Ok here is the GMER results. There was a pop up that said "Warning your registry has been changed" or something to that effect.
As far as how the computer has been acting, well my google searches are redirected, one time there was what sounded like a video or tv show playing in the background when the computer was NOT online, it was opening up multiple new windows in IE prior to the malwarebytes scan that was done 4 days ago, my mcafee has changed its firewall settings on its own a few times (i have been putting it on lockdown when im not sitting here online), today the computer showed a blue screen which said "shutting down for safety of your files" or something. restarted ok. i have been running mcafee scans every morning and once or twice throughout the day and it always finds 2-4 items and quarantines them. I think that is it that I can remember. Thanks for your help!
GMER 1.0.15.14966 -
http://www.gmer.netRootkit scan 2009-03-29 22:31:33
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xEF0B99AA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xEF0B9A41]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xEF0B9958]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xEF0B996C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xEF0B9A55]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xEF0B9A81]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xEF0B9AF4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xEF0B9AD9]
Code 82BDDBF8 ZwFlushInstructionCache
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xEF0B99EA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xEF0B9B1E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xEF0B9A2D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xEF0B9930]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xEF0B9944]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xEF0B99BE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xEF0B9B5A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xEF0B9AC3]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xEF0B9AAD]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xEF0B9A6B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xEF0B9B46]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xEF0B9B32]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xEF0B9996]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xEF0B9982]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xEF0B9A97]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xEF0B9A19]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xEF0B9B08]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xEF0B9A00]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xEF0B99D4]
Code 82BE1ED6 IofCallDriver
Code 82C2A096 IofCompleteRequest
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!IofCallDriver 804E37C5 5 Bytes JMP 82BE1EDB
.text ntoskrnl.exe!IofCompleteRequest 804E3BF6 5 Bytes JMP 82C2A09B
.text ntoskrnl.exe!ZwYieldExecution 804F0EA6 7 Bytes JMP EF0B99D8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwOpenKey 80568D59 5 Bytes JMP EF0B9A31 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryValueKey 8056A1F2 7 Bytes JMP EF0B9AB1 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtCreateFile 8056CDC0 5 Bytes JMP EF0B99AE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtSetInformationProcess 8056DC01 5 Bytes JMP EF0B9986 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateKey 8057065D 5 Bytes JMP EF0B9A45 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryKey 80570A6D 7 Bytes JMP EF0B9B5E \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwEnumerateKey 80570D64 5 Bytes JMP EF0B9AF8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenProcess 805717C7 5 Bytes JMP EF0B9934 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwProtectVirtualMemory 80571CB1 7 Bytes JMP EF0B99C2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwSetValueKey 80572889 7 Bytes JMP EF0B9A9B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnmapViewOfSection 805736E6 5 Bytes JMP EF0B9A04 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtMapViewOfSection 80573B61 7 Bytes JMP EF0B99EE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwFlushInstructionCache 80577693 5 Bytes JMP 82BDDBFC
PAGE ntoskrnl.exe!ZwCreateProcessEx 8057FC6C 7 Bytes JMP EF0B9970 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwTerminateProcess 805822EC 5 Bytes JMP EF0B9A1D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtOpenThread 8058A1C9 5 Bytes JMP EF0B9948 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwNotifyChangeKey 8058A699 5 Bytes JMP EF0B9B22 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwEnumerateValueKey 80590677 7 Bytes JMP EF0B9ADD \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwDeleteValueKey 80592D5C 7 Bytes JMP EF0B9A85 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwDeleteKey 805952CA 7 Bytes JMP EF0B9A59 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwCreateProcess 805B136A 5 Bytes JMP EF0B995C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwSetContextThread 8062DCF7 5 Bytes JMP EF0B999A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnloadKey 8064DA12 7 Bytes JMP EF0B9B0C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwQueryMultipleValueKey 8064E338 7 Bytes JMP EF0B9AC7 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwRenameKey 8064E7B6 7 Bytes JMP EF0B9A6F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwRestoreKey 8064ECA9 5 Bytes JMP EF0B9B36 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwReplaceKey 8064F112 5 Bytes JMP EF0B9B4A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[216] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00D2000A
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[216] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 00D3000A
.text C:\WINDOWS\system32\svchost.exe[296] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01010FEF
.text C:\WINDOWS\system32\svchost.exe[296] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01010F69
.text C:\WINDOWS\system32\svchost.exe[296] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01010054
.text C:\WINDOWS\system32\svchost.exe[296] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01010F7A
.text C:\WINDOWS\system32\svchost.exe[296] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01010F97
.text C:\WINDOWS\system32\svchost.exe[296] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0101002F
.text C:\WINDOWS\system32\svchost.exe[296] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 0101007B
.text C:\WINDOWS\system32\svchost.exe[296] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01010F33
.text C:\WINDOWS\system32\svchost.exe[296] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 010100A0
.text C:\WINDOWS\system32\svchost.exe[296] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01010F07
.text C:\WINDOWS\system32\svchost.exe[296] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 01010EEC
.text C:\WINDOWS\system32\svchost.exe[296] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 01010FA8
.text C:\WINDOWS\system32\svchost.exe[296] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 01010FDE
.text C:\WINDOWS\system32\svchost.exe[296] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 01010F44
.text C:\WINDOWS\system32\svchost.exe[296] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 0101001E
.text C:\WINDOWS\system32\svchost.exe[296] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 01010FCD
.text C:\WINDOWS\system32\svchost.exe[296] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 01010F22
.text C:\WINDOWS\system32\svchost.exe[296] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00FE002C
.text C:\WINDOWS\system32\svchost.exe[296] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00FE0FAC
.text C:\WINDOWS\system32\svchost.exe[296] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00FE0011
.text C:\WINDOWS\system32\svchost.exe[296] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00FE0000
