Here is my GMER log
GMER 1.0.15.14972 -
http://www.gmer.netRootkit scan 2009-06-16 14:24:37
Windows 6.0.6000
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0x806FF282]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0x806FF474]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0x806FEF32]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateUserProcess [0x806FF67C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0x8CC2B9C0]
Code 86CF78A0 ZwEnumerateKey
Code 86CF7B88 ZwFlushInstructionCache
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0x8CC2B9FE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0x8CC2BA41]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0x8CC2B930]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0x8CC2B944]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0x8CC2B9D4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0x8CC2BA69]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0x8CC2BA55]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0x8CC2B9AC]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0x8CC2B998]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0x8CC2BA14]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0x8CC2B9EA]
Code 86C5432D IofCallDriver
Code 86CF294E IofCompleteRequest
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!IofCallDriver 82027F37 5 Bytes JMP 86C54332
.text ntkrnlpa.exe!IofCompleteRequest 82027FA4 5 Bytes JMP 86CF2953
.text ntkrnlpa.exe!ZwYieldExecution 820B5AC6 5 Bytes JMP 8CC2B9EE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateKey 82137F06 5 Bytes JMP 86CF78A4
PAGE ntkrnlpa.exe!ZwNotifyChangeKey 8213870A 5 Bytes JMP 8CC2BA45 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRestoreKey 82139BA2 5 Bytes JMP 8CC2BA59 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwReplaceKey 8213BD3E 5 Bytes JMP 8CC2BA6D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtCreateFile 8218EC4E 5 Bytes JMP 8CC2B9C4 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 821D01E6 7 Bytes JMP 8CC2BA02 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 821E0BD0 5 Bytes JMP 8CC2BA18 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 821E849F 5 Bytes JMP 86CF7B8C
PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 821E8753 7 Bytes JMP 8CC2B9D8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess 822138F5 5 Bytes JMP 8CC2B934 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 82213C57 5 Bytes JMP 8CC2B948 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetInformationProcess 82215D0D 5 Bytes JMP 8CC2B99C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetContextThread 8221ACF3 5 Bytes JMP 8CC2B9B0 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[324] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[324] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[324] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe[380] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe[380] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe[380] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\csrss.exe[456] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\csrss.exe[456] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\csrss.exe[456] KERNEL32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[500] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[500] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\wininit.exe[500] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\csrss.exe[508] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\csrss.exe[508] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\csrss.exe[508] KERNEL32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\services.exe[548] kernel32.dll!VirtualProtect 773218BF 5 Bytes JMP 0073005B
.text C:\Windows\system32\services.exe[548] kernel32.dll!GetStartupInfoW 7732191A 5 Bytes JMP 00730F30
.text C:\Windows\system32\services.exe[548] kernel32.dll!GetStartupInfoA 773219B8 5 Bytes JMP 00730F41
.text C:\Windows\system32\services.exe[548] kernel32.dll!CreateProcessW 77321D27 5 Bytes JMP 0073009B
.text C:\Windows\system32\services.exe[548] kernel32.dll!CreateProcessA 77321D5C 5 Bytes JMP 00730F04
.text C:\Windows\system32\services.exe[548] kernel32.dll!CreateNamedPipeA 77322484 5 Bytes JMP 0073000A
.text C:\Windows\system32\services.exe[548] kernel32.dll!WinExec 773232DF 5 Bytes JMP 00730F1F
.text C:\Windows\system32\services.exe[548] kernel32.dll!CreateNamedPipeW 7732EDFE 5 Bytes JMP 00730025
.text C:\Windows\system32\services.exe[548] kernel32.dll!CreatePipe 7733B0AF 5 Bytes JMP 00730F52
.text C:\Windows\system32\services.exe[548] kernel32.dll!VirtualProtectEx 773460AB 5 Bytes JMP 0073006C
.text C:\Windows\system32\services.exe[548] kernel32.dll!LoadLibraryExW 773495A7 5 Bytes JMP 00730F8D
.text C:\Windows\system32\services.exe[548] kernel32.dll!LoadLibraryW 7734971F 5 Bytes JMP 00730FAF
.text C:\Windows\system32\services.exe[548] kernel32.dll!LoadLibraryExA 77349A6E 5 Bytes JMP 00730F9E
.text C:\Windows\system32\services.exe[548] kernel32.dll!LoadLibraryA 77349A96 5 Bytes JMP 00730036
.text C:\Windows\system32\services.exe[548] kernel32.dll!GetProcAddress 77364110 5 Bytes JMP 00730EF3
.text C:\Windows\system32\services.exe[548] kernel32.dll!CreateFileW 7736866C 5 Bytes JMP 00730FD4
.text C:\Windows\system32\services.exe[548] kernel32.dll!CreateFileA 77368CA4 5 Bytes JMP 00730FEF
.text C:\Windows\system32\services.exe[548] ADVAPI32.dll!RegCreateKeyW 77278229 5 Bytes JMP 00190025
.text C:\Windows\system32\services.exe[548] ADVAPI32.dll!RegCreateKeyExA 77283941 5 Bytes JMP 00190F7F
.text C:\Windows\system32\services.exe[548] ADVAPI32.dll!RegCreateKeyA 77283B9F 5 Bytes JMP 00190F90
.text C:\Windows\system32\services.exe[548] ADVAPI32.dll!RegCreateKeyExW 772904A2 5 Bytes JMP 00190042
.text C:\Windows\system32\services.exe[548] ADVAPI32.dll!RegOpenKeyExA 77290DDF 5 Bytes JMP 00190000
.text C:\Windows\system32\services.exe[548] ADVAPI32.dll!RegOpenKeyW 77297B8D 5 Bytes JMP 00190FD4
.text C:\Windows\system32\services.exe[548] ADVAPI32.dll!RegOpenKeyA 7729EAEA 5 Bytes JMP 00190FEF
.text C:\Windows\system32\services.exe[548] ADVAPI32.dll!RegOpenKeyExW 772A5ECD 5 Bytes JMP 00190FA1
.text C:\Windows\system32\services.exe[548] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\services.exe[548] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0B0F5A
.text C:\Windows\system32\services.exe[548] msvcrt.dll!_open 763BA890 5 Bytes JMP 00180FEF
.text C:\Windows\system32\services.exe[548] msvcrt.dll!_wsystem 763EAA4F 5 Bytes JMP 00180FAB
.text C:\Windows\system32\services.exe[548] msvcrt.dll!system 763EAB6B 5 Bytes JMP 00180036
.text C:\Windows\system32\services.exe[548] msvcrt.dll!_creat 763EE711 5 Bytes JMP 00180000
.text C:\Windows\system32\services.exe[548] msvcrt.dll!_wcreat 763EF9C6 5 Bytes JMP 0018001B
.text C:\Windows\system32\services.exe[548] msvcrt.dll!_wopen 763EFBA1 5 Bytes JMP 00180FC6
.text C:\Windows\system32\services.exe[548] WS2_32.dll!socket 77A64358 5 Bytes JMP 00780FEF
.text C:\Windows\system32\winlogon.exe[576] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\winlogon.exe[576] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\winlogon.exe[576] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\lsass.exe[600] kernel32.dll!VirtualProtect 773218BF 5 Bytes JMP 001D0F68
.text C:\Windows\system32\lsass.exe[600] kernel32.dll!GetStartupInfoW 7732191A 5 Bytes JMP 001D0F17
.text C:\Windows\system32\lsass.exe[600] kernel32.dll!GetStartupInfoA 773219B8 5 Bytes JMP 001D0F28
.text C:\Windows\system32\lsass.exe[600] kernel32.dll!CreateProcessW 77321D27 5 Bytes JMP 001D008C
.text C:\Windows\system32\lsass.exe[600] kernel32.dll!CreateProcessA 77321D5C 5 Bytes JMP 001D0EF5
.text C:\Windows\system32\lsass.exe[600] kernel32.dll!CreateNamedPipeA 77322484 5 Bytes JMP 001D0FB9
.text C:\Windows\system32\lsass.exe[600] kernel32.dll!WinExec 773232DF 5 Bytes JMP 001D0F06
.text C:\Windows\system32\lsass.exe[600] kernel32.dll!CreateNamedPipeW 7732EDFE 5 Bytes JMP 001D0000
.text C:\Windows\system32\lsass.exe[600] kernel32.dll!CreatePipe 7733B0AF 5 Bytes JMP 001D0053
.text C:\Windows\system32\lsass.exe[600] kernel32.dll!VirtualProtectEx 773460AB 5 Bytes JMP 001D0F43
.text C:\Windows\system32\lsass.exe[600] kernel32.dll!LoadLibraryExW 773495A7 5 Bytes JMP 001D0036
.text C:\Windows\system32\lsass.exe[600] kernel32.dll!LoadLibraryW 7734971F 5 Bytes JMP 001D0F83
.text C:\Windows\system32\lsass.exe[600] kernel32.dll!LoadLibraryExA 77349A6E 5 Bytes JMP 001D0025
.text C:\Windows\system32\lsass.exe[600] kernel32.dll!LoadLibraryA 77349A96 5 Bytes JMP 001D0F94
.text C:\Windows\system32\lsass.exe[600] kernel32.dll!GetProcAddress 77364110 5 Bytes JMP 001D009D
.text C:\Windows\system32\lsass.exe[600] kernel32.dll!CreateFileW 7736866C 5 Bytes JMP 001D0FD4
.text C:\Windows\system32\lsass.exe[600] kernel32.dll!CreateFileA 77368CA4 5 Bytes JMP 001D0FEF
.text C:\Windows\system32\lsass.exe[600] ADVAPI32.dll!RegCreateKeyW 77278229 5 Bytes JMP 001C0051
.text C:\Windows\system32\lsass.exe[600] ADVAPI32.dll!RegCreateKeyExA 77283941 5 Bytes JMP 001C006E
.text C:\Windows\system32\lsass.exe[600] ADVAPI32.dll!RegCreateKeyA 77283B9F 5 Bytes JMP 001C0036
.text C:\Windows\system32\lsass.exe[600] ADVAPI32.dll!RegCreateKeyExW 772904A2 5 Bytes JMP 001C0FAB
.text C:\Windows\system32\lsass.exe[600] ADVAPI32.dll!RegOpenKeyExA 77290DDF 5 Bytes JMP 001C0014
.text C:\Windows\system32\lsass.exe[600] ADVAPI32.dll!RegOpenKeyW 77297B8D 5 Bytes JMP 001C0FDE
.text C:\Windows\system32\lsass.exe[600] ADVAPI32.dll!RegOpenKeyA 7729EAEA 5 Bytes JMP 001C0FEF
.text C:\Windows\system32\lsass.exe[600] ADVAPI32.dll!RegOpenKeyExW 772A5ECD 5 Bytes JMP 001C0025
.text C:\Windows\system32\lsass.exe[600] msvcrt.dll!_open 763BA890 5 Bytes JMP 001B000C
.text C:\Windows\system32\lsass.exe[600] msvcrt.dll!_wsystem 763EAA4F 5 Bytes JMP 001B0055
.text C:\Windows\system32\lsass.exe[600] msvcrt.dll!system 763EAB6B 5 Bytes JMP 001B0044
.text C:\Windows\system32\lsass.exe[600] msvcrt.dll!_creat 763EE711 5 Bytes JMP 001B0029
.text C:\Windows\system32\lsass.exe[600] msvcrt.dll!_wcreat 763EF9C6 5 Bytes JMP 001B0FD4
.text C:\Windows\system32\lsass.exe[600] msvcrt.dll!_wopen 763EFBA1 5 Bytes JMP 001B0FEF
.text C:\Windows\system32\lsass.exe[600] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\lsass.exe[600] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0B0F5A
.text C:\Windows\system32\lsass.exe[600] WS2_32.dll!socket 77A64358 5 Bytes JMP 008D0FEF
.text C:\Windows\system32\lsm.exe[608] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsm.exe[608] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\lsm.exe[608] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[780] kernel32.dll!VirtualProtect 773218BF 5 Bytes JMP 01010FB2
.text C:\Windows\system32\svchost.exe[780] kernel32.dll!GetStartupInfoW 7732191A 5 Bytes JMP 010100F1
.text C:\Windows\system32\svchost.exe[780] kernel32.dll!GetStartupInfoA 773219B8 5 Bytes JMP 010100CC
.text C:\Windows\system32\svchost.exe[780] kernel32.dll!CreateProcessW 77321D27 5 Bytes JMP 01010F75
.text C:\Windows\system32\svchost.exe[780] kernel32.dll!CreateProcessA 77321D5C 5 Bytes JMP 01010102
.text C:\Windows\system32\svchost.exe[780] kernel32.dll!CreateNamedPipeA 77322484 5 Bytes JMP 0101001B
.text C:\Windows\system32\svchost.exe[780] kernel32.dll!WinExec 773232DF 5 Bytes JMP 01010F90
.text C:\Windows\system32\svchost.exe[780] kernel32.dll!CreateNamedPipeW 7732EDFE 5 Bytes JMP 01010040
.text C:\Windows\system32\svchost.exe[780] kernel32.dll!CreatePipe 7733B0AF 5 Bytes JMP 01010FA1
.text C:\Windows\system32\svchost.exe[780] kernel32.dll!VirtualProtectEx 773460AB 5 Bytes JMP 010100A7
.text C:\Windows\system32\svchost.exe[780] kernel32.dll!LoadLibraryExW 773495A7 5 Bytes JMP 01010080
.text C:\Windows\system32\svchost.exe[780] kernel32.dll!LoadLibraryW 7734971F 5 Bytes JMP 01010FC3
.text C:\Windows\system32\svchost.exe[780] kernel32.dll!LoadLibraryExA 77349A6E 5 Bytes JMP 01010065
.text C:\Windows\system32\svchost.exe[780] kernel32.dll!LoadLibraryA 77349A96 5 Bytes JMP 01010FD4
.text C:\Windows\system32\svchost.exe[780] kernel32.dll!GetProcAddress 77364110 5 Bytes JMP 01010F64
.text C:\Windows\system32\svchost.exe[780] kernel32.dll!CreateFileW 7736866C 5 Bytes JMP 01010000
.text C:\Windows\system32\svchost.exe[780] kernel32.dll!CreateFileA 77368CA4 5 Bytes JMP 01010FEF
.text C:\Windows\system32\svchost.exe[780] msvcrt.dll!_open 763BA890 5 Bytes JMP 00E70FE3
.text C:\Windows\system32\svchost.exe[780] msvcrt.dll!_wsystem 763EAA4F 2 Bytes JMP 00E70050
.text C:\Windows\system32\svchost.exe[780] msvcrt.dll!_wsystem + 3 763EAA52 2 Bytes [A8, 8A] {TEST AL, 0x8a}
