchost.exe[1940] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 00970FAF
.text C:\Windows\System32\svchost.exe[1940] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 0097004C
.text C:\Windows\System32\svchost.exe[1940] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 00970F57
.text C:\Windows\System32\svchost.exe[1940] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 00970F79
.text C:\Windows\System32\svchost.exe[1940] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 00970F68
.text C:\Windows\System32\svchost.exe[1940] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 00970F94
.text C:\Windows\System32\svchost.exe[1940] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 00970031
.text C:\Windows\System32\svchost.exe[1940] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 009700A7
.text C:\Windows\System32\svchost.exe[1940] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 00970FE5
.text C:\Windows\System32\svchost.exe[1940] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 00970000
.text C:\Windows\System32\svchost.exe[1940] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 0097008C
.text C:\Windows\System32\svchost.exe[1940] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 008B0042
.text C:\Windows\System32\svchost.exe[1940] msvcrt.dll!system 760B804B 5 Bytes JMP 008B001D
.text C:\Windows\System32\svchost.exe[1940] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 008B000C
.text C:\Windows\System32\svchost.exe[1940] msvcrt.dll!_open 760BD106 5 Bytes JMP 008B0FEF
.text C:\Windows\System32\svchost.exe[1940] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 008B0FAD
.text C:\Windows\System32\svchost.exe[1940] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 008B0FD2
.text C:\Windows\System32\svchost.exe[1940] ADVAPI32.dll!RegCreateKeyExA 776B39AB 5 Bytes JMP 0095004A
.text C:\Windows\System32\svchost.exe[1940] ADVAPI32.dll!RegCreateKeyA 776B3BA9 5 Bytes JMP 0095002F
.text C:\Windows\System32\svchost.exe[1940] ADVAPI32.dll!RegOpenKeyA 776B89C7 5 Bytes JMP 00950FEF
.text C:\Windows\System32\svchost.exe[1940] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 00950FA8
.text C:\Windows\System32\svchost.exe[1940] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 00950065
.text C:\Windows\System32\svchost.exe[1940] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 0095000A
.text C:\Windows\System32\svchost.exe[1940] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 00950FD4
.text C:\Windows\System32\svchost.exe[1940] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 00950FB9
.text C:\Windows\System32\svchost.exe[1940] WS2_32.dll!socket 761236D1 5 Bytes JMP 008C0000
.text C:\Windows\system32\svchost.exe[2380] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 00D50FEF
.text C:\Windows\system32\svchost.exe[2380] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 00D50FCA
.text C:\Windows\system32\svchost.exe[2380] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 00D50000
.text C:\Windows\system32\svchost.exe[2380] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 01100F3A
.text C:\Windows\system32\svchost.exe[2380] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 01100F4B
.text C:\Windows\system32\svchost.exe[2380] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 01100EF3
.text C:\Windows\system32\svchost.exe[2380] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 01100F04
.text C:\Windows\system32\svchost.exe[2380] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 01100065
.text C:\Windows\system32\svchost.exe[2380] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 0110000A
.text C:\Windows\system32\svchost.exe[2380] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 0110002F
.text C:\Windows\system32\svchost.exe[2380] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 01100F66
.text C:\Windows\system32\svchost.exe[2380] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 01100F97
.text C:\Windows\system32\svchost.exe[2380] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 01100FA8
.text C:\Windows\system32\svchost.exe[2380] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 0110004A
.text C:\Windows\system32\svchost.exe[2380] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 01100FC3
.text C:\Windows\system32\svchost.exe[2380] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 01100076
.text C:\Windows\system32\svchost.exe[2380] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 0110009B
.text C:\Windows\system32\svchost.exe[2380] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 01100FDE
.text C:\Windows\system32\svchost.exe[2380] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 01100FEF
.text C:\Windows\system32\svchost.exe[2380] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 01100F1F
.text C:\Windows\system32\svchost.exe[2380] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 008F002F
.text C:\Windows\system32\svchost.exe[2380] msvcrt.dll!system 760B804B 5 Bytes JMP 008F001E
.text C:\Windows\system32\svchost.exe[2380] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 008F0FB5
