Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

My computer is being waco


  • Please log in to reply
10 replies to this topic

#1 ayamcd

ayamcd

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:45 PM

Posted 19 May 2011 - 09:42 PM

Thank you in advance for your help. My computer is a Dell optiplex 960 and runs windows xp. It recently had the windows recovery virus that I thought I got rid of two days ago by doing a system restore. I don't think that I got all of it because now both of the antivirus software that are on the computer(McAfee and avast) will not stay on. The avast won't even start to do the real time scans anymore, and the McAfee won't stay on. I recently ran a boot scan with avast and got 27 different items, but one of them would not let me delete, or cure, or move it to the chest so I was forced to click ignore. I think it was classified as a Trojan and this is probably the problem file. I have ran both malwarebytes and the tdss rootkit removal things. Niether one of them found anything wrong. If you could tell me what to do specifically and step by step I would really appreciate it. Thank you for your time in advance.

BC AdBot (Login to Remove)

 


#2 ayamcd

ayamcd
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:45 PM

Posted 20 May 2011 - 02:53 PM

I posted this yesterday and still haven't gotten anyone to help. I would really appreciate it

#3 cryptodan

cryptodan

    Bleepin Madman


  • Members
  • 21,868 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Catonsville, Md
  • Local time:06:45 PM

Posted 21 May 2011 - 05:24 AM

Hello,

And welcome to BleepingComputer.com, before we can assist you with your question of: Am I infected? You will need to perform the following tasks and post the logs of each if you can.

Malwarebytes Anti-Malware

Please download Malwarebytes Anti-Malware and save it to your desktop.
Download Link 1
Download Link 2MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.

  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
    For instructions with screenshots, please refer to the How to use Malwarebytes' Anti-Malware Guide.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Full Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.


SUPERAntiSpyware:

Please download and scan with SUPERAntiSpyware Free

  • Double-click SUPERAntiSypware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If it will not start, go to Start > All Prgrams > SUPERAntiSpyware and click on Alternate Start.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download them from here. Double-click on the hyperlink for Download Installer and save SASDEFINITIONS.EXE to your desktop. Then double-click on SASDEFINITIONS.EXE to install the definitions.)
  • In the Main Menu, click the Preferences... button.
  • Click the "General and Startup" tab, and under Start-up Options, make sure "Start SUPERAntiSpyware when Windows starts" box is unchecked.
  • Click the "Scanning Control" tab, and under Scanner Options, make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen and exit the program.
  • Do not run a scan just yet.
Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Scan with SUPERAntiSpyware as follows:
  • Launch the program and back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan and click "Next".
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes" and reboot normally.
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.
If you have a problem downloading, installing or getting SAS to run, try downloading and using the SUPERAntiSpyware Portable Scanner instead. Save the randomly named file (i.e. SAS_1710895.COM) to a usb drive or CD and transfer to the infected computer. Then double-click on it to launch and scan. The file is randomly named to help keep malware from blocking the scanner.

Instructions:

Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download them from here. Double-click on the hyperlink for Download Installer and save SASDEFINITIONS.EXE to your desktop. Then double-click on SASDEFINITIONS.EXE to install the definitions.)
  • In the Main Menu, click the Preferences... button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.
If you have a problem downloading, installing or getting SAS to run, try downloading and using the SUPERAntiSpyware Portable Scanner instead. Save the randomly named file (i.e. SAS_1710895.COM) to a usb drive or CD and transfer to the infected computer. Then double-click on it to launch and scan. The file is randomly named to help keep malware from blocking the scanner.


Now GMER

GMER does not work in 64bit Mode!!!!!!

Please download GMER from one of the following locations and save it to your desktop:

  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

    Posted Image
  • GMER will open to the Rootkit/Malware tab and perform an automatic Full Scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and be sure to re-enable your anti-virus, Firewall and any other security programs you had disabled.
-- If you encounter any problems, try running GMER in safe mode.
-- If GMER crashes or keeps resulting in a BSODs, uncheck Devices on the right side before scanning
.



#4 ayamcd

ayamcd
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:45 PM

Posted 22 May 2011 - 07:20 AM

sorry about the time. it took me a while to do the scans.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 6516

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

5/21/2011 9:47:54 PM
mbam-log-2011-05-21 (21-47-54).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 300864
Time elapsed: 2 hour(s), 27 minute(s), 47 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Standard User\Local Settings\Application Data\Thinstall\Cache\Stubs\15ffa3daaf1ec55a35104e9032ee9952ae58d1aa\OffDiag.exe (Trojan.Backdoor) -> Quarantined and deleted successfully.
C:\Documents and Settings\Standard User\Local Settings\Application Data\Thinstall\Cache\Stubs\19dcf3cc751b914f6ccf29d31f9d81e168d0\ctfmon.exe (Trojan.Backdoor) -> Quarantined and deleted successfully.
C:\Documents and Settings\Standard User\Local Settings\Application Data\Thinstall\Cache\Stubs\b17b42f6a333ee89cc8b56f8aad1283ae7bee670\DW20.EXE (Trojan.Backdoor) -> Quarantined and deleted successfully.
C:\Documents and Settings\Standard User\Local Settings\Application Data\Thinstall\Cache\Stubs\bfcb3f9a4f9be2a223d249c0d4e1902e8eabf3be\CLVIEW.EXE (Trojan.Backdoor) -> Quarantined and deleted successfully.
C:\Documents and Settings\Standard User\Local Settings\Application Data\Thinstall\Cache\Stubs\dde9d7acc3165dee866178efdd365eb010156d82\OUTLOOK.EXE (Trojan.Backdoor) -> Quarantined and deleted successfully.


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 05/21/2011 at 11:33 PM

Application Version : 4.52.1000

Core Rules Database Version : 7109
Trace Rules Database Version: 4921

Scan type : Complete Scan
Total Scan Time : 01:05:11

Memory items scanned : 244
Memory threats detected : 0
Registry items scanned : 6796
Registry threats detected : 10
File items scanned : 133397
File threats detected : 1060