.text C:\Windows\system32\svchost.exe[780] msvcrt.dll!system 763EAB6B 5 Bytes JMP 00E7003F
.text C:\Windows\system32\svchost.exe[780] msvcrt.dll!_creat 763EE711 5 Bytes JMP 00E7001D
.text C:\Windows\system32\svchost.exe[780] msvcrt.dll!_wcreat 763EF9C6 5 Bytes JMP 00E7002E
.text C:\Windows\system32\svchost.exe[780] msvcrt.dll!_wopen 763EFBA1 5 Bytes JMP 00E7000C
.text C:\Windows\system32\svchost.exe[780] ADVAPI32.dll!RegCreateKeyW 77278229 5 Bytes JMP 00FC005A
.text C:\Windows\system32\svchost.exe[780] ADVAPI32.dll!RegCreateKeyExA 77283941 5 Bytes JMP 00FC0077
.text C:\Windows\system32\svchost.exe[780] ADVAPI32.dll!RegCreateKeyA 77283B9F 5 Bytes JMP 00FC0FCF
.text C:\Windows\system32\svchost.exe[780] ADVAPI32.dll!RegCreateKeyExW 772904A2 5 Bytes JMP 00FC0094
.text C:\Windows\system32\svchost.exe[780] ADVAPI32.dll!RegOpenKeyExA 77290DDF 5 Bytes JMP 00FC002C
.text C:\Windows\system32\svchost.exe[780] ADVAPI32.dll!RegOpenKeyW 77297B8D 5 Bytes JMP 00FC001B
.text C:\Windows\system32\svchost.exe[780] ADVAPI32.dll!RegOpenKeyA 7729EAEA 5 Bytes JMP 00FC000A
.text C:\Windows\system32\svchost.exe[780] ADVAPI32.dll!RegOpenKeyExW 772A5ECD 5 Bytes JMP 00FC003D
.text C:\Windows\system32\svchost.exe[780] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[780] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0B0F5A
.text C:\Windows\system32\svchost.exe[780] WS2_32.dll!socket 77A64358 5 Bytes JMP 01020000
.text C:\Windows\system32\svchost.exe[780] WININET.dll!InternetOpenA 7603D6C0 5 Bytes JMP 00DE0FEF
.text C:\Windows\system32\svchost.exe[780] WININET.dll!InternetOpenW 7603DB39 5 Bytes JMP 00DE0000
.text C:\Windows\system32\svchost.exe[780] WININET.dll!InternetOpenUrlA 7603F3D4 5 Bytes JMP 00DE0FCA
.text C:\Windows\system32\svchost.exe[780] WININET.dll!InternetOpenUrlW 76086DD7 5 Bytes JMP 00DE0FB9
.text C:\Windows\system32\nvvsvc.exe[836] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\nvvsvc.exe[836] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\nvvsvc.exe[836] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[852] kernel32.dll!VirtualProtect 773218BF 5 Bytes JMP 00E10F7C
.text C:\Windows\system32\svchost.exe[852] kernel32.dll!GetStartupInfoW 7732191A 5 Bytes JMP 00E10096
.text C:\Windows\system32\svchost.exe[852] kernel32.dll!GetStartupInfoA 773219B8 5 Bytes JMP 00E10071
.text C:\Windows\system32\svchost.exe[852] kernel32.dll!CreateProcessW 77321D27 5 Bytes JMP 00E100C2
.text C:\Windows\system32\svchost.exe[852] kernel32.dll!CreateProcessA 77321D5C 5 Bytes JMP 00E100B1
.text C:\Windows\system32\svchost.exe[852] kernel32.dll!CreateNamedPipeA 77322484 5 Bytes JMP 00E10FD4
.text C:\Windows\system32\svchost.exe[852] kernel32.dll!WinExec 773232DF 5 Bytes JMP 00E10F2B
.text C:\Windows\system32\svchost.exe[852] kernel32.dll!CreateNamedPipeW 7732EDFE 5 Bytes JMP 00E10FC3
.text C:\Windows\system32\svchost.exe[852] kernel32.dll!CreatePipe 7733B0AF 5 Bytes JMP 00E10F50
.text C:\Windows\system32\svchost.exe[852] kernel32.dll!VirtualProtectEx 773460AB 5 Bytes JMP 00E10F61
.text C:\Windows\system32\svchost.exe[852] kernel32.dll!LoadLibraryExW 773495A7 5 Bytes JMP 00E10056
.text C:\Windows\system32\svchost.exe[852] kernel32.dll!LoadLibraryW 7734971F 5 Bytes JMP 00E10FA8
.text C:\Windows\system32\svchost.exe[852] kernel32.dll!LoadLibraryExA 77349A6E 5 Bytes JMP 00E10F8D
.text C:\Windows\system32\svchost.exe[852] kernel32.dll!LoadLibraryA 77349A96 5 Bytes JMP 00E1002F
.text C:\Windows\system32\svchost.exe[852] kernel32.dll!GetProcAddress 77364110 5 Bytes JMP 00E10F06
.text C:\Windows\system32\svchost.exe[852] kernel32.dll!CreateFileW 7736866C 5 Bytes JMP 00E1000A
.text C:\Windows\system32\svchost.exe[852] kernel32.dll!CreateFileA 77368CA4 5 Bytes JMP 00E10FE5
.text C:\Windows\system32\svchost.exe[852] msvcrt.dll!_open 763BA890 5 Bytes JMP 00CB0FEF
.text C:\Windows\system32\svchost.exe[852] msvcrt.dll!_wsystem 763EAA4F 5 Bytes JMP 00CB0F9F
.text C:\Windows\system32\svchost.exe[852] msvcrt.dll!system 763EAB6B 5 Bytes JMP 00CB0FB0
.text C:\Windows\system32\svchost.exe[852] msvcrt.dll!_creat 763EE711 5 Bytes JMP 00CB0016
.text C:\Windows\system32\svchost.exe[852] msvcrt.dll!_wcreat 763EF9C6 5 Bytes JMP 00CB0FC1
.text C:\Windows\system32\svchost.exe[852] msvcrt.dll!_wopen 763EFBA1 5 Bytes JMP 00CB0FDE
.text C:\Windows\system32\svchost.exe[852] ADVAPI32.dll!RegCreateKeyW 77278229 5 Bytes JMP 00E00049
.text C:\Windows\system32\svchost.exe[852] ADVAPI32.dll!RegCreateKeyExA 77283941 5 Bytes JMP 00E00064
.text C:\Windows\system32\svchost.exe[852] ADVAPI32.dll!RegCreateKeyA 77283B9F 5 Bytes JMP 00E00FBE
.text C:\Windows\system32\svchost.exe[852] ADVAPI32.dll!RegCreateKeyExW 772904A2 5 Bytes JMP 00E00FAD
.text C:\Windows\system32\svchost.exe[852] ADVAPI32.dll!RegOpenKeyExA 77290DDF 5 Bytes JMP 00E00FCF
.text C:\Windows\system32\svchost.exe[852] ADVAPI32.dll!RegOpenKeyW 77297B8D 5 Bytes JMP 00E00011
.text C:\Windows\system32\svchost.exe[852] ADVAPI32.dll!RegOpenKeyA 7729EAEA 5 Bytes JMP 00E00000
.text C:\Windows\system32\svchost.exe[852] ADVAPI32.dll!RegOpenKeyExW 772A5ECD 5 Bytes JMP 00E0002E
.text C:\Windows\system32\svchost.exe[852] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[852] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0B0F5A
.text C:\Windows\system32\svchost.exe[852] WS2_32.dll!socket 77A64358 5 Bytes JMP 00E20000
.text C:\Windows\system32\svchost.exe[852] WININET.dll!InternetOpenA 7603D6C0 5 Bytes JMP 00CA0000
.text C:\Windows\system32\svchost.exe[852] WININET.dll!InternetOpenW 7603DB39 5 Bytes JMP 00CA001B
.text C:\Windows\system32\svchost.exe[852] WININET.dll!InternetOpenUrlA 7603F3D4 5 Bytes JMP 00CA0FE5
.text C:\Windows\system32\svchost.exe[852] WININET.dll!InternetOpenUrlW 76086DD7 5 Bytes JMP 00CA0036
.text C:\Windows\System32\svchost.exe[1008] kernel32.dll!VirtualProtect 773218BF 5 Bytes JMP 00FC006F
.text C:\Windows\System32\svchost.exe[1008] kernel32.dll!GetStartupInfoW 7732191A 5 Bytes JMP 00FC0F47
.text C:\Windows\System32\svchost.exe[1008] kernel32.dll!GetStartupInfoA 773219B8 5 Bytes JMP 00FC0F58
.text C:\Windows\System32\svchost.exe[1008] kernel32.dll!CreateProcessW 77321D27 5 Bytes JMP 00FC0F00
.text C:\Windows\System32\svchost.exe[1008] kernel32.dll!CreateProcessA 77321D5C 5 Bytes JMP 00FC0F1B
.text C:\Windows\System32\svchost.exe[1008] kernel32.dll!CreateNamedPipeA 77322484 5 Bytes JMP 00FC001B
.text C:\Windows\System32\svchost.exe[1008] kernel32.dll!WinExec 773232DF 5 Bytes JMP 00FC0F36
.text C:\Windows\System32\svchost.exe[1008] kernel32.dll!CreateNamedPipeW 7732EDFE 5 Bytes JMP 00FC0FD4
.text C:\Windows\System32\svchost.exe[1008] kernel32.dll!CreatePipe 7733B0AF 5 Bytes JMP 00FC0F69
.text C:\Windows\System32\svchost.exe[1008] kernel32.dll!VirtualProtectEx 773460AB 5 Bytes JMP 00FC0F7A
.text C:\Windows\System32\svchost.exe[1008] kernel32.dll!LoadLibraryExW 773495A7 5 Bytes JMP 00FC0F97
.text C:\Windows\System32\svchost.exe[1008] kernel32.dll!LoadLibraryW 7734971F 5 Bytes JMP 00FC0FA8
.text C:\Windows\System32\svchost.exe[1008] kernel32.dll!LoadLibraryExA 77349A6E 5 Bytes JMP 00FC004A
.text C:\Windows\System32\svchost.exe[1008] kernel32.dll!LoadLibraryA 77349A96 5 Bytes JMP 00FC0FB9
.text C:\Windows\System32\svchost.exe[1008] kernel32.dll!GetProcAddress 77364110 5 Bytes JMP 00FC00A8
.text C:\Windows\System32\svchost.exe[1008] kernel32.dll!CreateFileW 7736866C 5 Bytes JMP 00FC0FE5
.text C:\Windows\System32\svchost.exe[1008] kernel32.dll!CreateFileA 77368CA4 5 Bytes JMP 00FC0000
.text C:\Windows\System32\svchost.exe[1008] msvcrt.dll!_open 763BA890 5 Bytes JMP 00DF0FEF
.text C:\Windows\System32\svchost.exe[1008] msvcrt.dll!_wsystem 763EAA4F 2 Bytes JMP 00DF0038
.text C:\Windows\System32\svchost.exe[1008] msvcrt.dll!_wsystem + 3 763EAA52 2 Bytes [A0, 8A]
.text C:\Windows\System32\svchost.exe[1008] msvcrt.dll!system 763EAB6B 5 Bytes JMP 00DF0FAD
.text C:\Windows\System32\svchost.exe[1008] msvcrt.dll!_creat 763EE711 5 Bytes JMP 00DF0FC8
.text C:\Windows\System32\svchost.exe[1008] msvcrt.dll!_wcreat 763EF9C6 5 Bytes JMP 00DF001D
.text C:\Windows\System32\svchost.exe[1008] msvcrt.dll!_wopen 763EFBA1 5 Bytes JMP 00DF000C
.text C:\Windows\System32\svchost.exe[1008] ADVAPI32.dll!RegCreateKeyW 77278229 5 Bytes JMP 00E00FAF
.text C:\Windows\System32\svchost.exe[1008] ADVAPI32.dll!RegCreateKeyExA 77283941 5 Bytes JMP 00E00F9E
.text C:\Windows\System32\svchost.exe[1008] ADVAPI32.dll!RegCreateKeyA 77283B9F 5 Bytes JMP 00E00044
.text C:\Windows\System32\svchost.exe[1008] ADVAPI32.dll!RegCreateKeyExW 772904A2 5 Bytes JMP 00E00F8D
.text C:\Windows\System32\svchost.exe[1008] ADVAPI32.dll!RegOpenKeyExA 77290DDF 5 Bytes JMP 00E00016
.text C:\Windows\System32\svchost.exe[1008] ADVAPI32.dll!RegOpenKeyW 77297B8D 5 Bytes JMP 00E00FDE
.text C:\Windows\System32\svchost.exe[1008] ADVAPI32.dll!RegOpenKeyA 7729EAEA 5 Bytes JMP 00E00FEF
.text C:\Windows\System32\svchost.exe[1008] ADVAPI32.dll!RegOpenKeyExW 772A5ECD 5 Bytes JMP 00E00027
.text C:\Windows\System32\svchost.exe[1008] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\System32\svchost.exe[1008] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0B0F5A
.text C:\Windows\System32\svchost.exe[1008] WS2_32.dll!socket 77A64358 5 Bytes JMP 0105000A
.text C:\Windows\System32\svchost.exe[1008] WININET.dll!InternetOpenA 7603D6C0 5 Bytes JMP 00310FEF
.text C:\Windows\System32\svchost.exe[1008] WININET.dll!InternetOpenW 7603DB39 5 Bytes JMP 00310FD4
.text C:\Windows\System32\svchost.exe[1008] WININET.dll!InternetOpenUrlA 7603F3D4 5 Bytes JMP 00310FB9
.text C:\Windows\System32\svchost.exe[1008] WININET.dll!InternetOpenUrlW 76086DD7 5 Bytes JMP 0031000A
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!VirtualProtect 773218BF 5 Bytes JMP 00E30F6B
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!GetStartupInfoW 7732191A 5 Bytes JMP 00E3008C
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!GetStartupInfoA 773219B8 5 Bytes JMP 00E3007B
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!CreateProcessW 77321D27 5 Bytes JMP 00E30F10
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!CreateProcessA 77321D5C 5 Bytes JMP 00E30F2B
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!CreateNamedPipeA 77322484 5 Bytes JMP 00E30FD4
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!WinExec 773232DF 5 Bytes JMP 00E300A7
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!CreateNamedPipeW 7732EDFE 5 Bytes JMP 00E30FC3
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!CreatePipe 7733B0AF 5 Bytes JMP 00E30F50
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!VirtualProtectEx 773460AB 5 Bytes JMP 00E30060
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!LoadLibraryExW 773495A7 5 Bytes JMP 00E30F7C
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!LoadLibraryW 7734971F 5 Bytes JMP 00E30039
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!LoadLibraryExA 77349A6E 5 Bytes JMP 00E30F97
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!LoadLibraryA 77349A96 5 Bytes JMP 00E30FB2
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!GetProcAddress 77364110 5 Bytes JMP 00E300B8
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!CreateFileW 7736866C 5 Bytes JMP 00E3000A
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!CreateFileA 77368CA4 5 Bytes JMP 00E30FEF
.text C:\Windows\System32\svchost.exe[1064] msvcrt.dll!_open 763BA890 5 Bytes JMP 00D40FEF
.text C:\Windows\System32\svchost.exe[1064] msvcrt.dll!_wsystem 763EAA4F 2 Bytes JMP 00D4004B
.text C:\Windows\System32\svchost.exe[1064] msvcrt.dll!_wsystem + 3 763EAA52 2 Bytes [95, 8A]
.text C:\Windows\System32\svchost.exe[1064] msvcrt.dll!system 763EAB6B 5 Bytes JMP 00D4003A
.text C:\Windows\System32\svchost.exe[1064] msvcrt.dll!_creat 763EE711 5 Bytes JMP 00D40018
.text C:\Windows\System32\svchost.exe[1064] msvcrt.dll!_wcreat 763EF9C6 5 Bytes JMP 00D40029
.text C:\Windows\System32\svchost.exe[1064] msvcrt.dll!_wopen 763EFBA1 5 Bytes JMP 00D40FDE
.text C:\Windows\System32\svchost.exe[1064] ADVAPI32.dll!RegCreateKeyW 77278229 5 Bytes JMP 00D60044
.text C:\Windows\System32\svchost.exe[1064] ADVAPI32.dll!RegCreateKeyExA 77283941 5 Bytes JMP 00D60055
.text C:\Windows\System32\svchost.exe[1064] ADVAPI32.dll!RegCreateKeyA 77283B9F 5 Bytes JMP 00D60033
.text C:\Windows\System32\svchost.exe[1064] ADVAPI32.dll!RegCreateKeyExW 772904A2 5 Bytes JMP 00D60066
.text C:\Windows\System32\svchost.exe[1064] ADVAPI32.dll!RegOpenKeyExA 77290DDF 5 Bytes JMP 00D60011
.text C:\Windows\System32\svchost.exe[1064] ADVAPI32.dll!RegOpenKeyW 77297B8D 5 Bytes JMP 00D60FE5
.text C:\Windows\System32\svchost.exe[1064] ADVAPI32.dll!RegOpenKeyA 7729EAEA 5 Bytes JMP 00D60000
.text C:\Windows\System32\svchost.exe[1064] ADVAPI32.dll!RegOpenKeyExW 772A5ECD 5 Bytes JMP 00D60022