.text C:\Windows\system32\svchost.exe[2380] msvcrt.dll!_open 760BD106 5 Bytes JMP 008F0FE3
.text C:\Windows\system32\svchost.exe[2380] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 008F0FA4
.text C:\Windows\system32\svchost.exe[2380] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 008F0FC6
.text C:\Windows\system32\svchost.exe[2380] ADVAPI32.dll!RegCreateKeyExA 776B39AB 5 Bytes JMP 00910FC3
.text C:\Windows\system32\svchost.exe[2380] ADVAPI32.dll!RegCreateKeyA 776B3BA9 5 Bytes JMP 0091004A
.text C:\Windows\system32\svchost.exe[2380] ADVAPI32.dll!RegOpenKeyA 776B89C7 5 Bytes JMP 00910FEF
.text C:\Windows\system32\svchost.exe[2380] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 00910065
.text C:\Windows\system32\svchost.exe[2380] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 00910FA8
.text C:\Windows\system32\svchost.exe[2380] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 00910FDE
.text C:\Windows\system32\svchost.exe[2380] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 0091000A
.text C:\Windows\system32\svchost.exe[2380] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 0091002F
.text C:\Windows\system32\svchost.exe[2380] WS2_32.dll!socket 761236D1 5 Bytes JMP 00900FEF
.text C:\Windows\system32\svchost.exe[2380] WININET.dll!InternetOpenA 77864E3C 5 Bytes JMP 00920000
.text C:\Windows\system32\svchost.exe[2380] WININET.dll!InternetOpenUrlA 7786BFDE 5 Bytes JMP 00920FE5
.text C:\Windows\system32\svchost.exe[2380] WININET.dll!InternetOpenW 7789C126 5 Bytes JMP 00920011
.text C:\Windows\system32\svchost.exe[2380] WININET.dll!InternetOpenUrlW 778CD8D2 5 Bytes JMP 0092002C
.text C:\Windows\system32\svchost.exe[2736] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 00040000
.text C:\Windows\system32\svchost.exe[2736] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 00040FD4
.text C:\Windows\system32\svchost.exe[2736] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 00040FE5
.text C:\Windows\system32\svchost.exe[2736] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 00010F55
.text C:\Windows\system32\svchost.exe[2736] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 00010F70
.text C:\Windows\system32\svchost.exe[2736] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 00010F3A
.text C:\Windows\system32\svchost.exe[2736] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 000100D1
.text C:\Windows\system32\svchost.exe[2736] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 00010080
.text C:\Windows\system32\svchost.exe[2736] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 00010014
.text C:\Windows\system32\svchost.exe[2736] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 0001002F
.text C:\Windows\system32\svchost.exe[2736] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 0001009B
.text C:\Windows\system32\svchost.exe[2736] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 00010FA8
.text C:\Windows\system32\svchost.exe[2736] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 0001004A
.text C:\Windows\system32\svchost.exe[2736] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 0001005B
.text C:\Windows\system32\svchost.exe[2736] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 00010FB9
.text C:\Windows\system32\svchost.exe[2736] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 00010F81
.text C:\Windows\system32\svchost.exe[2736] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 00010F15
.text C:\Windows\system32\svchost.exe[2736] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 00010FDE
.text C:\Windows\system32\svchost.exe[2736] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 00010FEF
.text C:\Windows\system32\svchost.exe[2736] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 000100B6
.text C:\Windows\system32\svchost.exe[2736] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 0006004C
.text C:\Windows\system32\svchost.exe[2736] msvcrt.dll!system 760B804B 5 Bytes JMP 00060FC1
.text C:\Windows\system32\svchost.exe[2736] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 00060027
.text C:\Windows\system32\svchost.exe[2736] msvcrt.dll!_open 760BD106 5 Bytes JMP 00060000
.text C:\Windows\system32\svchost.exe[2736] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 00060FD2
.text C:\Windows\system32\svchost.exe[2736] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 00060FE3
.text C:\Windows\system32\svchost.exe[2736] ADVAPI32.dll!RegCreateKeyExA 776B39AB 5 Bytes JMP 0007006C
.text C:\Windows\system32\svchost.exe[2736] ADVAPI32.dll!RegCreateKeyA 776B3BA9 5 Bytes JMP 0007004A
.text C:\Windows\system32\svchost.exe[2736] ADVAPI32.dll!RegOpenKeyA 776B89C7 5 Bytes JMP 0007000A
.text C:\Windows\system32\svchost.exe[2736] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 0007005B
.text C:\Windows\system32\svchost.exe[2736] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 00070087
.text C:\Windows\system32\svchost.exe[2736] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 00070025
.text C:\Windows\system32\svchost.exe[2736] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 00070FE5
.text C:\Windows\system32\svchost.exe[2736] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 00070FD4