.text C:\WINDOWS\system32\svchost.exe[296] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00FE0069
.text C:\WINDOWS\system32\svchost.exe[296] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00FE0FEF
.text C:\WINDOWS\system32\svchost.exe[296] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00FE004E
.text C:\WINDOWS\system32\svchost.exe[296] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00FE003D
.text C:\WINDOWS\system32\svchost.exe[296] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00FD0FAD
.text C:\WINDOWS\system32\svchost.exe[296] msvcrt.dll!system 77C293C7 5 Bytes JMP 00FD0038
.text C:\WINDOWS\system32\svchost.exe[296] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00FD0FE3
.text C:\WINDOWS\system32\svchost.exe[296] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00FD0000
.text C:\WINDOWS\system32\svchost.exe[296] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00FD0FC8
.text C:\WINDOWS\system32\svchost.exe[296] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00FD0011
.text C:\WINDOWS\system32\svchost.exe[296] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 00FF000A
.text C:\WINDOWS\system32\svchost.exe[296] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 00FF001B
.text C:\WINDOWS\system32\svchost.exe[296] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00FF0036
.text C:\WINDOWS\system32\svchost.exe[296] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 00FF0047
.text C:\WINDOWS\system32\svchost.exe[296] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FC0FE5
.text C:\Program Files\Microsoft Office\Office\OSA.EXE[480] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 0094000A
.text C:\Program Files\Microsoft Office\Office\OSA.EXE[480] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0096000A
.text C:\WINDOWS\system32\winlogon.exe[644] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 0064000A
.text C:\WINDOWS\system32\winlogon.exe[644] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0065000A
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[668] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 0073000A
.text C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe[668] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0074000A
.text C:\WINDOWS\system32\services.exe[692] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 0064000A
.text C:\WINDOWS\system32\services.exe[692] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0065000A
.text C:\WINDOWS\system32\services.exe[692] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01580FEF
.text C:\WINDOWS\system32\services.exe[692] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 0158009A
.text C:\WINDOWS\system32\services.exe[692] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01580FA5
.text C:\WINDOWS\system32\services.exe[692] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0158007F
.text C:\WINDOWS\system32\services.exe[692] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01580058
.text C:\WINDOWS\system32\services.exe[692] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0158002C
.text C:\WINDOWS\system32\services.exe[692] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01580F63
.text C:\WINDOWS\system32\services.exe[692] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 015800AB
.text C:\WINDOWS\system32\services.exe[692] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 015800F2
.text C:\WINDOWS\system32\services.exe[692] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 015800E1
.text C:\WINDOWS\system32\services.exe[692] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 01580103
.text C:\WINDOWS\system32\services.exe[692] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 0158003D
.text C:\WINDOWS\system32\services.exe[692] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 0158000A
.text C:\WINDOWS\system32\services.exe[692] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 01580F80
.text C:\WINDOWS\system32\services.exe[692] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 01580FC0
.text C:\WINDOWS\system32\services.exe[692] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 0158001B
.text C:\WINDOWS\system32\services.exe[692] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 015800BC
.text C:\WINDOWS\system32\services.exe[692] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 0156001B
.text C:\WINDOWS\system32\services.exe[692] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 0156005B
.text C:\WINDOWS\system32\services.exe[692] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 01560FD4
.text C:\WINDOWS\system32\services.exe[692] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 0156000A
.text C:\WINDOWS\system32\services.exe[692] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 01560F9E
.text C:\WINDOWS\system32\services.exe[692] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 01560FEF
.text C:\WINDOWS\system32\services.exe[692] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 01560FB9
.text C:\WINDOWS\system32\services.exe[692] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [76, 89] {JBE 0xffffffffffffff8b}
.text C:\WINDOWS\system32\services.exe[692] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 01560040
.text C:\WINDOWS\system32\services.exe[692] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00FF0038
.text C:\WINDOWS\system32\services.exe[692] msvcrt.dll!system 77C293C7 5 Bytes JMP 00FF0FAD
.text C:\WINDOWS\system32\services.exe[692] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00FF0FE3
.text C:\WINDOWS\system32\services.exe[692] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00FF0000
.text C:\WINDOWS\system32\services.exe[692] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00FF0FC8
.text C:\WINDOWS\system32\services.exe[692] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00FF0011
.text C:\WINDOWS\system32\services.exe[692] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 01570000
.text C:\WINDOWS\system32\services.exe[692] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 01570FE5
.text C:\WINDOWS\system32\services.exe[692] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 0157001B
.text C:\WINDOWS\system32\services.exe[692] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 01570FCA
.text C:\WINDOWS\system32\services.exe[692] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FE0FEF
.text C:\WINDOWS\system32\lsass.exe[720] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 006F000A
.text C:\WINDOWS\system32\lsass.exe[720] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0072000A
.text C:\WINDOWS\system32\lsass.exe[720] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01290FEF
.text C:\WINDOWS\system32\lsass.exe[720] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 0129005B
.text C:\WINDOWS\system32\lsass.exe[720] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01290F66
.text C:\WINDOWS\system32\lsass.exe[720] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0129004A
.text C:\WINDOWS\system32\lsass.exe[720] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01290039
.text C:\WINDOWS\system32\lsass.exe[720] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01290FA8
.text C:\WINDOWS\system32\lsass.exe[720] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01290F1D
.text C:\WINDOWS\system32\lsass.exe[720] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01290F2E
.text C:\WINDOWS\system32\lsass.exe[720] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01290EE0
.text C:\WINDOWS\system32\lsass.exe[720] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01290EFB
.text C:\WINDOWS\system32\lsass.exe[720] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 01290EC5
.text C:\WINDOWS\system32\lsass.exe[720] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 01290F97
.text C:\WINDOWS\system32\lsass.exe[720] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 01290FDE