.text C:\Windows\System32\svchost.exe[1064] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\System32\svchost.exe[1064] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0B0F5A
.text C:\Windows\System32\svchost.exe[1064] WS2_32.dll!socket 77A64358 5 Bytes JMP 00E40000
.text C:\Windows\System32\svchost.exe[1064] WININET.dll!InternetOpenA 7603D6C0 5 Bytes JMP 00D30FE5
.text C:\Windows\System32\svchost.exe[1064] WININET.dll!InternetOpenW 7603DB39 5 Bytes JMP 00D30FD4
.text C:\Windows\System32\svchost.exe[1064] WININET.dll!InternetOpenUrlA 7603F3D4 5 Bytes JMP 00D3000A
.text C:\Windows\System32\svchost.exe[1064] WININET.dll!InternetOpenUrlW 76086DD7 5 Bytes JMP 00D30FC3
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!VirtualProtect 773218BF 5 Bytes JMP 00FA0F83
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!GetStartupInfoW 7732191A 5 Bytes JMP 00FA0089
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!GetStartupInfoA 773219B8 5 Bytes JMP 00FA0F43
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!CreateProcessW 77321D27 5 Bytes JMP 00FA009A
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!CreateProcessA 77321D5C 5 Bytes JMP 00FA0F0D
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!CreateNamedPipeA 77322484 5 Bytes JMP 00FA0FE5
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!WinExec 773232DF 5 Bytes JMP 00FA0F28
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!CreateNamedPipeW 7732EDFE 5 Bytes JMP 00FA0036
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!CreatePipe 7733B0AF 5 Bytes JMP 00FA0F54
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!VirtualProtectEx 773460AB 5 Bytes JMP 00FA006E
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!LoadLibraryExW 773495A7 5 Bytes JMP 00FA005D
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!LoadLibraryW 7734971F 5 Bytes JMP 00FA0FB9
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!LoadLibraryExA 77349A6E 5 Bytes JMP 00FA0F94
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!LoadLibraryA 77349A96 5 Bytes JMP 00FA0FCA
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!GetProcAddress 77364110 5 Bytes JMP 00FA00B5
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!CreateFileW 7736866C 5 Bytes JMP 00FA0011
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!CreateFileA 77368CA4 5 Bytes JMP 00FA0000
.text C:\Windows\system32\svchost.exe[1076] msvcrt.dll!_open 763BA890 5 Bytes JMP 00F80FEF
.text C:\Windows\system32\svchost.exe[1076] msvcrt.dll!_wsystem 763EAA4F 5 Bytes JMP 00F80FA6
.text C:\Windows\system32\svchost.exe[1076] msvcrt.dll!system 763EAB6B 5 Bytes JMP 00F80031
.text C:\Windows\system32\svchost.exe[1076] msvcrt.dll!_creat 763EE711 5 Bytes JMP 00F80FD2
.text C:\Windows\system32\svchost.exe[1076] msvcrt.dll!_wcreat 763EF9C6 5 Bytes JMP 00F80FC1
.text C:\Windows\system32\svchost.exe[1076] msvcrt.dll!_wopen 763EFBA1 5 Bytes JMP 00F8000C
.text C:\Windows\system32\svchost.exe[1076] ADVAPI32.dll!RegCreateKeyW 77278229 5 Bytes JMP 00F90F95
.text C:\Windows\system32\svchost.exe[1076] ADVAPI32.dll!RegCreateKeyExA 77283941 5 Bytes JMP 00F90F78
.text C:\Windows\system32\svchost.exe[1076] ADVAPI32.dll!RegCreateKeyA 77283B9F 5 Bytes JMP 00F90020
.text C:\Windows\system32\svchost.exe[1076] ADVAPI32.dll!RegCreateKeyExW 772904A2 5 Bytes JMP 00F90047
.text C:\Windows\system32\svchost.exe[1076] ADVAPI32.dll!RegOpenKeyExA 77290DDF 5 Bytes JMP 00F90FCD
.text C:\Windows\system32\svchost.exe[1076] ADVAPI32.dll!RegOpenKeyW 77297B8D 5 Bytes JMP 00F90FDE
.text C:\Windows\system32\svchost.exe[1076] ADVAPI32.dll!RegOpenKeyA 7729EAEA 5 Bytes JMP 00F90FEF
.text C:\Windows\system32\svchost.exe[1076] ADVAPI32.dll!RegOpenKeyExW 772A5ECD 5 Bytes JMP 00F90FBC
.text C:\Windows\system32\svchost.exe[1076] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[1076] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0B0F5A
.text C:\Windows\system32\svchost.exe[1076] WS2_32.dll!socket 77A64358 5 Bytes JMP 01050FEF
.text C:\Windows\system32\svchost.exe[1076] WININET.dll!InternetOpenA 7603D6C0 5 Bytes JMP 00F70FEF
.text C:\Windows\system32\svchost.exe[1076] WININET.dll!InternetOpenW 7603DB39 5 Bytes JMP 00F70014
.text C:\Windows\system32\svchost.exe[1076] WININET.dll!InternetOpenUrlA 7603F3D4 5 Bytes JMP 00F70025
.text C:\Windows\system32\svchost.exe[1076] WININET.dll!InternetOpenUrlW 76086DD7 5 Bytes JMP 00F70040
.text C:\Windows\system32\svchost.exe[1176] kernel32.dll!VirtualProtect 773218BF 5 Bytes JMP 00850058
.text C:\Windows\system32\svchost.exe[1176] kernel32.dll!GetStartupInfoW 7732191A 5 Bytes JMP 00850F41
.text C:\Windows\system32\svchost.exe[1176] kernel32.dll!GetStartupInfoA 773219B8 5 Bytes JMP 00850F5C
.text C:\Windows\system32\svchost.exe[1176] kernel32.dll!CreateProcessW 77321D27 5 Bytes JMP 008500C7
.text C:\Windows\system32\svchost.exe[1176] kernel32.dll!CreateProcessA 77321D5C 5 Bytes JMP 008500AC
.text C:\Windows\system32\svchost.exe[1176] kernel32.dll!CreateNamedPipeA 77322484 5 Bytes JMP 00850025
.text C:\Windows\system32\svchost.exe[1176] kernel32.dll!WinExec 773232DF 5 Bytes JMP 00850F30
.text C:\Windows\system32\svchost.exe[1176] kernel32.dll!CreateNamedPipeW 7732EDFE 5 Bytes JMP 00850036
.text C:\Windows\system32\svchost.exe[1176] kernel32.dll!CreatePipe 7733B0AF 5 Bytes JMP 00850F6D
.text C:\Windows\system32\svchost.exe[1176] kernel32.dll!VirtualProtectEx 773460AB 5 Bytes JMP 00850073
.text C:\Windows\system32\svchost.exe[1176] kernel32.dll!LoadLibraryExW 773495A7 5 Bytes JMP 00850F8A
.text C:\Windows\system32\svchost.exe[1176] kernel32.dll!LoadLibraryW 7734971F 5 Bytes JMP 00850047
.text C:\Windows\system32\svchost.exe[1176] kernel32.dll!LoadLibraryExA 77349A6E 5 Bytes JMP 00850FA5
.text C:\Windows\system32\svchost.exe[1176] kernel32.dll!LoadLibraryA 77349A96 5 Bytes JMP 00850FCA
.text C:\Windows\system32\svchost.exe[1176] kernel32.dll!GetProcAddress 77364110 5 Bytes JMP 008500E2
.text C:\Windows\system32\svchost.exe[1176] kernel32.dll!CreateFileW 7736866C 5 Bytes JMP 00850FEF
.text C:\Windows\system32\svchost.exe[1176] kernel32.dll!CreateFileA 77368CA4 5 Bytes JMP 00850000
.text C:\Windows\system32\svchost.exe[1176] msvcrt.dll!_open 763BA890 5 Bytes JMP 00220000
.text C:\Windows\system32\svchost.exe[1176] msvcrt.dll!_wsystem 763EAA4F 5 Bytes JMP 00220F86
.text C:\Windows\system32\svchost.exe[1176] msvcrt.dll!system 763EAB6B 5 Bytes JMP 00220FA1
.text C:\Windows\system32\svchost.exe[1176] msvcrt.dll!_creat 763EE711 5 Bytes JMP 00220011
.text C:\Windows\system32\svchost.exe[1176] msvcrt.dll!_wcreat 763EF9C6 5 Bytes JMP 00220FBC
.text C:\Windows\system32\svchost.exe[1176] msvcrt.dll!_wopen 763EFBA1 5 Bytes JMP 00220FD7
.text C:\Windows\system32\svchost.exe[1176] ADVAPI32.dll!RegCreateKeyW 77278229 5 Bytes JMP 00230F97
.text C:\Windows\system32\svchost.exe[1176] ADVAPI32.dll!RegCreateKeyExA 77283941 5 Bytes JMP 00230F86
.text C:\Windows\system32\svchost.exe[1176] ADVAPI32.dll!RegCreateKeyA 77283B9F 5 Bytes JMP 00230FB2
.text C:\Windows\system32\svchost.exe[1176] ADVAPI32.dll!RegCreateKeyExW 772904A2 5 Bytes JMP 00230049
.text C:\Windows\system32\svchost.exe[1176] ADVAPI32.dll!RegOpenKeyExA 77290DDF 5 Bytes JMP 00230022
.text C:\Windows\system32\svchost.exe[1176] ADVAPI32.dll!RegOpenKeyW 77297B8D 5 Bytes JMP 00230011
.text C:\Windows\system32\svchost.exe[1176] ADVAPI32.dll!RegOpenKeyA 7729EAEA 5 Bytes JMP 00230000
.text C:\Windows\system32\svchost.exe[1176] ADVAPI32.dll!RegOpenKeyExW 772A5ECD 5 Bytes JMP 00230FC3
.text C:\Windows\system32\svchost.exe[1176] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[1176] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0B0F5A
.text C:\Windows\system32\svchost.exe[1176] WS2_32.dll!socket 77A64358 5 Bytes JMP 00860000
.text C:\Windows\system32\svchost.exe[1176] WININET.dll!InternetOpenA 7603D6C0 5 Bytes JMP 0021000A
.text C:\Windows\system32\svchost.exe[1176] WININET.dll!InternetOpenW 7603DB39 5 Bytes JMP 00210025
.text C:\Windows\system32\svchost.exe[1176] WININET.dll!InternetOpenUrlA 7603F3D4 5 Bytes JMP 00210FEF
.text C:\Windows\system32\svchost.exe[1176] WININET.dll!InternetOpenUrlW 76086DD7 5 Bytes JMP 00210040
.text C:\Program Files\Bonjour\mDNSResponder.exe[1204] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1204] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1204] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!VirtualProtect 773218BF 5 Bytes JMP 00E40F72
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!GetStartupInfoW 7732191A 5 Bytes JMP 00E40F2E
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!GetStartupInfoA 773219B8 5 Bytes JMP 00E40F3F
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!CreateProcessW 77321D27 5 Bytes JMP 00E40F02
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!CreateProcessA 77321D5C 5 Bytes JMP 00E400A3
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!CreateNamedPipeA 77322484 5 Bytes JMP 00E40FCA
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!WinExec 773232DF 5 Bytes JMP 00E40F1D
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!CreateNamedPipeW 7732EDFE 5 Bytes JMP 00E4001B
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!CreatePipe 7733B0AF 5 Bytes JMP 00E40F50
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!VirtualProtectEx 773460AB 5 Bytes JMP 00E40F61
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!LoadLibraryExW 773495A7 5 Bytes JMP 00E4004C
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!LoadLibraryW 7734971F 5 Bytes JMP 00E40FA8
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!LoadLibraryExA 77349A6E 5 Bytes JMP 00E40F8D
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!LoadLibraryA 77349A96 5 Bytes JMP 00E40FB9
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!GetProcAddress 77364110 5 Bytes JMP 00E400B4
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!CreateFileW 7736866C 5 Bytes JMP 00E40000
.text C:\Windows\system32\svchost.exe[1216] kernel32.dll!CreateFileA 77368CA4 5 Bytes JMP 00E40FEF
.text C:\Windows\system32\svchost.exe[1216] msvcrt.dll!_open 763BA890 5 Bytes JMP 00DE000C
.text C:\Windows\system32\svchost.exe[1216] msvcrt.dll!_wsystem 763EAA4F 5 Bytes JMP 00DE0FA6
.text C:\Windows\system32\svchost.exe[1216] msvcrt.dll!system 763EAB6B 5 Bytes JMP 00DE0031
.text C:\Windows\system32\svchost.exe[1216] msvcrt.dll!_creat 763EE711 5 Bytes JMP 00DE0FD2
.text C:\Windows\system32\svchost.exe[1216] msvcrt.dll!_wcreat 763EF9C6 5 Bytes JMP 00DE0FC1
.text C:\Windows\system32\svchost.exe[1216] msvcrt.dll!_wopen 763EFBA1 5 Bytes JMP 00DE0FEF
.text C:\Windows\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyW 77278229 5 Bytes JMP 00E30070
.text C:\Windows\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyExA 77283941 5 Bytes JMP 00E30097
.text C:\Windows\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyA 77283B9F 5 Bytes JMP 00E3005F
.text C:\Windows\system32\svchost.exe[1216] ADVAPI32.dll!RegCreateKeyExW 772904A2 5 Bytes JMP 00E30FC8
.text C:\Windows\system32\svchost.exe[1216] ADVAPI32.dll!RegOpenKeyExA 77290DDF 5 Bytes JMP 00E30031
.text C:\Windows\system32\svchost.exe[1216] ADVAPI32.dll!RegOpenKeyW 77297B8D 5 Bytes JMP 00E30014
.text C:\Windows\system32\svchost.exe[1216] ADVAPI32.dll!RegOpenKeyA 7729EAEA 5 Bytes JMP 00E30FEF
.text C:\Windows\system32\svchost.exe[1216] ADVAPI32.dll!RegOpenKeyExW 772A5ECD 5 Bytes JMP 00E3004E
.text C:\Windows\system32\svchost.exe[1216] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[1216] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0B0F5A
.text C:\Windows\system32\svchost.exe[1216] WS2_32.dll!socket 77A64358 5 Bytes JMP 00E90FE5
.text C:\Windows\system32\svchost.exe[1216] WININET.dll!InternetOpenA 7603D6C0 5 Bytes JMP 00D90FEF
.text C:\Windows\system32\svchost.exe[1216] WININET.dll!InternetOpenW 7603DB39 5 Bytes JMP 00D90014
.text C:\Windows\system32\svchost.exe[1216] WININET.dll!InternetOpenUrlA 7603F3D4 5 Bytes JMP 00D90FDE
.text C:\Windows\system32\svchost.exe[1216] WININET.dll!InternetOpenUrlW 76086DD7 5 Bytes JMP 00D90FCD
.text C:\Windows\system32\svchost.exe[1324] kernel32.dll!VirtualProtect 773218BF 5 Bytes JMP 00E40F84
.text C:\Windows\system32\svchost.exe[1324] kernel32.dll!GetStartupInfoW 7732191A 5 Bytes JMP 00E40F55
.text C:\Windows\system32\svchost.exe[1324] kernel32.dll!GetStartupInfoA 773219B8 5 Bytes JMP 00E400A5
.text C:\Windows\system32\svchost.exe[1324] kernel32.dll!CreateProcessW 77321D27 5 Bytes JMP 00E400C0
.text C:\Windows\system32\svchost.exe[1324] kernel32.dll!CreateProcessA 77321D5C 5 Bytes JMP 00E40F33
.text C:\Windows\system32\svchost.exe[1324] kernel32.dll!CreateNamedPipeA 77322484 5 Bytes JMP 00E4002F