.text C:\Windows\system32\svchost.exe[2736] WS2_32.dll!socket 761236D1 5 Bytes JMP 0008000A
.text C:\Windows\system32\svchost.exe[3092] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 00040000
.text C:\Windows\system32\svchost.exe[3092] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 00040025
.text C:\Windows\system32\svchost.exe[3092] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 00040FE5
.text C:\Windows\system32\svchost.exe[3092] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 00010F23
.text C:\Windows\system32\svchost.exe[3092] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 00010F48
.text C:\Windows\system32\svchost.exe[3092] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 0001009F
.text C:\Windows\system32\svchost.exe[3092] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 00010F12
.text C:\Windows\system32\svchost.exe[3092] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 00010F63
.text C:\Windows\system32\svchost.exe[3092] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 00010011
.text C:\Windows\system32\svchost.exe[3092] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 0001002C
.text C:\Windows\system32\svchost.exe[3092] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 00010073
.text C:\Windows\system32\svchost.exe[3092] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 0001003D
.text C:\Windows\system32\svchost.exe[3092] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 00010F9B
.text C:\Windows\system32\svchost.exe[3092] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 00010F8A
.text C:\Windows\system32\svchost.exe[3092] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 00010FB6
.text C:\Windows\system32\svchost.exe[3092] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 00010058
.text C:\Windows\system32\svchost.exe[3092] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 000100BA
.text C:\Windows\system32\svchost.exe[3092] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 00010000
.text C:\Windows\system32\svchost.exe[3092] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 00010FEF
.text C:\Windows\system32\svchost.exe[3092] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 00010084
.text C:\Windows\system32\svchost.exe[3092] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 00060067
.text C:\Windows\system32\svchost.exe[3092] msvcrt.dll!system 760B804B 5 Bytes JMP 00060042
.text C:\Windows\system32\svchost.exe[3092] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 0006000C
.text C:\Windows\system32\svchost.exe[3092] msvcrt.dll!_open 760BD106 5 Bytes JMP 00060FE3
.text C:\Windows\system32\svchost.exe[3092] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 00060027
.text C:\Windows\system32\svchost.exe[3092] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 00060FD2
.text C:\Windows\system32\svchost.exe[3092] ADVAPI32.dll!RegCreateKeyExA 776B39AB 1 Byte [E9]
.text C:\Windows\system32\svchost.exe[3092] ADVAPI32.dll!RegCreateKeyExA 776B39AB 5 Bytes JMP 00070FAF
.text C:\Windows\system32\svchost.exe[3092] ADVAPI32.dll!RegCreateKeyA 776B3BA9 5 Bytes JMP 00070047
.text C:\Windows\system32\svchost.exe[3092] ADVAPI32.dll!RegOpenKeyA 776B89C7 5 Bytes JMP 0007000A
.text C:\Windows\system32\svchost.exe[3092] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 00070FC0
.text C:\Windows\system32\svchost.exe[3092] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 00070F94
.text C:\Windows\system32\svchost.exe[3092] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 0007001B
.text C:\Windows\system32\svchost.exe[3092] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 00070FEF
.text C:\Windows\system32\svchost.exe[3092] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 0007002C
.text C:\Windows\system32\svchost.exe[3092] WS2_32.dll!socket 761236D1 5 Bytes JMP 00080FE5
.text C:\Windows\system32\svchost.exe[3092] WININET.dll!InternetOpenA 77864E3C 5 Bytes JMP 0088000A
.text C:\Windows\system32\svchost.exe[3092] WININET.dll!InternetOpenUrlA 7786BFDE 5 Bytes JMP 0088001B
.text C:\Windows\system32\svchost.exe[3092] WININET.dll!InternetOpenW 7789C126 5 Bytes JMP 00880FEF
.text C:\Windows\system32\svchost.exe[3092] WININET.dll!InternetOpenUrlW 778CD8D2 5 Bytes JMP 0088002C
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 00040FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 00040FC3
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 00040FDE
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 00010F3C
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 00010F4D
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 00010EFC
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 00010F17
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 00010F68
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 00010FCA
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 00010FB9
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 00010078
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 00010F79
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 00010036