System.BrokenFileAssociation
HKCR\.exe

Adware.Tracking Cookie
C:\Documents and Settings\Standard User\Cookies\standard_user@homestore.122.2o7[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adxpansion[7].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@in.getclicky[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@tacoda.at.atwola[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@lucidmedia[9].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@azjmp[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@liveperson[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adserver.hardsextube[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@stats1.clicktracks[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@femalecelebrities[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.undertone[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@content.yieldmanager[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@lucidmedia[8].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@counter.hitslink[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@a1.interclick[7].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@pornshare4u[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@stats.paypal[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adbrite[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@collective-media[7].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@realmedia[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@lfstmedia[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@server.cpmstar[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@gotacha.rotator.hadj7.adjuggler[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ar.atwola[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.zeusclicks[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.youporn[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adnetxchange[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@revsci[9].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@imrworldwide[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@imagevenue.advertserve[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.sexogratis.com[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.thesexdump[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@atdmt[9].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@statse.webtrendslive[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adxpose[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@geobanner.facebookofsex[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@nativeadvertising[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@dmtracker[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.googleadservices[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.watchmygf[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@specificclick[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ad.wsod[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@specificmedia[7].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@hardsextube[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@apmebf[10].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@rapid-xxx[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@legolas-media[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adbrite[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@doubleclick[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@invitemedia[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@advertising[10].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@youporn[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@kantarmedia[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@serving-sys[7].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.glamourbabe[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@pointroll[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ru4[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@facebookofsex[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@liveperson[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.monster[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@questionmarket[7].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@megaupload-xxx[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@c.gigcount[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@pornmaxim[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@statcounter[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@mm.chitika[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.worldstarhiphop[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ero-advertising[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@zedo[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@mediabrandsww[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@sexss[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@yieldmanager[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.ad4game[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.pornmaxim[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adserver.adtechus[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.traffikings[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@citi.bridgetrack[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@find.mapmuse[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@interclick[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ad.yieldmanager[9].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@yadro[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@biglots.112.2o7[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@questionpro[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.crakmedia[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.whaleads[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@eaeacom.112.2o7[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@jobs3.netmedia1[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@pornstar-free-movies[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@divx.112.2o7[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@sexyshare[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@banners.facebookofsex[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@tracking.foxnews[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@media6degrees[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@counter4.sextracker[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.sexogratis.com[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.pointroll[10].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@kontera[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.youpornmate[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@solvemedia[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@at.atwola[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@dominionenterprises.112.2o7[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@kaspersky.122.2o7[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@lucidmedia[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@xxxcounter[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@sexogratis.com[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@a.intentmedia[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@counters.gigya[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@gotacha.rotator.hadj7.adjuggler[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.googleadservices[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@eporner[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.googleadservices[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@paypal.112.2o7[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.telegraph.co[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@eyewonder[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adultadworld[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@youpornmate[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@naked[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@sunporno[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@gamestats[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@asiafriendfinder[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.adgoto[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@gostats[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@account.live[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@realporntube[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@traveladvertising[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adserving.versaneeds[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@fastclick[7].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.eporner[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.pubmatic[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@pro-market[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@tribalfusion[7].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@thesexdump[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adserver.ignitad[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@media2.legacy[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@insightexpressai[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@247realmedia[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.ifanboy[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@counter16.sextracker[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@dc.tremormedia[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@amtk-media[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.gamestats[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@questionpro[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@daboxxx[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@media1.break[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.qtadclicks[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.mlsfinder[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@networldmedia[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@stat.onestat[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@trafficmp[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@steelhousemedia[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.cnn[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@usairways.112.2o7[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.youporn[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@sextracker[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adinterax[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@lucidmedia[7].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@sales.liveperson[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.intergi[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.burstnet[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@sexlist[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.fling[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.mlsfinder[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.mlsfinder[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.hardsextube[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@liveperson[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@mlsfinder[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.addynamix[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@dev.hardsextube[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@gossipsexy.blogspot[1].txt
a.ads2.msads.net [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
ads2.msads.net [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
advprotraffic.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
b.ads2.msads.net [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
banners.securedataimages.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
bc.youporn.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
cdn-www.pornhub.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
cdn.insights.gravity.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
cdn1.static.pornhub.phncdn.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
cdn2.themis-media.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
cdn4.specificclick.net [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
classicadultvideo.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
cloudfront.mediamatters.org [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
convoad.technoratimedia.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
convoad.technoratimedia.net [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
core.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
crackle.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
ds.serving-sys.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
ec.atdmt.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
files.youporn.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
googleads.g.doubleclick.net [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
i.adultswim.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
ia.media-imdb.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
interclick.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
konac.kontera.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
m1.2mdn.net [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
m3.2mdn.net [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
media.entertonement.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
media.heavy.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
media.ign.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
media.jambocast.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
media.kmov.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
media.kyte.tv [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
media.mtvnservices.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
media.onsugar.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
media.scanscout.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
media.socialvibe.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
media1.break.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
media1.idbleepher.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
media1.shufuni.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
media1.thegamehomepage.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
msnbcmedia.msn.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
msntest.serving-sys.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
naiadsystems.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
obamacountdownwidget.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
objects.tremormedia.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
pureadultweb.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
rmd.atdmt.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
s-sec.slutload-media.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
s0.2mdn.net [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
secure-it.imrworldwide.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
secure-us.imrworldwide.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
spe.atdmt.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
static.discoverymedia.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
static.sunporno.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
static.youporn.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
udn.specificclick.net [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
vidii.hardsextube.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
vidii2.hardsextube.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
www.adserverplatform.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
www.adultrental.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
www.adultswim.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
www.cellphone-gps-tracking.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
www.flashpornclips.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
www.gotgayporn.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
www.mofosex.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
www.naiadsystems.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
www.nakedstraightguys.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
www.porncor.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
www.pornhub.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
www.sextoysformen.net [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
www.sexyvirals.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
www.teenist.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
www.ttylmedia.info [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
www.ziporn.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
wwwstatic.megaporn.com [ C:\Documents and Settings\Standard User\Application Data\Macromedia\Flash Player\#SharedObjects\JBUY8HSK ]
.sexyshare.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.adbrite.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.atdmt.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.mediaplex.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.mediaplex.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.adlegend.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.zedo.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.specificmedia.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.advertising.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.paypal.112.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.stats.paypal.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.advertising.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.fastclick.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.dmtracker.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.247realmedia.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.media.photobucket.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
dc.tremormedia.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.advertising.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.advertising.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.bs.serving-sys.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.adultfriendfinder.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.yieldmanager.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.smartadserver.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.smartadserver.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.advertising.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.xiti.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.tribalfusion.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.tribalfusion.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.tribalfusion.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.tribalfusion.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
media.adrevolver.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.overture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjnycidzeeq.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.imrworldwide.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.imrworldwide.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wfkogidjmfo.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.a1.interclick.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.interclick.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.247realmedia.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjnywoajsho.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wglikldpkcp.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.mediaplex.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjny-1lczkh.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjnyghdpegp.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjkygldzakp.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.atdmt.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.superpages.122.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjk4gjdpcao.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjkoskdjslp.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.fastclick.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6whkiukdzkgo.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjnyegdpmho.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.pro-market.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjmywgajaho.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wmk4ehazmhp.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjny-1jczac.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjk4eldzsdo.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjny-1mdjge.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wclywhd5sgp.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjnysidpckq.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjnygmdzwep.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjkycic5gho.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wfkoqkc5sep.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjnycoazebq.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wdlyspdpwcp.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjkyckczolp.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
www5.addfreestats.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.realmedia.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.websponsors.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.websponsors.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.burstnet.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.interclick.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.yieldmanager.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjk4qndpecq.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjnyajdjado.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wdkysgdpahp.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6walyukazohp.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjnychczeko.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjk4qnd5mbp.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.bluestreak.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjkyakd5wfp.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjkogicpkhp.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjloqicjmeo.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.overture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.overture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
audit.median.hu [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.adbrite.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
statse.webtrendslive.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.msnportal.112.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.msnaccountservices.112.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
media.adrevolver.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.fortunecity.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.adultswim.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
ads.adultswim.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wfkyogcpgdq.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
profiles.hitslink.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.nhl.112.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wgkikldzacp.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjny-1kcjmb.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.latinadultery.littlemidgets.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
www.sexybits.org [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.inthecrack.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjkokodjaho.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjny-1nc5cd.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.realmedia.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.realmedia.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.adultworkfinder.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.tracking.realtor.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.homestore.122.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.247realmedia.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.nationalassociationofrealtors.112.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
www.adultfilmdatabase.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
www.adultfilmdatabase.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.adultfilmdatabase.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.videoegg.adbureau.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wgkyakd5kbo.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.stats.filmofilia.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.stats.filmofilia.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.eyewonder.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.timeoutcommunications.122.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.zedo.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjlyalazggp.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wfk4qgdpmkp.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.msnbc.112.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.linksynergy.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.linksynergy.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.linksynergy.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.iacas.adbureau.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.iacas.adbureau.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.iacas.adbureau.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.iacas.adbureau.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.iacas.adbureau.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.iacas.adbureau.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.planetout.122.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.peertracking.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.peertracking.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjny-1lc5kb.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.havamedia.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.eaeacom.112.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wgkisocpgep.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjkyokcjsdq.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjnygmcjwkp.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.estat.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
counter.cnw.cz [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.fastclick.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.fastclick.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
adprotraffic.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.hardsextube.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.hardsextube.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.enter.hardsextubepremium.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.hardsextubepremium.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wdl4coajmeo.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.yousextube.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjnychdpabo.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjnyohdzgbq.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.cgm.adbureau.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.cgm.adbureau.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.cgm.adbureau.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjkygkczcaq.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjnyupajmko.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.nextstat.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.nextstat.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.nextstat.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjk4oiczgdp.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjnycidzwhp.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjmiagcjmco.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wflosmazego.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.advertising.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.kelleybluebook.112.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.pornhub.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wcl4ckajwgo.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wgkygpczgko.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wfkoegczsgo.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.e-2dj6wjmywocpgfo.stats.esomniture.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.timeinc.122.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.naiadsystems.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.yieldmanager.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.torstardigital.122.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.youporn.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.youporn.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.youporn.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.megaporn.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.intermundomedia.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.idbleepher.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
stats.gamestop.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.porninspector.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.porninspector.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.porninspector.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.porninspector.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.kellyfind.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
www.free-porn-vid.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.adultdvdtalk.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.adultdvdtalk.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
forum.adultdvdtalk.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
forum.adultdvdtalk.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.famouspornstars.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.pornstarmoviezone.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.gotgayporn.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
www.gotgayporn.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
www.gotgayporn.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.adultadworld.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.revenue.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.porncor.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
www.porncor.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
www.porncor.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.alladultchannel.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.alladultchannel.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.alladultchannel.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.alladultchannel.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
ad.yieldmanager.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
rm.yieldmanager.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
rm.yieldmanager.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.webpower.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.secure.webpower.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.porno.dreammovies.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.media.brandreachsys.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.delivery.trafficjunky.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
stat.dealtime.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.kontera.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.bleepbookdating.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
eas.apm.emediate.eu [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.tribalfusion.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.adtech.de [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.mywebsearch.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.mywebsearch.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.mywebsearch.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.mywebsearch.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.tns-counter.ru [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.rambler.ru [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.avgtechnologies.112.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.divx.112.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
wstat.wibiya.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.fastclick.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.realmedia.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.questionmarket.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.tribalfusion.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.pointroll.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.pointroll.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.burstnet.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.burstnet.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.network.realmedia.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.realmedia.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
www.burstbeacon.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.burstbeacon.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.adbrite.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.adbrite.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.mediabrandsww.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
.questionmarket.com [ C:\Documents and Settings\Standard User\Application Data\Mozilla\Firefox\Profiles\zeyt3mkw.default\cookies.sqlite ]
C:\Documents and Settings\Standard User\Cookies\standard_user@1zz.cqcounter[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@247realmedia[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@247realmedia[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@2o7[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@2o7[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@2o7[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@2o7[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@a1.interclick[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@a1.interclick[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@a1.interclick[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@a1.interclick[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@a1.interclick[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@accounts.zynga[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ad.slutload[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ad.slutload[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ad.wsod[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ad.wsod[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ad.yieldmanager[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ad.yieldmanager[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ad.yieldmanager[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ad.yieldmanager[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ad.yieldmanager[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ad.yieldmanager[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ad.yieldmanager[7].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ad.zanox[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ad.zanox[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ad2.doublepimp[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ad2.doublepimp[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adbrite[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adbrite[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adbrite[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adbrite[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adecn[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adecn[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adinterax[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adlegend[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adnetxchange[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adnetxchange[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.3xoogle[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.ad4game[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.adgoto[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.adgoto[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.adultswim[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.bridgetrack[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.cnn[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.cnn[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.cnn[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.crakmedia[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.gamershell[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.ifanboy[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.lzjl[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.mysponsor[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.pointroll[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.pointroll[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.pointroll[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.pointroll[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.pointroll[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.pointroll[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.pointroll[7].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.pointroll[9].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.pubmatic[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.traffikings[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.undertone[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.undertone[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.watchmygf[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.watchmygf[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.watchmygf[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.whaleads[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.whaleads[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.whaleads[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.youporn[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ads.youporn[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adserver.adtechus[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adserver.adtechus[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adserver.hardsextube[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adserver.hardsextube[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adserver.sevenload[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adserving.contextualmarketplace[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adultadincome[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adultadworld[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adultadworld[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adultadworld[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adultfriendfinder[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adultswim[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@advertising[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@advertising[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@advertising[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@advertising[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@advertising[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@advertising[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@advertising[8].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@advertising[9].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adx.bidsystem[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adxpansion[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adxpansion[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adxpansion[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adxpansion[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adxpansion[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@adxpose[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@allbritton.122.2o7[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@amex-insights[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@apmebf[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@apmebf[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@apmebf[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@apmebf[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@apmebf[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@apmebf[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@apmebf[7].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@apmebf[8].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@at.atwola[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@at.atwola[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@at.atwola[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@at.atwola[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@atdmt[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@atdmt[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@atdmt[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@atdmt[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@atdmt[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@atdmt[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@atdmt[7].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@azjmp[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@azjmp[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@bannerbobber[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@beacon.dmsinsights[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@bluestreak[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@bs.serving-sys[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@bs.serving-sys[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@bs.serving-sys[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@bs.serving-sys[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@bs.serving-sys[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@burstbeacon[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@burstbeacon[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@burstnet[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@burstnet[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@casalemedia[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@cdn1.trafficmp[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@cdn4.specificclick[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@chitika[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@chitika[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@citi.bridgetrack[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@clicks.adengage[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@clicksor[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@clickztrax[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@cltomedia[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@cms.trafficmp[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@collective-media[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@collective-media[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@collective-media[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@collective-media[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@collective-media[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@content.yieldmanager[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@content.yieldmanager[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@content.yieldmanager[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@content.yieldmanager[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@content.yieldmanager[7].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@counter.hitslink[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@counter.hitslink[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@counter15.sextracker[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@counter6.sextracker[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@crackberry[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@crazyporndvds[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@d.mediaforge[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@dc.tremormedia[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@dc.tremormedia[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@dealtime[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@display.pornplayer[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@dmtracker[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@doubleclick[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@doubleclick[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@doubleclick[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@doubleclick[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6aekialazigp.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wakouidzagp.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wbl4apczcfq.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wcl4cgajilo.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wcl4shdjagp.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wcl4unazido.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wclickc5mfp.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wdkoeicpmdq.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wdloehajkbo.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wdmyelajeko.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wfk4qgdpmkp.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wfk4qidpsko.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wfkiajdjclp.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wfkiclc5alo.stats.esomniture[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wfkogidjmfo.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wfkycmd5kfo.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wfl4akd5gfq.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wfl4akd5gfq.stats.esomniture[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wfl4ghdpmeo.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wflisgdzcho.stats.esomniture[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wfloclcpwdq.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wflookazmgq.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wgkoglcjseq.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6whkokjczwdp.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjk4wjcpwco.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjkoamdpeeo.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjkoogdjiao.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjkyagd5kbp.stats.esomniture[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjkychcpsco.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjkycic5gho.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjkygndpsbo.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjkykjdjedq.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjkysmdzsgo.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjkysmdzsgo.stats.esomniture[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjkyugdjggp.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjkyuldzeko.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjkywpazglp.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjl4eodpaeq.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjliagdzebq.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjliskazwho.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjlyenazafo.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjmiwldzedp.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjmywpdpwfo.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjny-1gajsh.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjny-1oajsl.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjnycjcjwbq.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjnyghdpegp.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjnygndjifo.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjnyoic5kko.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjnyolc5keo.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjnyqgczceo.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjnysoazslo.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjnyujd5kbo.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wjnywmd5gap.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wmmyqpcjgko.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@e-2dj6wnkyegdzeep.stats.esomniture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@enter.hardsextubepremium[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@enter.hardsextubepremium[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@epochstats[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ero-advertising[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ero-advertising[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ero-advertising[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@eyewonder[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@eyewonder[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@fastclick[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@fastclick[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@fastclick[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@fastclick[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@fastclick[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@fastclick[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@findallporn[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@findarticles[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@forums.crackberry[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@bleepbookdating[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@gettingwildsex[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@hardsextubepremium[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@hardsextubepremium[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@hardsextube[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@hardsextube[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@hardsextube[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@hardsextube[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@hg1.hitbox[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@himedia.individuad[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@hitbox[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@hotlog[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ice.112.2o7[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@imagevenue.advertserve[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@imagevenue.advertserve[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@imagevenue.advertserve[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@imrworldwide[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@imrworldwide[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@in.getclicky[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@insightexpressai[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@insightexpressai[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@insightexpressai[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@interclick[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@interclick[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@interclick[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@intermundomedia[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@intporn[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@invitemedia[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@invitemedia[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@invitemedia[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@invitemedia[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@jobs3.netmedia1[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@kontera[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@kontera[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@legolas-media[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@legolas-media[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@lfstmedia[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@liveperson[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@liveperson[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@lockedonmedia[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@lucidmedia[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@lucidmedia[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@lucidmedia[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@lucidmedia[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@maxis.112.2o7[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@media.adfrontiers[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@media.bcdb[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@media.sandlab[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@media6degrees[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@media6degrees[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@media6degrees[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@media6degrees[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@mediabrandsww[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@mediabrandsww[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@mediacollege[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@mediamatters[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@mediaplex[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@mediaplex[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@mediaplex[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@mediaplex[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@mediaplex[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@mediatraffic[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@msnportal.112.2o7[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@mtvn.112.2o7[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@mtvn.112.2o7[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@myfirstsexteacher.littlemidgets[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@myroitracking[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@mywebsearch[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@naiadsystems[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@naked[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@naked[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@network.realmedia[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@network.realmedia[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@nextag[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@oasn04.247realmedia[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@oneclickfiles[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@open.ad.yieldmanager[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@optimize.indieclick[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ordie.adbureau[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@overture[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@paypal.112.2o7[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@paypal.112.2o7[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@philips.112.2o7[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@pointroll[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@pointroll[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@pointroll[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@porn613[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@porngata[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@pornotecapremium.blogspot[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@pornotecapremium.blogspot[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@pornotecapremium.blogspot[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@pornstar[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@pro-market[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@qksrv[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@questionmarket[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@questionmarket[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@questionmarket[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@questionmarket[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@questionmarket[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@questionmarket[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@r.t.q.cltomedia[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@realmedia[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@realmedia[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@realmedia[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@realmedia[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@revenue[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@revsci[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@revsci[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@revsci[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@revsci[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@revsci[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@revsci[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@revsci[8].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@richmedia.yahoo[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@rotator.adjuggler[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ru4[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ru4[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ru4[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@ru4[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@sales.liveperson[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@sales.liveperson[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@searchforxxx[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@server.cpmstar[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@server.cpmstar[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@server.iad.liveperson[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@serving-sys[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@serving-sys[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@serving-sys[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@serving-sys[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@serving-sys[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@serving.xxxwebtraffic[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@sextracker[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@sextracker[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@specificclick[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@specificclick[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@specificclick[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@specificclick[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@specificclick[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@specificmedia[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@specificmedia[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@specificmedia[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@specificmedia[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@specificmedia[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@starzmedia.122.2o7[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@stat.dealtime[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@stat.easydate[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@statcounter[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@statcounter[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@stats.paypal[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@stats.paypal[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@stats1.clicktracks[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@stats4.clicktracks[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@statse.webtrendslive[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@statse.webtrendslive[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@super.kitnmedia[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@tacoda.at.atwola[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@tacoda.at.atwola[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@tacoda[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@tacoda[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@tacoda[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@tacoda[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@tacoda[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@tacoda[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@toxxxicas[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@tracking.foxnews[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@tracking.foxnews[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@tracking.foxnews[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@tradedoubler[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@trafficmp[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@trafficmp[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@trafficmp[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@tribalfusion[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@tribalfusion[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@tribalfusion[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@tribalfusion[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@tribalfusion[5].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@tribalfusion[6].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@tubepornsearch[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@viacom.adbureau[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@viacom.adbureau[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@viacom.adbureau[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@videoegg.adbureau[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@videoegg.adbureau[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@videoegg.adbureau[4].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@walmart.112.2o7[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@wt.xxxmatch[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.burstbeacon[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.burstbeacon[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.burstnet[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.googleadservices[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.hardsextube[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.intporn[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.mywebstats[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.pornbb[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www.toxxxicas[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www7.addfreestats[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www9.addfreestats[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@www9.addfreestats[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@xxxbunker[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@yadro[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@yadro[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@yieldmanager[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@yieldmanager[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@youporn[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@z.blogads[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@zanox[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@zedo[1].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@zedo[2].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@zedo[3].txt
C:\Documents and Settings\Standard User\Cookies\standard_user@zedo[4].txt