.text C:\Windows\system32\svchost.exe[1324] kernel32.dll!WinExec 773232DF 5 Bytes JMP 00E40F44
.text C:\Windows\system32\svchost.exe[1324] kernel32.dll!CreateNamedPipeW 7732EDFE 5 Bytes JMP 00E40FDE
.text C:\Windows\system32\svchost.exe[1324] kernel32.dll!CreatePipe 7733B0AF 5 Bytes JMP 00E40094
.text C:\Windows\system32\svchost.exe[1324] kernel32.dll!VirtualProtectEx 773460AB 5 Bytes JMP 00E40079
.text C:\Windows\system32\svchost.exe[1324] kernel32.dll!LoadLibraryExW 773495A7 5 Bytes JMP 00E40FA1
.text C:\Windows\system32\svchost.exe[1324] kernel32.dll!LoadLibraryW 7734971F 5 Bytes JMP 00E40054
.text C:\Windows\system32\svchost.exe[1324] kernel32.dll!LoadLibraryExA 77349A6E 5 Bytes JMP 00E40FB2
.text C:\Windows\system32\svchost.exe[1324] kernel32.dll!LoadLibraryA 77349A96 5 Bytes JMP 00E40FCD
.text C:\Windows\system32\svchost.exe[1324] kernel32.dll!GetProcAddress 77364110 5 Bytes JMP 00E400D1
.text C:\Windows\system32\svchost.exe[1324] kernel32.dll!CreateFileW 7736866C 5 Bytes JMP 00E40014
.text C:\Windows\system32\svchost.exe[1324] kernel32.dll!CreateFileA 77368CA4 5 Bytes JMP 00E40FEF
.text C:\Windows\system32\svchost.exe[1324] msvcrt.dll!_open 763BA890 5 Bytes JMP 00E20FE3
.text C:\Windows\system32\svchost.exe[1324] msvcrt.dll!_wsystem 763EAA4F 2 Bytes JMP 00E20027
.text C:\Windows\system32\svchost.exe[1324] msvcrt.dll!_wsystem + 3 763EAA52 2 Bytes [A3, 8A]
.text C:\Windows\system32\svchost.exe[1324] msvcrt.dll!system 763EAB6B 5 Bytes JMP 00E20016
.text C:\Windows\system32\svchost.exe[1324] msvcrt.dll!_creat 763EE711 5 Bytes JMP 00E20FC1
.text C:\Windows\system32\svchost.exe[1324] msvcrt.dll!_wcreat 763EF9C6 5 Bytes JMP 00E20FB0
.text C:\Windows\system32\svchost.exe[1324] msvcrt.dll!_wopen 763EFBA1 5 Bytes JMP 00E20FD2
.text C:\Windows\system32\svchost.exe[1324] ADVAPI32.dll!RegCreateKeyW 77278229 5 Bytes JMP 00E30F9C
.text C:\Windows\system32\svchost.exe[1324] ADVAPI32.dll!RegCreateKeyExA 77283941 5 Bytes JMP 00E30F8B
.text C:\Windows\system32\svchost.exe[1324] ADVAPI32.dll!RegCreateKeyA 77283B9F 5 Bytes JMP 00E30027
.text C:\Windows\system32\svchost.exe[1324] ADVAPI32.dll!RegCreateKeyExW 772904A2 5 Bytes JMP 00E30F7A
.text C:\Windows\system32\svchost.exe[1324] ADVAPI32.dll!RegOpenKeyExA 77290DDF 5 Bytes JMP 00E30016
.text C:\Windows\system32\svchost.exe[1324] ADVAPI32.dll!RegOpenKeyW 77297B8D 5 Bytes JMP 00E30FD4
.text C:\Windows\system32\svchost.exe[1324] ADVAPI32.dll!RegOpenKeyA 7729EAEA 5 Bytes JMP 00E30FEF
.text C:\Windows\system32\svchost.exe[1324] ADVAPI32.dll!RegOpenKeyExW 772A5ECD 5 Bytes JMP 00E30FC3
.text C:\Windows\system32\svchost.exe[1324] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[1324] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0B0F5A
.text C:\Windows\system32\svchost.exe[1324] WS2_32.dll!socket 77A64358 5 Bytes JMP 00E50FEF
.text C:\Windows\system32\svchost.exe[1324] WININET.dll!InternetOpenA 7603D6C0 5 Bytes JMP 00E10FEF
.text C:\Windows\system32\svchost.exe[1324] WININET.dll!InternetOpenW 7603DB39 5 Bytes JMP 00E10FDE
.text C:\Windows\system32\svchost.exe[1324] WININET.dll!InternetOpenUrlA 7603F3D4 5 Bytes JMP 00E10FC3
.text C:\Windows\system32\svchost.exe[1324] WININET.dll!InternetOpenUrlW 76086DD7 5 Bytes JMP 00E10FA8
.text C:\Windows\system32\rundll32.exe[1368] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\rundll32.exe[1368] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\rundll32.exe[1368] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe[1408] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe[1408] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe[1408] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Windows\System32\spoolsv.exe[1580] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Windows\System32\spoolsv.exe[1580] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\System32\spoolsv.exe[1580] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[1608] kernel32.dll!VirtualProtect 773218BF 5 Bytes JMP 012C0F86
.text C:\Windows\system32\svchost.exe[1608] kernel32.dll!GetStartupInfoW 7732191A 5 Bytes JMP 012C0F50
.text C:\Windows\system32\svchost.exe[1608] kernel32.dll!GetStartupInfoA 773219B8 5 Bytes JMP 012C0F6B
.text C:\Windows\system32\svchost.exe[1608] kernel32.dll!CreateProcessW 77321D27 5 Bytes JMP 012C0F1D
.text C:\Windows\system32\svchost.exe[1608] kernel32.dll!CreateProcessA 77321D5C 5 Bytes JMP 012C0F2E
.text C:\Windows\system32\svchost.exe[1608] kernel32.dll!CreateNamedPipeA 77322484 5 Bytes JMP 012C0FCD
.text C:\Windows\system32\svchost.exe[1608] kernel32.dll!WinExec 773232DF 5 Bytes JMP 012C0F3F
.text C:\Windows\system32\svchost.exe[1608] kernel32.dll!CreateNamedPipeW 7732EDFE 5 Bytes JMP 012C0FBC
.text C:\Windows\system32\svchost.exe[1608] kernel32.dll!CreatePipe 7733B0AF 5 Bytes JMP 012C008C
.text C:\Windows\system32\svchost.exe[1608] kernel32.dll!VirtualProtectEx 773460AB 5 Bytes JMP 012C007B
.text C:\Windows\system32\svchost.exe[1608] kernel32.dll!LoadLibraryExW 773495A7 5 Bytes JMP 012C0060
.text C:\Windows\system32\svchost.exe[1608] kernel32.dll!LoadLibraryW 7734971F 5 Bytes JMP 012C0032
.text C:\Windows\system32\svchost.exe[1608] kernel32.dll!LoadLibraryExA 77349A6E 5 Bytes JMP 012C0043
.text C:\Windows\system32\svchost.exe[1608] kernel32.dll!LoadLibraryA 77349A96 5 Bytes JMP 012C0FA1
.text C:\Windows\system32\svchost.exe[1608] kernel32.dll!GetProcAddress 77364110 5 Bytes JMP 012C00CF
.text C:\Windows\system32\svchost.exe[1608] kernel32.dll!CreateFileW 7736866C 5 Bytes JMP 012C0FDE
.text C:\Windows\system32\svchost.exe[1608] kernel32.dll!CreateFileA 77368CA4 5 Bytes JMP 012C0FEF
.text C:\Windows\system32\svchost.exe[1608] msvcrt.dll!_open 763BA890 5 Bytes JMP 01160000
.text C:\Windows\system32\svchost.exe[1608] msvcrt.dll!_wsystem 763EAA4F 2 Bytes JMP 0116004B
.text C:\Windows\system32\svchost.exe[1608] msvcrt.dll!_wsystem + 3 763EAA52 2 Bytes [D7, 8A]
.text C:\Windows\system32\svchost.exe[1608] msvcrt.dll!system 763EAB6B 5 Bytes JMP 0116003A
.text C:\Windows\system32\svchost.exe[1608] msvcrt.dll!_creat 763EE711 5 Bytes JMP 01160FDE
.text C:\Windows\system32\svchost.exe[1608] msvcrt.dll!_wcreat 763EF9C6 5 Bytes JMP 01160029
.text C:\Windows\system32\svchost.exe[1608] msvcrt.dll!_wopen 763EFBA1 5 Bytes JMP 01160FEF
.text C:\Windows\system32\svchost.exe[1608] ADVAPI32.dll!RegCreateKeyW 77278229 5 Bytes JMP 012B0027
.text C:\Windows\system32\svchost.exe[1608] ADVAPI32.dll!RegCreateKeyExA 77283941 5 Bytes JMP 012B0038
.text C:\Windows\system32\svchost.exe[1608] ADVAPI32.dll!RegCreateKeyA 77283B9F 5 Bytes JMP 012B0016
.text C:\Windows\system32\svchost.exe[1608] ADVAPI32.dll!RegCreateKeyExW 772904A2 5 Bytes JMP 012B0049
.text C:\Windows\system32\svchost.exe[1608] ADVAPI32.dll!RegOpenKeyExA 77290DDF 5 Bytes JMP 012B0FC3
.text C:\Windows\system32\svchost.exe[1608] ADVAPI32.dll!RegOpenKeyW 77297B8D 5 Bytes JMP 012B0FD4
.text C:\Windows\system32\svchost.exe[1608] ADVAPI32.dll!RegOpenKeyA 7729EAEA 5 Bytes JMP 012B0FEF
.text C:\Windows\system32\svchost.exe[1608] ADVAPI32.dll!RegOpenKeyExW 772A5ECD 5 Bytes JMP 012B0FA6
.text C:\Windows\system32\svchost.exe[1608] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[1608] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0B0F5A
.text C:\Windows\system32\svchost.exe[1608] WS2_32.dll!socket 77A64358 5 Bytes JMP 012D0000
.text C:\Windows\system32\svchost.exe[1608] WININET.dll!InternetOpenA 7603D6C0 5 Bytes JMP 01110FEF
.text C:\Windows\system32\svchost.exe[1608] WININET.dll!InternetOpenW 7603DB39 5 Bytes JMP 01110FDE
.text C:\Windows\system32\svchost.exe[1608] WININET.dll!InternetOpenUrlA 7603F3D4 5 Bytes JMP 01110FC3
.text C:\Windows\system32\svchost.exe[1608] WININET.dll!InternetOpenUrlW 76086DD7 5 Bytes JMP 01110FB2
.text C:\Program Files\McAfee\MBK\MBackMonitor.exe[1672] KERNEL32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Program Files\McAfee\MBK\MBackMonitor.exe[1672] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Program Files\McAfee\MBK\MBackMonitor.exe[1672] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\lxbkcoms.exe[1752] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\lxbkcoms.exe[1752] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\lxbkcoms.exe[1752] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[1760] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[1760] kernel32.dll!LoadLibraryW 7734971F 5 Bytes JMP 0041C3C0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[1760] kernel32.dll!LoadLibraryA 77349A96 5 Bytes JMP 0041C340 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[1760] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[1760] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\taskeng.exe[1968] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\taskeng.exe[1968] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\taskeng.exe[1968] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\taskeng.exe[1968] USER32.dll!SetWindowPos 776A969F 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1968] USER32.dll!SetWindowPos + 4 776A96A3 2 Bytes [12, 5F]
.text C:\Windows\system32\taskeng.exe[1968] USER32.dll!SetForegroundWindow 776AAA8C 6 Bytes JMP 5F0D0F5A
.text C:\Windows\system32\taskeng.exe[1968] USER32.dll!ChangeDisplaySettingsExA 776CD7CD 6 Bytes JMP 5F140F5A
.text C:\Windows\system32\taskeng.exe[1968] USER32.dll!ChangeDisplaySettingsExW 776E470F 6 Bytes JMP 5F170F5A
.text C:\Windows\system32\Dwm.exe[1976] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\Dwm.exe[1976] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\Dwm.exe[1976] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Windows\Explorer.EXE[2040] kernel32.dll!VirtualProtect 773218BF 5 Bytes JMP 00C10F4B
.text C:\Windows\Explorer.EXE[2040] kernel32.dll!GetStartupInfoW 7732191A 5 Bytes JMP 00C10F04
.text C:\Windows\Explorer.EXE[2040] kernel32.dll!GetStartupInfoA 773219B8 5 Bytes JMP 00C10F15
.text C:\Windows\Explorer.EXE[2040] kernel32.dll!CreateProcessW 77321D27 5 Bytes JMP 00C10ECE
.text C:\Windows\Explorer.EXE[2040] kernel32.dll!CreateProcessA 77321D5C 5 Bytes JMP 00C10EDF
.text C:\Windows\Explorer.EXE[2040] kernel32.dll!CreateNamedPipeA 77322484 5 Bytes JMP 00C10FC3
.text C:\Windows\Explorer.EXE[2040] kernel32.dll!WinExec 773232DF 5 Bytes JMP 00C10065
.text C:\Windows\Explorer.EXE[2040] kernel32.dll!CreateNamedPipeW 7732EDFE 5 Bytes JMP 00C1000A
.text C:\Windows\Explorer.EXE[2040] kernel32.dll!CreatePipe 7733B0AF 5 Bytes JMP 00C1004A
.text C:\Windows\Explorer.EXE[2040] kernel32.dll!VirtualProtectEx 773460AB 5 Bytes JMP 00C10F30
.text C:\Windows\Explorer.EXE[2040] kernel32.dll!LoadLibraryExW 773495A7 5 Bytes JMP 00C10025
.text C:\Windows\Explorer.EXE[2040] kernel32.dll!LoadLibraryW 7734971F 5 Bytes JMP 00C10F8D
.text C:\Windows\Explorer.EXE[2040] kernel32.dll!LoadLibraryExA 77349A6E 1 Byte [E9]
.text C:\Windows\Explorer.EXE[2040] kernel32.dll!LoadLibraryExA 77349A6E 5 Bytes JMP 00C10F72
.text C:\Windows\Explorer.EXE[2040] kernel32.dll!LoadLibraryA 77349A96 5 Bytes JMP 00C10F9E
.text C:\Windows\Explorer.EXE[2040] kernel32.dll!GetProcAddress 77364110 5 Bytes JMP 00C10080
.text C:\Windows\Explorer.EXE[2040] kernel32.dll!CreateFileW 7736866C 5 Bytes JMP 00C10FD4
.text C:\Windows\Explorer.EXE[2040] kernel32.dll!CreateFileA 77368CA4 5 Bytes JMP 00C10FEF
.text C:\Windows\Explorer.EXE[2040] ADVAPI32.dll!RegCreateKeyW 77278229 5 Bytes JMP 00C00F95
.text C:\Windows\Explorer.EXE[2040] ADVAPI32.dll!RegCreateKeyExA 77283941 5 Bytes JMP 00C00031
.text C:\Windows\Explorer.EXE[2040] ADVAPI32.dll!RegCreateKeyA 77283B9F 5 Bytes JMP 00C00FA6
.text C:\Windows\Explorer.EXE[2040] ADVAPI32.dll!RegCreateKeyExW 772904A2 5 Bytes JMP 00C0004E
.text C:\Windows\Explorer.EXE[2040] ADVAPI32.dll!RegOpenKeyExA 77290DDF 5 Bytes JMP 00C0000A
.text C:\Windows\Explorer.EXE[2040] ADVAPI32.dll!RegOpenKeyW 77297B8D 5 Bytes JMP 00C00FD4
.text C:\Windows\Explorer.EXE[2040] ADVAPI32.dll!RegOpenKeyA 7729EAEA 5 Bytes JMP 00C00FEF
.text C:\Windows\Explorer.EXE[2040] ADVAPI32.dll!RegOpenKeyExW 772A5ECD 5 Bytes JMP 00C00FB7
.text C:\Windows\Explorer.EXE[2040] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\Explorer.EXE[2040] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0B0F5A
.text C:\Windows\Explorer.EXE[2040] msvcrt.dll!_open 763BA890 5 Bytes JMP 00AB0FEF
.text C:\Windows\Explorer.EXE[2040] msvcrt.dll!_wsystem 763EAA4F 2 Bytes JMP 00AB001D
.text C:\Windows\Explorer.EXE[2040] msvcrt.dll!_wsystem + 3 763EAA52 2 Bytes [6C, 8A]
.text C:\Windows\Explorer.EXE[2040] msvcrt.dll!system 763EAB6B 5 Bytes JMP 00AB0F92
.text C:\Windows\Explorer.EXE[2040] msvcrt.dll!_creat 763EE711 5 Bytes JMP 00AB0FC1
.text C:\Windows\Explorer.EXE[2040] msvcrt.dll!_wcreat 763EF9C6 5 Bytes JMP 00AB000C
