I have been directed here by boopme, from this topic >>
My link
I have had multiple malware intrusions such as Security Sphere, and Win 7 Total Security, I also had google redirects.
The most recent one was Security Sphere which I removed using the guide posted here at bleeping computer.
However, the repeated intrusions seemed to come out of nowhere...
So I was wondering if I could be assisted with completely removing any virus, spyware, malware or rootkit that could exist in my computer.
Thank you in advance.
Anyways here is the DDS log and GMER log:
-----------------------------------------------------------DDS---------------------------------------------------------------------------------------------------
DDS (Ver_2011-05-26.01) - NTFS_x86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
Run by Mihil at 0:07:02 on 2012-01-06
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.2.1033.18.3037.1894 [GMT -5:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\nvvsvc.exe
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\nvvsvc.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
C:\windows\System32\svchost.exe -k Akamai
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe
C:\windows\system32\mfevtps.exe
C:\windows\system32\rundll32.exe
C:\Program Files\Secunia\PSI\PSIA.exe
C:\Program Files\Bell\Internet Service Advisor\ServicepointService.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\system32\ThpSrv.exe
C:\windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ltmoh\ltmoh.exe
C:\Windows\System32\ThpSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe
C:\Program Files\TOSHIBA\TECO\TEco.exe
C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\system32\taskeng.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\windows\system32\DllHost.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\LSI SoftModem\agrsmsvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\windows\system32\UI0Detect.exe
C:\Program Files\TOSHIBA\RSelect\RSelSvc.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
c:\PROGRA~1\mcafee\msc\mcupdmgr.exe
C:\Users\Mihil\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mihil\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mihil\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mihil\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mihil\AppData\Local\Google\Chrome\Application\chrome.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.ca/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSCA&bmod=TSCA
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20110108210300.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [AdobeBridge]
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [LtMoh] c:\program files\ltmoh\Ltmoh.exe
mRun: [ThpSrv] c:\windows\system32\thpsrv /logon
mRun: [TUSBSleepChargeSrv] %ProgramFiles%\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe
mRun: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
mRun: [TWebCamera] "%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [TrueImageMonitor.exe] c:\program files\acronis\trueimagehome\TrueImageMonitor.exe
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {2AB1C516-6654-4D3A-B3D6-2185BBCEB409} - hxxps://mytdsb.on.ca/+CSCOL+/csvrloader32.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.7.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/plugins/activex/YoYo.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
TCP: DhcpNameServer = 192.168.2.1
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
mASetup: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\mihil\appdata\roaming\mozilla\firefox\profiles\82sdjskc.default\
FF - prefs.js: browser.search.selectedEngine - Secure Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/ig?hl=en&gl=ca#restore
FF - prefs.js: keyword.URL - hxxp://ca.search.yahoo.com/search?fr=mcafee&p=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\bell\internet service advisor\nprpspa.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mcafee\siteadvisor\NPMcFFPlg32.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\users\mihil\appdata\local\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\users\mihil\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\users\mihil\appdata\roaming\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\users\mihil\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2011-1-8 386840]
R0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258);c:\windows\system32\drivers\tdrpm258.sys [2010-12-22 911680]
R0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\drivers\thpdrv.sys [2009-6-29 30272]
R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\drivers\Thpevm.sys [2009-6-29 13120]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2011-2-21 218688]
R1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\drivers\mfenlfk.sys [2011-1-8 64304]
R1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2011-1-8 164840]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 afcdpsrv;Acronis Nonstop Backup service;c:\program files\common files\acronis\cdp\afcdpsrv.exe [2010-12-22 2480048]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2009-7-13 20992]
R2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\toshiba\configfree\CFIWmxSvcs.exe [2009-7-17 181616]
R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2009-3-10 46448]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\sitead~1\mcsacore.exe [2011-9-17 94880]
R2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-1-8 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-1-8 271480]
R2 McProxy;McAfee Proxy Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-1-8 271480]
R2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2011-1-8 171168]
R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2011-1-8 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2011-1-8 141792]
R2 RSELSVC;TOSHIBA Modem region select service;c:\program files\toshiba\rselect\RSelSvc.exe [2009-7-7 62832]
R2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\secunia\psi\psia.exe [2011-10-14 994360]
R2 ServicepointService;ServicepointService;c:\program files\bell\internet service advisor\ServicepointService.exe [2011-3-20 689464]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\toshiba\teco\TecoService.exe [2009-8-10 181616]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\drivers\TVALZFL.sys [2009-6-19 12920]
R2 WDDMService;WD SmartWare Drive Manager;c:\program files\western digital\wd smartware\wd drive manager\WDDMService.exe [2009-11-5 110592]
R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\western digital\wd smartware\front parlor\WDSmartWareBackgroundService.exe [2009-6-16 20480]
R3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [2010-12-22 160704]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2011-1-8 55840]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2011-1-8 152960]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2011-1-8 52104]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2011-1-8 313288]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2009-8-21 66592]
R3 PGEffect;Pangu effect driver;c:\windows\system32\drivers\PGEffect.sys [2009-12-8 24064]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-12-8 167936]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\drivers\rtl8192se.sys [2009-12-8 859136]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-13 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-3 135664]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2010-8-22 84832]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-12-30 14216]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-12-30 8456]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-2-3 135664]
S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\drivers\ivusb.sys [2009-7-24 25112]
S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2009-8-1 116136]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-1-8 84264]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-9-1 15544]
S3 SwitchBoard;Adobe SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 TMachInfo;TMachInfo;c:\program files\toshiba\toshiba service station\TMachInfo.exe [2009-12-8 51512]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\toshiba\toshiba hdd ssd alert\TosSmartSrv.exe [2009-8-3 111960]
S3 TPCHSrv;TPCH Service;c:\program files\toshiba\tphm\TPCHSrv.exe [2009-8-6 685424]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-2-27 1343400]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2009-2-13 11520]
S4 McOobeSv;McAfee OOBE Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2011-1-8 271480]
.
=============== Created Last 30 ================
.
2012-01-05 22:11:36 -------- d-----w- c:\program files\common files\Macrovision Shared
2012-01-03 23:31:16 -------- d-----w- c:\windows\pss
2012-01-02 19:47:59 -------- d--h--w- c:\windows\AxInstSV
2011-12-31 21:14:12 239616 ------r- c:\windows\system32\Hdk3ctnt.dll
2011-12-31 21:10:21 306688 ----a-w- c:\windows\IsUninst.exe
2011-12-31 02:40:14 -------- d-----w- c:\users\mihil\appdata\local\Secunia PSI
2011-12-31 02:40:02 -------- d-----w- c:\program files\Secunia
2011-12-26 03:24:38 -------- d-----w- c:\programdata\dD01300DfJbJ01300
2011-12-25 01:14:24 -------- d-----w- c:\users\mihil\appdata\local\FlashDevelop.old
2011-12-25 01:14:24 -------- d-----w- c:\users\mihil\appdata\local\FlashDevelop
2011-12-24 23:16:09 -------- d-----w- c:\program files\FlashDevelop
2011-12-14 16:20:54 2340352 ----a-w- c:\windows\system32\win32k.sys
2011-12-14 16:20:38 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-14 16:20:17 534528 ----a-w- c:\windows\system32\EncDec.dll
2011-12-14 16:20:16 38912 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-14 16:20:13 3901808 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-12-14 16:20:12 3957104 ----a-w- c:\windows\system32\ntkrnlpa.exe