Adware.MyWebSearch/FunWebProducts
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE#NextInstance
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#Service
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#Legacy
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#ConfigFlags
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#Class
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#ClassGUID
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#DeviceDesc

#5 ayamcd

ayamcd
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:45 PM

Posted 22 May 2011 - 07:22 AM

here is the gmer

GMER 1.0.15.15627 - http://www.gmer.net
Rootkit scan 2011-05-22 06:37:57
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST316081 rev.4.AD
Running: oc8qq34p[1].exe; Driver: C:\DOCUME~1\STANDA~1\LOCALS~1\Temp\fxtdapow.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x9FEC4202]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0x9FF2ACB2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwClose [0x9FEE86C1]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x9FEC681C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x9FEC6874]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x9FEC698A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateKey [0x9FEE8075]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x9FEC6772]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0x9FEC68C4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x9FEC67C6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x9FEC6938]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x9FEC4226]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteKey [0x9FEE8D87]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteValueKey [0x9FEE903D]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDuplicateObject [0x9FEC6C0E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateKey [0x9FEE8BF2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateValueKey [0x9FEE8A5D]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0x9FF2AD62]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x9FEC3FF0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x9FEC424A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x9FEC6D82]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x9FEC4CDA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x9FEC684C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x9FEC689C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x9FEC69B4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenKey [0x9FEE83D1]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x9FEC679E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenProcess [0x9FEC6A46]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x9FEC6904]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x9FEC67F4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenThread [0x9FEC6B2A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x9FEC6962]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0x9FF2ADFA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryKey [0x9FEE88D8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x9FEC4BA0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryValueKey [0x9FEE872A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwRenameKey [0x9FF33E48]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwRestoreKey [0x9FEE76E8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x9FEC426E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x9FEC4292]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x9FEC404A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x9FEC4186]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetValueKey [0x9FEE8E8E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x9FEC4162]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x9FEC41AA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x9FEC42B6]

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0x9FF40902]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xB9DD52A4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenProcess [0xB9DD51D4]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwOpenThread [0xB9DD51E8]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwSetSecurityObject [0xB9DD527A]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0xB9DD52CE]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xB9DD52BA]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0xB9DD528E]
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenProcess
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtOpenThread
Code mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtSetSecurityObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!ZwCallbackReturn + 2F14 805047B0 4 Bytes [E8, 76, EE, 9F]
.text ntkrnlpa.exe!ZwYieldExecution 80504B08 7 Bytes JMP B9DD5292 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 5EC 805A64A8 4 Bytes CALL 9FEC5335 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!NtMapViewOfSection 805B203A 7 Bytes JMP B9DD52A8 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805B2E48 5 Bytes JMP B9DD52BE mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 805BC556 5 Bytes JMP 9FF3C2BE \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!NtSetSecurityObject 805C062E 5 Bytes JMP B9DD527E mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ObInsertObject 805C2FDA 5 Bytes JMP 9FF3DD5C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!NtOpenProcess 805CB440 5 Bytes JMP B9DD51D8 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 805CB6CC 5 Bytes JMP B9DD51EC mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805D117A 7 Bytes JMP 9FF40906 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805D29E2 5 Bytes JMP B9DD52D2 mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xAC775000, 0x19DAB0, 0xE8000020]
.text win32k.sys!EngFreeUserMem + 674 BF80992D 5 Bytes JMP 9FEC7CCE \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngDeleteSurface + 45 BF81391C 5 Bytes JMP 9FEC7BDA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngSetLastError + 7976 BF82429D 5 Bytes JMP 9FEC6F60 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateBitmap + F9C BF828BFC 5 Bytes JMP 9FEC7E38 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngUnmapFontFileFD + 2C50 BF831609 5 Bytes JMP 9FEC8040 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngUnmapFontFileFD + B8F2 BF83A2AB 5 Bytes JMP 9FEC7B4A \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCopyBits + 5F1C BF857D78 5 Bytes JMP 9FEC6FD0 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XLATEOBJ_iXlate + 35B2 BF8676FE 5 Bytes JMP 9FEC71AC \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XLATEOBJ_iXlate + 363D BF867789 5 Bytes JMP 9FEC7352 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XLATEOBJ_iXlate + 406D BF8681B9 5 Bytes JMP 9FEC6E84 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XLATEOBJ_iXlate + AC22 BF86ED6E 5 Bytes JMP 9FEC7C04 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngUnicodeToMultiByteN + 2ED7 BF87268F 5 Bytes JMP 9FEC7F9E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngGetCurrentCodePage + 411E BF88D0D8 5 Bytes JMP 9FEC732A \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngTextOut + 4149 BF8B13B4 5 Bytes JMP 9FEC6E9C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreatePalette + 2647 BF8C263F 5 Bytes JMP 9FEC7D80 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStretchBltROP + 450 BF8C2FE4 5 Bytes JMP 9FEC706A \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngFillPath + 1517 BF8CB446 5 Bytes JMP 9FEC70DA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngFillPath + 1797 BF8CB6C6 5 Bytes JMP 9FEC7114 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngDeleteSemaphore + 3B3E BF8ED107 5 Bytes JMP 9FEC6DB8 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateClip + 19DF BF91406D 5 Bytes JMP 9FEC6F1C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateClip + 25B3 BF914C41 5 Bytes JMP 9FEC7034 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateClip + 4F12 BF9175A0 5 Bytes JMP 9FEC746C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngPlgBlt + 1940 BF9461CB 5 Bytes JMP 9FEC7EF6 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text ntdll.dll!LdrLoadDll 7C91632D 5 Bytes [E9, C6, 9E, 84, 83] {JMP 0xffffffff83849ecb}
.text ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes [E9, 2A, 92, 84, 83] {JMP 0xffffffff8384922f}