.text C:\WINDOWS\system32\lsass.exe[720] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 01290F4B
.text C:\WINDOWS\system32\lsass.exe[720] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 01290FC3
.text C:\WINDOWS\system32\lsass.exe[720] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 0129000A
.text C:\WINDOWS\system32\lsass.exe[720] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 01290F0C
.text C:\WINDOWS\system32\lsass.exe[720] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 01270FB2
.text C:\WINDOWS\system32\lsass.exe[720] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 01270F75
.text C:\WINDOWS\system32\lsass.exe[720] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 01270FC3
.text C:\WINDOWS\system32\lsass.exe[720] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 01270FDE
.text C:\WINDOWS\system32\lsass.exe[720] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 01270032
.text C:\WINDOWS\system32\lsass.exe[720] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 01270FEF
.text C:\WINDOWS\system32\lsass.exe[720] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 01270F90
.text C:\WINDOWS\system32\lsass.exe[720] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [47, 89]
.text C:\WINDOWS\system32\lsass.exe[720] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 01270FA1
.text C:\WINDOWS\system32\lsass.exe[720] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01260FBC
.text C:\WINDOWS\system32\lsass.exe[720] msvcrt.dll!system 77C293C7 5 Bytes JMP 01260FCD
.text C:\WINDOWS\system32\lsass.exe[720] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01260033
.text C:\WINDOWS\system32\lsass.exe[720] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0126000C
.text C:\WINDOWS\system32\lsass.exe[720] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01260FDE
.text C:\WINDOWS\system32\lsass.exe[720] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01260FEF
.text C:\WINDOWS\system32\lsass.exe[720] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01250000
.text C:\WINDOWS\system32\lsass.exe[720] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 01280000
.text C:\WINDOWS\system32\lsass.exe[720] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 01280FEF
.text C:\WINDOWS\system32\lsass.exe[720] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 01280FDE
.text C:\WINDOWS\system32\lsass.exe[720] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 01280FC3
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[772] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 0080000A
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[772] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0081000A
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[772] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0041C340 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[772] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 0041C3C0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe[776] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 008C000A
.text C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe[776] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 008E000A
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateFileA 7C801A28 3 Bytes JMP 010C0FE5
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateFileA + 4 7C801A2C 1 Byte [84]
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!VirtualProtectEx 7C801A61 3 Bytes JMP 010C005D
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!VirtualProtectEx + 4 7C801A65 1 Byte [84]
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!VirtualProtect 7C801AD4 3 Bytes JMP 010C004C
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!VirtualProtect + 4 7C801AD8 1 Byte [84]
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 010C0F72
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!LoadLibraryExA 7C801D53 3 Bytes JMP 010C0F83
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!LoadLibraryExA + 4 7C801D57 1 Byte [84]
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!LoadLibraryA 7C801D7B 3 Bytes JMP 010C0025
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!LoadLibraryA + 4 7C801D7F 1 Byte [84]
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!GetStartupInfoW 7C801E54 3 Bytes JMP 010C0F37
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!GetStartupInfoW + 4 7C801E58 1 Byte [84]
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 010C007F
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateProcessW 7C802336 3 Bytes JMP 010C0F01
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateProcessW + 4 7C80233A 1 Byte [84]
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateProcessA 7C80236B 3 Bytes JMP 010C009A
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateProcessA + 4 7C80236F 1 Byte [84]
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!GetProcAddress 7C80AE30 3 Bytes JMP 010C0EE6
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!GetProcAddress + 4 7C80AE34 1 Byte [84]
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!LoadLibraryW 7C80AEDB 3 Bytes JMP 010C0FA8
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!LoadLibraryW + 4 7C80AEDF 1 Byte [84]
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateFileW 7C8107F0 3 Bytes JMP 010C0FD4
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateFileW + 4 7C8107F4 1 Byte [84]
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 010C006E
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 010C000A
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 010C0FB9
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 010C0F1C
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 010A004A
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 010A0080
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 010A0025
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 010A0FEF
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 010A0FC3
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 010A000A
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 010A005B
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 010A0FD4
.text C:\WINDOWS\system32\svchost.exe[888] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01090066
.text C:\WINDOWS\system32\svchost.exe[888] msvcrt.dll!system 77C293C7 5 Bytes JMP 01090055
.text C:\WINDOWS\system32\svchost.exe[888] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01090FEF
.text C:\WINDOWS\system32\svchost.exe[888] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0109000C
.text C:\WINDOWS\system32\svchost.exe[888] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01090044
.text C:\WINDOWS\system32\svchost.exe[888] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01090029
.text C:\WINDOWS\system32\svchost.exe[888] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 010B0000
.text C:\WINDOWS\system32\svchost.exe[888] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 010B001B
.text C:\WINDOWS\system32\svchost.exe[888] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 010B0FE5
.text C:\WINDOWS\system32\svchost.exe[888] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 010B0FCA
.text C:\WINDOWS\system32\svchost.exe[888] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01060FEF
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01250FE5
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 012500A1
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01250090
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01250069
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01250FAC
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0125003D
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 012500C6
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01250F8A
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01250F45
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 012500E8
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!GetProcAddress 7C80AE30 1 Byte [E9]