.
==================== Find3M ====================
.
2011-12-10 20:24:06 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-03 22:47:42 1798144 ----a-w- c:\windows\system32\jscript9.dll
2011-11-03 22:40:21 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-11-03 22:39:47 1127424 ----a-w- c:\windows\system32\wininet.dll
2011-11-03 22:31:57 2382848 ----a-w- c:\windows\system32\mshtml.tlb
.
============= FINISH: 0:08:47.52 ===============
---------------------------------------------------------------------------GMER----------------------------------------------------------------------------------
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-01-02 23:44:01
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 TOSHIBA_ rev.FG02
Running: 0tm47gfi.exe; Driver: C:\Users\Mihil\AppData\Local\Temp\kwliypoc.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0x8479F0B8]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0x8479F0E2]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0x8479F0CE]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0x8479F0A4]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwYieldExecution 83847128 5 Bytes JMP 8479F0A8 \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 8385F5D9 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 83884092 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
PAGE ntkrnlpa.exe!ZwTerminateProcess 83A7E0AD 5 Bytes JMP 8479F0E6 \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 83A9824B 5 Bytes JMP 8479F0D2 \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 83A9B446 7 Bytes JMP 8479F0BC \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
.text C:\windows\system32\DRIVERS\tos_sps32.sys section is writeable [0x8455E000, 0x3C849, 0xE8000020]
.dsrt C:\windows\system32\DRIVERS\tos_sps32.sys unknown last section [0x845A3000, 0x3DC, 0x48000040]
---- User code sections - GMER 1.0.15 ----
.text C:\windows\System32\svchost.exe[496] ntdll.dll!NtCreateFile 77494870 5 Bytes JMP 003D0000
.text C:\windows\System32\svchost.exe[496] ntdll.dll!NtCreateProcess 77494940 5 Bytes JMP 003D0FCA
.text C:\windows\System32\svchost.exe[496] ntdll.dll!NtProtectVirtualMemory 774951C0 5 Bytes JMP 003D0FE5
.text C:\windows\System32\svchost.exe[496] kernel32.dll!GetStartupInfoA 76B81DF0 5 Bytes JMP 001E0F5A
.text C:\windows\System32\svchost.exe[496] kernel32.dll!CreateProcessW 76B8202D 5 Bytes JMP 001E00AF
.text C:\windows\System32\svchost.exe[496] kernel32.dll!CreateProcessA 76B82062 5 Bytes JMP 001E0094
.text C:\windows\System32\svchost.exe[496] kernel32.dll!CreateNamedPipeW 76BB1FEE 5 Bytes JMP 001E0FBC
.text C:\windows\System32\svchost.exe[496] kernel32.dll!CreatePipe 76BB4AAB 5 Bytes JMP 001E0F6B
.text C:\windows\System32\svchost.exe[496] kernel32.dll!VirtualProtect 76BC50CB 5 Bytes JMP 001E005E
.text C:\windows\System32\svchost.exe[496] kernel32.dll!LoadLibraryExW 76BCB647 5 Bytes JMP 001E0F86
.text C:\windows\System32\svchost.exe[496] kernel32.dll!LoadLibraryExA 76BCBC13 5 Bytes JMP 001E0F97
.text C:\windows\System32\svchost.exe[496] kernel32.dll!CreateFileW 76BD0AFD 5 Bytes JMP 001E0FDE
.text C:\windows\System32\svchost.exe[496] kernel32.dll!GetProcAddress 76BD17D7 5 Bytes JMP 001E00CA
.text C:\windows\System32\svchost.exe[496] kernel32.dll!LoadLibraryA 76BD2804 5 Bytes JMP 001E0028
.text C:\windows\System32\svchost.exe[496] kernel32.dll!LoadLibraryW 76BD2852 5 Bytes JMP 001E0039
.text C:\windows\System32\svchost.exe[496] kernel32.dll!CreateFileA 76BD289C 5 Bytes JMP 001E0FEF
.text C:\windows\System32\svchost.exe[496] kernel32.dll!GetStartupInfoW 76BD7C55 5 Bytes JMP 001E0F35
.text C:\windows\System32\svchost.exe[496] kernel32.dll!CreateNamedPipeA 76C0D577 5 Bytes JMP 001E0FCD
.text C:\windows\System32\svchost.exe[496] kernel32.dll!WinExec 76C0E739 5 Bytes JMP 001E0F24
.text C:\windows\System32\svchost.exe[496] kernel32.dll!VirtualProtectEx 76C0F6F1 5 Bytes JMP 001E0083
.text C:\windows\System32\svchost.exe[496] msvcrt.dll!_open 775F7E48 5 Bytes JMP 00430000
.text C:\windows\System32\svchost.exe[496] msvcrt.dll!_wsystem 7762B04F 5 Bytes JMP 0043004C
.text C:\windows\System32\svchost.exe[496] msvcrt.dll!system 7762B16F 5 Bytes JMP 00430FC1
.text C:\windows\System32\svchost.exe[496] msvcrt.dll!_creat 7762ED29 5 Bytes JMP 00430FE3
.text C:\windows\System32\svchost.exe[496] msvcrt.dll!_wcreat 7763038E 5 Bytes JMP 00430FD2
.text C:\windows\System32\svchost.exe[496] msvcrt.dll!_wopen 77630570 5 Bytes JMP 0043001D
.text C:\windows\System32\svchost.exe[496] WS2_32.dll!socket 77013F00 5 Bytes JMP 003E0FEF
.text C:\windows\System32\svchost.exe[496] ADVAPI32.dll!RegOpenKeyA 7725D2ED 5 Bytes JMP 001F0FEF
.text C:\windows\System32\svchost.exe[496] ADVAPI32.dll!RegCreateKeyA 7725D3C1 5 Bytes JMP 001F0040
.text C:\windows\System32\svchost.exe[496] ADVAPI32.dll!RegCreateKeyExA 77261B71 5 Bytes JMP 001F0FB9
.text C:\windows\System32\svchost.exe[496] ADVAPI32.dll!RegCreateKeyW 77261CC0 5 Bytes JMP 001F0051
.text C:\windows\System32\svchost.exe[496] ADVAPI32.dll!RegOpenKeyW 77263129 5 Bytes JMP 001F000A
.text C:\windows\System32\svchost.exe[496] ADVAPI32.dll!RegCreateKeyExW 7726B946 5 Bytes JMP 001F0FA8
.text C:\windows\System32\svchost.exe[496] ADVAPI32.dll!RegOpenKeyExA 7726BC0D 5 Bytes JMP 001F002F
.text C:\windows\System32\svchost.exe[496] ADVAPI32.dll!RegOpenKeyExW 7726BEC4 5 Bytes JMP 001F0FD4
.text C:\windows\System32\svchost.exe[496] WININET.dll!InternetOpenA 759A4E3C 5 Bytes JMP 00190FE5
.text C:\windows\System32\svchost.exe[496] WININET.dll!InternetOpenUrlA 759ABFDE 5 Bytes JMP 0019001B
.text C:\windows\System32\svchost.exe[496] WININET.dll!InternetOpenW 759DC126 5 Bytes JMP 0019000A
.text C:\windows\System32\svchost.exe[496] WININET.dll!InternetOpenUrlW 75A0D8D2 5 Bytes JMP 00190FCA
.text C:\windows\system32\services.exe[928] ntdll.dll!NtCreateFile 77494870 5 Bytes JMP 0031000A
.text C:\windows\system32\services.exe[928] ntdll.dll!NtCreateProcess 77494940 5 Bytes JMP 00310FD4
.text C:\windows\system32\services.exe[928] ntdll.dll!NtProtectVirtualMemory 774951C0 5 Bytes JMP 00310FE5
.text C:\windows\system32\services.exe[928] kernel32.dll!GetStartupInfoA 76B81DF0 5 Bytes JMP 00100F79
.text C:\windows\system32\services.exe[928] kernel32.dll!CreateProcessW 76B8202D 5 Bytes JMP 00100F5E
.text C:\windows\system32\services.exe[928] kernel32.dll!CreateProcessA 76B82062 5 Bytes JMP 001000E9
.text C:\windows\system32\services.exe[928] kernel32.dll!CreateNamedPipeW 76BB1FEE 5 Bytes JMP 00100FC0
.text C:\windows\system32\services.exe[928] kernel32.dll!CreatePipe 76BB4AAB 5 Bytes JMP 001000A2
.text C:\windows\system32\services.exe[928] kernel32.dll!VirtualProtect 76BC50CB 5 Bytes JMP 00100062
.text C:\windows\system32\services.exe[928] kernel32.dll!LoadLibraryExW 76BCB647 5 Bytes JMP 00100051
.text C:\windows\system32\services.exe[928] kernel32.dll!LoadLibraryExA 76BCBC13 5 Bytes JMP 00100036
.text C:\windows\system32\services.exe[928] kernel32.dll!CreateFileW 76BD0AFD 5 Bytes JMP 00100000
.text C:\windows\system32\services.exe[928] kernel32.dll!GetProcAddress 76BD17D7 5 Bytes JMP 00100F43
.text C:\windows\system32\services.exe[928] kernel32.dll!LoadLibraryA 76BD2804 5 Bytes JMP 00100FAF
.text C:\windows\system32\services.exe[928] kernel32.dll!LoadLibraryW 76BD2852 5 Bytes JMP 00100F94
.text C:\windows\system32\services.exe[928] kernel32.dll!CreateFileA 76BD289C 5 Bytes JMP 00100FE5
.text C:\windows\system32\services.exe[928] kernel32.dll!GetStartupInfoW 76BD7C55 5 Bytes JMP 001000C7
.text C:\windows\system32\services.exe[928] kernel32.dll!CreateNamedPipeA 76C0D577 5 Bytes JMP 00100011
.text C:\windows\system32\services.exe[928] kernel32.dll!WinExec 76C0E739 5 Bytes JMP 001000D8
.text C:\windows\system32\services.exe[928] kernel32.dll!VirtualProtectEx 76C0F6F1 5 Bytes JMP 00100087
.text C:\windows\system32\services.exe[928] msvcrt.dll!_open 775F7E48 5 Bytes JMP 00380FEF
.text C:\windows\system32\services.exe[928] msvcrt.dll!_wsystem 7762B04F 5 Bytes JMP 00380FC3
.text C:\windows\system32\services.exe[928] msvcrt.dll!system 7762B16F 5 Bytes JMP 0038004E
.text C:\windows\system32\services.exe[928] msvcrt.dll!_creat 7762ED29 5 Bytes JMP 00380018
.text C:\windows\system32\services.exe[928] msvcrt.dll!_wcreat 7763038E 5 Bytes JMP 00380033
.text C:\windows\system32\services.exe[928] msvcrt.dll!_wopen 77630570 5 Bytes JMP 00380FDE
.text C:\windows\system32\services.exe[928] ADVAPI32.dll!RegOpenKeyA 7725D2ED 5 Bytes JMP 0033000A
.text C:\windows\system32\services.exe[928] ADVAPI32.dll!RegCreateKeyA 7725D3C1 5 Bytes JMP 00330040
.text C:\windows\system32\services.exe[928] ADVAPI32.dll!RegCreateKeyExA 77261B71 5 Bytes JMP 00330062
.text C:\windows\system32\services.exe[928] ADVAPI32.dll!RegCreateKeyW 77261CC0 5 Bytes JMP 00330051
.text C:\windows\system32\services.exe[928] ADVAPI32.dll!RegOpenKeyW 77263129 5 Bytes JMP 00330025
.text C:\windows\system32\services.exe[928] ADVAPI32.dll!RegCreateKeyExW 7726B946 5 Bytes JMP 00330FA5
.text C:\windows\system32\services.exe[928] ADVAPI32.dll!RegOpenKeyExA 7726BC0D 5 Bytes JMP 00330FEF
.text C:\windows\system32\services.exe[928] ADVAPI32.dll!RegOpenKeyExW 7726BEC4 5 Bytes JMP 00330FD4
.text C:\windows\system32\services.exe[928] WS2_32.dll!socket 77013F00 5 Bytes JMP 00320000
.text C:\windows\system32\lsass.exe[956] ntdll.dll!NtCreateFile 77494870 5 Bytes JMP 000D000A
.text C:\windows\system32\lsass.exe[956] ntdll.dll!NtCreateProcess 77494940 5 Bytes JMP 000D001B
.text C:\windows\system32\lsass.exe[956] ntdll.dll!NtProtectVirtualMemory 774951C0 5 Bytes JMP 000D0FE5
.text C:\windows\system32\lsass.exe[956] kernel32.dll!GetStartupInfoA 76B81DF0 5 Bytes JMP 000C0087
.text C:\windows\system32\lsass.exe[956] kernel32.dll!CreateProcessW 76B8202D 5 Bytes JMP 000C00E9
.text C:\windows\system32\lsass.exe[956] kernel32.dll!CreateProcessA 76B82062 5 Bytes JMP 000C00CE