---- User code sections - GMER 1.0.15 ----

.text C:\WINDOWS\system32\wbem\wmiprvse.exe[144] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[144] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[144] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[144] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[144] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[144] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[144] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[144] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[144] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[144] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[144] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[144] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[144] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[144] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[144] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[144] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[144] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[312] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[312] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[312] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[312] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[312] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003F1014
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[312] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003F0804
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[312] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003F0A08
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[312] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003F0C0C
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[312] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003F0E10
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[312] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003F01F8
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[312] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003F03FC
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[312] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003F0600
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[312] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00500804
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[312] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00500A08
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[312] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00500600
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[312] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 005001F8
.text C:\Program Files\Intel\WiFi\bin\S24EvMon.exe[312] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 005003FC
.text C:\WINDOWS\system32\svchost.exe[396] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00930FE5
.text C:\WINDOWS\system32\svchost.exe[396] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00930011
.text C:\WINDOWS\system32\svchost.exe[396] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00930000
.text C:\WINDOWS\system32\svchost.exe[396] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text C:\WINDOWS\system32\svchost.exe[396] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[396] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text C:\WINDOWS\system32\svchost.exe[396] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 0092000A
.text C:\WINDOWS\system32\svchost.exe[396] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00920F8D
.text C:\WINDOWS\system32\svchost.exe[396] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00920FA8
.text C:\WINDOWS\system32\svchost.exe[396] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00920076
.text C:\WINDOWS\system32\svchost.exe[396] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00920FB9
.text C:\WINDOWS\system32\svchost.exe[396] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00920FD4
.text C:\WINDOWS\system32\svchost.exe[396] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00920F72
.text C:\WINDOWS\system32\svchost.exe[396] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 009200BA
.text C:\WINDOWS\system32\svchost.exe[396] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00920101
.text C:\WINDOWS\system32\svchost.exe[396] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 009200F0
.text C:\WINDOWS\system32\svchost.exe[396] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00920F57
.text C:\WINDOWS\system32\svchost.exe[396] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0092005B
.text C:\WINDOWS\system32\svchost.exe[396] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0092001B
.text C:\WINDOWS\system32\svchost.exe[396] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 0092009D
.text C:\WINDOWS\system32\svchost.exe[396] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00920FE5
.text C:\WINDOWS\system32\svchost.exe[396] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00920040
.text C:\WINDOWS\system32\svchost.exe[396] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 009200D5
.text C:\WINDOWS\system32\svchost.exe[396] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[396] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0096001B
.text C:\WINDOWS\system32\svchost.exe[396] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 0096004E
.text C:\WINDOWS\system32\svchost.exe[396] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0096000A
.text C:\WINDOWS\system32\svchost.exe[396] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00960FD4
.text C:\WINDOWS\system32\svchost.exe[396] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00960F9B
.text C:\WINDOWS\system32\svchost.exe[396] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00960FE5
.text C:\WINDOWS\system32\svchost.exe[396] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 0096003D
.text C:\WINDOWS\system32\svchost.exe[396] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0096002C
.text C:\WINDOWS\system32\svchost.exe[396] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text C:\WINDOWS\system32\svchost.exe[396] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text C:\WINDOWS\system32\svchost.exe[396] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text C:\WINDOWS\system32\svchost.exe[396] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text C:\WINDOWS\system32\svchost.exe[396] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text C:\WINDOWS\system32\svchost.exe[396] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text C:\WINDOWS\system32\svchost.exe[396] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text C:\WINDOWS\system32\svchost.exe[396] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text C:\WINDOWS\system32\svchost.exe[396] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text C:\WINDOWS\system32\svchost.exe[396] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text C:\WINDOWS\system32\svchost.exe[396] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text C:\WINDOWS\system32\svchost.exe[396] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text C:\WINDOWS\system32\svchost.exe[396] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text C:\WINDOWS\system32\svchost.exe[396] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00950047
.text C:\WINDOWS\system32\svchost.exe[396] msvcrt.dll!system 77C293C7 5 Bytes JMP 00950FB2
.text C:\WINDOWS\system32\svchost.exe[396] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00950FD7
.text C:\WINDOWS\system32\svchost.exe[396] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00950000
.text C:\WINDOWS\system32\svchost.exe[396] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0095002C
.text C:\WINDOWS\system32\svchost.exe[396] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00950011
.text C:\WINDOWS\system32\svchost.exe[396] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00940000
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[460] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[460] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[460] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[460] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[460] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[460] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[460] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[460] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[460] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[460] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[460] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[460] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[460] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A0804
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[460] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0A08
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[460] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A0600
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[460] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A01F8
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[460] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A03FC
.text C:\Program Files\Java\jre6\bin\jqs.exe[468] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8
.text C:\Program Files\Java\jre6\bin\jqs.exe[468] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\Java\jre6\bin\jqs.exe[468] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC
.text C:\Program Files\Java\jre6\bin\jqs.exe[468] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Program Files\Java\jre6\bin\jqs.exe[468] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014
.text C:\Program Files\Java\jre6\bin\jqs.exe[468] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804
.text C:\Program Files\Java\jre6\bin\jqs.exe[468] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08
.text C:\Program Files\Java\jre6\bin\jqs.exe[468] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C
.text C:\Program Files\Java\jre6\bin\jqs.exe[468] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10
.text C:\Program Files\Java\jre6\bin\jqs.exe[468] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8
.text C:\Program Files\Java\jre6\bin\jqs.exe[468] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC
.text C:\Program Files\Java\jre6\bin\jqs.exe[468] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600
.text C:\Program Files\Java\jre6\bin\jqs.exe[468] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A0804
.text C:\Program Files\Java\jre6\bin\jqs.exe[468] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0A08
.text C:\Program Files\Java\jre6\bin\jqs.exe[468] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A0600
.text C:\Program Files\Java\jre6\bin\jqs.exe[468] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A01F8
.text C:\Program Files\Java\jre6\bin\jqs.exe[468] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A03FC
.text C:\WINDOWS\system32\svchost.exe[476] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00A30000
.text C:\WINDOWS\system32\svchost.exe[476] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00A30FE5
.text C:\WINDOWS\system32\svchost.exe[476] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00A3001B
.text C:\WINDOWS\system32\svchost.exe[476] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text C:\WINDOWS\system32\svchost.exe[476] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[476] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text C:\WINDOWS\system32\svchost.exe[476] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00700FE5
.text C:\WINDOWS\system32\svchost.exe[476] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00700084
.text C:\WINDOWS\system32\svchost.exe[476] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00700073
.text C:\WINDOWS\system32\svchost.exe[476] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00700062
.text C:\WINDOWS\system32\svchost.exe[476] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00700FA5
.text C:\WINDOWS\system32\svchost.exe[476] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00700036
.text C:\WINDOWS\system32\svchost.exe[476] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00700F74
.text C:\WINDOWS\system32\svchost.exe[476] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 007000B0
.text C:\WINDOWS\system32\svchost.exe[476] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 007000EB
.text C:\WINDOWS\system32\svchost.exe[476] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00700F48
.text C:\WINDOWS\system32\svchost.exe[476] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 007000FC
.text C:\WINDOWS\system32\svchost.exe[476] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00700047
.text C:\WINDOWS\system32\svchost.exe[476] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00700FD4
.text C:\WINDOWS\system32\svchost.exe[476] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 0070009F
.text C:\WINDOWS\system32\svchost.exe[476] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00700011
.text C:\WINDOWS\system32\svchost.exe[476] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00700000
.text C:\WINDOWS\system32\svchost.exe[476] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00700F59
.text C:\WINDOWS\system32\svchost.exe[476] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[476] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00A60011
.text C:\WINDOWS\system32\svchost.exe[476] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00A60062
.text C:\WINDOWS\system32\svchost.exe[476] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00A60FC0
.text C:\WINDOWS\system32\svchost.exe[476] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00A60000
.text C:\WINDOWS\system32\svchost.exe[476] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00A60051
.text C:\WINDOWS\system32\svchost.exe[476] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00A60FE5
.text C:\WINDOWS\system32\svchost.exe[476] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00A60FA5
.text C:\WINDOWS\system32\svchost.exe[476] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [C6, 88]
.text C:\WINDOWS\system32\svchost.exe[476] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00A60022
.text C:\WINDOWS\system32\svchost.exe[476] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text C:\WINDOWS\system32\svchost.exe[476] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text C:\WINDOWS\system32\svchost.exe[476] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text C:\WINDOWS\system32\svchost.exe[476] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text C:\WINDOWS\system32\svchost.exe[476] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text C:\WINDOWS\system32\svchost.exe[476] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text C:\WINDOWS\system32\svchost.exe[476] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text C:\WINDOWS\system32\svchost.exe[476] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text C:\WINDOWS\system32\svchost.exe[476] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text C:\WINDOWS\system32\svchost.exe[476] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text C:\WINDOWS\system32\svchost.exe[476] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text C:\WINDOWS\system32\svchost.exe[476] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text C:\WINDOWS\system32\svchost.exe[476] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text C:\WINDOWS\system32\svchost.exe[476] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00A5002E
.text C:\WINDOWS\system32\svchost.exe[476] msvcrt.dll!system 77C293C7 5 Bytes JMP 00A5001D
.text C:\WINDOWS\system32\svchost.exe[476] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00A50FB7
.text C:\WINDOWS\system32\svchost.exe[476] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00A50FEF
.text C:\WINDOWS\system32\svchost.exe[476] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00A5000C
.text C:\WINDOWS\system32\svchost.exe[476] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00A50FD2
.text C:\WINDOWS\system32\svchost.exe[476] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00A40FEF
.text C:\WINDOWS\Explorer.EXE[496] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 06A90FE5
.text C:\WINDOWS\Explorer.EXE[496] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 06A90025
.text C:\WINDOWS\Explorer.EXE[496] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 06A90000
.text C:\WINDOWS\Explorer.EXE[496] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text C:\WINDOWS\Explorer.EXE[496] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\WINDOWS\Explorer.EXE[496] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text C:\WINDOWS\Explorer.EXE[496] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 06A8000A
.text C:\WINDOWS\Explorer.EXE[496] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 06A80087
.text C:\WINDOWS\Explorer.EXE[496] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 06A80F92
.text C:\WINDOWS\Explorer.EXE[496] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 06A8006C
.text C:\WINDOWS\Explorer.EXE[496] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 06A80FB9
.text C:\WINDOWS\Explorer.EXE[496] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 06A80051
.text C:\WINDOWS\Explorer.EXE[496] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 06A80F6D
.text C:\WINDOWS\Explorer.EXE[496] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 06A800B5
.text C:\WINDOWS\Explorer.EXE[496] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 06A80F37
.text C:\WINDOWS\Explorer.EXE[496] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 06A800D0
.text C:\WINDOWS\Explorer.EXE[496] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 06A800E1
.text C:\WINDOWS\Explorer.EXE[496] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 06A80FCA
.text C:\WINDOWS\Explorer.EXE[496] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 06A80025
.text C:\WINDOWS\Explorer.EXE[496] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 06A80098
.text C:\WINDOWS\Explorer.EXE[496] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 06A80FE5
.text C:\WINDOWS\Explorer.EXE[496] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 06A80036
.text C:\WINDOWS\Explorer.EXE[496] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 06A80F48
.text C:\WINDOWS\Explorer.EXE[496] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\Explorer.EXE[496] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 06A70FB9
.text C:\WINDOWS\Explorer.EXE[496] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 06A70F97
.text C:\WINDOWS\Explorer.EXE[496] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 06A70FD4
.text C:\WINDOWS\Explorer.EXE[496] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 06A70FE5
.text C:\WINDOWS\Explorer.EXE[496] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 06A7004A
.text C:\WINDOWS\Explorer.EXE[496] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 06A70000
.text C:\WINDOWS\Explorer.EXE[496] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 06A70FA8
.text C:\WINDOWS\Explorer.EXE[496] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [C7, 8E]
.text C:\WINDOWS\Explorer.EXE[496] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 06A70025
.text C:\WINDOWS\Explorer.EXE[496] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002C1014
.text C:\WINDOWS\Explorer.EXE[496] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002C0804
.text C:\WINDOWS\Explorer.EXE[496] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002C0A08
.text C:\WINDOWS\Explorer.EXE[496] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002C0C0C
.text C:\WINDOWS\Explorer.EXE[496] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002C0E10
.text C:\WINDOWS\Explorer.EXE[496] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002C01F8