.text C:\Windows\Explorer.EXE[2040] msvcrt.dll!_wopen 763EFBA1 5 Bytes JMP 00AB0FD2
.text C:\Windows\Explorer.EXE[2040] WS2_32.dll!socket 77A64358 5 Bytes JMP 00C30FE5
.text C:\Windows\Explorer.EXE[2040] WININET.dll!InternetOpenA 7603D6C0 5 Bytes JMP 01EF0FEF
.text C:\Windows\Explorer.EXE[2040] WININET.dll!InternetOpenW 7603DB39 5 Bytes JMP 01EF0FCA
.text C:\Windows\Explorer.EXE[2040] WININET.dll!InternetOpenUrlA 7603F3D4 5 Bytes JMP 01EF0000
.text C:\Windows\Explorer.EXE[2040] WININET.dll!InternetOpenUrlW 76086DD7 5 Bytes JMP 01EF0FAF
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2068] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2068] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2068] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2108] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2108] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2108] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[2156] kernel32.dll!VirtualProtect 773218BF 5 Bytes JMP 00D50F99
.text C:\Windows\system32\svchost.exe[2156] kernel32.dll!GetStartupInfoW 7732191A 5 Bytes JMP 00D50F37
.text C:\Windows\system32\svchost.exe[2156] kernel32.dll!GetStartupInfoA 773219B8 5 Bytes JMP 00D50F48
.text C:\Windows\system32\svchost.exe[2156] kernel32.dll!CreateProcessW 77321D27 5 Bytes JMP 00D500D8
.text C:\Windows\system32\svchost.exe[2156] kernel32.dll!CreateProcessA 77321D5C 5 Bytes JMP 00D500B3
.text C:\Windows\system32\svchost.exe[2156] kernel32.dll!CreateNamedPipeA 77322484 5 Bytes JMP 00D50FDB
.text C:\Windows\system32\svchost.exe[2156] kernel32.dll!WinExec 773232DF 5 Bytes JMP 00D500A2
.text C:\Windows\system32\svchost.exe[2156] kernel32.dll!CreateNamedPipeW 7732EDFE 5 Bytes JMP 00D50036
.text C:\Windows\system32\svchost.exe[2156] kernel32.dll!CreatePipe 7733B0AF 5 Bytes JMP 00D50F63
.text C:\Windows\system32\svchost.exe[2156] kernel32.dll!VirtualProtectEx 773460AB 5 Bytes JMP 00D50F7E
.text C:\Windows\system32\svchost.exe[2156] kernel32.dll!LoadLibraryExW 773495A7 5 Bytes JMP 00D50FAA
.text C:\Windows\system32\svchost.exe[2156] kernel32.dll!LoadLibraryW 7734971F 5 Bytes JMP 00D50058
.text C:\Windows\system32\svchost.exe[2156] kernel32.dll!LoadLibraryExA 77349A6E 5 Bytes JMP 00D50069
.text C:\Windows\system32\svchost.exe[2156] kernel32.dll!LoadLibraryA 77349A96 5 Bytes JMP 00D50047
.text C:\Windows\system32\svchost.exe[2156] kernel32.dll!GetProcAddress 77364110 5 Bytes JMP 00D500E9
.text C:\Windows\system32\svchost.exe[2156] kernel32.dll!CreateFileW 7736866C 5 Bytes JMP 00D5001B
.text C:\Windows\system32\svchost.exe[2156] kernel32.dll!CreateFileA 77368CA4 5 Bytes JMP 00D5000A
.text C:\Windows\system32\svchost.exe[2156] msvcrt.dll!_open 763BA890 5 Bytes JMP 00D30FEF
.text C:\Windows\system32\svchost.exe[2156] msvcrt.dll!_wsystem 763EAA4F 5 Bytes JMP 00D30F84
.text C:\Windows\system32\svchost.exe[2156] msvcrt.dll!system 763EAB6B 5 Bytes JMP 00D30F9F
.text C:\Windows\system32\svchost.exe[2156] msvcrt.dll!_creat 763EE711 5 Bytes JMP 00D30FC1
.text C:\Windows\system32\svchost.exe[2156] msvcrt.dll!_wcreat 763EF9C6 5 Bytes JMP 00D30FB0
.text C:\Windows\system32\svchost.exe[2156] msvcrt.dll!_wopen 763EFBA1 5 Bytes JMP 00D30FD2
.text C:\Windows\system32\svchost.exe[2156] ADVAPI32.dll!RegCreateKeyW 77278229 5 Bytes JMP 00D40036
.text C:\Windows\system32\svchost.exe[2156] ADVAPI32.dll!RegCreateKeyExA 77283941 5 Bytes JMP 00D40051
.text C:\Windows\system32\svchost.exe[2156] ADVAPI32.dll!RegCreateKeyA 77283B9F 5 Bytes JMP 00D40025
.text C:\Windows\system32\svchost.exe[2156] ADVAPI32.dll!RegCreateKeyExW 772904A2 5 Bytes JMP 00D40F8E
.text C:\Windows\system32\svchost.exe[2156] ADVAPI32.dll!RegOpenKeyExA 77290DDF 5 Bytes JMP 00D40FC1
.text C:\Windows\system32\svchost.exe[2156] ADVAPI32.dll!RegOpenKeyW 77297B8D 5 Bytes JMP 00D40FDE
.text C:\Windows\system32\svchost.exe[2156] ADVAPI32.dll!RegOpenKeyA 7729EAEA 5 Bytes JMP 00D40FEF
.text C:\Windows\system32\svchost.exe[2156] ADVAPI32.dll!RegOpenKeyExW 772A5ECD 5 Bytes JMP 00D40014
.text C:\Windows\system32\svchost.exe[2156] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[2156] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0B0F5A
.text C:\Windows\system32\svchost.exe[2156] WS2_32.dll!socket 77A64358 5 Bytes JMP 00D60FEF
.text C:\Windows\system32\svchost.exe[2156] WININET.dll!InternetOpenA 7603D6C0 5 Bytes JMP 00990000
.text C:\Windows\system32\svchost.exe[2156] WININET.dll!InternetOpenW 7603DB39 5 Bytes JMP 00990FE5
.text C:\Windows\system32\svchost.exe[2156] WININET.dll!InternetOpenUrlA 7603F3D4 5 Bytes JMP 00990011
.text C:\Windows\system32\svchost.exe[2156] WININET.dll!InternetOpenUrlW 76086DD7 5 Bytes JMP 00990022
.text C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe[2256] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe[2256] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe[2256] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2524] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2524] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2524] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Spyware Doctor\pctsSvc.exe[2540] kernel32.dll!CreateThread + 1A 773637F9 4 Bytes CALL 0044AD11 C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2744] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2744] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2744] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[2760] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[2760] kernel32.dll!CreateThread + 1A 773637F9 4 Bytes CALL 0044AB89 C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
.text C:\Program Files\Spyware Doctor\pctsTray.exe[2760] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[2760] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[2772] kernel32.dll!VirtualProtect 773218BF 5 Bytes JMP 0002006E
.text C:\Windows\system32\svchost.exe[2772] kernel32.dll!GetStartupInfoW 7732191A 5 Bytes JMP 000200AB
.text C:\Windows\system32\svchost.exe[2772] kernel32.dll!GetStartupInfoA 773219B8 5 Bytes JMP 00020F6F
.text C:\Windows\system32\svchost.exe[2772] kernel32.dll!CreateProcessW 77321D27 5 Bytes JMP 00020F14
.text C:\Windows\system32\svchost.exe[2772] kernel32.dll!CreateProcessA 77321D5C 5 Bytes JMP 00020F2F
.text C:\Windows\system32\svchost.exe[2772] kernel32.dll!CreateNamedPipeA 77322484 5 Bytes JMP 00020FD1
.text C:\Windows\system32\svchost.exe[2772] kernel32.dll!WinExec 773232DF 5 Bytes JMP 00020F4A
.text C:\Windows\system32\svchost.exe[2772] kernel32.dll!CreateNamedPipeW 7732EDFE 5 Bytes JMP 00020FC0
.text C:\Windows\system32\svchost.exe[2772] kernel32.dll!CreatePipe 7733B0AF 5 Bytes JMP 0002009A
.text C:\Windows\system32\svchost.exe[2772] kernel32.dll!VirtualProtectEx 773460AB 5 Bytes JMP 00020089
.text C:\Windows\system32\svchost.exe[2772] kernel32.dll!LoadLibraryExW 773495A7 5 Bytes JMP 00020F94
.text C:\Windows\system32\svchost.exe[2772] kernel32.dll!LoadLibraryW 7734971F 5 Bytes JMP 00020047
.text C:\Windows\system32\svchost.exe[2772] kernel32.dll!LoadLibraryExA 77349A6E 5 Bytes JMP 00020FA5
.text C:\Windows\system32\svchost.exe[2772] kernel32.dll!LoadLibraryA 77349A96 5 Bytes JMP 00020036
.text C:\Windows\system32\svchost.exe[2772] kernel32.dll!GetProcAddress 77364110 5 Bytes JMP 00020EF9
.text C:\Windows\system32\svchost.exe[2772] kernel32.dll!CreateFileW 7736866C 5 Bytes JMP 00020011
.text C:\Windows\system32\svchost.exe[2772] kernel32.dll!CreateFileA 77368CA4 5 Bytes JMP 00020000
.text C:\Windows\system32\svchost.exe[2772] msvcrt.dll!_open 763BA890 5 Bytes JMP 00060FEF
.text C:\Windows\system32\svchost.exe[2772] msvcrt.dll!_wsystem 763EAA4F 5 Bytes JMP 00060F9C
.text C:\Windows\system32\svchost.exe[2772] msvcrt.dll!system 763EAB6B 5 Bytes JMP 00060027
.text C:\Windows\system32\svchost.exe[2772] msvcrt.dll!_creat 763EE711 5 Bytes JMP 00060FB7
.text C:\Windows\system32\svchost.exe[2772] msvcrt.dll!_wcreat 763EF9C6 5 Bytes JMP 00060016
.text C:\Windows\system32\svchost.exe[2772] msvcrt.dll!_wopen 763EFBA1 5 Bytes JMP 00060FDE
.text C:\Windows\system32\svchost.exe[2772] ADVAPI32.dll!RegCreateKeyW 77278229 5 Bytes JMP 00070016
.text C:\Windows\system32\svchost.exe[2772] ADVAPI32.dll!RegCreateKeyExA 77283941 5 Bytes JMP 00070033
.text C:\Windows\system32\svchost.exe[2772] ADVAPI32.dll!RegCreateKeyA 77283B9F 5 Bytes JMP 00070F8B
.text C:\Windows\system32\svchost.exe[2772] ADVAPI32.dll!RegCreateKeyExW 772904A2 5 Bytes JMP 00070044
.text C:\Windows\system32\svchost.exe[2772] ADVAPI32.dll!RegOpenKeyExA 77290DDF 5 Bytes JMP 00070FB9
.text C:\Windows\system32\svchost.exe[2772] ADVAPI32.dll!RegOpenKeyW 77297B8D 5 Bytes JMP 00070FCA
.text C:\Windows\system32\svchost.exe[2772] ADVAPI32.dll!RegOpenKeyA 7729EAEA 5 Bytes JMP 00070FEF
.text C:\Windows\system32\svchost.exe[2772] ADVAPI32.dll!RegOpenKeyExW 772A5ECD 5 Bytes JMP 00070F9C
.text C:\Windows\system32\svchost.exe[2772] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\svchost.exe[2772] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0B0F5A
.text C:\Windows\system32\svchost.exe[2772] WS2_32.dll!socket 77A64358 5 Bytes JMP 000B0FEF
.text C:\Windows\system32\svchost.exe[2772] WININET.dll!InternetOpenA 7603D6C0 5 Bytes JMP 00120000
.text C:\Windows\system32\svchost.exe[2772] WININET.dll!InternetOpenW 7603DB39 5 Bytes JMP 0012001B
.text C:\Windows\system32\svchost.exe[2772] WININET.dll!InternetOpenUrlA 7603F3D4 5 Bytes JMP 0012002C
.text C:\Windows\system32\svchost.exe[2772] WININET.dll!InternetOpenUrlW 76086DD7 5 Bytes JMP 00120047
.text C:\Windows\System32\svchost.exe[2800] kernel32.dll!VirtualProtect 773218BF 5 Bytes JMP 00020F9E
.text C:\Windows\System32\svchost.exe[2800] kernel32.dll!GetStartupInfoW 7732191A 5 Bytes JMP 00020F61
.text C:\Windows\System32\svchost.exe[2800] kernel32.dll!GetStartupInfoA 773219B8 5 Bytes JMP 0002009D
.text C:\Windows\System32\svchost.exe[2800] kernel32.dll!CreateProcessW 77321D27 1 Byte [E9]
.text C:\Windows\System32\svchost.exe[2800] kernel32.dll!CreateProcessW 77321D27 5 Bytes JMP 00020F2B
.text C:\Windows\System32\svchost.exe[2800] kernel32.dll!CreateProcessA 77321D5C 5 Bytes JMP 000200C2
.text C:\Windows\System32\svchost.exe[2800] kernel32.dll!CreateNamedPipeA 77322484 5 Bytes JMP 00020FE5
.text C:\Windows\System32\svchost.exe[2800] kernel32.dll!WinExec 773232DF 5 Bytes JMP 00020F50
.text C:\Windows\System32\svchost.exe[2800] kernel32.dll!CreateNamedPipeW 7732EDFE 5 Bytes JMP 00020040
.text C:\Windows\System32\svchost.exe[2800] kernel32.dll!CreatePipe 7733B0AF 5 Bytes JMP 00020F7C
.text C:\Windows\System32\svchost.exe[2800] kernel32.dll!VirtualProtectEx 773460AB 5 Bytes JMP 00020F8D
.text C:\Windows\System32\svchost.exe[2800] kernel32.dll!LoadLibraryExW 773495A7 5 Bytes JMP 00020FAF
.text C:\Windows\System32\svchost.exe[2800] kernel32.dll!LoadLibraryW 7734971F 5 Bytes JMP 00020062
.text C:\Windows\System32\svchost.exe[2800] kernel32.dll!LoadLibraryExA 77349A6E 5 Bytes JMP 00020FCA
.text C:\Windows\System32\svchost.exe[2800] kernel32.dll!LoadLibraryA 77349A96 5 Bytes JMP 00020051
.text C:\Windows\System32\svchost.exe[2800] kernel32.dll!GetProcAddress 77364110 5 Bytes JMP 00020F1A
.text C:\Windows\System32\svchost.exe[2800] kernel32.dll!CreateFileW 7736866C 5 Bytes JMP 0002001B
.text C:\Windows\System32\svchost.exe[2800] kernel32.dll!CreateFileA 77368CA4 5 Bytes JMP 0002000A
.text C:\Windows\System32\svchost.exe[2800] msvcrt.dll!_open 763BA890 5 Bytes JMP 00060FEF
.text C:\Windows\System32\svchost.exe[2800] msvcrt.dll!_wsystem 763EAA4F 2 Bytes JMP 00060038
.text C:\Windows\System32\svchost.exe[2800] msvcrt.dll!_wsystem + 3 763EAA52 2 Bytes [C7, 89]
.text C:\Windows\System32\svchost.exe[2800] msvcrt.dll!system 763EAB6B 5 Bytes JMP 00060FAD
.text C:\Windows\System32\svchost.exe[2800] msvcrt.dll!_creat 763EE711 5 Bytes JMP 0006001D
.text C:\Windows\System32\svchost.exe[2800] msvcrt.dll!_wcreat 763EF9C6 5 Bytes JMP 00060FBE
.text C:\Windows\System32\svchost.exe[2800] msvcrt.dll!_wopen 763EFBA1 5 Bytes JMP 0006000C
.text C:\Windows\System32\svchost.exe[2800] ADVAPI32.dll!RegCreateKeyW 77278229 5 Bytes JMP 00070F90
.text C:\Windows\System32\svchost.exe[2800] ADVAPI32.dll!RegCreateKeyExA 77283941 5 Bytes JMP 00070036
.text C:\Windows\System32\svchost.exe[2800] ADVAPI32.dll!RegCreateKeyA 77283B9F 5 Bytes JMP 00070FA1
.text C:\Windows\System32\svchost.exe[2800] ADVAPI32.dll!RegCreateKeyExW 772904A2 5 Bytes JMP 00070053
.text C:\Windows\System32\svchost.exe[2800] ADVAPI32.dll!RegOpenKeyExA 77290DDF 5 Bytes JMP 00070FC8
.text C:\Windows\System32\svchost.exe[2800] ADVAPI32.dll!RegOpenKeyW 77297B8D 5 Bytes JMP 0007000A
.text C:\Windows\System32\svchost.exe[2800] ADVAPI32.dll!RegOpenKeyA 7729EAEA 5 Bytes JMP 00070FEF