.text C:\windows\system32\lsass.exe[956] kernel32.dll!CreateNamedPipeW 76BB1FEE 5 Bytes JMP 000C0014
.text C:\windows\system32\lsass.exe[956] kernel32.dll!CreatePipe 76BB4AAB 5 Bytes JMP 000C0076
.text C:\windows\system32\lsass.exe[956] kernel32.dll!VirtualProtect 76BC50CB 5 Bytes JMP 000C0F68
.text C:\windows\system32\lsass.exe[956] kernel32.dll!LoadLibraryExW 76BCB647 5 Bytes JMP 000C0040
.text C:\windows\system32\lsass.exe[956] kernel32.dll!LoadLibraryExA 76BCBC13 5 Bytes JMP 000C0F8D
.text C:\windows\system32\lsass.exe[956] kernel32.dll!CreateFileW 76BD0AFD 5 Bytes JMP 000C0FDE
.text C:\windows\system32\lsass.exe[956] kernel32.dll!GetProcAddress 76BD17D7 5 Bytes JMP 000C0104
.text C:\windows\system32\lsass.exe[956] kernel32.dll!LoadLibraryA 76BD2804 5 Bytes JMP 000C0FA8
.text C:\windows\system32\lsass.exe[956] kernel32.dll!LoadLibraryW 76BD2852 5 Bytes JMP 000C002F
.text C:\windows\system32\lsass.exe[956] kernel32.dll!CreateFileA 76BD289C 5 Bytes JMP 000C0FEF
.text C:\windows\system32\lsass.exe[956] kernel32.dll!GetStartupInfoW 76BD7C55 5 Bytes JMP 000C00A2
.text C:\windows\system32\lsass.exe[956] kernel32.dll!CreateNamedPipeA 76C0D577 5 Bytes JMP 000C0FC3
.text C:\windows\system32\lsass.exe[956] kernel32.dll!WinExec 76C0E739 5 Bytes JMP 000C00BD
.text C:\windows\system32\lsass.exe[956] kernel32.dll!VirtualProtectEx 76C0F6F1 5 Bytes JMP 000C005B
.text C:\windows\system32\lsass.exe[956] msvcrt.dll!_open 775F7E48 5 Bytes JMP 00630FE3
.text C:\windows\system32\lsass.exe[956] msvcrt.dll!_wsystem 7762B04F 5 Bytes JMP 00630F90
.text C:\windows\system32\lsass.exe[956] msvcrt.dll!system 7762B16F 5 Bytes JMP 0063001B
.text C:\windows\system32\lsass.exe[956] msvcrt.dll!_creat 7762ED29 5 Bytes JMP 00630FC6
.text C:\windows\system32\lsass.exe[956] msvcrt.dll!_wcreat 7763038E 5 Bytes JMP 00630FAB
.text C:\windows\system32\lsass.exe[956] msvcrt.dll!_wopen 77630570 5 Bytes JMP 00630000
.text C:\windows\system32\lsass.exe[956] ADVAPI32.dll!RegOpenKeyA 7725D2ED 5 Bytes JMP 000F0FEF
.text C:\windows\system32\lsass.exe[956] ADVAPI32.dll!RegCreateKeyA 7725D3C1 5 Bytes JMP 000F002C
.text C:\windows\system32\lsass.exe[956] ADVAPI32.dll!RegCreateKeyExA 77261B71 5 Bytes JMP 000F0F9B
.text C:\windows\system32\lsass.exe[956] ADVAPI32.dll!RegCreateKeyW 77261CC0 5 Bytes JMP 000F003D
.text C:\windows\system32\lsass.exe[956] ADVAPI32.dll!RegOpenKeyW 77263129 5 Bytes JMP 000F0000
.text C:\windows\system32\lsass.exe[956] ADVAPI32.dll!RegCreateKeyExW 7726B946 5 Bytes JMP 000F0F80
.text C:\windows\system32\lsass.exe[956] ADVAPI32.dll!RegOpenKeyExA 7726BC0D 5 Bytes JMP 000F0FCA
.text C:\windows\system32\lsass.exe[956] ADVAPI32.dll!RegOpenKeyExW 7726BEC4 5 Bytes JMP 000F0011
.text C:\windows\system32\lsass.exe[956] WS2_32.dll!socket 77013F00 5 Bytes JMP 000E0000
.text C:\windows\system32\svchost.exe[1068] ntdll.dll!NtCreateFile 77494870 5 Bytes JMP 001B0000
.text C:\windows\system32\svchost.exe[1068] ntdll.dll!NtCreateProcess 77494940 5 Bytes JMP 001B002C
.text C:\windows\system32\svchost.exe[1068] ntdll.dll!NtProtectVirtualMemory 774951C0 5 Bytes JMP 001B001B
.text C:\windows\system32\svchost.exe[1068] kernel32.dll!GetStartupInfoA 76B81DF0 5 Bytes JMP 001A0F3C
.text C:\windows\system32\svchost.exe[1068] kernel32.dll!CreateProcessW 76B8202D 5 Bytes JMP 001A00A5
.text C:\windows\system32\svchost.exe[1068] kernel32.dll!CreateProcessA 76B82062 5 Bytes JMP 001A0094
.text C:\windows\system32\svchost.exe[1068] kernel32.dll!CreateNamedPipeW 76BB1FEE 5 Bytes JMP 001A0FC3
.text C:\windows\system32\svchost.exe[1068] kernel32.dll!CreatePipe 76BB4AAB 5 Bytes JMP 001A0F57
.text C:\windows\system32\svchost.exe[1068] kernel32.dll!VirtualProtect 76BC50CB 5 Bytes JMP 001A0F72
.text C:\windows\system32\svchost.exe[1068] kernel32.dll!LoadLibraryExW 76BCB647 5 Bytes JMP 001A0F8D
.text C:\windows\system32\svchost.exe[1068] kernel32.dll!LoadLibraryExA 76BCBC13 5 Bytes JMP 001A0040
.text C:\windows\system32\svchost.exe[1068] kernel32.dll!CreateFileW 76BD0AFD 5 Bytes JMP 001A0000
.text C:\windows\system32\svchost.exe[1068] kernel32.dll!GetProcAddress 76BD17D7 5 Bytes JMP 001A00B6
.text C:\windows\system32\svchost.exe[1068] kernel32.dll!LoadLibraryA 76BD2804 5 Bytes JMP 001A002F
.text C:\windows\system32\svchost.exe[1068] kernel32.dll!LoadLibraryW 76BD2852 5 Bytes JMP 001A0FA8
.text C:\windows\system32\svchost.exe[1068] kernel32.dll!CreateFileA 76BD289C 5 Bytes JMP 001A0FE5
.text C:\windows\system32\svchost.exe[1068] kernel32.dll!GetStartupInfoW 76BD7C55 5 Bytes JMP 001A0F2B
.text C:\windows\system32\svchost.exe[1068] kernel32.dll!CreateNamedPipeA 76C0D577 5 Bytes JMP 001A0FD4
.text C:\windows\system32\svchost.exe[1068] kernel32.dll!WinExec 76C0E739 5 Bytes JMP 001A0F1A
.text C:\windows\system32\svchost.exe[1068] kernel32.dll!VirtualProtectEx 76C0F6F1 5 Bytes JMP 001A0065
.text C:\windows\system32\svchost.exe[1068] msvcrt.dll!_open 775F7E48 5 Bytes JMP 003A0000
.text C:\windows\system32\svchost.exe[1068] msvcrt.dll!_wsystem 7762B04F 5 Bytes JMP 003A0064
.text C:\windows\system32\svchost.exe[1068] msvcrt.dll!system 7762B16F 5 Bytes JMP 003A0053
.text C:\windows\system32\svchost.exe[1068] msvcrt.dll!_creat 7762ED29 5 Bytes JMP 003A0FE3
.text C:\windows\system32\svchost.exe[1068] msvcrt.dll!_wcreat 7763038E 5 Bytes JMP 003A0038
.text C:\windows\system32\svchost.exe[1068] msvcrt.dll!_wopen 77630570 5 Bytes JMP 003A001D
.text C:\windows\system32\svchost.exe[1068] ADVAPI32.dll!RegOpenKeyA 7725D2ED 5 Bytes JMP 00290FE5
.text C:\windows\system32\svchost.exe[1068] ADVAPI32.dll!RegCreateKeyA 7725D3C1 5 Bytes JMP 00290FA8
.text C:\windows\system32\svchost.exe[1068] ADVAPI32.dll!RegCreateKeyExA 77261B71 5 Bytes JMP 00290039
.text C:\windows\system32\svchost.exe[1068] ADVAPI32.dll!RegCreateKeyW 77261CC0 5 Bytes JMP 00290F97
.text C:\windows\system32\svchost.exe[1068] ADVAPI32.dll!RegOpenKeyW 77263129 5 Bytes JMP 00290FCA
.text C:\windows\system32\svchost.exe[1068] ADVAPI32.dll!RegCreateKeyExW 7726B946 5 Bytes JMP 00290F7C
.text C:\windows\system32\svchost.exe[1068] ADVAPI32.dll!RegOpenKeyExA 7726BC0D 5 Bytes JMP 0029000A
.text C:\windows\system32\svchost.exe[1068] ADVAPI32.dll!RegOpenKeyExW 7726BEC4 5 Bytes JMP 00290FB9
.text C:\windows\system32\svchost.exe[1068] WS2_32.dll!socket 77013F00 5 Bytes JMP 00280FEF
.text C:\windows\system32\svchost.exe[1156] ntdll.dll!NtCreateFile 77494870 5 Bytes JMP 00200FEF
.text C:\windows\system32\svchost.exe[1156] ntdll.dll!NtCreateProcess 77494940 5 Bytes JMP 0020000A
.text C:\windows\system32\svchost.exe[1156] ntdll.dll!NtProtectVirtualMemory 774951C0 5 Bytes JMP 00200FD4
.text C:\windows\system32\svchost.exe[1156] kernel32.dll!GetStartupInfoA 76B81DF0 5 Bytes JMP 001A0F76
.text C:\windows\system32\svchost.exe[1156] kernel32.dll!CreateProcessW 76B8202D 5 Bytes JMP 001A00DF
.text C:\windows\system32\svchost.exe[1156] kernel32.dll!CreateProcessA 76B82062 5 Bytes JMP 001A0F40
.text C:\windows\system32\svchost.exe[1156] kernel32.dll!CreateNamedPipeW 76BB1FEE 5 Bytes JMP 001A0047
.text C:\windows\system32\svchost.exe[1156] kernel32.dll!CreatePipe 76BB4AAB 5 Bytes JMP 001A0F87
.text C:\windows\system32\svchost.exe[1156] kernel32.dll!VirtualProtect 76BC50CB 5 Bytes JMP 001A008E
.text C:\windows\system32\svchost.exe[1156] kernel32.dll!LoadLibraryExW 76BCB647 5 Bytes JMP 001A0073
.text C:\windows\system32\svchost.exe[1156] kernel32.dll!LoadLibraryExA 76BCBC13 5 Bytes JMP 001A0FC0
.text C:\windows\system32\svchost.exe[1156] kernel32.dll!CreateFileW 76BD0AFD 5 Bytes JMP 001A001B
.text C:\windows\system32\svchost.exe[1156] kernel32.dll!GetProcAddress 76BD17D7 5 Bytes JMP 001A0F2F
.text C:\windows\system32\svchost.exe[1156] kernel32.dll!LoadLibraryA 76BD2804 5 Bytes JMP 001A0FD1
.text C:\windows\system32\svchost.exe[1156] kernel32.dll!LoadLibraryW 76BD2852 5 Bytes JMP 001A0062
.text C:\windows\system32\svchost.exe[1156] kernel32.dll!CreateFileA 76BD289C 5 Bytes JMP 001A000A
.text C:\windows\system32\svchost.exe[1156] kernel32.dll!GetStartupInfoW 76BD7C55 5 Bytes JMP 001A00BA
.text C:\windows\system32\svchost.exe[1156] kernel32.dll!CreateNamedPipeA 76C0D577 5 Bytes JMP 001A0036
.text C:\windows\system32\svchost.exe[1156] kernel32.dll!WinExec 76C0E739 5 Bytes JMP 001A0F5B
.text C:\windows\system32\svchost.exe[1156] kernel32.dll!VirtualProtectEx 76C0F6F1 5 Bytes JMP 001A009F
.text C:\windows\system32\svchost.exe[1156] msvcrt.dll!_open 775F7E48 5 Bytes JMP 00390FEF
.text C:\windows\system32\svchost.exe[1156] msvcrt.dll!_wsystem 7762B04F 5 Bytes JMP 00390F9A
.text C:\windows\system32\svchost.exe[1156] msvcrt.dll!system 7762B16F 5 Bytes JMP 00390FAB
.text C:\windows\system32\svchost.exe[1156] msvcrt.dll!_creat 7762ED29 5 Bytes JMP 00390000
.text C:\windows\system32\svchost.exe[1156] msvcrt.dll!_wcreat 7763038E 5 Bytes JMP 0039001B
.text C:\windows\system32\svchost.exe[1156] msvcrt.dll!_wopen 77630570 5 Bytes JMP 00390FC6
.text C:\windows\system32\svchost.exe[1156] ADVAPI32.dll!RegOpenKeyA 7725D2ED 5 Bytes JMP 00280000
.text C:\windows\system32\svchost.exe[1156] ADVAPI32.dll!RegCreateKeyA 7725D3C1 5 Bytes JMP 00280FD4
.text C:\windows\system32\svchost.exe[1156] ADVAPI32.dll!RegCreateKeyExA 77261B71 5 Bytes JMP 00280F9E
.text C:\windows\system32\svchost.exe[1156] ADVAPI32.dll!RegCreateKeyW 77261CC0 5 Bytes JMP 00280FB9
.text C:\windows\system32\svchost.exe[1156] ADVAPI32.dll!RegOpenKeyW 77263129 5 Bytes JMP 0028001B
.text C:\windows\system32\svchost.exe[1156] ADVAPI32.dll!RegCreateKeyExW 7726B946 5 Bytes JMP 00280F8D
.text C:\windows\system32\svchost.exe[1156] ADVAPI32.dll!RegOpenKeyExA 7726BC0D 5 Bytes JMP 00280FE5
.text C:\windows\system32\svchost.exe[1156] ADVAPI32.dll!RegOpenKeyExW 7726BEC4 5 Bytes JMP 00280040
.text C:\windows\system32\svchost.exe[1156] WS2_32.dll!socket 77013F00 5 Bytes JMP 00270FE5
.text C:\windows\System32\svchost.exe[1212] ntdll.dll!NtCreateFile 77494870 5 Bytes JMP 00E40000