.text C:\WINDOWS\Explorer.EXE[496] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002C03FC
.text C:\WINDOWS\Explorer.EXE[496] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002C0600
.text C:\WINDOWS\Explorer.EXE[496] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002D0804
.text C:\WINDOWS\Explorer.EXE[496] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002D0A08
.text C:\WINDOWS\Explorer.EXE[496] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002D0600
.text C:\WINDOWS\Explorer.EXE[496] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002D01F8
.text C:\WINDOWS\Explorer.EXE[496] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002D03FC
.text C:\WINDOWS\Explorer.EXE[496] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 06AC0FCD
.text C:\WINDOWS\Explorer.EXE[496] msvcrt.dll!system 77C293C7 5 Bytes JMP 06AC0058
.text C:\WINDOWS\Explorer.EXE[496] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 06AC0FDE
.text C:\WINDOWS\Explorer.EXE[496] msvcrt.dll!_open 77C2F566 5 Bytes JMP 06AC0FEF
.text C:\WINDOWS\Explorer.EXE[496] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 06AC003D
.text C:\WINDOWS\Explorer.EXE[496] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 06AC0018
.text C:\WINDOWS\Explorer.EXE[496] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 06AA000A
.text C:\WINDOWS\Explorer.EXE[496] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 06AA0025
.text C:\WINDOWS\Explorer.EXE[496] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 06AA0036
.text C:\WINDOWS\Explorer.EXE[496] WININET.dll!InternetOpenUrlW 3D9A6D5F 5 Bytes JMP 06AA0FE5
.text C:\WINDOWS\Explorer.EXE[496] WS2_32.dll!socket 71AB4211 5 Bytes JMP 06AB0000
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[760] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001601F8
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[760] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[760] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001603FC
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[760] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[760] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A1014
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[760] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A0804
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[760] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0A08
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[760] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A0C0C
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[760] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0E10
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[760] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A01F8
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[760] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A03FC
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[760] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003A0600
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[760] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003B0804
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[760] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003B0A08
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[760] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003B0600
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[760] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003B01F8
.text C:\Program Files\McAfee.com\Agent\mcagent.exe[760] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003B03FC
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[820] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001601F8
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[820] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[820] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001603FC
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[820] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[820] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A1014
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[820] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A0804
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[820] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0A08
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[820] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A0C0C
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[820] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0E10
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[820] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A01F8
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[820] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A03FC
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[820] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003A0600
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[820] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003B0804
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[820] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003B0A08
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[820] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003B0600
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[820] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003B01F8
.text C:\Program Files\DivX\DivX Update\DivXUpdate.exe[820] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003B03FC
.text C:\Program Files\AVAST Software\Avast\avastUI.exe[836] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\AVAST Software\Avast\avastUI.exe[836] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\system32\ctfmon.exe[844] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000A01F8
.text C:\WINDOWS\system32\ctfmon.exe[844] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\WINDOWS\system32\ctfmon.exe[844] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000A03FC
.text C:\WINDOWS\system32\ctfmon.exe[844] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\system32\ctfmon.exe[844] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002C1014
.text C:\WINDOWS\system32\ctfmon.exe[844] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002C0804
.text C:\WINDOWS\system32\ctfmon.exe[844] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002C0A08
.text C:\WINDOWS\system32\ctfmon.exe[844] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002C0C0C
.text C:\WINDOWS\system32\ctfmon.exe[844] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002C0E10
.text C:\WINDOWS\system32\ctfmon.exe[844] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002C01F8
.text C:\WINDOWS\system32\ctfmon.exe[844] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002C03FC
.text C:\WINDOWS\system32\ctfmon.exe[844] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002C0600
.text C:\WINDOWS\system32\ctfmon.exe[844] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002D0804
.text C:\WINDOWS\system32\ctfmon.exe[844] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002D0A08
.text C:\WINDOWS\system32\ctfmon.exe[844] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002D0600
.text C:\WINDOWS\system32\ctfmon.exe[844] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002D01F8
.text C:\WINDOWS\system32\ctfmon.exe[844] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002D03FC
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[860] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000B01F8
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[860] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[860] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000B03FC
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[860] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[860] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00371014
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[860] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00370804
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[860] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00370A08
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[860] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00370C0C
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[860] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00370E10
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[860] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003701F8
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[860] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003703FC
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[860] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00370600
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[860] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00380804
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[860] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00380A08
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[860] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00380600
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[860] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003801F8
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[860] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003803FC
.text C:\Program Files\Steam\Steam.exe[872] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001601F8
.text C:\Program Files\Steam\Steam.exe[872] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\Steam\Steam.exe[872] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001603FC
.text C:\Program Files\Steam\Steam.exe[872] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Program Files\Steam\Steam.exe[872] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014
.text C:\Program Files\Steam\Steam.exe[872] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804
.text C:\Program Files\Steam\Steam.exe[872] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08
.text C:\Program Files\Steam\Steam.exe[872] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C
.text C:\Program Files\Steam\Steam.exe[872] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10
.text C:\Program Files\Steam\Steam.exe[872] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8
.text C:\Program Files\Steam\Steam.exe[872] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC
.text C:\Program Files\Steam\Steam.exe[872] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600
.text C:\Program Files\Steam\Steam.exe[872] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A0804
.text C:\Program Files\Steam\Steam.exe[872] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0A08
.text C:\Program Files\Steam\Steam.exe[872] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A0600
.text C:\Program Files\Steam\Steam.exe[872] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A01F8
.text C:\Program Files\Steam\Steam.exe[872] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A03FC
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1048] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1048] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP }
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1048] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\system32\Ati2evxx.exe[1060] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001401F8
.text C:\WINDOWS\system32\Ati2evxx.exe[1060] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\WINDOWS\system32\Ati2evxx.exe[1060] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001403FC
.text C:\WINDOWS\system32\Ati2evxx.exe[1060] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\system32\Ati2evxx.exe[1060] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00380804
.text C:\WINDOWS\system32\Ati2evxx.exe[1060] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00380A08
.text C:\WINDOWS\system32\Ati2evxx.exe[1060] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00380600
.text C:\WINDOWS\system32\Ati2evxx.exe[1060] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003801F8
.text C:\WINDOWS\system32\Ati2evxx.exe[1060] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003803FC
.text C:\WINDOWS\system32\Ati2evxx.exe[1060] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014
.text C:\WINDOWS\system32\Ati2evxx.exe[1060] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804
.text C:\WINDOWS\system32\Ati2evxx.exe[1060] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08
.text C:\WINDOWS\system32\Ati2evxx.exe[1060] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C
.text C:\WINDOWS\system32\Ati2evxx.exe[1060] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10
.text C:\WINDOWS\system32\Ati2evxx.exe[1060] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8
.text C:\WINDOWS\system32\Ati2evxx.exe[1060] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC
.text C:\WINDOWS\system32\Ati2evxx.exe[1060] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600
.text C:\WINDOWS\System32\vssvc.exe[1076] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text C:\WINDOWS\System32\vssvc.exe[1076] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\WINDOWS\System32\vssvc.exe[1076] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text C:\WINDOWS\System32\vssvc.exe[1076] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\System32\vssvc.exe[1076] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002B0804
.text C:\WINDOWS\System32\vssvc.exe[1076] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002B0A08
.text C:\WINDOWS\System32\vssvc.exe[1076] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002B0600
.text C:\WINDOWS\System32\vssvc.exe[1076] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002B01F8
.text C:\WINDOWS\System32\vssvc.exe[1076] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002B03FC
.text C:\WINDOWS\System32\vssvc.exe[1076] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002C1014
.text C:\WINDOWS\System32\vssvc.exe[1076] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002C0804
.text C:\WINDOWS\System32\vssvc.exe[1076] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002C0A08
.text C:\WINDOWS\System32\vssvc.exe[1076] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002C0C0C
.text C:\WINDOWS\System32\vssvc.exe[1076] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002C0E10
.text C:\WINDOWS\System32\vssvc.exe[1076] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002C01F8
.text C:\WINDOWS\System32\vssvc.exe[1076] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002C03FC
.text C:\WINDOWS\System32\vssvc.exe[1076] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002C0600
.text c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe[1156] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8
.text c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe[1156] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe[1156] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC
.text c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe[1156] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe[1156] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00390804
.text c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe[1156] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390A08
.text c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe[1156] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00390600
.text c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe[1156] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003901F8
.text c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe[1156] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003903FC
.text c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe[1156] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A1014
.text c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe[1156] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A0804
.text c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe[1156] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0A08
.text c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe[1156] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A0C0C
.text c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe[1156] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0E10
.text c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe[1156] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A01F8
.text c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe[1156] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A03FC
.text c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe[1156] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003A0600
.text C:\WINDOWS\System32\smss.exe[1360] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe[1420] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001601F8
.text C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe[1420] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe[1420] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001603FC
.text C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe[1420] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe[1420] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00390804
.text C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe[1420] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390A08
.text C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe[1420] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00390600
.text C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe[1420] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003901F8
.text C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe[1420] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003903FC
.text C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe[1420] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A1014
.text C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe[1420] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A0804
.text C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe[1420] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0A08
.text C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe[1420] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A0C0C
.text C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe[1420] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0E10
.text C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe[1420] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A01F8
.text C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe[1420] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A03FC
.text C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe[1420] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003A0600
.text C:\WINDOWS\system32\csrss.exe[1436] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\WINDOWS\system32\csrss.exe[1436] KERNEL32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\system32\winlogon.exe[1468] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000701F8
.text C:\WINDOWS\system32\winlogon.exe[1468] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\WINDOWS\system32\winlogon.exe[1468] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000703FC
.text C:\WINDOWS\system32\winlogon.exe[1468] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\system32\winlogon.exe[1468] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text C:\WINDOWS\system32\winlogon.exe[1468] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text C:\WINDOWS\system32\winlogon.exe[1468] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text C:\WINDOWS\system32\winlogon.exe[1468] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text C:\WINDOWS\system32\winlogon.exe[1468] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text C:\WINDOWS\system32\winlogon.exe[1468] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text C:\WINDOWS\system32\winlogon.exe[1468] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text C:\WINDOWS\system32\winlogon.exe[1468] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600