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 00010F94
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 00010025
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 0001005D
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 000100AE
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 0001000A
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] kernel32.dll!CreateThread 77ADCB2E 5 Bytes JMP 6BEE7303 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 00010FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 00010093
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] ADVAPI32.dll!RegCreateKeyExA 776B39AB 5 Bytes JMP 00150F8D
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] ADVAPI32.dll!RegCreateKeyA 776B3BA9 5 Bytes JMP 0015002F
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] ADVAPI32.dll!RegOpenKeyA 776B89C7 5 Bytes JMP 00150FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 00150FA8
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 00150F7C
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 00150000
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 00150FCA
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 00150FB9
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!CreateDialogParamW 762072A2 5 Bytes JMP 6C076628 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!GetAsyncKeyState 7620863C 5 Bytes JMP 6BECDD8D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!SetWindowsHookExW 762087AD 5 Bytes JMP 6BF22194 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!CallNextHookEx 76208E3B 5 Bytes JMP 6BF47BB7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!UnhookWindowsHookEx 762098DB 5 Bytes JMP 6BF6EB74 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!EnableWindow 7620CD8B 5 Bytes JMP 6BF29A14 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!DefWindowProcA 7620DB88 7 Bytes JMP 6BEE952D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!CreateWindowExA 7620DC2A 5 Bytes JMP 6BEF3363 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!CreateWindowExW 76211305 5 Bytes JMP 6BF4FF8F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!GetKeyState 76218CB1 5 Bytes JMP 6BECDC67 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!DefWindowProcW 762203B4 7 Bytes JMP 6BF47C1A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!IsDialogMessageW 76220745 5 Bytes JMP 6C076D82 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!CreateDialogParamA 762217AA 5 Bytes JMP 6C0765F0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!IsDialogMessage 76221847 2 Bytes JMP 6C076D5A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!IsDialogMessage + 3 7622184A 2 Bytes [E5, F5] {IN EAX, 0xf5}
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!CreateDialogIndirectParamA 762226F1 5 Bytes JMP 6C076660 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!CreateDialogIndirectParamW 76229A62 5 Bytes JMP 6C076698 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!SetKeyboardState 76230987 5 Bytes JMP 6C077649 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!DialogBoxParamW 762310B0 5 Bytes JMP 6BE8170B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!DialogBoxIndirectParamW 76232EF5 5 Bytes JMP 6C0762BE C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!SendInput 76232F75 5 Bytes JMP 6C0775F1 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!EndDialog 7623326E 5 Bytes JMP 6C07702E C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!SetCursorPos 76246FB2 5 Bytes JMP 6C0776CA C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!DialogBoxParamA 76248152 5 Bytes JMP 6C076259 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!DialogBoxIndirectParamA 7624847D 5 Bytes JMP 6C076323 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!MessageBoxIndirectA 7625D4D9 5 Bytes JMP 6C0761E0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!MessageBoxIndirectW 7625D5D3 5 Bytes JMP 6C076167 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!MessageBoxExA 7625D639 5 Bytes JMP 6C076103 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!MessageBoxExW 7625D65D 5 Bytes JMP 6C07609F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] USER32.dll!keybd_event 7625D972 5 Bytes JMP 6C0775AE C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 00160031
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] msvcrt.dll!system 760B804B 5 Bytes JMP 00160FA6
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 00160FC1
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] msvcrt.dll!_open 760BD106 5 Bytes JMP 00160FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 00160016
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 00160FD2
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] SHELL32.dll!SHRestricted + D95 76AD89A8 4 Bytes [CF, 01, DE, 6B]
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] SHELL32.dll!SHRestricted + D9D 76AD89B0 8 Bytes [E0, 61, DD, 6B, 79, F7, DD, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] ole32.dll!OleLoadFromStream 76541E80 5 Bytes JMP 6C076A8C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] WININET.dll!InternetCloseHandle 7784B7C4 5 Bytes JMP 6B1843D0 c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] WININET.dll!InternetReadFile 7784EA3A 5 Bytes JMP 6B1844F0 c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] WININET.dll!InternetOpenA 77864E3C 5 Bytes JMP 00170000