.text C:\windows\System32\svchost.exe[1212] ntdll.dll!NtCreateProcess 77494940 5 Bytes JMP 00E4002F
.text C:\windows\System32\svchost.exe[1212] ntdll.dll!NtProtectVirtualMemory 774951C0 5 Bytes JMP 00E40FEF
.text C:\windows\System32\svchost.exe[1212] kernel32.dll!GetStartupInfoA 76B81DF0 5 Bytes JMP 00A6006C
.text C:\windows\System32\svchost.exe[1212] kernel32.dll!CreateProcessW 76B8202D 5 Bytes JMP 00A60F03
.text C:\windows\System32\svchost.exe[1212] kernel32.dll!CreateProcessA 76B82062 5 Bytes JMP 00A60098
.text C:\windows\System32\svchost.exe[1212] kernel32.dll!CreateNamedPipeW 76BB1FEE 5 Bytes JMP 00A60011
.text C:\windows\System32\svchost.exe[1212] kernel32.dll!CreatePipe 76BB4AAB 5 Bytes JMP 00A60F43
.text C:\windows\System32\svchost.exe[1212] kernel32.dll!VirtualProtect 76BC50CB 5 Bytes JMP 00A60F6F
.text C:\windows\System32\svchost.exe[1212] kernel32.dll!LoadLibraryExW 76BCB647 5 Bytes JMP 00A60F8A
.text C:\windows\System32\svchost.exe[1212] kernel32.dll!LoadLibraryExA 76BCBC13 5 Bytes JMP 00A60047
.text C:\windows\System32\svchost.exe[1212] kernel32.dll!CreateFileW 76BD0AFD 5 Bytes JMP 00A60FCA
.text C:\windows\System32\svchost.exe[1212] kernel32.dll!GetProcAddress 76BD17D7 5 Bytes JMP 00A60EE8
.text C:\windows\System32\svchost.exe[1212] kernel32.dll!LoadLibraryA 76BD2804 5 Bytes JMP 00A60FA5
.text C:\windows\System32\svchost.exe[1212] kernel32.dll!LoadLibraryW 76BD2852 5 Bytes JMP 00A6002C
.text C:\windows\System32\svchost.exe[1212] kernel32.dll!CreateFileA 76BD289C 5 Bytes JMP 00A60FEF
.text C:\windows\System32\svchost.exe[1212] kernel32.dll!GetStartupInfoW 76BD7C55 5 Bytes JMP 00A60F1E
.text C:\windows\System32\svchost.exe[1212] kernel32.dll!CreateNamedPipeA 76C0D577 5 Bytes JMP 00A60000
.text C:\windows\System32\svchost.exe[1212] kernel32.dll!WinExec 76C0E739 5 Bytes JMP 00A6007D
.text C:\windows\System32\svchost.exe[1212] kernel32.dll!VirtualProtectEx 76C0F6F1 5 Bytes JMP 00A60F5E
.text C:\windows\System32\svchost.exe[1212] msvcrt.dll!_open 775F7E48 5 Bytes JMP 00EF0FE3
.text C:\windows\System32\svchost.exe[1212] msvcrt.dll!_wsystem 7762B04F 5 Bytes JMP 00EF0FAD
.text C:\windows\System32\svchost.exe[1212] msvcrt.dll!system 7762B16F 5 Bytes JMP 00EF0038
.text C:\windows\System32\svchost.exe[1212] msvcrt.dll!_creat 7762ED29 5 Bytes JMP 00EF000C
.text C:\windows\System32\svchost.exe[1212] msvcrt.dll!_wcreat 7763038E 3 Bytes JMP 00EF0027
.text C:\windows\System32\svchost.exe[1212] msvcrt.dll!_wcreat + 4 77630392 1 Byte [89]
.text C:\windows\System32\svchost.exe[1212] msvcrt.dll!_wopen 77630570 5 Bytes JMP 00EF0FD2
.text C:\windows\System32\svchost.exe[1212] ADVAPI32.dll!RegOpenKeyA 7725D2ED 5 Bytes JMP 00EE000A
.text C:\windows\System32\svchost.exe[1212] ADVAPI32.dll!RegCreateKeyA 7725D3C1 5 Bytes JMP 00EE0039
.text C:\windows\System32\svchost.exe[1212] ADVAPI32.dll!RegCreateKeyExA 77261B71 5 Bytes JMP 00EE0FA1
.text C:\windows\System32\svchost.exe[1212] ADVAPI32.dll!RegCreateKeyW 77261CC0 5 Bytes JMP 00EE0FB2
.text C:\windows\System32\svchost.exe[1212] ADVAPI32.dll!RegOpenKeyW 77263129 5 Bytes JMP 00EE0FEF
.text C:\windows\System32\svchost.exe[1212] ADVAPI32.dll!RegCreateKeyExW 7726B946 5 Bytes JMP 00EE005E
.text C:\windows\System32\svchost.exe[1212] ADVAPI32.dll!RegOpenKeyExA 7726BC0D 5 Bytes JMP 00EE0FDE
.text C:\windows\System32\svchost.exe[1212] ADVAPI32.dll!RegOpenKeyExW 7726BEC4 5 Bytes JMP 00EE0FCD
.text C:\windows\System32\svchost.exe[1212] WS2_32.dll!socket 77013F00 5 Bytes JMP 00ED0FE5
.text C:\windows\System32\svchost.exe[1264] ntdll.dll!NtCreateFile 77494870 5 Bytes JMP 009F0FEF
.text C:\windows\System32\svchost.exe[1264] ntdll.dll!NtCreateProcess 77494940 5 Bytes JMP 009F0FD4
.text C:\windows\System32\svchost.exe[1264] ntdll.dll!NtProtectVirtualMemory 774951C0 5 Bytes JMP 009F000A
.text C:\windows\System32\svchost.exe[1264] kernel32.dll!GetStartupInfoA 76B81DF0 5 Bytes JMP 009200D8
.text C:\windows\System32\svchost.exe[1264] kernel32.dll!CreateProcessW 76B8202D 5 Bytes JMP 009200F3
.text C:\windows\System32\svchost.exe[1264] kernel32.dll!CreateProcessA 76B82062 5 Bytes JMP 00920F68
.text C:\windows\System32\svchost.exe[1264] kernel32.dll!CreateNamedPipeW 76BB1FEE 5 Bytes JMP 00920051
.text C:\windows\System32\svchost.exe[1264] kernel32.dll!CreatePipe 76BB4AAB 5 Bytes JMP 009200C7
.text C:\windows\System32\svchost.exe[1264] kernel32.dll!VirtualProtect 76BC50CB 5 Bytes JMP 0092009B
.text C:\windows\System32\svchost.exe[1264] kernel32.dll!LoadLibraryExW 76BCB647 5 Bytes JMP 00920FB9
.text C:\windows\System32\svchost.exe[1264] kernel32.dll!LoadLibraryExA 76BCBC13 5 Bytes JMP 00920080
.text C:\windows\System32\svchost.exe[1264] kernel32.dll!CreateFileW 76BD0AFD 5 Bytes JMP 00920025
.text C:\windows\System32\svchost.exe[1264] kernel32.dll!GetProcAddress 76BD17D7 5 Bytes JMP 00920F39
.text C:\windows\System32\svchost.exe[1264] kernel32.dll!LoadLibraryA 76BD2804 5 Bytes JMP 00920FE5
.text C:\windows\System32\svchost.exe[1264] kernel32.dll!LoadLibraryW 76BD2852 5 Bytes JMP 00920FD4
.text C:\windows\System32\svchost.exe[1264] kernel32.dll!CreateFileA 76BD289C 5 Bytes JMP 0092000A
.text C:\windows\System32\svchost.exe[1264] kernel32.dll!GetStartupInfoW 76BD7C55 5 Bytes JMP 00920F9E
.text C:\windows\System32\svchost.exe[1264] kernel32.dll!CreateNamedPipeA 76C0D577 5 Bytes JMP 00920040
.text C:\windows\System32\svchost.exe[1264] kernel32.dll!WinExec 76C0E739 5 Bytes JMP 00920F83
.text C:\windows\System32\svchost.exe[1264] kernel32.dll!VirtualProtectEx 76C0F6F1 5 Bytes JMP 009200AC
.text C:\windows\System32\svchost.exe[1264] msvcrt.dll!_open 775F7E48 5 Bytes JMP 00D30000
.text C:\windows\System32\svchost.exe[1264] msvcrt.dll!_wsystem 7762B04F 5 Bytes JMP 00D3004A
.text C:\windows\System32\svchost.exe[1264] msvcrt.dll!system 7762B16F 5 Bytes JMP 00D30FB5
.text C:\windows\System32\svchost.exe[1264] msvcrt.dll!_creat 7762ED29 5 Bytes JMP 00D30011
.text C:\windows\System32\svchost.exe[1264] msvcrt.dll!_wcreat 7763038E 5 Bytes JMP 00D30FC6
.text C:\windows\System32\svchost.exe[1264] msvcrt.dll!_wopen 77630570 5 Bytes JMP 00D30FD7
.text C:\windows\System32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyA 7725D2ED 5 Bytes JMP 00A10000
.text C:\windows\System32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyA 7725D3C1 5 Bytes JMP 00A10FAF
.text C:\windows\System32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyExA 77261B71 5 Bytes JMP 00A10036
.text C:\windows\System32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyW 77261CC0 5 Bytes JMP 00A10F9E
.text C:\windows\System32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyW 77263129 5 Bytes JMP 00A1001B
.text C:\windows\System32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyExW 7726B946 5 Bytes JMP 00A10051
.text C:\windows\System32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyExA 7726BC0D 5 Bytes JMP 00A10FE5
.text C:\windows\System32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyExW 7726BEC4 5 Bytes JMP 00A10FD4
.text C:\windows\System32\svchost.exe[1264] WS2_32.dll!socket 77013F00 5 Bytes JMP 00A00FEF
.text C:\windows\system32\svchost.exe[1292] ntdll.dll!NtCreateFile 77494870 5 Bytes JMP 00D60000
.text C:\windows\system32\svchost.exe[1292] ntdll.dll!NtCreateProcess 77494940 5 Bytes JMP 00D60FD4
.text C:\windows\system32\svchost.exe[1292] ntdll.dll!NtProtectVirtualMemory 774951C0 5 Bytes JMP 00D60FEF
.text C:\windows\system32\svchost.exe[1292] kernel32.dll!GetStartupInfoA 76B81DF0 5 Bytes JMP 00D50F97
.text C:\windows\system32\svchost.exe[1292] kernel32.dll!CreateProcessW 76B8202D 5 Bytes JMP 00D50F46
.text C:\windows\system32\svchost.exe[1292] kernel32.dll!CreateProcessA 76B82062 5 Bytes JMP 00D50F61
.text C:\windows\system32\svchost.exe[1292] kernel32.dll!CreateNamedPipeW 76BB1FEE 5 Bytes JMP 00D50040
.text C:\windows\system32\svchost.exe[1292] kernel32.dll!CreatePipe 76BB4AAB 5 Bytes JMP 00D50FA8
.text C:\windows\system32\svchost.exe[1292] kernel32.dll!VirtualProtect 76BC50CB 5 Bytes JMP 00D50FC3
.text C:\windows\system32\svchost.exe[1292] kernel32.dll!LoadLibraryExW 76BCB647 5 Bytes JMP 00D5009B
.text C:\windows\system32\svchost.exe[1292] kernel32.dll!LoadLibraryExA 76BCBC13 5 Bytes JMP 00D50FDE
.text C:\windows\system32\svchost.exe[1292] kernel32.dll!CreateFileW 76BD0AFD 5 Bytes JMP 00D5000A
.text C:\windows\system32\svchost.exe[1292] kernel32.dll!GetProcAddress 76BD17D7 5 Bytes JMP 00D500F6
.text C:\windows\system32\svchost.exe[1292] kernel32.dll!LoadLibraryA 76BD2804 5 Bytes JMP 00D50065
.text C:\windows\system32\svchost.exe[1292] kernel32.dll!LoadLibraryW 76BD2852 5 Bytes JMP 00D50076
.text C:\windows\system32\svchost.exe[1292] kernel32.dll!CreateFileA 76BD289C 5 Bytes JMP 00D50FEF
.text C:\windows\system32\svchost.exe[1292] kernel32.dll!GetStartupInfoW 76BD7C55 5 Bytes JMP 00D500DB
.text C:\windows\system32\svchost.exe[1292] kernel32.dll!CreateNamedPipeA 76C0D577 5 Bytes JMP 00D50025
.text C:\windows\system32\svchost.exe[1292] kernel32.dll!WinExec 76C0E739 5 Bytes JMP 00D50F72
.text C:\windows\system32\svchost.exe[1292] kernel32.dll!VirtualProtectEx 76C0F6F1 5 Bytes JMP 00D500B6
.text C:\windows\system32\svchost.exe[1292] msvcrt.dll!_open 775F7E48 5 Bytes JMP 00E40FEF
.text C:\windows\system32\svchost.exe[1292] msvcrt.dll!_wsystem 7762B04F 5 Bytes JMP 00E40045
.text C:\windows\system32\svchost.exe[1292] msvcrt.dll!system 7762B16F 5 Bytes JMP 00E40FB0
.text C:\windows\system32\svchost.exe[1292] msvcrt.dll!_creat 7762ED29 5 Bytes JMP 00E4000C
.text C:\windows\system32\svchost.exe[1292] msvcrt.dll!_wcreat 7763038E 5 Bytes JMP 00E40FC1
.text C:\windows\system32\svchost.exe[1292] msvcrt.dll!_wopen 77630570 5 Bytes JMP 00E40FD2
.text C:\windows\system32\svchost.exe[1292] ADVAPI32.dll!RegOpenKeyA 7725D2ED 5 Bytes JMP 00D80FE5
.text C:\windows\system32\svchost.exe[1292] ADVAPI32.dll!RegCreateKeyA 7725D3C1 5 Bytes JMP 00D8000A
.text C:\windows\system32\svchost.exe[1292] ADVAPI32.dll!RegCreateKeyExA 77261B71 5 Bytes JMP 00D8001B