.text C:\Windows\System32\svchost.exe[2800] ADVAPI32.dll!RegOpenKeyExW 772A5ECD 5 Bytes JMP 0007001B
.text C:\Windows\System32\svchost.exe[2800] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\System32\svchost.exe[2800] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0B0F5A
.text C:\Windows\System32\svchost.exe[2800] WS2_32.dll!socket 77A64358 5 Bytes JMP 007F0FEF
.text C:\Windows\System32\svchost.exe[2800] WININET.dll!InternetOpenA 7603D6C0 5 Bytes JMP 00820FE5
.text C:\Windows\System32\svchost.exe[2800] WININET.dll!InternetOpenW 7603DB39 5 Bytes JMP 00820000
.text C:\Windows\System32\svchost.exe[2800] WININET.dll!InternetOpenUrlA 7603F3D4 5 Bytes JMP 00820011
.text C:\Windows\System32\svchost.exe[2800] WININET.dll!InternetOpenUrlW 76086DD7 5 Bytes JMP 00820FCA
.text C:\Windows\system32\SearchIndexer.exe[2840] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\SearchIndexer.exe[2840] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\SearchIndexer.exe[2840] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\DRIVERS\xaudio.exe[2892] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\DRIVERS\xaudio.exe[2892] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\DRIVERS\xaudio.exe[2892] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\WUDFHost.exe[3152] kernel32.dll!LoadLibraryExW 773495A7 6 Bytes JMP 5F070F5A
.text C:\Windows\system32\WUDFHost.exe[3152] USER32.dll!SetWindowsHookExA 7769891A 6 Bytes JMP 5F040F5A
.text C:\Windows\system32\WUDFHost.exe[3152] USER32.dll!SetWindowsHookExW 7769913D 6 Bytes JMP 5F0A0F5A
.text C:\Windows\system32\svchost.exe[3896] kernel32.dll!VirtualProtect 773218BF 5 Bytes JMP 000200AC
.text C:\Windows\system32\svchost.exe[3896] kernel32.dll!GetStartupInfoW 7732191A 5 Bytes JMP 00020F81
.text C:\Windows\system32\svchost.exe[3896] kernel32.dll!GetStartupInfoA 773219B8 5 Bytes JMP 00020F92
.text C:\Windows\system32\svchost.exe[3896] kernel32.dll!CreateProcessW 77321D27 5 Bytes JMP 00020F55
.text C:\Windows\system32\svchost.exe[3896] kernel32.dll!CreateProcessA 77321D5C 5 Bytes JMP 00020F70
.text C:\Windows\system32\svchost.exe[3896] kernel32.dll!CreateNamedPipeA 77322484 5 Bytes JMP 00020FE5
.text C:\Windows\system32\svchost.exe[3896] kernel32.dll!WinExec 773232DF 5 Bytes JMP 000200EC
.text C:\Windows\system32\svchost.exe[3896] kernel32.dll!CreateNamedPipeW 7732EDFE 5 Bytes JMP 00020FD4
.text C:\Windows\system32\svchost.exe[3896] kernel32.dll!CreatePipe 7733B0AF 5 Bytes JMP 000200BD
.text C:\Windows\system32\svchost.exe[3896] kernel32.dll!VirtualProtectEx 773460AB 5 Bytes JMP 00020FAD
.text C:\Windows\system32\svchost.exe[3896] kernel32.dll!LoadLibraryExW 773495A7 5 Bytes JMP 00020091
.text C:\Windows\system32\svchost.exe[3896] kernel32.dll!LoadLibraryW 7734971F 5 Bytes JMP 0002005B
.text C:\Windows\system32\svchost.exe[3896] kernel32.dll!LoadLibraryExA 77349A6E 5 Bytes JMP 00020076
.text C:\Windows\system32\svchost.exe[3896] kernel32.dll!LoadLibraryA 77349A96 5 Bytes JMP 00020040
.text C:\Windows\system32\svchost.exe[3896] kernel32.dll!GetProcAddress 77364110 5 Bytes JMP 00020107
.text C:\Windows\system32\svchost.exe[3896] kernel32.dll!CreateFileW 7736866C 5 Bytes JMP 0002001B
.text C:\Windows\system32\svchost.exe[3896] kernel32.dll!CreateFileA 77368CA4 5 Bytes JMP 00020000
.text C:\Windows\system32\svchost.exe[3896] msvcrt.dll!_open 763BA890 5 Bytes JMP 0006000C
.text C:\Windows\system32\svchost.exe[3896] msvcrt.dll!_wsystem 763EAA4F 1 Byte [E9]
.text C:\Windows\system32\svchost.exe[3896] msvcrt.dll!_wsystem + 3 763EAA52 2 Bytes [C7, 89]
.text C:\Windows\system32\svchost.exe[3896] msvcrt.dll!system 763EAB6B 5 Bytes JMP 00060FC8
.text C:\Windows\system32\svchost.exe[3896] msvcrt.dll!_creat 763EE711 5 Bytes JMP 0006002E
.text C:\Windows\system32\svchost.exe[3896] msvcrt.dll!_wcreat 763EF9C6 5 Bytes JMP 00060FD9
.text C:\Windows\system32\svchost.exe[3896] msvcrt.dll!_wopen 763EFBA1 5 Bytes JMP 0006001D
.text C:\Windows\system32\svchost.exe[3896] ADVAPI32.dll!RegCreateKeyW 77278229 5 Bytes JMP 0007001B
.text C:\Windows\system32\svchost.exe[3896] ADVAPI32.dll!RegCreateKeyExA 77283941 5 Bytes JMP 00070F75
.text C:\Windows\system32\svchost.exe[3896] ADVAPI32.dll!RegCreateKeyA 77283B9F 5 Bytes JMP 00070F9A
.text C:\Windows\system32\svchost.exe[3896] ADVAPI32.dll!RegCreateKeyExW 772904A2 5 Bytes JMP 00070F58
.text C:\Windows\system32\svchost.exe[3896] ADVAPI32.dll!RegOpenKeyExA 77290DDF 5 Bytes JMP 0007000A
.text C:\Windows\system32\svchost.exe[3896] ADVAPI32.dll!RegOpenKeyW 77297B8D 5 Bytes JMP 00070FD4
.text C:\Windows\system32\svchost.exe[3896] ADVAPI32.dll!RegOpenKeyA 7729EAEA 5 Bytes JMP 00070FEF
.text C:\Windows\system32\svchost.exe[3896] ADVAPI32.dll!RegOpenKeyExW 772A5ECD 5 Bytes JMP 00070FAB
.text C:\Windows\system32\svchost.exe[3896] WS2_32.dll!socket 77A64358 5 Bytes JMP 000B000A
.text C:\Windows\system32\svchost.exe[3896] WININET.dll!InternetOpenA 7603D6C0 5 Bytes JMP 00170000
.text C:\Windows\system32\svchost.exe[3896] WININET.dll!InternetOpenW 7603DB39 5 Bytes JMP 0017001B
.text C:\Windows\system32\svchost.exe[3896] WININET.dll!InternetOpenUrlA 7603F3D4 5 Bytes JMP 0017002C
.text C:\Windows\system32\svchost.exe[3896] WININET.dll!InternetOpenUrlW 76086DD7 5 Bytes JMP 0017003D
.text C:\Windows\system32\wuauclt.exe[4232] kernel32.dll!VirtualProtect 773218BF 5 Bytes JMP 00010051
.text C:\Windows\system32\wuauclt.exe[4232] kernel32.dll!GetStartupInfoW 7732191A 5 Bytes JMP 00010091
.text C:\Windows\system32\wuauclt.exe[4232] kernel32.dll!GetStartupInfoA 773219B8 5 Bytes JMP 00010F41
.text C:\Windows\system32\wuauclt.exe[4232] kernel32.dll!CreateProcessW 77321D27 5 Bytes JMP 000100C7
.text C:\Windows\system32\wuauclt.exe[4232] kernel32.dll!CreateProcessA 77321D5C 5 Bytes JMP 000100AC
.text C:\Windows\system32\wuauclt.exe[4232] kernel32.dll!CreateNamedPipeA 77322484 5 Bytes JMP 00010025
.text C:\Windows\system32\wuauclt.exe[4232] kernel32.dll!WinExec 773232DF 5 Bytes JMP 00010F30
.text C:\Windows\system32\wuauclt.exe[4232] kernel32.dll!CreateNamedPipeW 7732EDFE 5 Bytes JMP 00010036
.text C:\Windows\system32\wuauclt.exe[4232] kernel32.dll!CreatePipe 7733B0AF 5 Bytes JMP 00010062
.text C:\Windows\system32\wuauclt.exe[4232] kernel32.dll!VirtualProtectEx 773460AB 5 Bytes JMP 00010F5C
.text C:\Windows\system32\wuauclt.exe[4232] kernel32.dll!LoadLibraryExW 773495A7 5 Bytes JMP 00010F83
.text C:\Windows\system32\wuauclt.exe[4232] kernel32.dll!LoadLibraryW 7734971F 5 Bytes JMP 00010FB9
.text C:\Windows\system32\wuauclt.exe[4232] kernel32.dll!LoadLibraryExA 77349A6E 5 Bytes JMP 00010F94
.text C:\Windows\system32\wuauclt.exe[4232] kernel32.dll!LoadLibraryA 77349A96 5 Bytes JMP 00010FCA
.text C:\Windows\system32\wuauclt.exe[4232] kernel32.dll!GetProcAddress 77364110 5 Bytes JMP 00010F15
.text C:\Windows\system32\wuauclt.exe[4232] kernel32.dll!CreateFileW 7736866C 5 Bytes JMP 00010FEF
.text C:\Windows\system32\wuauclt.exe[4232] kernel32.dll!CreateFileA 77368CA4 5 Bytes JMP 0001000A
.text C:\Windows\system32\wuauclt.exe[4232] msvcrt.dll!_open 763BA890 5 Bytes JMP 0006000C
.text C:\Windows\system32\wuauclt.exe[4232] msvcrt.dll!_wsystem 763EAA4F 5 Bytes JMP 00060FB7
.text C:\Windows\system32\wuauclt.exe[4232] msvcrt.dll!system 763EAB6B 5 Bytes JMP 00060042
.text C:\Windows\system32\wuauclt.exe[4232] msvcrt.dll!_creat 763EE711 5 Bytes JMP 0006001D
.text C:\Windows\system32\wuauclt.exe[4232] msvcrt.dll!_wcreat 763EF9C6 5 Bytes JMP 00060FC8
.text C:\Windows\system32\wuauclt.exe[4232] msvcrt.dll!_wopen 763EFBA1 5 Bytes JMP 00060FEF
.text C:\Windows\system32\wuauclt.exe[4232] ADVAPI32.dll!RegCreateKeyW 77278229 5 Bytes JMP 00070FC6
.text C:\Windows\system32\wuauclt.exe[4232] ADVAPI32.dll!RegCreateKeyExA 77283941 5 Bytes JMP 00070078
.text C:\Windows\system32\wuauclt.exe[4232] ADVAPI32.dll!RegCreateKeyA 77283B9F 5 Bytes JMP 00070047
.text C:\Windows\system32\wuauclt.exe[4232] ADVAPI32.dll!RegCreateKeyExW 772904A2 5 Bytes JMP 00070FB5
.text C:\Windows\system32\wuauclt.exe[4232] ADVAPI32.dll!RegOpenKeyExA 77290DDF 5 Bytes JMP 00070036
.text C:\Windows\system32\wuauclt.exe[4232] ADVAPI32.dll!RegOpenKeyW 77297B8D 5 Bytes JMP 00070025
.text C:\Windows\system32\wuauclt.exe[4232] ADVAPI32.dll!RegOpenKeyA 7729EAEA 5 Bytes JMP 00070000
.text C:\Windows\system32\wuauclt.exe[4232] ADVAPI32.dll!RegOpenKeyExW 772A5ECD 5 Bytes JMP 00070FE3
.text C:\Windows\system32\wuauclt.exe[4232] WS2_32.dll!socket 77A64358 5 Bytes JMP 00090FEF
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\system32\services.exe[548] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\services.exe[548] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\services.exe[548] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\services.exe[548] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\services.exe[548] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\services.exe[548] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\services.exe[548] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\services.exe[548] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\lsass.exe[600] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\lsass.exe[600] @ C:\Windows\system32\LSASRV.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\lsass.exe[600] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\lsass.exe[600] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\lsass.exe[600] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\lsass.exe[600] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\lsass.exe[600] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[780] @ C:\Windows\system32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[780] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[780] @ C:\Windows\system32\OLE32.DLL [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[780] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[780] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[780] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[780] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[780] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[780] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[780] @ c:\windows\system32\rpcss.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[780] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[852] @ C:\Windows\system32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[852] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[852] @ C:\Windows\system32\OLE32.DLL [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[852] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[852] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[852] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[852] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[852] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[852] @ c:\windows\system32\rpcss.