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] WININET.dll!InternetOpenUrlA 7786BFDE 5 Bytes JMP 00170011
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] WININET.dll!InternetConnectA 77875556 5 Bytes JMP 6B184790 c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] WININET.dll!HttpOpenRequestA 77875639 5 Bytes JMP 6B184690 c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] WININET.dll!InternetOpenW 7789C126 5 Bytes JMP 00170FE5
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] WININET.dll!InternetOpenUrlW 778CD8D2 5 Bytes JMP 0017002C
.text C:\Program Files\Internet Explorer\iexplore.exe[5756] WS2_32.dll!socket 761236D1 5 Bytes JMP 00A00000
.text C:\Windows\Explorer.EXE[6564] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 0004000A
.text C:\Windows\Explorer.EXE[6564] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 0004002C
.text C:\Windows\Explorer.EXE[6564] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 0004001B
.text C:\Windows\Explorer.EXE[6564] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 00010F44
.text C:\Windows\Explorer.EXE[6564] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 00010F55
.text C:\Windows\Explorer.EXE[6564] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 00010F18
.text C:\Windows\Explorer.EXE[6564] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 000100AF
.text C:\Windows\Explorer.EXE[6564] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 00010F8B
.text C:\Windows\Explorer.EXE[6564] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 00010025
.text C:\Windows\Explorer.EXE[6564] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 00010FD4
.text C:\Windows\Explorer.EXE[6564] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 0001008A
.text C:\Windows\Explorer.EXE[6564] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 00010065
.text C:\Windows\Explorer.EXE[6564] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 00010FB9
.text C:\Windows\Explorer.EXE[6564] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 00010FA8
.text C:\Windows\Explorer.EXE[6564] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 00010040
.text C:\Windows\Explorer.EXE[6564] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 00010F70
.text C:\Windows\Explorer.EXE[6564] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 00010EFD
.text C:\Windows\Explorer.EXE[6564] kernel32.dll!CreateFileW 77ADB0EB 1 Byte [E9]
.text C:\Windows\Explorer.EXE[6564] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 00010FEF
.text C:\Windows\Explorer.EXE[6564] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 0001000A
.text C:\Windows\Explorer.EXE[6564] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 00010F33
.text C:\Windows\Explorer.EXE[6564] ADVAPI32.dll!RegCreateKeyExA 776B39AB 5 Bytes JMP 00060073
.text C:\Windows\Explorer.EXE[6564] ADVAPI32.dll!RegCreateKeyA 776B3BA9 5 Bytes JMP 00060051
.text C:\Windows\Explorer.EXE[6564] ADVAPI32.dll!RegOpenKeyA 776B89C7 5 Bytes JMP 00060000
.text C:\Windows\Explorer.EXE[6564] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 00060062
.text C:\Windows\Explorer.EXE[6564] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 0006008E
.text C:\Windows\Explorer.EXE[6564] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 00060025
.text C:\Windows\Explorer.EXE[6564] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 00060FEF
.text C:\Windows\Explorer.EXE[6564] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 00060040
.text C:\Windows\Explorer.EXE[6564] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 0007002C
.text C:\Windows\Explorer.EXE[6564] msvcrt.dll!system 760B804B 5 Bytes JMP 0007001B
.text C:\Windows\Explorer.EXE[6564] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 00070000
.text C:\Windows\Explorer.EXE[6564] msvcrt.dll!_open 760BD106 5 Bytes JMP 00070FEF
.text C:\Windows\Explorer.EXE[6564] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 00070FAB
.text C:\Windows\Explorer.EXE[6564] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 00070FC6
.text C:\Windows\Explorer.EXE[6564] WININET.dll!InternetCloseHandle 7784B7C4 5 Bytes JMP 6B1843D0 c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Windows\Explorer.EXE[6564] WININET.dll!InternetReadFile 7784EA3A 5 Bytes JMP 6B1844F0 c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Windows\Explorer.EXE[6564] WININET.dll!InternetOpenA 77864E3C 5 Bytes JMP 03AB0FE5
.text C:\Windows\Explorer.EXE[6564] WININET.dll!InternetOpenUrlA 7786BFDE 5 Bytes JMP 03AB0FCA
.text C:\Windows\Explorer.EXE[6564] WININET.dll!InternetConnectA 77875556 5 Bytes JMP 6B184790 c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Windows\Explorer.EXE[6564] WININET.dll!HttpOpenRequestA 77875639 5 Bytes JMP 6B184690 c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (SiteAdvisor/McAfee, Inc.)