.text C:\windows\system32\svchost.exe[1292] ADVAPI32.dll!RegCreateKeyW 77261CC0 5 Bytes JMP 00D80F83
.text C:\windows\system32\svchost.exe[1292] ADVAPI32.dll!RegOpenKeyW 77263129 5 Bytes JMP 00D80FD4
.text C:\windows\system32\svchost.exe[1292] ADVAPI32.dll!RegCreateKeyExW 7726B946 5 Bytes JMP 00D8002C
.text C:\windows\system32\svchost.exe[1292] ADVAPI32.dll!RegOpenKeyExA 7726BC0D 5 Bytes JMP 00D80FB9
.text C:\windows\system32\svchost.exe[1292] ADVAPI32.dll!RegOpenKeyExW 7726BEC4 5 Bytes JMP 00D80FA8
.text C:\windows\system32\svchost.exe[1292] WS2_32.dll!socket 77013F00 5 Bytes JMP 00D70FE5
.text C:\windows\system32\svchost.exe[1400] ntdll.dll!NtCreateFile 77494870 5 Bytes JMP 0095000A
.text C:\windows\system32\svchost.exe[1400] ntdll.dll!NtCreateProcess 77494940 5 Bytes JMP 00950025
.text C:\windows\system32\svchost.exe[1400] ntdll.dll!NtProtectVirtualMemory 774951C0 5 Bytes JMP 00950FEF
.text C:\windows\system32\svchost.exe[1400] kernel32.dll!GetStartupInfoA 76B81DF0 5 Bytes JMP 00550F54
.text C:\windows\system32\svchost.exe[1400] kernel32.dll!CreateProcessW 76B8202D 5 Bytes JMP 00550F1E
.text C:\windows\system32\svchost.exe[1400] kernel32.dll!CreateProcessA 76B82062 5 Bytes JMP 005500B3
.text C:\windows\system32\svchost.exe[1400] kernel32.dll!CreateNamedPipeW 76BB1FEE 5 Bytes JMP 00550FCA
.text C:\windows\system32\svchost.exe[1400] kernel32.dll!CreatePipe 76BB4AAB 5 Bytes JMP 0055007D
.text C:\windows\system32\svchost.exe[1400] kernel32.dll!VirtualProtect 76BC50CB 5 Bytes JMP 00550F79
.text C:\windows\system32\svchost.exe[1400] kernel32.dll!LoadLibraryExW 76BCB647 5 Bytes JMP 00550051
.text C:\windows\system32\svchost.exe[1400] kernel32.dll!LoadLibraryExA 76BCBC13 5 Bytes JMP 00550040
.text C:\windows\system32\svchost.exe[1400] kernel32.dll!CreateFileW 76BD0AFD 5 Bytes JMP 00550FE5
.text C:\windows\system32\svchost.exe[1400] kernel32.dll!GetProcAddress 76BD17D7 5 Bytes JMP 00550F0D
.text C:\windows\system32\svchost.exe[1400] kernel32.dll!LoadLibraryA 76BD2804 5 Bytes JMP 00550FB9
.text C:\windows\system32\svchost.exe[1400] kernel32.dll!LoadLibraryW 76BD2852 5 Bytes JMP 00550F9E
.text C:\windows\system32\svchost.exe[1400] kernel32.dll!CreateFileA 76BD289C 5 Bytes JMP 00550000
.text C:\windows\system32\svchost.exe[1400] kernel32.dll!GetStartupInfoW 76BD7C55 5 Bytes JMP 00550F43
.text C:\windows\system32\svchost.exe[1400] kernel32.dll!CreateNamedPipeA 76C0D577 5 Bytes JMP 0055001B
.text C:\windows\system32\svchost.exe[1400] kernel32.dll!WinExec 76C0E739 5 Bytes JMP 005500A2
.text C:\windows\system32\svchost.exe[1400] kernel32.dll!VirtualProtectEx 76C0F6F1 5 Bytes JMP 0055006C
.text C:\windows\system32\svchost.exe[1400] msvcrt.dll!_open 775F7E48 5 Bytes JMP 00A4000C
.text C:\windows\system32\svchost.exe[1400] msvcrt.dll!_wsystem 7762B04F 5 Bytes JMP 00A40033
.text C:\windows\system32\svchost.exe[1400] msvcrt.dll!system 7762B16F 5 Bytes JMP 00A40FB2
.text C:\windows\system32\svchost.exe[1400] msvcrt.dll!_creat 7762ED29 5 Bytes JMP 00A40FDE
.text C:\windows\system32\svchost.exe[1400] msvcrt.dll!_wcreat 7763038E 5 Bytes JMP 00A40FC3
.text C:\windows\system32\svchost.exe[1400] msvcrt.dll!_wopen 77630570 5 Bytes JMP 00A40FEF
.text C:\windows\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyA 7725D2ED 5 Bytes JMP 00970000
.text C:\windows\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyA 7725D3C1 5 Bytes JMP 00970FC0
.text C:\windows\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyExA 77261B71 5 Bytes JMP 00970F94
.text C:\windows\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyW 77261CC0 5 Bytes JMP 00970FA5
.text C:\windows\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyW 77263129 5 Bytes JMP 0097001B
.text C:\windows\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyExW 7726B946 5 Bytes JMP 00970F83
.text C:\windows\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyExA 7726BC0D 5 Bytes JMP 00970FE5
.text C:\windows\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyExW 7726BEC4 5 Bytes JMP 0097002C
.text C:\windows\system32\svchost.exe[1400] WS2_32.dll!socket 77013F00 5 Bytes JMP 00960FE5
.text C:\windows\system32\svchost.exe[1496] ntdll.dll!NtCreateFile 77494870 5 Bytes JMP 008F0FE5
.text C:\windows\system32\svchost.exe[1496] ntdll.dll!NtCreateProcess 77494940 5 Bytes JMP 008F0FAF
.text C:\windows\system32\svchost.exe[1496] ntdll.dll!NtProtectVirtualMemory 774951C0 5 Bytes JMP 008F0FCA
.text C:\windows\system32\svchost.exe[1496] kernel32.dll!GetStartupInfoA 76B81DF0 5 Bytes JMP 00890F6F
.text C:\windows\system32\svchost.exe[1496] kernel32.dll!CreateProcessW 76B8202D 5 Bytes JMP 008900FA
.text C:\windows\system32\svchost.exe[1496] kernel32.dll!CreateProcessA 76B82062 5 Bytes JMP 008900DF
.text C:\windows\system32\svchost.exe[1496] kernel32.dll!CreateNamedPipeW 76BB1FEE 5 Bytes JMP 00890040
.text C:\windows\system32\svchost.exe[1496] kernel32.dll!CreatePipe 76BB4AAB 5 Bytes JMP 0089008E
.text C:\windows\system32\svchost.exe[1496] kernel32.dll!VirtualProtect 76BC50CB 5 Bytes JMP 0089006C
.text C:\windows\system32\svchost.exe[1496] kernel32.dll!LoadLibraryExW 76BCB647 5 Bytes JMP 00890F94
.text C:\windows\system32\svchost.exe[1496] kernel32.dll!LoadLibraryExA 76BCBC13 5 Bytes JMP 0089005B
.text C:\windows\system32\svchost.exe[1496] kernel32.dll!CreateFileW 76BD0AFD 5 Bytes JMP 00890025
.text C:\windows\system32\svchost.exe[1496] kernel32.dll!GetProcAddress 76BD17D7 5 Bytes JMP 00890F4A
.text C:\windows\system32\svchost.exe[1496] kernel32.dll!LoadLibraryA 76BD2804 5 Bytes JMP 00890FD4
.text C:\windows\system32\svchost.exe[1496] kernel32.dll!LoadLibraryW 76BD2852 5 Bytes JMP 00890FC3
.text C:\windows\system32\svchost.exe[1496] kernel32.dll!CreateFileA 76BD289C 5 Bytes JMP 0089000A
.text C:\windows\system32\svchost.exe[1496] kernel32.dll!GetStartupInfoW 76BD7C55 5 Bytes JMP 008900BD
.text C:\windows\system32\svchost.exe[1496] kernel32.dll!CreateNamedPipeA 76C0D577 5 Bytes JMP 00890FEF
.text C:\windows\system32\svchost.exe[1496] kernel32.dll!WinExec 76C0E739 5 Bytes JMP 008900CE
.text C:\windows\system32\svchost.exe[1496] kernel32.dll!VirtualProtectEx 76C0F6F1 5 Bytes JMP 0089007D
.text C:\windows\system32\svchost.exe[1496] msvcrt.dll!_open 775F7E48 5 Bytes JMP 00990FEF
.text C:\windows\system32\svchost.exe[1496] msvcrt.dll!_wsystem 7762B04F 5 Bytes JMP 00990FAD
.text C:\windows\system32\svchost.exe[1496] msvcrt.dll!system 7762B16F 5 Bytes JMP 00990038
.text C:\windows\system32\svchost.exe[1496] msvcrt.dll!_creat 7762ED29 5 Bytes JMP 00990FC8
.text C:\windows\system32\svchost.exe[1496] msvcrt.dll!_wcreat 7763038E 5 Bytes JMP 0099001D
.text C:\windows\system32\svchost.exe[1496] msvcrt.dll!_wopen 77630570 5 Bytes JMP 0099000C
.text C:\windows\system32\svchost.exe[1496] ADVAPI32.dll!RegOpenKeyA 7725D2ED 5 Bytes JMP 008E0FEF
.text C:\windows\system32\svchost.exe[1496] ADVAPI32.dll!RegCreateKeyA 7725D3C1 5 Bytes JMP 008E0028
.text C:\windows\system32\svchost.exe[1496] ADVAPI32.dll!RegCreateKeyExA 77261B71 5 Bytes JMP 008E0F90
.text C:\windows\system32\svchost.exe[1496] ADVAPI32.dll!RegCreateKeyW 77261CC0 5 Bytes JMP 008E0FA1
.text C:\windows\system32\svchost.exe[1496] ADVAPI32.dll!RegOpenKeyW 77263129 5 Bytes JMP 008E0FDE
.text C:\windows\system32\svchost.exe[1496] ADVAPI32.dll!RegCreateKeyExW 7726B946 5 Bytes JMP 008E0F75
.text C:\windows\system32\svchost.exe[1496] ADVAPI32.dll!RegOpenKeyExA 7726BC0D 5 Bytes JMP 008E0FCD
.text C:\windows\system32\svchost.exe[1496] ADVAPI32.dll!RegOpenKeyExW 7726BEC4 5 Bytes JMP 008E0FBC
.text C:\windows\system32\svchost.exe[1496] WS2_32.dll!socket 77013F00 5 Bytes JMP 00980FEF
.text C:\windows\system32\svchost.exe[1816] ntdll.dll!NtCreateFile 77494870 5 Bytes JMP 008E0000
.text C:\windows\system32\svchost.exe[1816] ntdll.dll!NtCreateProcess 77494940 5 Bytes JMP 008E002C
.text C:\windows\system32\svchost.exe[1816] ntdll.dll!NtProtectVirtualMemory 774951C0 5 Bytes JMP 008E0011
.text C:\windows\system32\svchost.exe[1816] kernel32.dll!GetStartupInfoA 76B81DF0 5 Bytes JMP 00550F3F
.text C:\windows\system32\svchost.exe[1816] kernel32.dll!CreateProcessW 76B8202D 5 Bytes JMP 005500B9
.text C:\windows\system32\svchost.exe[1816] kernel32.dll!CreateProcessA 76B82062 5 Bytes JMP 0055009E
.text C:\windows\system32\svchost.exe[1816] kernel32.dll!CreateNamedPipeW 76BB1FEE 5 Bytes JMP 00550FB9
.text C:\windows\system32\svchost.exe[1816] kernel32.dll!CreatePipe 76BB4AAB 5 Bytes JMP 00550F50
.text C:\windows\system32\svchost.exe[1816] kernel32.dll!VirtualProtect 76BC50CB 5 Bytes JMP 00550054
.text C:\windows\system32\svchost.exe[1816] kernel32.dll!LoadLibraryExW 76BCB647 5 Bytes JMP 00550F86
.text C:\windows\system32\svchost.exe[1816] kernel32.dll!LoadLibraryExA 76BCBC13 5 Bytes JMP 00550F97
.text C:\windows\system32\svchost.exe[1816] kernel32.dll!CreateFileW 76BD0AFD 5 Bytes JMP 00550FDE
.text C:\windows\system32\svchost.exe[1816] kernel32.dll!GetProcAddress 76BD17D7 5 Bytes JMP 005500CA
.text C:\windows\system32\svchost.exe[1816] kernel32.dll!LoadLibraryA 76BD2804 5 Bytes JMP 0055002F
.text C:\windows\system32\svchost.exe[1816] kernel32.dll!LoadLibraryW 76BD2852 5 Bytes JMP 00550FA8
.text C:\windows\system32\svchost.exe[1816] kernel32.dll!CreateFileA 76BD289C 5 Bytes JMP 00550FEF
.text C:\windows\system32\svchost.exe[1816] kernel32.dll!GetStartupInfoW 76BD7C55 5 Bytes JMP 00550079
.text C:\windows\system32\svchost.exe[1816] kernel32.dll!CreateNamedPipeA 76C0D577 5 Bytes JMP 00550014
.text C:\windows\system32\svchost.exe[1816] kernel32.dll!WinExec 76C0E739 5 Bytes JMP 00550F1A
.text C:\windows\system32\svchost.exe[1816] kernel32.dll!VirtualProtectEx 76C0F6F1 5 Bytes JMP 00550F61
.text C:\windows\system32\svchost.exe[1816] msvcrt.dll!_open 775F7E48 5 Bytes JMP 00980000
.text C:\windows\system32\svchost.exe[1816] msvcrt.dll!_wsystem 7762B04F 5 Bytes JMP 00980FBC