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 01250F34
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 01250058
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 01250000
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 01250F9B
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 0125002C
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 0125001B
.text C:\WINDOWS\system32\svchost.exe[940] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 012500D7
.text C:\WINDOWS\system32\svchost.exe[940] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 01230FE5
.text C:\WINDOWS\system32\svchost.exe[940] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 01230F8D
.text C:\WINDOWS\system32\svchost.exe[940] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 0123002C
.text C:\WINDOWS\system32\svchost.exe[940] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 0123001B
.text C:\WINDOWS\system32\svchost.exe[940] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 01230FA8
.text C:\WINDOWS\system32\svchost.exe[940] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 0123000A
.text C:\WINDOWS\system32\svchost.exe[940] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 01230FC3
.text C:\WINDOWS\system32\svchost.exe[940] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [43, 89]
.text C:\WINDOWS\system32\svchost.exe[940] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 01230FD4
.text C:\WINDOWS\system32\svchost.exe[940] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0122007A
.text C:\WINDOWS\system32\svchost.exe[940] msvcrt.dll!system 77C293C7 5 Bytes JMP 0122005F
.text C:\WINDOWS\system32\svchost.exe[940] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01220029
.text C:\WINDOWS\system32\svchost.exe[940] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0122000C
.text C:\WINDOWS\system32\svchost.exe[940] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01220044
.text C:\WINDOWS\system32\svchost.exe[940] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01220FEF
.text C:\WINDOWS\system32\svchost.exe[940] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 01240FEF
.text C:\WINDOWS\system32\svchost.exe[940] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 0124000A
.text C:\WINDOWS\system32\svchost.exe[940] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 01240FD4
.text C:\WINDOWS\system32\svchost.exe[940] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 01240FAF
.text C:\WINDOWS\system32\svchost.exe[940] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01210000
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[996] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 006D000A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[996] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 006E000A
.text C:\WINDOWS\System32\svchost.exe[1040] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02550000
.text C:\WINDOWS\System32\svchost.exe[1040] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02550F68
.text C:\WINDOWS\System32\svchost.exe[1040] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02550F79
.text C:\WINDOWS\System32\svchost.exe[1040] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02550F8A
.text C:\WINDOWS\System32\svchost.exe[1040] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02550FA5
.text C:\WINDOWS\System32\svchost.exe[1040] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0255003D
.text C:\WINDOWS\System32\svchost.exe[1040] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02550095
.text C:\WINDOWS\System32\svchost.exe[1040] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02550084
.text C:\WINDOWS\System32\svchost.exe[1040] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02550F10
.text C:\WINDOWS\System32\svchost.exe[1040] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 02550F21
.text C:\WINDOWS\System32\svchost.exe[1040] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 025500C4
.text C:\WINDOWS\System32\svchost.exe[1040] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 02550FB6
.text C:\WINDOWS\System32\svchost.exe[1040] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 02550FE5
.text C:\WINDOWS\System32\svchost.exe[1040] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 02550F4D
.text C:\WINDOWS\System32\svchost.exe[1040] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 0255002C
.text C:\WINDOWS\System32\svchost.exe[1040] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 02550011
.text C:\WINDOWS\System32\svchost.exe[1040] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 02550F3C
.text C:\WINDOWS\System32\svchost.exe[1040] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 024B0FEF
.text C:\WINDOWS\System32\svchost.exe[1040] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 024B0FA8
.text C:\WINDOWS\System32\svchost.exe[1040] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 024B0036
.text C:\WINDOWS\System32\svchost.exe[1040] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 024B001B
.text C:\WINDOWS\System32\svchost.exe[1040] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 024B0065
.text C:\WINDOWS\System32\svchost.exe[1040] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 024B000A
.text C:\WINDOWS\System32\svchost.exe[1040] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 024B0FCD
.text C:\WINDOWS\System32\svchost.exe[1040] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [6B, 8A]
.text C:\WINDOWS\System32\svchost.exe[1040] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 024B0FDE
.text C:\WINDOWS\System32\svchost.exe[1040] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 024A004E
.text C:\WINDOWS\System32\svchost.exe[1040] msvcrt.dll!system 77C293C7 5 Bytes JMP 024A0FC3
.text C:\WINDOWS\System32\svchost.exe[1040] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 024A0029
.text C:\WINDOWS\System32\svchost.exe[1040] msvcrt.dll!_open 77C2F566 5 Bytes JMP 024A000C
.text C:\WINDOWS\System32\svchost.exe[1040] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 024A0FD4
.text C:\WINDOWS\System32\svchost.exe[1040] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 024A0FEF
.text C:\WINDOWS\System32\svchost.exe[1040] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 024C0FE5
.text C:\WINDOWS\System32\svchost.exe[1040] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 024C0000
.text C:\WINDOWS\System32\svchost.exe[1040] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 024C0FD4
.text C:\WINDOWS\System32\svchost.exe[1040] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 024C0FC3
.text C:\WINDOWS\System32\svchost.exe[1040] WS2_32.dll!socket 71AB4211 5 Bytes JMP 02490FE5
.text C:\Program Files\Bonjour\mDNSResponder.exe[1076] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 0071000A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1076] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0072000A
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00D20FEF
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00D20F79
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00D20F94
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00D2006E
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00D20FA5
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00D20036
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00D200AB
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00D2009A
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D200D7
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D20F48
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00D20F23
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00D20047
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00D2000A
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00D20089
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00D2001B
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00D20FCA