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[852] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[852] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[1008] @ C:\Windows\System32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[1008] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[1008] @ C:\Windows\system32\OLE32.DLL [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[1008] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[1008] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[1008] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[1008] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[1008] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[1008] @ C:\Windows\System32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[1064] @ C:\Windows\System32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[1064] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[1064] @ C:\Windows\system32\OLE32.DLL [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[1064] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[1064] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[1064] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[1064] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[1064] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[1064] @ C:\Windows\System32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[1064] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1076] @ C:\Windows\system32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1076] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1076] @ C:\Windows\system32\OLE32.DLL [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1076] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1076] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1076] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1076] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1076] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1076] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1076] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1176] @ C:\Windows\system32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1176] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1176] @ C:\Windows\system32\OLE32.DLL [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1176] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1176] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1176] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1176] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1176] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1216] @ C:\Windows\system32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1216] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1216] @ C:\Windows\system32\OLE32.DLL [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1216] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1216] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1216] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1216] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1216] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1216] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1216] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1324] @ C:\Windows\system32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1324] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1324] @ C:\Windows\system32\OLE32.DLL [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1324] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1324] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1324] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1324] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1324] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1324] @ c:\windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1324] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1608] @ C:\Windows\system32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1608] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1608] @ C:\Windows\system32\OLE32.DLL [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1608] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1608] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1608] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1608] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1608] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1608] @ c:\windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[1608] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\Explorer.EXE[2040] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\Explorer.EXE[2040] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\Explorer.EXE[2040] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\Explorer.EXE[2040] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\Explorer.EXE[2040] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\Explorer.EXE[2040] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\Explorer.EXE[2040] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\Explorer.EXE[2040] @ C:\Windows\System32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\Explorer.EXE[2040] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[2156] @ C:\Windows\system32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[2156] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[2156] @ C:\Windows\system32\OLE32.DLL [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[2156] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[2156] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[2156] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[2156] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[2156] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[2156] @ c:\windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[2156] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[2540] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044AE68] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[2540] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044AE68] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[2760] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044ACE0] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[2760] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044ACE0] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
IAT C:\Windows\system32\svchost.exe[2772] @ C:\Windows\system32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[2772] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[2772] @ C:\Windows\system32\OLE32.DLL [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[2772] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[2772] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[2772] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[2772] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[2772] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[2772] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\svchost.exe[2772] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[2800] @ C:\Windows\System32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[2800] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[2800] @ C:\Windows\system32\OLE32.DLL [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[2800] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[2800] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[2800] @ C:\Windows\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[2800] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\System32\svchost.exe[2800] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\Windows\system32\SearchProtocolHost.exe[5256] @ C:\Windows\system32\ole32.dll [USER32.dll!DialogBoxParamW] [6F37D6EF] C:\Windows\AppPatch\AcSpecfc.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Windows\system32\SearchProtocolHost.exe[5256] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DialogBoxParamW] [6F37D6EF] C:\Windows\AppPatch\AcSpecfc.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Windows\system32\SearchProtocolHost.exe[5256] @ C:\Windows\system32\SHELL32.dll [USER32.dll!DialogBoxParamW] [6F37D6EF] C:\Windows\AppPatch\AcSpecfc.DLL (Windows Compatibility DLL/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
---- Processes - GMER 1.0.15 ----
Library \\?\globalroot\systemroot\system32\gxvxcfgnghjhbhfnpicwrpgsucicmxrmobfen.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [780] 0x10000000
---- Services - GMER 1.0.15 ----
Service C:\Windows\system32\drivers\gxvxcqsuxjqsacycmmwxfikivjmaqvtwuplir.sys (*** hidden *** ) [SYSTEM] gxvxcserv.sys <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys@imagepath \systemroot\system32\drivers\gxvxcqsuxjqsacycmmwxfikivjmaqvtwuplir.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys\modules@gxvxcserv \\?\globalroot\systemroot\system32\drivers\gxvxcqsuxjqsacycmmwxfikivjmaqvtwuplir.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys\modules@gxvxcl \\?\globalroot\systemroot\system32\gxvxcfgnghjhbhfnpicwrpgsucicmxrmobfen.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys\modules@gxvxcclk \\?\globalroot\systemroot\system32\gxvxcussofgtkvxsffbygomxfdqeqnvruvpjm.dll
Reg HKLM\SYSTEM\ControlSet002\Services\gxvxcserv.sys
Reg HKLM\SYSTEM\ControlSet002\Services\gxvxcserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\gxvxcserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\gxvxcserv.sys@imagepath \systemroot\system32\drivers\gxvxcqsuxjqsacycmmwxfikivjmaqvtwuplir.sys
Reg HKLM\SYSTEM\ControlSet002\Services\gxvxcserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\gxvxcserv.sys\modules
Reg HKLM\SYSTEM\ControlSet002\Services\gxvxcserv.sys\modules@gxvxcserv \\?\globalroot\systemroot\system32\drivers\gxvxcqsuxjqsacycmmwxfikivjmaqvtwuplir.sys
Reg HKLM\SYSTEM\ControlSet002\Services\gxvxcserv.sys\modules@gxvxcl \\?\globalroot\systemroot\system32\gxvxcfgnghjhbhfnpicwrpgsucicmxrmobfen.dll
Reg HKLM\SYSTEM\ControlSet002\Services\gxvxcserv.sys\modules@gxvxcclk \\?\globalroot\systemroot\system32\gxvxcussofgtkvxsffbygomxfdqeqnvruvpjm.dll
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys@imagepath \systemroot\system32\drivers\gxvxcqsuxjqsacycmmwxfikivjmaqvtwuplir.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys\modules
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys\modules@gxvxcserv \\?\globalroot\systemroot\system32\drivers\gxvxcqsuxjqsacycmmwxfikivjmaqvtwuplir.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys\modules@gxvxcl \\?\globalroot\systemroot\system32\gxvxcfgnghjhbhfnpicwrpgsucicmxrmobfen.dll
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys\modules@gxvxcclk \\?\globalroot\systemroot\system32\gxvxcussofgtkvxsffbygomxfdqeqnvruvpjm.dll
Reg HKLM\SYSTEM\ControlSet004\Services\gxvxcserv.sys
Reg HKLM\SYSTEM\ControlSet004\Services\gxvxcserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet004\Services\gxvxcserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet004\Services\gxvxcserv.sys@imagepath \systemroot\system32\drivers\gxvxcqsuxjqsacycmmwxfikivjmaqvtwuplir.sys
Reg HKLM\SYSTEM\ControlSet004\Services\gxvxcserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet004\Services\gxvxcserv.sys\modules
Reg HKLM\SYSTEM\ControlSet004\Services\gxvxcserv.sys\modules@gxvxcserv \\?\globalroot\systemroot\system32\drivers\gxvxcqsuxjqsacycmmwxfikivjmaqvtwuplir.sys
Reg HKLM\SYSTEM\ControlSet004\Services\gxvxcserv.sys\modules@gxvxcl \\?\globalroot\systemroot\system32\gxvxcfgnghjhbhfnpicwrpgsucicmxrmobfen.dll
Reg HKLM\SYSTEM\ControlSet004\Services\gxvxcserv.sys\modules@gxvxcclk \\?\globalroot\systemroot\system32\gxvxcussofgtkvxsffbygomxfdqeqnvruvpjm.dll
Reg HKLM\SYSTEM\ControlSet005\Services\gxvxcserv.sys
Reg HKLM\SYSTEM\ControlSet005\Services\gxvxcserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet005\Services\gxvxcserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet005\Services\gxvxcserv.sys@imagepath \systemroot\system32\drivers\gxvxcqsuxjqsacycmmwxfikivjmaqvtwuplir.sys
Reg HKLM\SYSTEM\ControlSet005\Services\gxvxcserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet005\Services\gxvxcserv.sys\modules
Reg HKLM\SYSTEM\ControlSet005\Services\gxvxcserv.sys\modules@gxvxcserv \\?\globalroot\systemroot\system32\drivers\gxvxcqsuxjqsacycmmwxfikivjmaqvtwuplir.sys
Reg HKLM\SYSTEM\ControlSet005\Services\gxvxcserv.sys\modules@gxvxcl \\?\globalroot\systemroot\system32\gxvxcfgnghjhbhfnpicwrpgsucicmxrmobfen.dll
Reg HKLM\SYSTEM\ControlSet005\Services\gxvxcserv.sys\modules@gxvxcclk \\?\globalroot\systemroot\system32\gxvxcussofgtkvxsffbygomxfdqeqnvruvpjm.dll
Reg HKLM\SYSTEM\ControlSet006\Services\gxvxcserv.sys
Reg HKLM\SYSTEM\ControlSet006\Services\gxvxcserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet006\Services\gxvxcserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet006\Services\gxvxcserv.sys@imagepath \systemroot\system32\drivers\gxvxcqsuxjqsacycmmwxfikivjmaqvtwuplir.sys
Reg HKLM\SYSTEM\ControlSet006\Services\gxvxcserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet006\Services\gxvxcserv.sys\modules
Reg HKLM\SYSTEM\ControlSet006\Services\gxvxcserv.sys\modules@gxvxcserv \\?\globalroot\systemroot\system32\drivers\gxvxcqsuxjqsacycmmwxfikivjmaqvtwuplir.sys
Reg HKLM\SYSTEM\ControlSet006\Services\gxvxcserv.sys\modules@gxvxcl \\?\globalroot\systemroot\system32\gxvxcfgnghjhbhfnpicwrpgsucicmxrmobfen.dll
Reg HKLM\SYSTEM\ControlSet006\Services\gxvxcserv.sys\modules@gxvxcclk \\?\globalroot\systemroot\system32\gxvxcussofgtkvxsffbygomxfdqeqnvruvpjm.dll
Reg HKLM\SYSTEM\ControlSet007\Services\gxvxcserv.sys
Reg HKLM\SYSTEM\ControlSet007\Services\gxvxcserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet007\Services\gxvxcserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet007\Services\gxvxcserv.sys@imagepath \systemroot\system32\drivers\gxvxcqsuxjqsacycmmwxfikivjmaqvtwuplir.sys
Reg HKLM\SYSTEM\ControlSet007\Services\gxvxcserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet007\Services\gxvxcserv.sys\modules
Reg HKLM\SYSTEM\ControlSet007\Services\gxvxcserv.sys\modules@gxvxcserv \\?\globalroot\systemroot\system32\drivers\gxvxcqsuxjqsacycmmwxfikivjmaqvtwuplir.sys
Reg HKLM\SYSTEM\ControlSet007\Services\gxvxcserv.sys\modules@gxvxcl \\?\globalroot\systemroot\system32\gxvxcfgnghjhbhfnpicwrpgsucicmxrmobfen.dll
Reg HKLM\SYSTEM\ControlSet007\Services\gxvxcserv.sys\modules@gxvxcclk \\?\globalroot\systemroot\system32\gxvxcussofgtkvxsffbygomxfdqeqnvruvpjm.dll
---- Files - GMER 1.0.15 ----
File C:\Windows\System32\drivers\gxvxcqsuxjqsacycmmwxfikivjmaqvtwuplir.sys 48128 bytes executable <-- ROOTKIT !!!