.text C:\windows\system32\svchost.exe[1816] msvcrt.dll!system 7762B16F 5 Bytes JMP 00980FD7
.text C:\windows\system32\svchost.exe[1816] msvcrt.dll!_creat 7762ED29 5 Bytes JMP 0098002C
.text C:\windows\system32\svchost.exe[1816] msvcrt.dll!_wcreat 7763038E 5 Bytes JMP 00980047
.text C:\windows\system32\svchost.exe[1816] msvcrt.dll!_wopen 77630570 5 Bytes JMP 00980011
.text C:\windows\system32\svchost.exe[1816] ADVAPI32.dll!RegOpenKeyA 7725D2ED 5 Bytes JMP 00890000
.text C:\windows\system32\svchost.exe[1816] ADVAPI32.dll!RegCreateKeyA 7725D3C1 5 Bytes JMP 00890FC0
.text C:\windows\system32\svchost.exe[1816] ADVAPI32.dll!RegCreateKeyExA 77261B71 5 Bytes JMP 00890047
.text C:\windows\system32\svchost.exe[1816] ADVAPI32.dll!RegCreateKeyW 77261CC0 5 Bytes JMP 00890FA5
.text C:\windows\system32\svchost.exe[1816] ADVAPI32.dll!RegOpenKeyW 77263129 5 Bytes JMP 0089001B
.text C:\windows\system32\svchost.exe[1816] ADVAPI32.dll!RegCreateKeyExW 7726B946 5 Bytes JMP 00890058
.text C:\windows\system32\svchost.exe[1816] ADVAPI32.dll!RegOpenKeyExA 7726BC0D 5 Bytes JMP 0089002C
.text C:\windows\system32\svchost.exe[1816] ADVAPI32.dll!RegOpenKeyExW 7726BEC4 5 Bytes JMP 00890FDB
.text C:\windows\system32\svchost.exe[1816] WS2_32.dll!socket 77013F00 5 Bytes JMP 00930FEF
.text C:\windows\system32\svchost.exe[2136] ntdll.dll!NtCreateFile 77494870 5 Bytes JMP 00240000
.text C:\windows\system32\svchost.exe[2136] ntdll.dll!NtCreateProcess 77494940 5 Bytes JMP 0024001B
.text C:\windows\system32\svchost.exe[2136] ntdll.dll!NtProtectVirtualMemory 774951C0 5 Bytes JMP 00240FE5
.text C:\windows\system32\svchost.exe[2136] kernel32.dll!GetStartupInfoA 76B81DF0 5 Bytes JMP 001E0F43
.text C:\windows\system32\svchost.exe[2136] kernel32.dll!CreateProcessW 76B8202D 5 Bytes JMP 001E0F14
.text C:\windows\system32\svchost.exe[2136] kernel32.dll!CreateProcessA 76B82062 5 Bytes JMP 001E00A9
.text C:\windows\system32\svchost.exe[2136] kernel32.dll!CreateNamedPipeW 76BB1FEE 5 Bytes JMP 001E001B
.text C:\windows\system32\svchost.exe[2136] kernel32.dll!CreatePipe 76BB4AAB 5 Bytes JMP 001E006C
.text C:\windows\system32\svchost.exe[2136] kernel32.dll!VirtualProtect 76BC50CB 5 Bytes JMP 001E0F5E
.text C:\windows\system32\svchost.exe[2136] kernel32.dll!LoadLibraryExW 76BCB647 5 Bytes JMP 001E0F6F
.text C:\windows\system32\svchost.exe[2136] kernel32.dll!LoadLibraryExA 76BCBC13 5 Bytes JMP 001E002C
.text C:\windows\system32\svchost.exe[2136] kernel32.dll!CreateFileW 76BD0AFD 5 Bytes JMP 001E000A
.text C:\windows\system32\svchost.exe[2136] kernel32.dll!GetProcAddress 76BD17D7 5 Bytes JMP 001E0F03
.text C:\windows\system32\svchost.exe[2136] kernel32.dll!LoadLibraryA 76BD2804 5 Bytes JMP 001E0FA5
.text C:\windows\system32\svchost.exe[2136] kernel32.dll!LoadLibraryW 76BD2852 5 Bytes JMP 001E0F8A
.text C:\windows\system32\svchost.exe[2136] kernel32.dll!CreateFileA 76BD289C 5 Bytes JMP 001E0FEF
.text C:\windows\system32\svchost.exe[2136] kernel32.dll!GetStartupInfoW 76BD7C55 5 Bytes JMP 001E0087
.text C:\windows\system32\svchost.exe[2136] kernel32.dll!CreateNamedPipeA 76C0D577 5 Bytes JMP 001E0FCA
.text C:\windows\system32\svchost.exe[2136] kernel32.dll!WinExec 76C0E739 5 Bytes JMP 001E0098
.text C:\windows\system32\svchost.exe[2136] kernel32.dll!VirtualProtectEx 76C0F6F1 5 Bytes JMP 001E0051
.text C:\windows\system32\svchost.exe[2136] msvcrt.dll!_open 775F7E48 5 Bytes JMP 00260FEF
.text C:\windows\system32\svchost.exe[2136] msvcrt.dll!_wsystem 7762B04F 5 Bytes JMP 00260F7F
.text C:\windows\system32\svchost.exe[2136] msvcrt.dll!system 7762B16F 5 Bytes JMP 00260F90
.text C:\windows\system32\svchost.exe[2136] msvcrt.dll!_creat 7762ED29 5 Bytes JMP 00260000
.text C:\windows\system32\svchost.exe[2136] msvcrt.dll!_wcreat 7763038E 5 Bytes JMP 00260FAB
.text C:\windows\system32\svchost.exe[2136] msvcrt.dll!_wopen 77630570 5 Bytes JMP 00260FD2
.text C:\windows\system32\svchost.exe[2136] ADVAPI32.dll!RegOpenKeyA 7725D2ED 5 Bytes JMP 001F0FEF
.text C:\windows\system32\svchost.exe[2136] ADVAPI32.dll!RegCreateKeyA 7725D3C1 5 Bytes JMP 001F0FA8
.text C:\windows\system32\svchost.exe[2136] ADVAPI32.dll!RegCreateKeyExA 77261B71 5 Bytes JMP 001F0F7C
.text C:\windows\system32\svchost.exe[2136] ADVAPI32.dll!RegCreateKeyW 77261CC0 5 Bytes JMP 001F0F8D
.text C:\windows\system32\svchost.exe[2136] ADVAPI32.dll!RegOpenKeyW 77263129 5 Bytes JMP 001F0FDE
.text C:\windows\system32\svchost.exe[2136] ADVAPI32.dll!RegCreateKeyExW 7726B946 5 Bytes JMP 001F0043
.text C:\windows\system32\svchost.exe[2136] ADVAPI32.dll!RegOpenKeyExA 7726BC0D 5 Bytes JMP 001F0FC3
.text C:\windows\system32\svchost.exe[2136] ADVAPI32.dll!RegOpenKeyExW 7726BEC4 5 Bytes JMP 001F0014
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[3392] kernel32.dll!LoadLibraryA 76BD2804 5 Bytes JMP 69EE9A20 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[3392] kernel32.dll!LoadLibraryW 76BD2852 5 Bytes JMP 69EE9AE2 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\windows\system32\svchost.exe[3456] ntdll.dll!NtCreateFile 77494870 5 Bytes JMP 002D000A
.text C:\windows\system32\svchost.exe[3456] ntdll.dll!NtCreateProcess 77494940 5 Bytes JMP 002D0025
.text C:\windows\system32\svchost.exe[3456] ntdll.dll!NtProtectVirtualMemory 774951C0 5 Bytes JMP 002D0FEF
.text C:\windows\system32\svchost.exe[3456] kernel32.dll!GetStartupInfoA 76B81DF0 5 Bytes JMP 001A00AC
.text C:\windows\system32\svchost.exe[3456] kernel32.dll!CreateProcessW 76B8202D 5 Bytes JMP 001A0F43
.text C:\windows\system32\svchost.exe[3456] kernel32.dll!CreateProcessA 76B82062 5 Bytes JMP 001A00D8
.text C:\windows\system32\svchost.exe[3456] kernel32.dll!CreateNamedPipeW 76BB1FEE 5 Bytes JMP 001A0025
.text C:\windows\system32\svchost.exe[3456] kernel32.dll!CreatePipe 76BB4AAB 5 Bytes JMP 001A009B
.text C:\windows\system32\svchost.exe[3456] kernel32.dll!VirtualProtect 76BC50CB 5 Bytes JMP 001A0076
.text C:\windows\system32\svchost.exe[3456] kernel32.dll!LoadLibraryExW 76BCB647 5 Bytes JMP 001A0F94
.text C:\windows\system32\svchost.exe[3456] kernel32.dll!LoadLibraryExA 76BCBC13 5 Bytes JMP 001A005B
.text C:\windows\system32\svchost.exe[3456] kernel32.dll!CreateFileW 76BD0AFD 5 Bytes JMP 001A0FE5
.text C:\windows\system32\svchost.exe[3456] kernel32.dll!GetProcAddress 76BD17D7 5 Bytes JMP 001A00F3
.text C:\windows\system32\svchost.exe[3456] kernel32.dll!LoadLibraryA 76BD2804 5 Bytes JMP 001A0FC3
.text C:\windows\system32\svchost.exe[3456] kernel32.dll!LoadLibraryW 76BD2852 5 Bytes JMP 001A004A
.text C:\windows\system32\svchost.exe[3456] kernel32.dll!CreateFileA 76BD289C 5 Bytes JMP 001A0000
.text C:\windows\system32\svchost.exe[3456] kernel32.dll!GetStartupInfoW 76BD7C55 5 Bytes JMP 001A0F68
.text C:\windows\system32\svchost.exe[3456] kernel32.dll!CreateNamedPipeA 76C0D577 5 Bytes JMP 001A0FD4
.text C:\windows\system32\svchost.exe[3456] kernel32.dll!WinExec 76C0E739 5 Bytes JMP 001A00BD
.text C:\windows\system32\svchost.exe[3456] kernel32.dll!VirtualProtectEx 76C0F6F1 5 Bytes JMP 001A0F83
.text C:\windows\system32\svchost.exe[3456] msvcrt.dll!_open 775F7E48 5 Bytes JMP 002E0000
.text C:\windows\system32\svchost.exe[3456] msvcrt.dll!_wsystem 7762B04F 5 Bytes JMP 002E0FC1
.text C:\windows\system32\svchost.exe[3456] msvcrt.dll!system 7762B16F 5 Bytes JMP 002E0FD2
.text C:\windows\system32\svchost.exe[3456] msvcrt.dll!_creat 7762ED29 5 Bytes JMP 002E0027
.text C:\windows\system32\svchost.exe[3456] msvcrt.dll!_wcreat 7763038E 5 Bytes JMP 002E0038
.text C:\windows\system32\svchost.exe[3456] msvcrt.dll!_wopen 77630570 5 Bytes JMP 002E0FE3
.text C:\windows\system32\svchost.exe[3456] ADVAPI32.dll!RegOpenKeyA 7725D2ED 5 Bytes JMP 00280FEF
.text C:\windows\system32\svchost.exe[3456] ADVAPI32.dll!RegCreateKeyA 7725D3C1 5 Bytes JMP 0028001B
.text C:\windows\system32\svchost.exe[3456] ADVAPI32.dll!RegCreateKeyExA 77261B71 5 Bytes JMP 00280F83
.text C:\windows\system32\svchost.exe[3456] ADVAPI32.dll!RegCreateKeyW 77261CC0 5 Bytes JMP 00280F94
.text C:\windows\system32\svchost.exe[3456] ADVAPI32.dll!RegOpenKeyW 77263129 5 Bytes JMP 0028000A
.text C:\windows\system32\svchost.exe[3456] ADVAPI32.dll!RegCreateKeyExW 7726B946 5 Bytes JMP 00280040
.text C:\windows\system32\svchost.exe[3456] ADVAPI32.dll!RegOpenKeyExA 7726BC0D 5 Bytes JMP 00280FD4
.text C:\windows\system32\svchost.exe[3456] ADVAPI32.dll!RegOpenKeyExW 7726BEC4 5 Bytes JMP 00280FAF
.text C:\windows\system32\svchost.exe[3456] WS2_32.dll!socket 77013F00 5 Bytes JMP 00270000
.text C:\windows\system32\svchost.exe[4364] ntdll.dll!NtCreateFile 77494870 5 Bytes JMP 00200000
.text C:\windows\system32\svchost.exe[4364] ntdll.dll!NtCreateProcess 77494940 5 Bytes JMP 00200FE5
.text C:\windows\system32\svchost.exe[4364] ntdll.dll!NtProtectVirtualMemory 774951C0 5 Bytes JMP 00200011
.text C:\windows\system32\svchost.exe[4364] kernel32.dll!GetStartupInfoA 76B81DF0 5 Bytes JMP 001D00D8
.text C:\windows\system32\svchost.exe[4364] kernel32.dll!CreateProcessW 76B8202D 5 Bytes JMP 001D010E
.text C:\windows\system32\svchost.exe[4364] kernel32.dll!CreateProcessA 76B82062 5 Bytes JMP 001D00F3
.text C:\windows\system32\svchost.exe[4364] kernel32.dll!CreateNamedPipeW 76BB1FEE 5 Bytes JMP 001D0040
.text C:\windows\system32\svchost.exe[4364] kernel32.dll!CreatePipe 76BB4AAB 5 Bytes JMP 001D0FA5
.text C:\windows\system32\svchost.exe[4364] kernel32.dll!VirtualProtect 76BC50CB 5 Bytes JMP 001D008E
.text C:\windows\system32\svchost.exe[4364] kernel32.dll!LoadLibraryExW 76BCB647 5 Bytes JMP 001D007D
.text C:\windows\system32\svchost.exe[4364] kernel32.dll!LoadLibraryExA 76BCBC13 5 Bytes JMP 001D0FC0
.text C:\windows\system32\svchost.exe[4364] kernel32.dll!CreateFileW 76BD0AFD 5 Bytes JMP 001D000A
.text C:\windows\system32\svchost.exe[4364] kernel32.dll!GetProcAddress 76BD17D7 5 Bytes JMP 001D011F
.text C:\windows\system32\svchost.exe[4364] kernel32.dll!LoadLibraryA 76BD2804 5 Bytes JMP 001D0051