and the second half

.text C:\WINDOWS\system32\winlogon.exe[1468] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text C:\WINDOWS\system32\winlogon.exe[1468] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text C:\WINDOWS\system32\winlogon.exe[1468] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text C:\WINDOWS\system32\winlogon.exe[1468] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text C:\WINDOWS\system32\winlogon.exe[1468] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text C:\WINDOWS\system32\services.exe[1512] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00050000
.text C:\WINDOWS\system32\services.exe[1512] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00050025
.text C:\WINDOWS\system32\services.exe[1512] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00050FE5
.text C:\WINDOWS\system32\services.exe[1512] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text C:\WINDOWS\system32\services.exe[1512] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\WINDOWS\system32\services.exe[1512] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text C:\WINDOWS\system32\services.exe[1512] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00040000
.text C:\WINDOWS\system32\services.exe[1512] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00040F91
.text C:\WINDOWS\system32\services.exe[1512] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00040FAC
.text C:\WINDOWS\system32\services.exe[1512] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00040086
.text C:\WINDOWS\system32\services.exe[1512] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00040069
.text C:\WINDOWS\system32\services.exe[1512] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0004004E
.text C:\WINDOWS\system32\services.exe[1512] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 000400A3
.text C:\WINDOWS\system32\services.exe[1512] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00040F5B
.text C:\WINDOWS\system32\services.exe[1512] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 000400B4
.text C:\WINDOWS\system32\services.exe[1512] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00040F1B
.text C:\WINDOWS\system32\services.exe[1512] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00040F00
.text C:\WINDOWS\system32\services.exe[1512] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00040FBD
.text C:\WINDOWS\system32\services.exe[1512] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00040011
.text C:\WINDOWS\system32\services.exe[1512] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00040F6C
.text C:\WINDOWS\system32\services.exe[1512] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 0004003D
.text C:\WINDOWS\system32\services.exe[1512] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00040022
.text C:\WINDOWS\system32\services.exe[1512] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00040F40
.text C:\WINDOWS\system32\services.exe[1512] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\system32\services.exe[1512] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00720FD1
.text C:\WINDOWS\system32\services.exe[1512] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00720F80
.text C:\WINDOWS\system32\services.exe[1512] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00720022
.text C:\WINDOWS\system32\services.exe[1512] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00720011
.text C:\WINDOWS\system32\services.exe[1512] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00720F9B
.text C:\WINDOWS\system32\services.exe[1512] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00720000
.text C:\WINDOWS\system32\services.exe[1512] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00720FAC
.text C:\WINDOWS\system32\services.exe[1512] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [92, 88]
.text C:\WINDOWS\system32\services.exe[1512] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0072003D
.text C:\WINDOWS\system32\services.exe[1512] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text C:\WINDOWS\system32\services.exe[1512] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text C:\WINDOWS\system32\services.exe[1512] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text C:\WINDOWS\system32\services.exe[1512] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text C:\WINDOWS\system32\services.exe[1512] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text C:\WINDOWS\system32\services.exe[1512] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text C:\WINDOWS\system32\services.exe[1512] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text C:\WINDOWS\system32\services.exe[1512] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text C:\WINDOWS\system32\services.exe[1512] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00070FC3
.text C:\WINDOWS\system32\services.exe[1512] msvcrt.dll!system 77C293C7 5 Bytes JMP 0007004E
.text C:\WINDOWS\system32\services.exe[1512] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00070018
.text C:\WINDOWS\system32\services.exe[1512] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00070FEF
.text C:\WINDOWS\system32\services.exe[1512] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0007003D
.text C:\WINDOWS\system32\services.exe[1512] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00070FDE
.text C:\WINDOWS\system32\services.exe[1512] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text C:\WINDOWS\system32\services.exe[1512] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text C:\WINDOWS\system32\services.exe[1512] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text C:\WINDOWS\system32\services.exe[1512] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text C:\WINDOWS\system32\services.exe[1512] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text C:\WINDOWS\system32\services.exe[1512] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00060FEF
.text C:\WINDOWS\system32\lsass.exe[1524] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00970000
.text C:\WINDOWS\system32\lsass.exe[1524] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00970011
.text C:\WINDOWS\system32\lsass.exe[1524] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00970FE5
.text C:\WINDOWS\system32\lsass.exe[1524] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text C:\WINDOWS\system32\lsass.exe[1524] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\WINDOWS\system32\lsass.exe[1524] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text C:\WINDOWS\system32\lsass.exe[1524] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 0096000A
.text C:\WINDOWS\system32\lsass.exe[1524] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00960FB9
.text C:\WINDOWS\system32\lsass.exe[1524] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 009600A4
.text C:\WINDOWS\system32\lsass.exe[1524] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00960087
.text C:\WINDOWS\system32\lsass.exe[1524] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0096006C
.text C:\WINDOWS\system32\lsass.exe[1524] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00960040
.text C:\WINDOWS\system32\lsass.exe[1524] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 009600DC
.text C:\WINDOWS\system32\lsass.exe[1524] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00960F94
.text C:\WINDOWS\system32\lsass.exe[1524] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 0096012D
.text C:\WINDOWS\system32\lsass.exe[1524] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00960108
.text C:\WINDOWS\system32\lsass.exe[1524] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 0096013E
.text C:\WINDOWS\system32\lsass.exe[1524] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0096005B
.text C:\WINDOWS\system32\lsass.exe[1524] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00960FEF
.text C:\WINDOWS\system32\lsass.exe[1524] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 009600BF
.text C:\WINDOWS\system32\lsass.exe[1524] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 0096001B
.text C:\WINDOWS\system32\lsass.exe[1524] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00960FCA
.text C:\WINDOWS\system32\lsass.exe[1524] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 009600F7
.text C:\WINDOWS\system32\lsass.exe[1524] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\system32\lsass.exe[1524] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00C30FE5
.text C:\WINDOWS\system32\lsass.exe[1524] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00C30080
.text C:\WINDOWS\system32\lsass.exe[1524] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00C30036
.text C:\WINDOWS\system32\lsass.exe[1524] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00C3001B
.text C:\WINDOWS\system32\lsass.exe[1524] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00C30FB9
.text C:\WINDOWS\system32\lsass.exe[1524] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00C3000A
.text C:\WINDOWS\system32\lsass.exe[1524] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00C30FCA
.text C:\WINDOWS\system32\lsass.exe[1524] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [E3, 88] {JECXZ 0xffffffffffffff8a}
.text C:\WINDOWS\system32\lsass.exe[1524] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00C30047
.text C:\WINDOWS\system32\lsass.exe[1524] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text C:\WINDOWS\system32\lsass.exe[1524] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text C:\WINDOWS\system32\lsass.exe[1524] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text C:\WINDOWS\system32\lsass.exe[1524] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text C:\WINDOWS\system32\lsass.exe[1524] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text C:\WINDOWS\system32\lsass.exe[1524] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text C:\WINDOWS\system32\lsass.exe[1524] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text C:\WINDOWS\system32\lsass.exe[1524] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text C:\WINDOWS\system32\lsass.exe[1524] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text C:\WINDOWS\system32\lsass.exe[1524] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text C:\WINDOWS\system32\lsass.exe[1524] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text C:\WINDOWS\system32\lsass.exe[1524] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text C:\WINDOWS\system32\lsass.exe[1524] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text C:\WINDOWS\system32\lsass.exe[1524] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00990F97
.text C:\WINDOWS\system32\lsass.exe[1524] msvcrt.dll!system 77C293C7 5 Bytes JMP 0099002C
.text C:\WINDOWS\system32\lsass.exe[1524] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00990011
.text C:\WINDOWS\system32\lsass.exe[1524] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00990FE3
.text C:\WINDOWS\system32\lsass.exe[1524] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00990FBC
.text C:\WINDOWS\system32\lsass.exe[1524] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00990000
.text C:\WINDOWS\system32\lsass.exe[1524] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00980FEF
.text C:\WINDOWS\system32\Ati2evxx.exe[1700] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001401F8
.text C:\WINDOWS\system32\Ati2evxx.exe[1700] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\WINDOWS\system32\Ati2evxx.exe[1700] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001403FC
.text C:\WINDOWS\system32\Ati2evxx.exe[1700] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\system32\Ati2evxx.exe[1700] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00380804
.text C:\WINDOWS\system32\Ati2evxx.exe[1700] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00380A08
.text C:\WINDOWS\system32\Ati2evxx.exe[1700] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00380600
.text C:\WINDOWS\system32\Ati2evxx.exe[1700] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003801F8
.text C:\WINDOWS\system32\Ati2evxx.exe[1700] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003803FC
.text C:\WINDOWS\system32\Ati2evxx.exe[1700] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014
.text C:\WINDOWS\system32\Ati2evxx.exe[1700] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804
.text C:\WINDOWS\system32\Ati2evxx.exe[1700] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08
.text C:\WINDOWS\system32\Ati2evxx.exe[1700] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C
.text C:\WINDOWS\system32\Ati2evxx.exe[1700] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10
.text C:\WINDOWS\system32\Ati2evxx.exe[1700] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8
.text C:\WINDOWS\system32\Ati2evxx.exe[1700] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC
.text C:\WINDOWS\system32\Ati2evxx.exe[1700] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600
.text C:\WINDOWS\system32\svchost.exe[1720] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00A40000
.text C:\WINDOWS\system32\svchost.exe[1720] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00A40FCA
.text C:\WINDOWS\system32\svchost.exe[1720] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00A40FE5
.text C:\WINDOWS\system32\svchost.exe[1720] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text C:\WINDOWS\system32\svchost.exe[1720] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[1720] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text C:\WINDOWS\system32\svchost.exe[1720] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00A30FEF
.text C:\WINDOWS\system32\svchost.exe[1720] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00A30F4D
.text C:\WINDOWS\system32\svchost.exe[1720] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00A3004C
.text C:\WINDOWS\system32\svchost.exe[1720] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00A3003B
.text C:\WINDOWS\system32\svchost.exe[1720] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00A30F7C
.text C:\WINDOWS\system32\svchost.exe[1720] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00A30FA8
.text C:\WINDOWS\system32\svchost.exe[1720] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00A30F10
.text C:\WINDOWS\system32\svchost.exe[1720] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00A30F21
.text C:\WINDOWS\system32\svchost.exe[1720] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00A30084
.text C:\WINDOWS\system32\svchost.exe[1720] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00A30073
.text C:\WINDOWS\system32\svchost.exe[1720] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00A30ED0
.text C:\WINDOWS\system32\svchost.exe[1720] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00A30F8D
.text C:\WINDOWS\system32\svchost.exe[1720] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00A3000A
.text C:\WINDOWS\system32\svchost.exe[1720] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00A30F32
.text C:\WINDOWS\system32\svchost.exe[1720] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00A30FB9
.text C:\WINDOWS\system32\svchost.exe[1720] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00A30FCA
.text C:\WINDOWS\system32\svchost.exe[1720] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00A30EFF
.text C:\WINDOWS\system32\svchost.exe[1720] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[1720] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00B80047
.text C:\WINDOWS\system32\svchost.exe[1720] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00B8008E
.text C:\WINDOWS\system32\svchost.exe[1720] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00B80036
.text C:\WINDOWS\system32\svchost.exe[1720] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00B80025
.text C:\WINDOWS\system32\svchost.exe[1720] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00B80FD1
.text C:\WINDOWS\system32\svchost.exe[1720] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00B8000A
.text C:\WINDOWS\system32\svchost.exe[1720] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00B80073
.text C:\WINDOWS\system32\svchost.exe[1720] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00B80062
.text C:\WINDOWS\system32\svchost.exe[1720] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text C:\WINDOWS\system32\svchost.exe[1720] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text C:\WINDOWS\system32\svchost.exe[1720] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text C:\WINDOWS\system32\svchost.exe[1720] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text C:\WINDOWS\system32\svchost.exe[1720] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text C:\WINDOWS\system32\svchost.exe[1720] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text C:\WINDOWS\system32\svchost.exe[1720] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text C:\WINDOWS\system32\svchost.exe[1720] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text C:\WINDOWS\system32\svchost.exe[1720] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text C:\WINDOWS\system32\svchost.exe[1720] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text C:\WINDOWS\system32\svchost.exe[1720] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text C:\WINDOWS\system32\svchost.exe[1720] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text C:\WINDOWS\system32\svchost.exe[1720] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text C:\WINDOWS\system32\svchost.exe[1720] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00A6005D
.text C:\WINDOWS\system32\svchost.exe[1720] msvcrt.dll!system 77C293C7 5 Bytes JMP 00A60042
.text C:\WINDOWS\system32\svchost.exe[1720] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00A60FE3
.text C:\WINDOWS\system32\svchost.exe[1720] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00A60000
.text C:\WINDOWS\system32\svchost.exe[1720] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00A60FC8
.text C:\WINDOWS\system32\svchost.exe[1720] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00A6001D
.text C:\WINDOWS\system32\svchost.exe[1720] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00A50000
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[1736] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[1736] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[1736] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[1736] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[1736] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00381014
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[1736] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00380804
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[1736] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00380A08
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[1736] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00380C0C
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[1736] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00380E10
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[1736] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003801F8
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[1736] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003803FC
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[1736] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00380600
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[1736] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00390804
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[1736] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390A08
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[1736] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00390600
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[1736] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003901F8
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[1736] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003903FC
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1744] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1744] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1744] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1744] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1744] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00381014
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1744] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00380804
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1744] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00380A08
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1744] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00380C0C
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1744] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00380E10
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1744] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003801F8
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1744] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003803FC
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1744] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00380600