File C:\Windows\System32\gxvxccount 4 bytes
File C:\Windows\System32\gxvxcfgnghjhbhfnpicwrpgsucicmxrmobfen.dll 22529 bytes executable
File C:\Windows\System32\gxvxcussofgtkvxsffbygomxfdqeqnvruvpjm.dll 27649 bytes executable
---- EOF - GMER 1.0.15 ----
Here is my new DDS logDDS (Ver_09-05-14.01) - NTFSx86
Run by Richard at 14:26:39.00 on Tue 06/16/2009
Internet Explorer: 8.0.6001.18783
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1033.18.1982.924 [GMT -4:00]
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
SP: McAfee VirusScan *enabled* (Updated) {C78B3C70-4777-4742-BB91-9D615CC575E6}
SP: Spyware Doctor *enabled* (Updated) {1C3EDD79-273E-46ac-99F8-EFA9E7CBC301}
SP: Windows Defender *disabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\rundll32.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Windows\system32\lxbkcoms.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskeng.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\Users\Richard\AppData\Roaming\mjusbsp\magicJack.exe
C:\Users\Richard\Desktop\444iwxxq.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Users\Richard\Desktop\dds.scr
C:\PROGRA~1\mcafee\msc\mcshell.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\McAfee\Core\mchost.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
uWindow Title = Internet Explorer provided by Dell
uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2070730
mDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2070730
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {7370F91F-6994-4595-9949-601FA2261C8D} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\2.0.301.7164\swg.dll
BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
BHO: 1 (0x1) - No File
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
TB: {724D43A0-0D85-11D4-9908-00400523E39A} - No File
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [cdloader] "c:\users\richard\appdata\roaming\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [Uniblue RegistryBooster 2] c:\program files\uniblue\registrybooster 2\StartRegistryBooster.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [mcagent_exe] c:\program files\mcafee.com\agent\mcagent.exe /runkey
mRun: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [McAfee Backup] c:\program files\mcafee\mbk\McAfeeDataBackup.exe
mRun: [MBkLogOnHook] c:\program files\mcafee\mbk\LogOnHook.exe
mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49}
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~1.0_0\bin\ssv.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
LSP: c:\windows\system32\wpclsp.dll
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Chessmaster%20Challenge/Images/stg_drm.ocx
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab
DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} - hxxp://www.auctiva.com/Aurigma/ImageUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab56649.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/Chessmaster%20Challenge/Images/armhelper.ocx
DPF: {F773E7B2-62A9-4524-9109-87D2F0BEFAA4} - hxxp://zone.msn.com/bingame/zpagames/zpa_kqrp.cab56961.cab
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL
============= SERVICES / DRIVERS ===============
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-6-3 130936]
R2 IntuitUpdateService;Intuit Update Service;c:\program files\common files\intuit\update service\IntuitUpdateService.exe [2009-2-25 13088]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-7-30 29744]
S3 PCD5SRVC{FBEA8B78-1B22F121-05040000};PCD5SRVC{FBEA8B78-1B22F121-05040000} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\dellsu~2\hwdiag\bin\PCD5SRVC.pkms [2007-12-5 20640]
S3 USB_RNDIS_VISTA;Westell WireSpeed Dual Connect Modem;c:\windows\system32\drivers\usb8023.sys [2006-11-2 14848]
S4 nvrd32;NVIDIA nForce RAID Driver;c:\windows\system32\drivers\nvrd32.sys [2007-7-30 129832]
=============== Created Last 30 ================
2009-06-16 09:13 40,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-16 09:13 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-06-16 09:13 <DIR> --d----- c:\programdata\Malwarebytes
2009-06-16 09:13 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-06-16 09:13 <DIR> --d----- c:\progra~2\Malwarebytes
2009-06-11 02:00 2,028,032 a------- c:\windows\system32\win32k.sys
2009-06-11 02:00 696,832 a------- c:\windows\system32\localspl.dll
2009-06-08 12:15 819,200 a------- c:\windows\system32\xvidcore.dll
2009-06-08 12:15 180,224 a------- c:\windows\system32\xvidvfw.dll
2009-06-08 12:15 77,824 a------- c:\windows\system32\xvid.ax
2009-06-08 12:15 <DIR> --d----- c:\program files\Xvid
2009-06-04 11:03 <DIR> --d----- c:\program files\iPod
2009-06-04 11:03 <DIR> --d----- c:\program files\iTunes
2009-06-03 13:42 <DIR> --d----- c:\program files\Trend Micro
2009-06-03 13:40 <DIR> --d-h--- c:\windows\PIF
2009-06-03 01:46 179,704 a---h--- c:\windows\system32\mlfcache.dat
2009-06-03 01:11 159,600 a------- c:\windows\system32\drivers\pctgntdi.sys
2009-06-03 01:11 130,936 a------- c:\windows\system32\drivers\PCTCore.sys
2009-06-03 01:11 73,840 a------- c:\windows\system32\drivers\PCTAppEvent.sys
2009-06-03 01:11 <DIR> --d----- c:\program files\common files\PC Tools
2009-06-03 01:11 64,392 a------- c:\windows\system32\drivers\pctplsg.sys
2009-06-03 01:11 <DIR> --d----- c:\users\richard\appdata\roaming\PC Tools
2009-06-03 01:11 <DIR> --d----- c:\programdata\PC Tools
2009-06-03 01:11 <DIR> --d----- c:\program files\Spyware Doctor
2009-06-03 01:11 <DIR> --d----- c:\progra~2\PC Tools
2009-06-03 01:03 414,480,582 a------- c:\windows\MEMORY.DMP
2009-06-03 00:56 <DIR> --d----- c:\programdata\Spybot - Search & Destroy
2009-06-03 00:56 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-06-03 00:56 <DIR> --d----- c:\progra~2\Spybot - Search & Destroy
2009-05-26 17:18 90,112 a------- c:\windows\system32\QuickTimeVR.qtx
2009-05-26 17:18 57,344 a------- c:\windows\system32\QuickTime.qts
2009-05-21 14:02 56,597 a------- c:\programdata\nvModes.dat
2009-05-21 14:02 56,597 a------- c:\progra~2\nvModes.dat
2009-05-21 13:17 <DIR> --d----- C:\NVIDIA
2009-05-21 13:13 <DIR> --d----- c:\program files\SystemRequirementsLab
==================== Find3M ====================
2009-06-04 10:54 86,016 a------- c:\windows\inf\infstrng.dat
2009-06-04 10:54 86,016 a------- c:\windows\inf\infstor.dat
2009-06-04 10:54 51,200 a------- c:\windows\inf\infpub.dat
2009-05-09 03:01 268,800 a------- c:\windows\system32\es.dll
2009-05-09 01:50 915,456 a------- c:\windows\system32\wininet.dll
2009-05-09 01:34 71,680 a------- c:\windows\system32\iesetup.dll
2009-05-08 03:03 174 a--sh--- c:\program files\desktop.ini
2009-05-08 02:45 665,600 a------- c:\windows\inf\drvindex.dat
2009-05-08 01:34 28,672 a------- c:\windows\system32\FwRemoteSvr.dll
2009-05-08 01:34 361,984 a------- c:\windows\system32\IPSECSVC.DLL
2009-05-08 01:34 272,896 a------- c:\windows\system32\polstore.dll
2009-05-08 01:34 61,440 a------- c:\windows\system32\winipsec.dll
2009-05-08 01:30 241,152 a------- c:\windows\system32\PortableDeviceApi.dll
2009-05-08 01:30 160,768 a------- c:\windows\system32\PortableDeviceTypes.dll
2009-05-08 01:30 95,232 a------- c:\windows\system32\PortableDeviceClassExtension.dll
2009-05-08 01:28 39,424 a------- c:\windows\system32\ACCTRES.dll
2009-05-08 01:28 205,824 a------- c:\windows\system32\msoeacct.dll
2009-05-08 01:28 87,040 a------- c:\windows\system32\msoert2.dll
2009-05-08 01:26 704,000 a------- c:\windows\system32\PhotoScreensaver.scr
2009-05-08 01:26 356,352 a------- c:\windows\system32\wbem\wbemcomn.dll
2009-05-08 01:26 24,064 a------- c:\windows\system32\wtsapi32.dll
2009-05-08 01:26 258,232 a------- c:\windows\system32\drivers\acpi.sys
2009-05-08 01:26 542,720 a------- c:\windows\system32\sysmain.dll
2009-05-08 01:26 502,784 a------- c:\windows\system32\wlansvc.dll
2009-05-08 01:26 297,984 a------- c:\windows\system32\wlansec.dll
2009-05-08 01:26 290,816 a------- c:\windows\system32\wlanmsm.dll
2009-05-08 01:26 67,584 a------- c:\windows\system32\wlanhlp.dll
2009-05-08 01:26 47,104 a------- c:\windows\system32\wlanapi.dll
2009-05-08 01:24 194,560 a------- c:\windows\system32\WebClnt.dll
2009-05-08 01:24 110,080 a------- c:\windows\system32\drivers\mrxdav.sys
2009-05-08 01:18 376,832 a------- c:\windows\system32\winhttp.dll
2009-05-08 01:14 297,472 a------- c:\windows\system32\gdi32.dll
2009-05-08 01:12 1,060,920 a------- c:\windows\system32\drivers\ntfs.sys
2009-05-08 01:12 41,984 a------- c:\windows\system32\drivers\monitor.sys
2009-05-08 01:10 211,456 a------- c:\windows\system32\drivers\mrxsmb10.sys
2009-05-08 01:08 500,736 a------- c:\windows\system32\msdtcprx.dll
2009-05-08 01:08 30,208 a------- c:\windows\system32\xolehlp.dll
2009-05-08 01:02 28,672 a------- c:\windows\system32\Apphlpdm.dll
2009-05-08 01:02 2,560 a------- c:\windows\apppatch\AcRes.dll
2009-05-08 01:02 2,144,256 a------- c:\windows\apppatch\AcGenral.dll
2009-05-08 01:02 537,600 a------- c:\windows\apppatch\AcLayers.dll
2009-05-08 01:02 449,536 a------- c:\windows\apppatch\AcSpecfc.dll
2009-05-08 01:02 173,056 a------- c:\windows\apppatch\AcXtrnal.dll
2009-05-08 01:02 4,247,552 a------- c:\windows\system32\GameUXLegacyGDFs.dll
2009-05-08 01:02 1,687,040 a------- c:\windows\system32\gameux.dll
2009-05-08 00:59 303,616 a------- c:\windows\system32\wmpeffects.dll
2009-05-08 00:57 1,194,496 a------- c:\windows\system32\msxml3.dll
2009-05-08 00:57 2,048 a------- c:\windows\system32\msxml3r.dll
2009-05-08 00:55 356,864 a------- c:\windows\system32\MediaMetadataHandler.dll
2009-05-08 00:54 392,192 a------- c:\windows\system32\FirewallAPI.dll
2009-05-08 00:54 396,800 a------- c:\windows\system32\MPSSVC.dll
2009-05-08 00:54 86,016 a------- c:\windows\system32\icfupgd.dll
2009-05-08 00:54 63,488 a------- c:\windows\system32\drivers\mpsdrv.sys
2009-05-08 00:54 16,896 a------- c:\windows\system32\wfapigp.dll
2009-05-08 00:53 178,688 a------- c:\windows\system32\iphlpsvc.dll
2009-05-08 00:53 61,952 a------- c:\windows\system32\cmifw.dll
2009-05-08 00:53 23,040 a------- c:\windows\system32\drivers\tunnel.sys
2009-05-08 00:53 15,360 a------- c:\windows\system32\drivers\TUNMP.SYS
2009-05-08 00:49 2,048 a------- c:\windows\system32\tzres.dll
2009-05-08 00:45 8,147,968 a------- c:\windows\system32\wmploc.DLL
2009-05-08 00:45 7,680 a------- c:\windows\system32\spwmp.dll
2009-05-08 00:45 4,096 a------- c:\windows\system32\dxmasf.dll
2009-05-08 00:33 110,136 a------- c:\windows\system32\drivers\ataport.sys
2009-05-08 00:33 45,112 a------- c:\windows\system32\drivers\pciidex.sys
2009-05-08 00:33 21,560 a------- c:\windows\system32\drivers\atapi.sys
2009-05-08 00:33 15,928 a------- c:\windows\system32\drivers\pciide.sys
2009-05-08 00:33 211,000 a------- c:\windows\system32\drivers\volsnap.sys
2009-05-08 00:33 154,624 a------- c:\windows\system32\drivers\nwifi.sys
2009-05-08 00:29 2,923,520 a------- c:\windows\explorer.exe
2009-05-08 00:20 216,632 a------- c:\windows\system32\drivers\netio.sys
2009-05-08 00:20 167,424 a------- c:\windows\system32\tcpipcfg.dll
2009-05-08 00:20 24,064 a------- c:\windows\system32\netcfg.exe
2009-05-08 00:20 22,016 a------- c:\windows\system32\netiougc.exe
2009-05-08 00:20 803,328 a------- c:\windows\system32\drivers\tcpip.sys
2009-05-08 00:10 1,585,664 a------- c:\windows\system32\setupapi.dll
2009-05-08 00:08 595,456 a------- c:\windows\system32\schedsvc.dll
2009-05-08 00:08 495,160 a------- c:\windows\system32\drivers\Wdf01000.sys
2009-05-08 00:08 35,384 a------- c:\windows\system32\drivers\WdfLdr.sys
2009-05-08 00:08 7,168 a------- c:\windows\system32\f3ahvoas.dll
2009-05-08 00:08 35,328 a------- c:\windows\system32\dispci.dll
2009-05-08 00:08 12,800 a------- c:\windows\system32\batt.dll
2009-05-08 00:08 34,360 a------- c:\windows\system32\drivers\mouclass.sys
2009-05-08 00:08 19,968 a------- c:\windows\system32\drivers\sermouse.sys
2009-05-08 00:08 15,872 a------- c:\windows\system32\drivers\mouhid.sys
2009-05-08 00:08 54,784 a------- c:\windows\system32\drivers\i8042prt.sys
2009-05-08 00:08 35,384 a------- c:\windows\system32\drivers\kbdclass.sys
2009-05-08 00:08 15,872 a------- c:\windows\system32\drivers\kbdhid.sys
2009-05-07 23:42 9,728 a------- c:\windows\system32\LAPRXY.DLL
2009-05-07 23:42 2,048 a------- c:\windows\system32\asferror.dll
2009-05-07 23:42 223,232 a------- c:\windows\system32\WMASF.DLL
2009-05-07 23:36 1,233,408 a------- c:\windows\system32\lsasrv.dll
2009-05-07 23:36 72,704 a------- c:\windows\system32\secur32.dll
2009-05-07 23:36 7,680 a------- c:\windows\system32\lsass.exe
2009-05-07 23:35 25,600 a------- c:\windows\system32\amxread.dll
2009-05-07 23:35 40,960 a------- c:\windows\apppatch\apihex86.dll
2009-05-07 23:35 14,848 a------- c:\windows\system32\apilogen.dll
2009-05-07 23:30 223,232 a------- c:\windows\system32\SLC.dll
2009-05-07 23:30 268,288 a------- c:\windows\system32\mcbuilder.exe
2009-05-07 23:30 33,280 a------- c:\windows\system32\slwmi.dll
2009-05-07 23:30:08 A------- 566,784 c:\windows\system32\SLCommDlg.dll
2008-11-19 15:51 16,384 a--sh--- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2008-11-19 15:51 32,768 a--sh--- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2008-11-19 15:51 16,384 a--sh--- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat
2007-09-21 14:37 80 a--shr-- c:\windows\system32\8556520F18.dll
2007-07-30 16:21 8,192 a--sh--- c:\windows\users\default\NTUSER.DAT
============= FINISH: 14:28:07.90 ===============