.text C:\Windows\Explorer.EXE[6564] WININET.dll!InternetOpenW 7789C126 5 Bytes JMP 03AB0000
.text C:\Windows\Explorer.EXE[6564] WININET.dll!InternetOpenUrlW 778CD8D2 5 Bytes JMP 03AB0FB9
.text C:\Windows\Explorer.EXE[6564] WS2_32.dll!socket 761236D1 5 Bytes JMP 03C10FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] ntdll.dll!NtCreateFile 779C4224 5 Bytes JMP 00040FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] ntdll.dll!NtCreateProcess 779C42E4 5 Bytes JMP 00040FC3
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] ntdll.dll!NtProtectVirtualMemory 779C4B84 5 Bytes JMP 00040FDE
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] kernel32.dll!GetStartupInfoW 77A91929 5 Bytes JMP 000100DA
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] kernel32.dll!GetStartupInfoA 77A919C9 5 Bytes JMP 000100BF
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] kernel32.dll!CreateProcessW 77A91BF3 5 Bytes JMP 00010117
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] kernel32.dll!CreateProcessA 77A91C28 5 Bytes JMP 00010106
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] kernel32.dll!VirtualProtect 77A91DC3 5 Bytes JMP 00010082
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] kernel32.dll!CreateNamedPipeA 77A92EF5 5 Bytes JMP 00010FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] kernel32.dll!CreateNamedPipeW 77A95C0C 5 Bytes JMP 00010036
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] kernel32.dll!CreatePipe 77AB8F06 5 Bytes JMP 000100A4
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] kernel32.dll!LoadLibraryExW 77AB927C 5 Bytes JMP 00010067
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] kernel32.dll!LoadLibraryW 77AB9400 5 Bytes JMP 00010FB9
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] kernel32.dll!LoadLibraryExA 77AB9554 5 Bytes JMP 00010F9E
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] kernel32.dll!LoadLibraryA 77AB957C 5 Bytes JMP 00010FCA
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] kernel32.dll!VirtualProtectEx 77ABDC52 5 Bytes JMP 00010093
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] kernel32.dll!GetProcAddress 77AD925B 5 Bytes JMP 0001013C
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] kernel32.dll!CreateFileW 77ADB0EB 5 Bytes JMP 00010025
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] kernel32.dll!CreateFileA 77ADD07F 5 Bytes JMP 0001000A
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] kernel32.dll!WinExec 77B260CF 5 Bytes JMP 000100EB
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] ADVAPI32.dll!RegCreateKeyExA 776B39AB 5 Bytes JMP 00050F79
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] ADVAPI32.dll!RegCreateKeyA 776B3BA9 5 Bytes JMP 00050F9E
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] ADVAPI32.dll!RegOpenKeyA 776B89C7 5 Bytes JMP 00050FE5
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] ADVAPI32.dll!RegCreateKeyW 776C391E 5 Bytes JMP 0005001B
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] ADVAPI32.dll!RegCreateKeyExW 776C41F1 5 Bytes JMP 00050F5E
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] ADVAPI32.dll!RegOpenKeyExA 776C7C42 5 Bytes JMP 0005000A
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] ADVAPI32.dll!RegOpenKeyW 776CE2B5 5 Bytes JMP 00050FD4
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] ADVAPI32.dll!RegOpenKeyExW 776D7BA1 5 Bytes JMP 00050FAF