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1744] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00390804
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1744] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390A08
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1744] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00390600
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1744] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003901F8
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[1744] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003903FC
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1768] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1768] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1768] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1768] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1768] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00380804
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1768] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00380A08
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1768] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00380600
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1768] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003801F8
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1768] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003803FC
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1768] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1768] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1768] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1768] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1768] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1768] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1768] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[1768] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1776] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001601F8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1776] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1776] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001603FC
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1776] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1776] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A1014
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1776] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A0804
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1776] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0A08
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1776] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A0C0C
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1776] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0E10
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1776] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A01F8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1776] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A03FC
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1776] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003A0600
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1776] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003B0804
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1776] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003B0A08
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1776] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003B0600
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1776] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003B01F8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1776] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003B03FC
.text C:\WINDOWS\system32\svchost.exe[1812] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00B40FEF
.text C:\WINDOWS\system32\svchost.exe[1812] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00B4002F
.text C:\WINDOWS\system32\svchost.exe[1812] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B40014
.text C:\WINDOWS\system32\svchost.exe[1812] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text C:\WINDOWS\system32\svchost.exe[1812] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[1812] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text C:\WINDOWS\system32\svchost.exe[1812] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00B30000
.text C:\WINDOWS\system32\svchost.exe[1812] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00B30F80
.text C:\WINDOWS\system32\svchost.exe[1812] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00B30F9B
.text C:\WINDOWS\system32\svchost.exe[1812] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00B30069
.text C:\WINDOWS\system32\svchost.exe[1812] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00B30058
.text C:\WINDOWS\system32\svchost.exe[1812] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00B30FB6
.text C:\WINDOWS\system32\svchost.exe[1812] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00B30F41
.text C:\WINDOWS\system32\svchost.exe[1812] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00B30F5E
.text C:\WINDOWS\system32\svchost.exe[1812] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00B30F15
.text C:\WINDOWS\system32\svchost.exe[1812] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00B30F26
.text C:\WINDOWS\system32\svchost.exe[1812] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00B30EFA
.text C:\WINDOWS\system32\svchost.exe[1812] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00B30033
.text C:\WINDOWS\system32\svchost.exe[1812] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00B30011
.text C:\WINDOWS\system32\svchost.exe[1812] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00B30F6F
.text C:\WINDOWS\system32\svchost.exe[1812] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00B30FD1
.text C:\WINDOWS\system32\svchost.exe[1812] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00B30022
.text C:\WINDOWS\system32\svchost.exe[1812] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00B300A4
.text C:\WINDOWS\system32\svchost.exe[1812] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[1812] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00C20FC3
.text C:\WINDOWS\system32\svchost.exe[1812] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00C20F8D
.text C:\WINDOWS\system32\svchost.exe[1812] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00C20FDE
.text C:\WINDOWS\system32\svchost.exe[1812] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00C20014
.text C:\WINDOWS\system32\svchost.exe[1812] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00C20FA8
.text C:\WINDOWS\system32\svchost.exe[1812] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00C20FEF
.text C:\WINDOWS\system32\svchost.exe[1812] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00C2004A
.text C:\WINDOWS\system32\svchost.exe[1812] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00C2002F
.text C:\WINDOWS\system32\svchost.exe[1812] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text C:\WINDOWS\system32\svchost.exe[1812] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text C:\WINDOWS\system32\svchost.exe[1812] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text C:\WINDOWS\system32\svchost.exe[1812] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text C:\WINDOWS\system32\svchost.exe[1812] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text C:\WINDOWS\system32\svchost.exe[1812] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text C:\WINDOWS\system32\svchost.exe[1812] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text C:\WINDOWS\system32\svchost.exe[1812] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text C:\WINDOWS\system32\svchost.exe[1812] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text C:\WINDOWS\system32\svchost.exe[1812] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text C:\WINDOWS\system32\svchost.exe[1812] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text C:\WINDOWS\system32\svchost.exe[1812] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text C:\WINDOWS\system32\svchost.exe[1812] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text C:\WINDOWS\system32\svchost.exe[1812] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00B60FBE
.text C:\WINDOWS\system32\svchost.exe[1812] msvcrt.dll!system 77C293C7 5 Bytes JMP 00B60049
.text C:\WINDOWS\system32\svchost.exe[1812] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00B6002E
.text C:\WINDOWS\system32\svchost.exe[1812] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00B60000
.text C:\WINDOWS\system32\svchost.exe[1812] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00B60FCF
.text C:\WINDOWS\system32\svchost.exe[1812] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00B6001D
.text C:\WINDOWS\system32\svchost.exe[1812] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00B50000
.text C:\WINDOWS\System32\svchost.exe[2028] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 01D00FEF
.text C:\WINDOWS\System32\svchost.exe[2028] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 01D0001E
.text C:\WINDOWS\System32\svchost.exe[2028] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 01D00FDE
.text C:\WINDOWS\System32\svchost.exe[2028] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text C:\WINDOWS\System32\svchost.exe[2028] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\WINDOWS\System32\svchost.exe[2028] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text C:\WINDOWS\System32\svchost.exe[2028] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 018E0FEF
.text C:\WINDOWS\System32\svchost.exe[2028] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 018E0082
.text C:\WINDOWS\System32\svchost.exe[2028] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 018E0071
.text C:\WINDOWS\System32\svchost.exe[2028] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 018E0F8D
.text C:\WINDOWS\System32\svchost.exe[2028] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 018E004A
.text C:\WINDOWS\System32\svchost.exe[2028] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 018E0FC3
.text C:\WINDOWS\System32\svchost.exe[2028] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 018E00B8
.text C:\WINDOWS\System32\svchost.exe[2028] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 018E00A7
.text C:\WINDOWS\System32\svchost.exe[2028] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 018E0F33
.text C:\WINDOWS\System32\svchost.exe[2028] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 018E0F4E
.text C:\WINDOWS\System32\svchost.exe[2028] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 018E0F22
.text C:\WINDOWS\System32\svchost.exe[2028] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 018E0FB2
.text C:\WINDOWS\System32\svchost.exe[2028] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 018E000A
.text C:\WINDOWS\System32\svchost.exe[2028] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 018E0F7C
.text C:\WINDOWS\System32\svchost.exe[2028] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 018E0025
.text C:\WINDOWS\System32\svchost.exe[2028] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 018E0FD4
.text C:\WINDOWS\System32\svchost.exe[2028] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 018E0F5F
.text C:\WINDOWS\System32\svchost.exe[2028] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\System32\svchost.exe[2028] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01D60FC3
.text C:\WINDOWS\System32\svchost.exe[2028] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01D60076
.text C:\WINDOWS\System32\svchost.exe[2028] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01D60FD4
.text C:\WINDOWS\System32\svchost.exe[2028] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01D60000
.text C:\WINDOWS\System32\svchost.exe[2028] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01D60065
.text C:\WINDOWS\System32\svchost.exe[2028] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01D60FEF
.text C:\WINDOWS\System32\svchost.exe[2028] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 01D60054
.text C:\WINDOWS\System32\svchost.exe[2028] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01D60039
.text C:\WINDOWS\System32\svchost.exe[2028] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text C:\WINDOWS\System32\svchost.exe[2028] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text C:\WINDOWS\System32\svchost.exe[2028] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text C:\WINDOWS\System32\svchost.exe[2028] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text C:\WINDOWS\System32\svchost.exe[2028] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text C:\WINDOWS\System32\svchost.exe[2028] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text C:\WINDOWS\System32\svchost.exe[2028] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text C:\WINDOWS\System32\svchost.exe[2028] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text C:\WINDOWS\System32\svchost.exe[2028] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text C:\WINDOWS\System32\svchost.exe[2028] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text C:\WINDOWS\System32\svchost.exe[2028] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text C:\WINDOWS\System32\svchost.exe[2028] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text C:\WINDOWS\System32\svchost.exe[2028] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text C:\WINDOWS\System32\svchost.exe[2028] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01D50FA3
.text C:\WINDOWS\System32\svchost.exe[2028] msvcrt.dll!system 77C293C7 5 Bytes JMP 01D5002E
.text C:\WINDOWS\System32\svchost.exe[2028] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01D50FE3
.text C:\WINDOWS\System32\svchost.exe[2028] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01D5000C
.text C:\WINDOWS\System32\svchost.exe[2028] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01D50FBE
.text C:\WINDOWS\System32\svchost.exe[2028] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01D5001D
.text C:\WINDOWS\System32\svchost.exe[2028] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01D20FE5
.text C:\WINDOWS\System32\svchost.exe[2028] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 01D10000
.text C:\WINDOWS\System32\svchost.exe[2028] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 01D10FEF
.text C:\WINDOWS\System32\svchost.exe[2028] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 01D1002F
.text C:\WINDOWS\System32\svchost.exe[2028] WININET.dll!InternetOpenUrlW 3D9A6D5F 5 Bytes JMP 01D10FDE
.text C:\WINDOWS\system32\rundll32.exe[2112] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text C:\WINDOWS\system32\rundll32.exe[2112] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\WINDOWS\system32\rundll32.exe[2112] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text C:\WINDOWS\system32\rundll32.exe[2112] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\system32\rundll32.exe[2112] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002B0804
.text C:\WINDOWS\system32\rundll32.exe[2112] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002B0A08
.text C:\WINDOWS\system32\rundll32.exe[2112] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002B0600
.text C:\WINDOWS\system32\rundll32.exe[2112] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002B01F8
.text C:\WINDOWS\system32\rundll32.exe[2112] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002B03FC
.text C:\WINDOWS\system32\rundll32.exe[2112] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002C1014
.text C:\WINDOWS\system32\rundll32.exe[2112] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002C0804
.text C:\WINDOWS\system32\rundll32.exe[2112] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002C0A08
.text C:\WINDOWS\system32\rundll32.exe[2112] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002C0C0C
.text C:\WINDOWS\system32\rundll32.exe[2112] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002C0E10
.text C:\WINDOWS\system32\rundll32.exe[2112] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002C01F8
.text C:\WINDOWS\system32\rundll32.exe[2112] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002C03FC
.text C:\WINDOWS\system32\rundll32.exe[2112] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002C0600
.text C:\WINDOWS\System32\alg.exe[2480] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text C:\WINDOWS\System32\alg.exe[2480] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\WINDOWS\System32\alg.exe[2480] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text C:\WINDOWS\System32\alg.exe[2480] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\System32\alg.exe[2480] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002B0804
.text C:\WINDOWS\System32\alg.exe[2480] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002B0A08
.text C:\WINDOWS\System32\alg.exe[2480] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002B0600
.text C:\WINDOWS\System32\alg.exe[2480] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002B01F8
.text C:\WINDOWS\System32\alg.exe[2480] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002B03FC
.text C:\WINDOWS\System32\alg.exe[2480] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002C1014
.text C:\WINDOWS\System32\alg.exe[2480] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002C0804
.text C:\WINDOWS\System32\alg.exe[2480] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002C0A08
.text C:\WINDOWS\System32\alg.exe[2480] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002C0C0C
.text C:\WINDOWS\System32\alg.exe[2480] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002C0E10
.text C:\WINDOWS\System32\alg.exe[2480] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002C01F8
.text C:\WINDOWS\System32\alg.exe[2480] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002C03FC
.text C:\WINDOWS\System32\alg.exe[2480] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002C0600
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2500] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2500] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2500] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2500] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 62419A20 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2500] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 62419AE2 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2500] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2500] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2500] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2500] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2500] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2500] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2500] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2500] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2500] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2500] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A0804
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2500] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0A08
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2500] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A0600
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2500] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A01F8
.text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2500] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A03FC
.text C:\WINDOWS\system32\mfevtps.exe[2604] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8
.text C:\WINDOWS\system32\mfevtps.exe[2604] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\WINDOWS\system32\mfevtps.exe[2604] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC
.text C:\WINDOWS\system32\mfevtps.exe[2604] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\system32\mfevtps.exe[2604] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014
.text C:\WINDOWS\system32\mfevtps.exe[2604] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804
.text C:\WINDOWS\system32\mfevtps.exe[2604] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08
.text C:\WINDOWS\system32\mfevtps.exe[2604] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C
.text C:\WINDOWS\system32\mfevtps.exe[2604] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10
.text C:\WINDOWS\system32\mfevtps.exe[2604] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8
.text C:\WINDOWS\system32\mfevtps.exe[2604] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC
.text C:\WINDOWS\system32\mfevtps.exe[2604] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600
.text C:\WINDOWS\system32\mfevtps.exe[2604] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A0804
.text C:\WINDOWS\system32\mfevtps.exe[2604] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0A08
.text C:\WINDOWS\system32\mfevtps.exe[2604] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A0600