.text C:\windows\system32\svchost.exe[4364] kernel32.dll!LoadLibraryW 76BD2852 5 Bytes JMP 001D0062
.text C:\windows\system32\svchost.exe[4364] kernel32.dll!CreateFileA 76BD289C 5 Bytes JMP 001D0FEF
.text C:\windows\system32\svchost.exe[4364] kernel32.dll!GetStartupInfoW 76BD7C55 5 Bytes JMP 001D0F94
.text C:\windows\system32\svchost.exe[4364] kernel32.dll!CreateNamedPipeA 76C0D577 5 Bytes JMP 001D0025
.text C:\windows\system32\svchost.exe[4364] kernel32.dll!WinExec 76C0E739 5 Bytes JMP 001D0F83
.text C:\windows\system32\svchost.exe[4364] kernel32.dll!VirtualProtectEx 76C0F6F1 5 Bytes JMP 001D00B3
.text C:\windows\system32\svchost.exe[4364] msvcrt.dll!_open 775F7E48 5 Bytes JMP 00360FE3
.text C:\windows\system32\svchost.exe[4364] msvcrt.dll!_wsystem 7762B04F 5 Bytes JMP 00360038
.text C:\windows\system32\svchost.exe[4364] msvcrt.dll!system 7762B16F 5 Bytes JMP 00360FAD
.text C:\windows\system32\svchost.exe[4364] msvcrt.dll!_creat 7762ED29 5 Bytes JMP 0036001D
.text C:\windows\system32\svchost.exe[4364] msvcrt.dll!_wcreat 7763038E 5 Bytes JMP 00360FC8
.text C:\windows\system32\svchost.exe[4364] msvcrt.dll!_wopen 77630570 5 Bytes JMP 0036000C
.text C:\windows\system32\svchost.exe[4364] ADVAPI32.dll!RegOpenKeyA 7725D2ED 5 Bytes JMP 001F0FEF
.text C:\windows\system32\svchost.exe[4364] ADVAPI32.dll!RegCreateKeyA 7725D3C1 5 Bytes JMP 001F0025
.text C:\windows\system32\svchost.exe[4364] ADVAPI32.dll!RegCreateKeyExA 77261B71 5 Bytes JMP 001F0F83
.text C:\windows\system32\svchost.exe[4364] ADVAPI32.dll!RegCreateKeyW 77261CC0 5 Bytes JMP 001F0F94
.text C:\windows\system32\svchost.exe[4364] ADVAPI32.dll!RegOpenKeyW 77263129 5 Bytes JMP 001F0000
.text C:\windows\system32\svchost.exe[4364] ADVAPI32.dll!RegCreateKeyExW 7726B946 5 Bytes JMP 001F0040
.text C:\windows\system32\svchost.exe[4364] ADVAPI32.dll!RegOpenKeyExA 7726BC0D 5 Bytes JMP 001F0FCA
.text C:\windows\system32\svchost.exe[4364] ADVAPI32.dll!RegOpenKeyExW 7726BEC4 5 Bytes JMP 001F0FAF
.text C:\windows\system32\svchost.exe[4364] WS2_32.dll!socket 77013F00 5 Bytes JMP 001E0FE5
.text C:\windows\system32\DllHost.exe[5936] ntdll.dll!NtCreateFile 77494870 5 Bytes JMP 00040000
.text C:\windows\system32\DllHost.exe[5936] ntdll.dll!NtCreateProcess 77494940 5 Bytes JMP 0004001B
.text C:\windows\system32\DllHost.exe[5936] ntdll.dll!NtProtectVirtualMemory 774951C0 5 Bytes JMP 00040FE5
.text C:\windows\system32\DllHost.exe[5936] kernel32.dll!GetStartupInfoA 76B81DF0 5 Bytes JMP 000100AC
.text C:\windows\system32\DllHost.exe[5936] kernel32.dll!CreateProcessW 76B8202D 5 Bytes JMP 000100F3
.text C:\windows\system32\DllHost.exe[5936] kernel32.dll!CreateProcessA 76B82062 5 Bytes JMP 000100D8
.text C:\windows\system32\DllHost.exe[5936] kernel32.dll!CreateNamedPipeW 76BB1FEE 5 Bytes JMP 00010014
.text C:\windows\system32\DllHost.exe[5936] kernel32.dll!CreatePipe 76BB4AAB 5 Bytes JMP 00010091
.text C:\windows\system32\DllHost.exe[5936] kernel32.dll!VirtualProtect 76BC50CB 5 Bytes JMP 00010F94
.text C:\windows\system32\DllHost.exe[5936] kernel32.dll!LoadLibraryExW 76BCB647 5 Bytes JMP 0001006C
.text C:\windows\system32\DllHost.exe[5936] kernel32.dll!LoadLibraryExA 76BCBC13 5 Bytes JMP 00010051
.text C:\windows\system32\DllHost.exe[5936] kernel32.dll!CreateFileW 76BD0AFD 5 Bytes JMP 00010FD4
.text C:\windows\system32\DllHost.exe[5936] kernel32.dll!GetProcAddress 76BD17D7 5 Bytes JMP 00010F39
.text C:\windows\system32\DllHost.exe[5936] kernel32.dll!LoadLibraryA 76BD2804 5 Bytes JMP 0001002F
.text C:\windows\system32\DllHost.exe[5936] kernel32.dll!LoadLibraryW 76BD2852 5 Bytes JMP 00010040
.text C:\windows\system32\DllHost.exe[5936] kernel32.dll!CreateFileA 76BD289C 5 Bytes JMP 00010FEF
.text C:\windows\system32\DllHost.exe[5936] kernel32.dll!GetStartupInfoW 76BD7C55 5 Bytes JMP 00010F5E
.text C:\windows\system32\DllHost.exe[5936] kernel32.dll!CreateNamedPipeA 76C0D577 5 Bytes JMP 00010FC3
.text C:\windows\system32\DllHost.exe[5936] kernel32.dll!WinExec 76C0E739 5 Bytes JMP 000100BD
.text C:\windows\system32\DllHost.exe[5936] kernel32.dll!VirtualProtectEx 76C0F6F1 5 Bytes JMP 00010F79
.text C:\windows\system32\DllHost.exe[5936] msvcrt.dll!_open 775F7E48 5 Bytes JMP 00060000
.text C:\windows\system32\DllHost.exe[5936] msvcrt.dll!_wsystem 7762B04F 5 Bytes JMP 00060FC3
.text C:\windows\system32\DllHost.exe[5936] msvcrt.dll!system 7762B16F 5 Bytes JMP 0006004E
.text C:\windows\system32\DllHost.exe[5936] msvcrt.dll!_creat 7762ED29 5 Bytes JMP 00060022
.text C:\windows\system32\DllHost.exe[5936] msvcrt.dll!_wcreat 7763038E 5 Bytes JMP 0006003D
.text C:\windows\system32\DllHost.exe[5936] msvcrt.dll!_wopen 77630570 5 Bytes JMP 00060011
.text C:\windows\system32\DllHost.exe[5936] ADVAPI32.dll!RegOpenKeyA 7725D2ED 5 Bytes JMP 000A0000
.text C:\windows\system32\DllHost.exe[5936] ADVAPI32.dll!RegCreateKeyA 7725D3C1 5 Bytes JMP 000A004A
.text C:\windows\system32\DllHost.exe[5936] ADVAPI32.dll!RegCreateKeyExA 77261B71 5 Bytes JMP 000A0FB2
.text C:\windows\system32\DllHost.exe[5936] ADVAPI32.dll!RegCreateKeyW 77261CC0 5 Bytes JMP 000A0FC3
.text C:\windows\system32\DllHost.exe[5936] ADVAPI32.dll!RegOpenKeyW 77263129 5 Bytes JMP 000A0FE5
.text C:\windows\system32\DllHost.exe[5936] ADVAPI32.dll!RegCreateKeyExW 7726B946 5 Bytes JMP 000A0FA1
.text C:\windows\system32\DllHost.exe[5936] ADVAPI32.dll!RegOpenKeyExA 7726BC0D 5 Bytes JMP 000A001B
.text C:\windows\system32\DllHost.exe[5936] ADVAPI32.dll!RegOpenKeyExW 7726BEC4 5 Bytes JMP 000A0FD4
.text C:\windows\system32\DllHost.exe[5936] WININET.dll!InternetOpenA 759A4E3C 5 Bytes JMP 00140FE5
.text C:\windows\system32\DllHost.exe[5936] WININET.dll!InternetOpenUrlA 759ABFDE 5 Bytes JMP 00140011
.text C:\windows\system32\DllHost.exe[5936] WININET.dll!InternetOpenW 759DC126 5 Bytes JMP 00140000
.text C:\windows\system32\DllHost.exe[5936] WININET.dll!InternetOpenUrlW 75A0D8D2 5 Bytes JMP 00140FCA
.text C:\windows\Explorer.exe[6036] ntdll.dll!NtCreateFile 77494870 5 Bytes JMP 0004000A
.text C:\windows\Explorer.exe[6036] ntdll.dll!NtCreateProcess 77494940 5 Bytes JMP 00040025
.text C:\windows\Explorer.exe[6036] ntdll.dll!NtProtectVirtualMemory 774951C0 5 Bytes JMP 00040FE5
.text C:\windows\Explorer.exe[6036] kernel32.dll!GetStartupInfoA 76B81DF0 5 Bytes JMP 00010F43
.text C:\windows\Explorer.exe[6036] kernel32.dll!CreateProcessW 76B8202D 5 Bytes JMP 00010F0D
.text C:\windows\Explorer.exe[6036] kernel32.dll!CreateProcessA 76B82062 5 Bytes JMP 000100A2
.text C:\windows\Explorer.exe[6036] kernel32.dll!CreateNamedPipeW 76BB1FEE 5 Bytes JMP 00010FC0
.text C:\windows\Explorer.exe[6036] kernel32.dll!CreatePipe 76BB4AAB 5 Bytes JMP 0001006C
.text C:\windows\Explorer.exe[6036] kernel32.dll!VirtualProtect 76BC50CB 5 Bytes JMP 00010F6F
.text C:\windows\Explorer.exe[6036] kernel32.dll!LoadLibraryExW 76BCB647 5 Bytes JMP 00010F8A
.text C:\windows\Explorer.exe[6036] kernel32.dll!LoadLibraryExA 76BCBC13 5 Bytes JMP 00010047
.text C:\windows\Explorer.exe[6036] kernel32.dll!CreateFileW 76BD0AFD 5 Bytes JMP 00010FDB
.text C:\windows\Explorer.exe[6036] kernel32.dll!GetProcAddress 76BD17D7 5 Bytes JMP 00010EFC
.text C:\windows\Explorer.exe[6036] kernel32.dll!LoadLibraryA 76BD2804 5 Bytes JMP 0001002C
.text C:\windows\Explorer.exe[6036] kernel32.dll!LoadLibraryW 76BD2852 5 Bytes JMP 00010FA5
.text C:\windows\Explorer.exe[6036] kernel32.dll!CreateFileA 76BD289C 5 Bytes JMP 00010000
.text C:\windows\Explorer.exe[6036] kernel32.dll!GetStartupInfoW 76BD7C55 5 Bytes JMP 00010F32
.text C:\windows\Explorer.exe[6036] kernel32.dll!CreateNamedPipeA 76C0D577 5 Bytes JMP 0001001B
.text C:\windows\Explorer.exe[6036] kernel32.dll!WinExec 76C0E739 5 Bytes JMP 00010087
.text C:\windows\Explorer.exe[6036] kernel32.dll!VirtualProtectEx 76C0F6F1 5 Bytes JMP 00010F5E
.text C:\windows\Explorer.exe[6036] ADVAPI32.dll!RegOpenKeyA 7725D2ED 5 Bytes JMP 00070FEF
.text C:\windows\Explorer.exe[6036] ADVAPI32.dll!RegCreateKeyA 7725D3C1 5 Bytes JMP 00070FBC
.text C:\windows\Explorer.exe[6036] ADVAPI32.dll!RegCreateKeyExA 77261B71 5 Bytes JMP 00070043
.text C:\windows\Explorer.exe[6036] ADVAPI32.dll!RegCreateKeyW 77261CC0 5 Bytes JMP 00070FA1
.text C:\windows\Explorer.exe[6036] ADVAPI32.dll!RegOpenKeyW 77263129 5 Bytes JMP 00070FDE
.text C:\windows\Explorer.exe[6036] ADVAPI32.dll!RegCreateKeyExW 7726B946 5 Bytes JMP 00070F86
.text C:\windows\Explorer.exe[6036] ADVAPI32.dll!RegOpenKeyExA 7726BC0D 5 Bytes JMP 00070FCD
.text C:\windows\Explorer.exe[6036] ADVAPI32.dll!RegOpenKeyExW 7726BEC4 5 Bytes JMP 0007001E
.text C:\windows\Explorer.exe[6036] msvcrt.dll!_open 775F7E48 5 Bytes JMP 00080FEF
.text C:\windows\Explorer.exe[6036] msvcrt.dll!_wsystem 7762B04F 5 Bytes JMP 00080F97
.text C:\windows\Explorer.exe[6036] msvcrt.dll!system 7762B16F 5 Bytes JMP 00080FB2
.text C:\windows\Explorer.exe[6036] msvcrt.dll!_creat 7762ED29 5 Bytes JMP 00080FCD
.text C:\windows\Explorer.exe[6036] msvcrt.dll!_wcreat 7763038E 5 Bytes JMP 00080022
.text C:\windows\Explorer.exe[6036] msvcrt.dll!_wopen 77630570 5 Bytes JMP 00080FDE
.text C:\windows\Explorer.exe[6036] WININET.dll!InternetOpenA 759A4E3C 5 Bytes JMP 00BC000A
.text C:\windows\Explorer.exe[6036] WININET.dll!InternetOpenUrlA 759ABFDE 5 Bytes JMP 00BC002C
.text C:\windows\Explorer.exe[6036] WININET.dll!InternetOpenW 759DC126 5 Bytes JMP 00BC001B
.text C:\windows\Explorer.exe[6036] WININET.dll!InternetOpenUrlW 75A0D8D2 5 Bytes JMP 00BC0FDB
.text C:\windows\Explorer.exe[6036] WS2_32.dll!socket 77013F00 5 Bytes JMP 04CC0FEF
.text C:\windows\System32\svchost.exe[6096] ntdll.dll!NtCreateFile 77494870 5 Bytes JMP 00040000
.text C:\windows\System32\svchost.exe[6096] ntdll.dll!NtCreateProcess 77494940 5 Bytes JMP 00040FD4
.text C:\windows\System32\svchost.exe[6096] ntdll.dll!NtProtectVirtualMemory 774951C0 5 Bytes JMP 00040FEF
.text C:\windows\System32\svchost.exe[6096] kernel32.dll!GetStartupInfoA 76B81DF0 5 Bytes JMP 00010098