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] USER32.dll!EnableWindow 7620CD8B 5 Bytes JMP 6BF29A14 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] USER32.dll!DialogBoxParamW 762310B0 5 Bytes JMP 6BE8170B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] USER32.dll!DialogBoxIndirectParamW 76232EF5 5 Bytes JMP 6C0762BE C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] USER32.dll!DialogBoxParamA 76248152 5 Bytes JMP 6C076259 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] USER32.dll!DialogBoxIndirectParamA 7624847D 5 Bytes JMP 6C076323 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] USER32.dll!MessageBoxIndirectA 7625D4D9 5 Bytes JMP 6C0761E0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] USER32.dll!MessageBoxIndirectW 7625D5D3 5 Bytes JMP 6C076167 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] USER32.dll!MessageBoxExA 7625D639 5 Bytes JMP 6C076103 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] USER32.dll!MessageBoxExW 7625D65D 5 Bytes JMP 6C07609F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] msvcrt.dll!_wsystem 760B7F2F 5 Bytes JMP 00060053
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] msvcrt.dll!system 760B804B 5 Bytes JMP 00060038
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] msvcrt.dll!_creat 760BBBE1 5 Bytes JMP 00060FC8
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] msvcrt.dll!_open 760BD106 5 Bytes JMP 00060FE3
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] msvcrt.dll!_wcreat 760BD326 5 Bytes JMP 0006001D
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] msvcrt.dll!_wopen 760BD501 5 Bytes JMP 0006000C
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] WININET.dll!InternetOpenA 77864E3C 5 Bytes JMP 00070FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] WININET.dll!InternetOpenUrlA 7786BFDE 5 Bytes JMP 00070FC3
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] WININET.dll!InternetOpenW 7789C126 5 Bytes JMP 00070FDE
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] WININET.dll!InternetOpenUrlW 778CD8D2 5 Bytes JMP 00070014
.text C:\Program Files\Internet Explorer\iexplore.exe[7432] WS2_32.dll!socket 761236D1 5 Bytes JMP 009F0FEF
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\Tcp mfewfpk.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\Udp mfewfpk.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
---- Files - GMER 1.0.15 ----
File C:\Windows\$NtUninstallKB23016$\3688710486 0 bytes
File C:\Windows\$NtUninstallKB23016$\3931943860 0 bytes
File C:\Windows\$NtUninstallKB23016$\3931943860\@ 2048 bytes
File C:\Windows\$NtUninstallKB23016$\3931943860\bckfg.tmp 849 bytes
File C:\Windows\$NtUninstallKB23016$\3931943860\cfg.ini 216 bytes
File C:\Windows\$NtUninstallKB23016$\3931943860\Desktop.ini 4608 bytes
File C:\Windows\$NtUninstallKB23016$\3931943860\keywords 116 bytes
File C:\Windows\$NtUninstallKB23016$\3931943860\kwrd.dll 223744 bytes
File C:\Windows\$NtUninstallKB23016$\3931943860\L 0 bytes
File C:\Windows\$NtUninstallKB23016$\3931943860\L\qnbwvoto 273408 bytes
File C:\Windows\$NtUninstallKB23016$\3931943860\U 0 bytes
File C:\Windows\$NtUninstallKB23016$\3931943860\U\00000001.@ 2048 bytes
File C:\Windows\$NtUninstallKB23016$\3931943860\U\00000002.@ 224768 bytes
File C:\Windows\$NtUninstallKB23016$\3931943860\U\00000004.@ 1024 bytes
File C:\Windows\$NtUninstallKB23016$\3931943860\U\80000000.@ 11264 bytes
File C:\Windows\$NtUninstallKB23016$\3931943860\U\80000004.@ 12800 bytes
File C:\Windows\$NtUninstallKB23016$\3931943860\U\80000032.@ 77312 bytes
---- EOF - GMER 1.0.15 ----