.text C:\WINDOWS\system32\svchost.exe[1080] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00D200C6
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00BD0014
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00BD0F83
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00BD0FB9
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00BD0FD4
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00BD0F9E
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00BD0FEF
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00BD0040
.text C:\WINDOWS\system32\svchost.exe[1080] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00BD002F
.text C:\WINDOWS\system32\svchost.exe[1080] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00BC0049
.text C:\WINDOWS\system32\svchost.exe[1080] msvcrt.dll!system 77C293C7 5 Bytes JMP 00BC0038
.text C:\WINDOWS\system32\svchost.exe[1080] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00BC0FD2
.text C:\WINDOWS\system32\svchost.exe[1080] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00BC0000
.text C:\WINDOWS\system32\svchost.exe[1080] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00BC0027
.text C:\WINDOWS\system32\svchost.exe[1080] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00BC0FE3
.text C:\WINDOWS\system32\svchost.exe[1080] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 00BE0FEF
.text C:\WINDOWS\system32\svchost.exe[1080] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 00BE0FD4
.text C:\WINDOWS\system32\svchost.exe[1080] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00BE000A
.text C:\WINDOWS\system32\svchost.exe[1080] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 00BE002F
.text C:\WINDOWS\system32\svchost.exe[1080] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00BB0000
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00CF0000
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00CF00A4
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00CF0093
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00CF0FAF
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00CF006C
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00CF0047
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00CF00E3
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00CF00D2
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00CF0108
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!CreateProcessA 7C80236B 1 Byte [E9]
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00CF0F6F
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00CF012D
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00CF0FCA
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00CF0011
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00CF00B5
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00CF0FDB
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00CF0022
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00CF0F8A
.text C:\WINDOWS\system32\svchost.exe[1196] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00CD0FAF
.text C:\WINDOWS\system32\svchost.exe[1196] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00CD0047
.text C:\WINDOWS\system32\svchost.exe[1196] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00CD0FC0
.text C:\WINDOWS\system32\svchost.exe[1196] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00CD0FE5
.text C:\WINDOWS\system32\svchost.exe[1196] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00CD0022
.text C:\WINDOWS\system32\svchost.exe[1196] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00CD0000
.text C:\WINDOWS\system32\svchost.exe[1196] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00CD0011
.text C:\WINDOWS\system32\svchost.exe[1196] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00CD0F94
.text C:\WINDOWS\system32\svchost.exe[1196] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00CC0FB9
.text C:\WINDOWS\system32\svchost.exe[1196] msvcrt.dll!system 77C293C7 5 Bytes JMP 00CC0FCA
.text C:\WINDOWS\system32\svchost.exe[1196] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00CC0FEF
.text C:\WINDOWS\system32\svchost.exe[1196] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00CC000C
.text C:\WINDOWS\system32\svchost.exe[1196] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00CC0044
.text C:\WINDOWS\system32\svchost.exe[1196] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00CC001D
.text C:\WINDOWS\system32\svchost.exe[1196] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 00CE0FEF
.text C:\WINDOWS\system32\svchost.exe[1196] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 00CE000A
.text C:\WINDOWS\system32\svchost.exe[1196] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00CE001B
.text C:\WINDOWS\system32\svchost.exe[1196] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 00CE0FD4
.text C:\WINDOWS\system32\svchost.exe[1196] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00CB0FEF
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1272] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 008B000A
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1272] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 008C000A
.text C:\WINDOWS\system32\svchost.exe[1320] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00FE0FE5
.text C:\WINDOWS\system32\svchost.exe[1320] kernel32.dll!VirtualProtectEx 7C801A61 1 Byte [E9]
.text C:\WINDOWS\system32\svchost.exe[1320] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00FE0065
.text C:\WINDOWS\system32\svchost.exe[1320] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00FE0054
.text C:\WINDOWS\system32\svchost.exe[1320] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00FE0F7C
.text C:\WINDOWS\system32\svchost.exe[1320] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00FE0F97
.text C:\WINDOWS\system32\svchost.exe[1320] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00FE002F
.text C:\WINDOWS\system32\svchost.exe[1320] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00FE0091
.text C:\WINDOWS\system32\svchost.exe[1320] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00FE0080
.text C:\WINDOWS\system32\svchost.exe[1320] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FE0F2E
.text C:\WINDOWS\system32\svchost.exe[1320] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FE00C7
.text C:\WINDOWS\system32\svchost.exe[1320] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00FE0F1D
.text C:\WINDOWS\system32\svchost.exe[1320] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00FE0FA8
.text C:\WINDOWS\system32\svchost.exe[1320] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00FE0000
.text C:\WINDOWS\system32\svchost.exe[1320] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00FE0F5F
.text C:\WINDOWS\system32\svchost.exe[1320] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00FE0FB9
.text C:\WINDOWS\system32\svchost.exe[1320] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00FE0FCA
.text C:\WINDOWS\system32\svchost.exe[1320] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00FE00AC
.text C:\WINDOWS\system32\svchost.exe[1320] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00F20FCA
.text C:\WINDOWS\system32\svchost.exe[1320] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00F20F8A
.text C:\WINDOWS\system32\svchost.exe[1320] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00F20FDB
.text C:\WINDOWS\system32\svchost.exe[1320] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00F20011
.text C:\WINDOWS\system32\svchost.exe[1320] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00F20047
.text C:\WINDOWS\system32\svchost.exe[1320] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00F20000
.text C:\WINDOWS\system32\svchost.exe[1320] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00F20036
.text C:\WINDOWS\system32\svchost.exe[1320] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00F20FB9
.text C:\WINDOWS\system32\svchost.exe[1320] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00F10038