.text C:\windows\System32\svchost.exe[6096] kernel32.dll!CreateProcessW 76B8202D 5 Bytes JMP 00010F28
.text C:\windows\System32\svchost.exe[6096] kernel32.dll!CreateProcessA 76B82062 5 Bytes JMP 00010F4D
.text C:\windows\System32\svchost.exe[6096] kernel32.dll!CreateNamedPipeW 76BB1FEE 5 Bytes JMP 00010025
.text C:\windows\System32\svchost.exe[6096] kernel32.dll!CreatePipe 76BB4AAB 5 Bytes JMP 00010F79
.text C:\windows\System32\svchost.exe[6096] kernel32.dll!VirtualProtect 76BC50CB 5 Bytes JMP 0001006C
.text C:\windows\System32\svchost.exe[6096] kernel32.dll!LoadLibraryExW 76BCB647 5 Bytes JMP 00010051
.text C:\windows\System32\svchost.exe[6096] kernel32.dll!LoadLibraryExA 76BCBC13 5 Bytes JMP 00010F94
.text C:\windows\System32\svchost.exe[6096] kernel32.dll!CreateFileW 76BD0AFD 5 Bytes JMP 00010FDE
.text C:\windows\System32\svchost.exe[6096] kernel32.dll!GetProcAddress 76BD17D7 5 Bytes JMP 000100D8
.text C:\windows\System32\svchost.exe[6096] kernel32.dll!LoadLibraryA 76BD2804 5 Bytes JMP 00010FB9
.text C:\windows\System32\svchost.exe[6096] kernel32.dll!LoadLibraryW 76BD2852 5 Bytes JMP 00010040
.text C:\windows\System32\svchost.exe[6096] kernel32.dll!CreateFileA 76BD289C 5 Bytes JMP 00010FEF
.text C:\windows\System32\svchost.exe[6096] kernel32.dll!GetStartupInfoW 76BD7C55 5 Bytes JMP 00010F5E
.text C:\windows\System32\svchost.exe[6096] kernel32.dll!CreateNamedPipeA 76C0D577 5 Bytes JMP 00010014
.text C:\windows\System32\svchost.exe[6096] kernel32.dll!WinExec 76C0E739 5 Bytes JMP 000100C7
.text C:\windows\System32\svchost.exe[6096] kernel32.dll!VirtualProtectEx 76C0F6F1 5 Bytes JMP 00010087
.text C:\windows\System32\svchost.exe[6096] msvcrt.dll!_open 775F7E48 5 Bytes JMP 00120000
.text C:\windows\System32\svchost.exe[6096] msvcrt.dll!_wsystem 7762B04F 5 Bytes JMP 00120038
.text C:\windows\System32\svchost.exe[6096] msvcrt.dll!system 7762B16F 5 Bytes JMP 00120FAD
.text C:\windows\System32\svchost.exe[6096] msvcrt.dll!_creat 7762ED29 5 Bytes JMP 00120FD2
.text C:\windows\System32\svchost.exe[6096] msvcrt.dll!_wcreat 7763038E 5 Bytes JMP 00120027
.text C:\windows\System32\svchost.exe[6096] msvcrt.dll!_wopen 77630570 5 Bytes JMP 00120FE3
.text C:\windows\System32\svchost.exe[6096] WS2_32.dll!socket 77013F00 5 Bytes JMP 00130FE5
.text C:\windows\System32\svchost.exe[6096] ADVAPI32.dll!RegOpenKeyA 7725D2ED 5 Bytes JMP 00190000
.text C:\windows\System32\svchost.exe[6096] ADVAPI32.dll!RegCreateKeyA 7725D3C1 5 Bytes JMP 00190036
.text C:\windows\System32\svchost.exe[6096] ADVAPI32.dll!RegCreateKeyExA 77261B71 5 Bytes JMP 0019005B
.text C:\windows\System32\svchost.exe[6096] ADVAPI32.dll!RegCreateKeyW 77261CC0 5 Bytes JMP 00190FAF
.text C:\windows\System32\svchost.exe[6096] ADVAPI32.dll!RegOpenKeyW 77263129 5 Bytes JMP 0019001B
.text C:\windows\System32\svchost.exe[6096] ADVAPI32.dll!RegCreateKeyExW 7726B946 5 Bytes JMP 0019006C
.text C:\windows\System32\svchost.exe[6096] ADVAPI32.dll!RegOpenKeyExA 7726BC0D 5 Bytes JMP 00190FE5
.text C:\windows\System32\svchost.exe[6096] ADVAPI32.dll!RegOpenKeyExW 7726BEC4 5 Bytes JMP 00190FCA
.text C:\windows\system32\wuauclt.exe[6152] ntdll.dll!NtCreateFile 77494870 5 Bytes JMP 00040000
.text C:\windows\system32\wuauclt.exe[6152] ntdll.dll!NtCreateProcess 77494940 5 Bytes JMP 0004002C
.text C:\windows\system32\wuauclt.exe[6152] ntdll.dll!NtProtectVirtualMemory 774951C0 5 Bytes JMP 0004001B
.text C:\windows\system32\wuauclt.exe[6152] kernel32.dll!GetStartupInfoA 76B81DF0 5 Bytes JMP 00010069
.text C:\windows\system32\wuauclt.exe[6152] kernel32.dll!CreateProcessW 76B8202D 5 Bytes JMP 00010F03
.text C:\windows\system32\wuauclt.exe[6152] kernel32.dll!CreateProcessA 76B82062 5 Bytes JMP 00010F14
.text C:\windows\system32\wuauclt.exe[6152] kernel32.dll!CreateNamedPipeW 76BB1FEE 5 Bytes JMP 00010FC0
.text C:\windows\system32\wuauclt.exe[6152] kernel32.dll!CreatePipe 76BB4AAB 5 Bytes JMP 00010F40
.text C:\windows\system32\wuauclt.exe[6152] kernel32.dll!VirtualProtect 76BC50CB 5 Bytes JMP 00010F65
.text C:\windows\system32\wuauclt.exe[6152] kernel32.dll!LoadLibraryExW 76BCB647 5 Bytes JMP 0001003D
.text C:\windows\system32\wuauclt.exe[6152] kernel32.dll!LoadLibraryExA 76BCBC13 5 Bytes JMP 00010022
.text C:\windows\system32\wuauclt.exe[6152] kernel32.dll!CreateFileW 76BD0AFD 5 Bytes JMP 00010011
.text C:\windows\system32\wuauclt.exe[6152] kernel32.dll!GetProcAddress 76BD17D7 5 Bytes JMP 000100A9
.text C:\windows\system32\wuauclt.exe[6152] kernel32.dll!LoadLibraryA 76BD2804 5 Bytes JMP 00010FA5
.text C:\windows\system32\wuauclt.exe[6152] kernel32.dll!LoadLibraryW 76BD2852 5 Bytes JMP 00010F8A
.text C:\windows\system32\wuauclt.exe[6152] kernel32.dll!CreateFileA 76BD289C 5 Bytes JMP 00010000
.text C:\windows\system32\wuauclt.exe[6152] kernel32.dll!GetStartupInfoW 76BD7C55 5 Bytes JMP 00010F2F
.text C:\windows\system32\wuauclt.exe[6152] kernel32.dll!CreateNamedPipeA 76C0D577 5 Bytes JMP 00010FD1
.text C:\windows\system32\wuauclt.exe[6152] kernel32.dll!WinExec 76C0E739 5 Bytes JMP 0001008E
.text C:\windows\system32\wuauclt.exe[6152] kernel32.dll!VirtualProtectEx 76C0F6F1 5 Bytes JMP 00010058
.text C:\windows\system32\wuauclt.exe[6152] msvcrt.dll!_open 775F7E48 5 Bytes JMP 00080FEF
.text C:\windows\system32\wuauclt.exe[6152] msvcrt.dll!_wsystem 7762B04F 5 Bytes JMP 00080069
.text C:\windows\system32\wuauclt.exe[6152] msvcrt.dll!system 7762B16F 5 Bytes JMP 0008004E
.text C:\windows\system32\wuauclt.exe[6152] msvcrt.dll!_creat 7762ED29 5 Bytes JMP 00080FDE
.text C:\windows\system32\wuauclt.exe[6152] msvcrt.dll!_wcreat 7763038E 5 Bytes JMP 0008003D
.text C:\windows\system32\wuauclt.exe[6152] msvcrt.dll!_wopen 77630570 5 Bytes JMP 00080018
.text C:\windows\system32\wuauclt.exe[6152] ADVAPI32.dll!RegOpenKeyA 7725D2ED 5 Bytes JMP 0009000A
.text C:\windows\system32\wuauclt.exe[6152] ADVAPI32.dll!RegCreateKeyA 7725D3C1 5 Bytes JMP 00090036
.text C:\windows\system32\wuauclt.exe[6152] ADVAPI32.dll!RegCreateKeyExA 77261B71 5 Bytes JMP 00090051
.text C:\windows\system32\wuauclt.exe[6152] ADVAPI32.dll!RegCreateKeyW 77261CC0 5 Bytes JMP 00090FAF
.text C:\windows\system32\wuauclt.exe[6152] ADVAPI32.dll!RegOpenKeyW 77263129 5 Bytes JMP 00090FE5
.text C:\windows\system32\wuauclt.exe[6152] ADVAPI32.dll!RegCreateKeyExW 7726B946 5 Bytes JMP 00090F94
.text C:\windows\system32\wuauclt.exe[6152] ADVAPI32.dll!RegOpenKeyExA 7726BC0D 5 Bytes JMP 0009001B
.text C:\windows\system32\wuauclt.exe[6152] ADVAPI32.dll!RegOpenKeyExW 7726BEC4 5 Bytes JMP 00090FCA
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\windows\system32\mfevtps.exe[1388] @ C:\windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [00DC77A0] C:\windows\system32\mfevtps.exe (McAfee Process Validation Service/McAfee, Inc.)
IAT C:\windows\system32\rundll32.exe[1524] @ C:\windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75535E25] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\windows\system32\rundll32.exe[1524] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75535E25] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\windows\system32\rundll32.exe[1524] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75535E25] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\windows\system32\rundll32.exe[1524] @ C:\windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75535E25] C:\windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\windows\Explorer.exe[6036] @ C:\windows\Explorer.exe [gdiplus.dll!GdipAlloc] [73682494] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.exe[6036] @ C:\windows\Explorer.exe [gdiplus.dll!GdiplusStartup] [73665624] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.exe[6036] @ C:\windows\Explorer.exe [gdiplus.dll!GdiplusShutdown] [736656E2] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.exe[6036] @ C:\windows\Explorer.exe [gdiplus.dll!GdipFree] [7368250F] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.exe[6036] @ C:\windows\Explorer.exe [gdiplus.dll!GdipDeleteGraphics] [73678573] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.exe[6036] @ C:\windows\Explorer.exe [gdiplus.dll!GdipDisposeImage] [73674D27] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.exe[6036] @ C:\windows\Explorer.exe [gdiplus.dll!GdipGetImageWidth] [736750CE] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.exe[6036] @ C:\windows\Explorer.exe [gdiplus.dll!GdipGetImageHeight] [736751A3] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.exe[6036] @ C:\windows\Explorer.exe [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [736766D0] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.exe[6036] @ C:\windows\Explorer.exe [gdiplus.dll!GdipCreateFromHDC] [736782CA] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.exe[6036] @ C:\windows\Explorer.exe [gdiplus.dll!GdipSetCompositingMode] [73678819] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.exe[6036] @ C:\windows\Explorer.exe [gdiplus.dll!GdipSetInterpolationMode] [7367907A] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.exe[6036] @ C:\windows\Explorer.exe [gdiplus.dll!GdipDrawImageRectI] [7367E21D] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\windows\Explorer.exe[6036] @ C:\windows\Explorer.exe [gdiplus.dll!GdipCloneImage] [73674C59] C:\windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
AttachedDevice mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
AttachedDevice tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\00000055 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
Device volmgr.sys (Volume Manager Driver/Microsoft Corporation)
Device iaStor.sys (Intel Matrix Storage Manager driver - ia32/Intel Corporation)
---- Threads - GMER 1.0.15 ----
Thread System [4:5844] 9F724730
---- EOF - GMER 1.0.15 ----
The attach.txt file is attached.
Attached File(s)
-
attach.txt (13.39K)
Number of downloads: 1
This post has been edited by faith766: 06 January 2012 - 12:22 AM

Help
This topic is locked


Back to top