.text C:\WINDOWS\system32\svchost.exe[1320] msvcrt.dll!system 77C293C7 5 Bytes JMP 00F1001D
.text C:\WINDOWS\system32\svchost.exe[1320] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00F10FC8
.text C:\WINDOWS\system32\svchost.exe[1320] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00F10000
.text C:\WINDOWS\system32\svchost.exe[1320] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00F10FAD
.text C:\WINDOWS\system32\svchost.exe[1320] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00F10FE3
.text C:\WINDOWS\system32\svchost.exe[1320] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 00F3000A
.text C:\WINDOWS\system32\svchost.exe[1320] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 00F30FEF
.text C:\WINDOWS\system32\svchost.exe[1320] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00F30FDE
.text C:\WINDOWS\system32\svchost.exe[1320] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 00F30FC3
.text C:\WINDOWS\system32\svchost.exe[1320] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00F00FE5
.text c:\program files\common files\mcafee\mna\mcnasvc.exe[1376] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00A5000A
.text c:\program files\common files\mcafee\mna\mcnasvc.exe[1376] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 00A6000A
.text C:\WINDOWS\system32\spoolsv.exe[1448] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 0097000A
.text C:\WINDOWS\system32\spoolsv.exe[1448] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0098000A
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[1644] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 006D000A
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[1644] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 006E000A
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[1788] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 0089000A
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[1788] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 008A000A
.text C:\WINDOWS\Explorer.EXE[1816] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00C0000A
.text C:\WINDOWS\Explorer.EXE[1816] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 00C1000A
.text C:\WINDOWS\Explorer.EXE[1816] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 03660FE5
.text C:\WINDOWS\Explorer.EXE[1816] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 0366004F
.text C:\WINDOWS\Explorer.EXE[1816] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 03660034
.text C:\WINDOWS\Explorer.EXE[1816] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 03660F5A
.text C:\WINDOWS\Explorer.EXE[1816] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 03660F75
.text C:\WINDOWS\Explorer.EXE[1816] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 03660F97
.text C:\WINDOWS\Explorer.EXE[1816] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 0366008A
.text C:\WINDOWS\Explorer.EXE[1816] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 03660F38
.text C:\WINDOWS\Explorer.EXE[1816] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 03660F0C
.text C:\WINDOWS\Explorer.EXE[1816] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 036600A5
.text C:\WINDOWS\Explorer.EXE[1816] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 03660EFB
.text C:\WINDOWS\Explorer.EXE[1816] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 03660F86
.text C:\WINDOWS\Explorer.EXE[1816] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 03660FD4
.text C:\WINDOWS\Explorer.EXE[1816] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 03660F49
.text C:\WINDOWS\Explorer.EXE[1816] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 03660FA8
.text C:\WINDOWS\Explorer.EXE[1816] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 03660FB9
.text C:\WINDOWS\Explorer.EXE[1816] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 03660F27
.text C:\WINDOWS\Explorer.EXE[1816] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 01B1001B
.text C:\WINDOWS\Explorer.EXE[1816] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 01B10054
.text C:\WINDOWS\Explorer.EXE[1816] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 01B10FD4
.text C:\WINDOWS\Explorer.EXE[1816] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 01B10FE5
.text C:\WINDOWS\Explorer.EXE[1816] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 01B10F97
.text C:\WINDOWS\Explorer.EXE[1816] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 01B10000
.text C:\WINDOWS\Explorer.EXE[1816] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 01B10FA8
.text C:\WINDOWS\Explorer.EXE[1816] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [D1, 89]
.text C:\WINDOWS\Explorer.EXE[1816] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 01B10FB9
.text C:\WINDOWS\Explorer.EXE[1816] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01AF0FA6
.text C:\WINDOWS\Explorer.EXE[1816] msvcrt.dll!system 77C293C7 5 Bytes JMP 01AF0031
.text C:\WINDOWS\Explorer.EXE[1816] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01AF0FC1
.text C:\WINDOWS\Explorer.EXE[1816] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01AF0FEF
.text C:\WINDOWS\Explorer.EXE[1816] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01AF0016
.text C:\WINDOWS\Explorer.EXE[1816] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01AF0FD2
.text C:\WINDOWS\Explorer.EXE[1816] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 03650000
.text C:\WINDOWS\Explorer.EXE[1816] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 03650FE5
.text C:\WINDOWS\Explorer.EXE[1816] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 03650FD4
.text C:\WINDOWS\Explorer.EXE[1816] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 0365001B
.text C:\WINDOWS\Explorer.EXE[1816] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01970FEF
.text C:\WINDOWS\system32\ctfmon.exe[2020] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 0098000A
.text C:\WINDOWS\system32\ctfmon.exe[2020] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0099000A
.text C:\WINDOWS\system32\RioMSC.exe[2032] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 006E000A
.text C:\WINDOWS\system32\RioMSC.exe[2032] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 006F000A
.text C:\WINDOWS\wanmpsvc.exe[2244] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 0076000A
.text C:\WINDOWS\wanmpsvc.exe[2244] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0077000A
.text C:\WINDOWS\System32\alg.exe[3088] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 006F000A
.text C:\WINDOWS\System32\alg.exe[3088] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0070000A
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[3908] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 0085000A
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[3908] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0086000A
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[4104] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 0084000A
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[4104] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0085000A
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[4444] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00CD000A
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[4444] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 00CF000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00A3000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 00A4000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00280FEF
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00280F66
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00280F77
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00280051
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00280F94
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00280025
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00280F4B
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00280087
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00280F15
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 002800AE
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 002800D3
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00280036
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00280FD4
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00280076
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00280FC3
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00280014
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00280F30
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00370FCA
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00370FA8
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00370011
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00370000
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 0037005B
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00370FEF
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00370040
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00370FB9
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 42F0F341 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 430A187F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 430A1800 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 430A1844 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 430A178C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 430A17C6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 430A18BA C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 42F316F6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00380050
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] msvcrt.dll!system 77C293C7 5 Bytes JMP 0038003F
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00380FD9
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0038000C
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0038002E
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0038001D
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] WININET.dll!HttpAddRequestHeadersA 7805FB35 5 Bytes JMP 00E2000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 00BE0000
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 00BE0011
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00BE0022
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 00BE0033
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] WININET.dll!HttpAddRequestHeadersW 780CCF65 5 Bytes JMP 00EA000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 00EBFC50 \\?\globalroot\systemroot\system32\UACoulnxwpm.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00EC0CC0 \\?\globalroot\systemroot\system32\UACoulnxwpm.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00F90000
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 00EC0B00 \\?\globalroot\systemroot\system32\UACoulnxwpm.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00EC09E0 \\?\globalroot\systemroot\system32\UACoulnxwpm.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] WS2_32.dll!gethostbyname 71AB5355 5 Bytes JMP 00EC0000 \\?\globalroot\systemroot\system32\UACoulnxwpm.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[7220] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00EC0230 \\?\globalroot\systemroot\system32\UACoulnxwpm.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00A3000A
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 00A4000A
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00280FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 0028006A
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00280059
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00280032
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00280F75
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00280FA1
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 0028008C
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 0028007B
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 002800B1
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00280F0E
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 002800C2
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00280F90
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00280FDE
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00280F5A
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00280FB2
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00280FCD
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00280F29
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00370036
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00370F8A
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 0037001B
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00370FE5
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00370FA5
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00370000
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 00370FC0
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [57, 88]
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00370047
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 42F0F341 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 430A187F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 430A1800 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 430A1844 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 430A178C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 430A17C6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 430A18BA C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 42F316F6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00380042
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] msvcrt.dll!system 77C293C7 5 Bytes JMP 00380FB7
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00380FE3
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0038000C
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00380FC8
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0038001D
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] WININET.dll!HttpAddRequestHeadersA 7805FB35 5 Bytes JMP 00E2000A
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 00BE0000
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 00BE0FDB
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00BE001B
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 00BE0FC0
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] WININET.dll!HttpAddRequestHeadersW 780CCF65 5 Bytes JMP 00EA000A
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 00EBFC50 \\?\globalroot\systemroot\system32\UACoulnxwpm.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00EC0CC0 \\?\globalroot\systemroot\system32\UACoulnxwpm.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00F90FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 00EC0B00 \\?\globalroot\systemroot\system32\UACoulnxwpm.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00EC09E0 \\?\globalroot\systemroot\system32\UACoulnxwpm.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] WS2_32.dll!gethostbyname 71AB5355 5 Bytes JMP 00EC0000 \\?\globalroot\systemroot\system32\UACoulnxwpm.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[7892] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00EC0230 \\?\globalroot\systemroot\system32\UACoulnxwpm.dll
.text C:\DOCUME~1\Stacy\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe[8780] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 009E000A
.text C:\DOCUME~1\Stacy\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe[8780] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 009F000A
.text C:\Documents and Settings\Stacy\Desktop\z5ou3jbw.exe[9828] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 009E000A
.text C:\Documents and Settings\Stacy\Desktop\z5ou3jbw.exe[9828] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 009F000A
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
---- Modules - GMER 1.0.15 ----
Module \systemroot\system32\drivers\UACsucbivkj.sys (*** hidden *** ) F88C8000-F88D7000 (61440 bytes)
---- Processes - GMER 1.0.15 ----
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\Program Files\McAfee.com\Agent\mcagent.exe [216] 0x00DE0000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [296] 0x00A00000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\Program Files\Microsoft Office\Office\OSA.EXE [480] 0x00D30000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\WINDOWS\system32\winlogon.exe [644] 0x00870000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [668] 0x00B10000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\WINDOWS\system32\services.exe [692] 0x00970000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\WINDOWS\system32\lsass.exe [720] 0x00A30000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [772] 0x00AF0000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe [776] 0x00CB0000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [888] 0x00A00000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [940] 0x00A00000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [996] 0x00AC0000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [1040] 0x00A00000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\Program Files\Bonjour\mDNSResponder.exe [1076] 0x00B00000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1080] 0x00A00000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1196] 0x00A00000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [1272] 0x00B90000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1320] 0x00A00000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ c:\program files\common files\mcafee\mna\mcnasvc.exe [1376] 0x00D30000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\WINDOWS\system32\spoolsv.exe [1448] 0x00C90000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [1644] 0x00AC0000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\Program Files\McAfee\MPF\MPFSrv.exe [1788] 0x00B80000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\WINDOWS\Explorer.EXE [1816] 0x00D00000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\WINDOWS\system32\ctfmon.exe [2020] 0x00CA0000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\WINDOWS\system32\RioMSC.exe [2032] 0x00AD0000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\WINDOWS\wanmpsvc.exe [2244] 0x00B40000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\WINDOWS\System32\alg.exe [3088] 0x00A10000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [3908] 0x00B40000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [4104] 0x00B20000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe [4444] 0x00DA0000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\Program Files\Internet Explorer\Iexplore.exe [7220] 0x00EB0000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\Program Files\Internet Explorer\iexplore.exe [7892] 0x00EB0000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\DOCUME~1\Stacy\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe [8780] 0x00DD0000
Library \\?\globalroot\systemroot\system32\UACoulnxwpm.dll (*** hidden *** ) @ C:\Documents and Settings\Stacy\Desktop\z5ou3jbw.exe [9828] 0x00DD0000
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\drivers\UACsucbivkj.sys (*** hidden *** ) [SYSTEM] UACd.sys <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@imagepath \systemroot\system32\drivers\UACsucbivkj.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@UACd \\?\globalroot\systemroot\system32\drivers\UACsucbivkj.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@UACc \\?\globalroot\systemroot\system32\UACyxxuoxsr.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacsr \\?\globalroot\systemroot\system32\UACapuumnbo.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uaclog \\?\globalroot\systemroot\system32\UACesxutbhy.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacmask \\?\globalroot\systemroot\system32\UAClqgoendm.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacserf \\?\globalroot\systemroot\system32\UACpudubgoy.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacbbr \\?\globalroot\systemroot\system32\UACoulnxwpm.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@UACproc \\?\globalroot\systemroot\system32\UACwfvldvkt.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacurls \\?\globalroot\systemroot\system32\UACqrjddmxt.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacerrors \\?\globalroot\systemroot\system32\UACaiddudju.log
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@imagepath \systemroot\system32\drivers\UACsucbivkj.sys
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@UACd \\?\globalroot\systemroot\system32\drivers\UACsucbivkj.sys
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@UACc \\?\globalroot\systemroot\system32\UACyxxuoxsr.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacsr \\?\globalroot\systemroot\system32\UACapuumnbo.dat
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uaclog \\?\globalroot\systemroot\system32\UACesxutbhy.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacmask \\?\globalroot\systemroot\system32\UAClqgoendm.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacserf \\?\globalroot\systemroot\system32\UACpudubgoy.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacbbr \\?\globalroot\systemroot\system32\UACoulnxwpm.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@UACproc \\?\globalroot\systemroot\system32\UACwfvldvkt.log
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacurls \\?\globalroot\systemroot\system32\UACqrjddmxt.log
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacerrors \\?\globalroot\systemroot\system32\UACaiddudju.log
Reg HKLM\SOFTWARE\Classes\so_activex.SOActiveX@ SOActiveX Class
Reg HKLM\SOFTWARE\Classes\so_activex.SOActiveX\CLSID
Reg HKLM\SOFTWARE\Classes\so_activex.SOActiveX\CLSID@ {67F2A879-82D5-4A6D-8CC5-FFB3C114B69D}
Reg HKLM\SOFTWARE\Classes\so_activex.SOActiveX\CurVer
Reg HKLM\SOFTWARE\Classes\so_activex.SOActiveX\CurVer@ so_activex.SOActiveX.1
Reg HKLM\SOFTWARE\Classes\so_activex.SOActiveX.1@ SOActiveX Class
Reg HKLM\SOFTWARE\Classes\so_activex.SOActiveX.1\CLSID
Reg HKLM\SOFTWARE\Classes\so_activex.SOActiveX.1\CLSID@ {67F2A879-82D5-4A6D-8CC5-FFB3C114B69D}
---- Files - GMER 1.0.15 ----
File C:\Documents and Settings\Stacy\Local Settings\Temp\UAC67b6.tmp 343040 bytes executable
File C:\Documents and Settings\Stacy\Local Settings\Temporary Internet Files\Content.IE5\663077YY\s14502868239_4527[1].jpg 0 bytes
File C:\Documents and Settings\Stacy\Local Settings\Temporary Internet Files\Content.IE5\663077YY\s691842011_1710316_2064397[1].jpg 0 bytes
File C:\Documents and Settings\Stacy\Local Settings\Temporary Internet Files\Content.IE5\663077YY\photo-thumb-94959[1].jpg 1230 bytes
File C:\Documents and Settings\Stacy\Local Settings\Temporary Internet Files\Content.IE5\663077YY\__utm[7].gif 35 bytes
File C:\Documents and Settings\Stacy\Local Settings\Temporary Internet Files\Content.IE5\663077YY\q1474570358_6171[1].jpg 2196 bytes
File C:\Documents and Settings\Stacy\Local Settings\Temporary Internet Files\Content.IE5\663077YY\q1581340026_8496[1].jpg 2801 bytes
File C:\Documents and Settings\Stacy\Local Settings\Temporary Internet Files\Content.IE5\663077YY\q1582342544_5309[1].jpg 2113 bytes
File C:\Documents and Settings\Stacy\Local Settings\Temporary Internet Files\Content.IE5\663077YY\q615898423_3449[1].jpg 2908 bytes
File C:\WINDOWS\system32\drivers\UACsucbivkj.sys 49664 bytes executable <-- ROOTKIT !!!
File C:\WINDOWS\system32\UACaiddudju.log 111 bytes
File C:\WINDOWS\system32\UACapuumnbo.dat 127 bytes
File C:\WINDOWS\system32\UACesxutbhy.dll 19968 bytes executable
File C:\WINDOWS\system32\uacinit.dll 5501 bytes
File C:\WINDOWS\system32\UAClqgoendm.dll 17408 bytes executable
File C:\WINDOWS\system32\UACoulnxwpm.dll 66048 bytes
File C:\WINDOWS\system32\UACpudubgoy.dll 18944 bytes executable
File C:\WINDOWS\system32\UACwfvldvkt.log 3468 bytes
File C:\WINDOWS\system32\UACyxxuoxsr.dll 23552 bytes executable
---- EOF - GMER 1.0.15 ----