.text C:\WINDOWS\system32\mfevtps.exe[2604] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A01F8
.text C:\WINDOWS\system32\mfevtps.exe[2604] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A03FC
.text C:\WINDOWS\system32\spoolsv.exe[2744] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text C:\WINDOWS\system32\spoolsv.exe[2744] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\WINDOWS\system32\spoolsv.exe[2744] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text C:\WINDOWS\system32\spoolsv.exe[2744] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\system32\spoolsv.exe[2744] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text C:\WINDOWS\system32\spoolsv.exe[2744] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text C:\WINDOWS\system32\spoolsv.exe[2744] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text C:\WINDOWS\system32\spoolsv.exe[2744] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text C:\WINDOWS\system32\spoolsv.exe[2744] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text C:\WINDOWS\system32\spoolsv.exe[2744] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text C:\WINDOWS\system32\spoolsv.exe[2744] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text C:\WINDOWS\system32\spoolsv.exe[2744] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text C:\WINDOWS\system32\spoolsv.exe[2744] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text C:\WINDOWS\system32\spoolsv.exe[2744] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text C:\WINDOWS\system32\spoolsv.exe[2744] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text C:\WINDOWS\system32\spoolsv.exe[2744] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text C:\WINDOWS\system32\spoolsv.exe[2744] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text C:\Program Files\McAfee Online Backup\MOBKbackup.exe[2836] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8
.text C:\Program Files\McAfee Online Backup\MOBKbackup.exe[2836] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\McAfee Online Backup\MOBKbackup.exe[2836] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC
.text C:\Program Files\McAfee Online Backup\MOBKbackup.exe[2836] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Program Files\McAfee Online Backup\MOBKbackup.exe[2836] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003D1014
.text C:\Program Files\McAfee Online Backup\MOBKbackup.exe[2836] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003D0804
.text C:\Program Files\McAfee Online Backup\MOBKbackup.exe[2836] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003D0A08
.text C:\Program Files\McAfee Online Backup\MOBKbackup.exe[2836] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003D0C0C
.text C:\Program Files\McAfee Online Backup\MOBKbackup.exe[2836] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003D0E10
.text C:\Program Files\McAfee Online Backup\MOBKbackup.exe[2836] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003D01F8
.text C:\Program Files\McAfee Online Backup\MOBKbackup.exe[2836] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003D03FC
.text C:\Program Files\McAfee Online Backup\MOBKbackup.exe[2836] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003D0600
.text C:\Program Files\McAfee Online Backup\MOBKbackup.exe[2836] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003E0804
.text C:\Program Files\McAfee Online Backup\MOBKbackup.exe[2836] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003E0A08
.text C:\Program Files\McAfee Online Backup\MOBKbackup.exe[2836] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003E0600
.text C:\Program Files\McAfee Online Backup\MOBKbackup.exe[2836] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003E01F8
.text C:\Program Files\McAfee Online Backup\MOBKbackup.exe[2836] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003E03FC
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3112] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3112] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3112] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3112] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3112] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002E1014
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3112] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002E0804
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3112] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002E0A08
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3112] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002E0C0C
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3112] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002E0E10
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3112] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002E01F8
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3112] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002E03FC
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3112] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002E0600
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3112] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002F0804
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3112] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002F0A08
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3112] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002F0600
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3112] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002F01F8
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3112] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002F03FC
.text C:\WINDOWS\system32\svchost.exe[3212] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00A20FEF
.text C:\WINDOWS\system32\svchost.exe[3212] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00A20FB9
.text C:\WINDOWS\system32\svchost.exe[3212] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00A20FD4
.text C:\WINDOWS\system32\svchost.exe[3212] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text C:\WINDOWS\system32\svchost.exe[3212] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[3212] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text C:\WINDOWS\system32\svchost.exe[3212] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00A10FEF
.text C:\WINDOWS\system32\svchost.exe[3212] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00A10F64
.text C:\WINDOWS\system32\svchost.exe[3212] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00A10F75
.text C:\WINDOWS\system32\svchost.exe[3212] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00A10F86
.text C:\WINDOWS\system32\svchost.exe[3212] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00A10F97
.text C:\WINDOWS\system32\svchost.exe[3212] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00A10FB9
.text C:\WINDOWS\system32\svchost.exe[3212] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00A10F2C
.text C:\WINDOWS\system32\svchost.exe[3212] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00A10F49
.text C:\WINDOWS\system32\svchost.exe[3212] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00A1008F
.text C:\WINDOWS\system32\svchost.exe[3212] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00A10F00
.text C:\WINDOWS\system32\svchost.exe[3212] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00A10EE5
.text C:\WINDOWS\system32\svchost.exe[3212] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00A10FA8
.text C:\WINDOWS\system32\svchost.exe[3212] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00A1000A
.text C:\WINDOWS\system32\svchost.exe[3212] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00A10074
.text C:\WINDOWS\system32\svchost.exe[3212] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00A10FD4
.text C:\WINDOWS\system32\svchost.exe[3212] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00A10025
.text C:\WINDOWS\system32\svchost.exe[3212] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00A10F1B
.text C:\WINDOWS\system32\svchost.exe[3212] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[3212] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00A00025
.text C:\WINDOWS\system32\svchost.exe[3212] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00A0006C
.text C:\WINDOWS\system32\svchost.exe[3212] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00A0000A
.text C:\WINDOWS\system32\svchost.exe[3212] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00A00FD4
.text C:\WINDOWS\system32\svchost.exe[3212] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00A00051
.text C:\WINDOWS\system32\svchost.exe[3212] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00A00FEF
.text C:\WINDOWS\system32\svchost.exe[3212] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00A00FB9
.text C:\WINDOWS\system32\svchost.exe[3212] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [C0, 88]
.text C:\WINDOWS\system32\svchost.exe[3212] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00A00036
.text C:\WINDOWS\system32\svchost.exe[3212] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text C:\WINDOWS\system32\svchost.exe[3212] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text C:\WINDOWS\system32\svchost.exe[3212] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text C:\WINDOWS\system32\svchost.exe[3212] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text C:\WINDOWS\system32\svchost.exe[3212] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text C:\WINDOWS\system32\svchost.exe[3212] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text C:\WINDOWS\system32\svchost.exe[3212] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text C:\WINDOWS\system32\svchost.exe[3212] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text C:\WINDOWS\system32\svchost.exe[3212] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text C:\WINDOWS\system32\svchost.exe[3212] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text C:\WINDOWS\system32\svchost.exe[3212] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text C:\WINDOWS\system32\svchost.exe[3212] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text C:\WINDOWS\system32\svchost.exe[3212] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text C:\WINDOWS\system32\svchost.exe[3212] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 009F005F
.text C:\WINDOWS\system32\svchost.exe[3212] msvcrt.dll!system 77C293C7 5 Bytes JMP 009F0044
.text C:\WINDOWS\system32\svchost.exe[3212] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 009F0FDE
.text C:\WINDOWS\system32\svchost.exe[3212] msvcrt.dll!_open 77C2F566 5 Bytes JMP 009F0FEF
.text C:\WINDOWS\system32\svchost.exe[3212] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 009F0033
.text C:\WINDOWS\system32\svchost.exe[3212] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 009F0018
.text C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe[3244] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001401F8
.text C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe[3244] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe[3244] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001403FC
.text C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe[3244] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe[3244] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00381014
.text C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe[3244] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00380804
.text C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe[3244] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00380A08
.text C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe[3244] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00380C0C
.text C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe[3244] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00380E10
.text C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe[3244] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003801F8
.text C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe[3244] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003803FC
.text C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe[3244] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00380600
.text C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe[3244] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00390804
.text C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe[3244] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390A08
.text C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe[3244] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00390600
.text C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe[3244] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003901F8
.text C:\Program Files\VMware\VMware View\Client\bin\wsnm.exe[3244] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003903FC
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[3336] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[3336] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[3336] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[3336] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[3336] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00390804
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[3336] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390A08
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[3336] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00390600
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[3336] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003901F8
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[3336] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003903FC
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[3336] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A1014
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[3336] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A0804
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[3336] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0A08
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[3336] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A0C0C
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[3336] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0E10
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[3336] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A01F8
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[3336] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A03FC
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe[3336] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003A0600
.text C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe[3484] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8
.text C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe[3484] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe[3484] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC
.text C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe[3484] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe[3484] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014
.text C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe[3484] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804
.text C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe[3484] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08
.text C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe[3484] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C
.text C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe[3484] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10
.text C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe[3484] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8
.text C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe[3484] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC
.text C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe[3484] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600
.text C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe[3484] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A0804
.text C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe[3484] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0A08
.text C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe[3484] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A0600
.text C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe[3484] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A01F8
.text C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe[3484] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A03FC
.text C:\Documents and Settings\Standard User\Local Settings\Temporary Internet Files\Content.IE5\RC4F0XP2\oc8qq34p[1].exe[3572] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001601F8
.text C:\Documents and Settings\Standard User\Local Settings\Temporary Internet Files\Content.IE5\RC4F0XP2\oc8qq34p[1].exe[3572] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Documents and Settings\Standard User\Local Settings\Temporary Internet Files\Content.IE5\RC4F0XP2\oc8qq34p[1].exe[3572] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001603FC
.text C:\Documents and Settings\Standard User\Local Settings\Temporary Internet Files\Content.IE5\RC4F0XP2\oc8qq34p[1].exe[3572] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Documents and Settings\Standard User\Local Settings\Temporary Internet Files\Content.IE5\RC4F0XP2\oc8qq34p[1].exe[3572] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003E1014
.text C:\Documents and Settings\Standard User\Local Settings\Temporary Internet Files\Content.IE5\RC4F0XP2\oc8qq34p[1].exe[3572] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003E0804
.text C:\Documents and Settings\Standard User\Local Settings\Temporary Internet Files\Content.IE5\RC4F0XP2\oc8qq34p[1].exe[3572] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003E0A08
.text C:\Documents and Settings\Standard User\Local Settings\Temporary Internet Files\Content.IE5\RC4F0XP2\oc8qq34p[1].exe[3572] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003E0C0C
.text C:\Documents and Settings\Standard User\Local Settings\Temporary Internet Files\Content.IE5\RC4F0XP2\oc8qq34p[1].exe[3572] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003E0E10
.text C:\Documents and Settings\Standard User\Local Settings\Temporary Internet Files\Content.IE5\RC4F0XP2\oc8qq34p[1].exe[3572] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003E01F8
.text C:\Documents and Settings\Standard User\Local Settings\Temporary Internet Files\Content.IE5\RC4F0XP2\oc8qq34p[1].exe[3572] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003E03FC
.text C:\Documents and Settings\Standard User\Local Settings\Temporary Internet Files\Content.IE5\RC4F0XP2\oc8qq34p[1].exe[3572] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003E0600
.text C:\Documents and Settings\Standard User\Local Settings\Temporary Internet Files\Content.IE5\RC4F0XP2\oc8qq34p[1].exe[3572] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003F0804
.text C:\Documents and Settings\Standard User\Local Settings\Temporary Internet Files\Content.IE5\RC4F0XP2\oc8qq34p[1].exe[3572] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003F0A08
.text C:\Documents and Settings\Standard User\Local Settings\Temporary Internet Files\Content.IE5\RC4F0XP2\oc8qq34p[1].exe[3572] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003F0600
.text C:\Documents and Settings\Standard User\Local Settings\Temporary Internet Files\Content.IE5\RC4F0XP2\oc8qq34p[1].exe[3572] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003F01F8
.text C:\Documents and Settings\Standard User\Local Settings\Temporary Internet Files\Content.IE5\RC4F0XP2\oc8qq34p[1].exe[3572] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003F03FC
.text C:\WINDOWS\system32\svchost.exe[3720] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 00C50000
.text C:\WINDOWS\system32\svchost.exe[3720] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00C50FEF
.text C:\WINDOWS\system32\svchost.exe[3720] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00C5001B
.text C:\WINDOWS\system32\svchost.exe[3720] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text C:\WINDOWS\system32\svchost.exe[3720] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[3720] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text C:\WINDOWS\system32\svchost.exe[3720] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C40000
.text C:\WINDOWS\system32\svchost.exe[3720] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00C4006C
.text C:\WINDOWS\system32\svchost.exe[3720] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00C40F81
.text C:\WINDOWS\system32\svchost.exe[3720] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00C40F92
.text C:\WINDOWS\system32\svchost.exe[3720] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00C4005B
.text C:\WINDOWS\system32\svchost.exe[3720] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00C40036
.text C:\WINDOWS\system32\svchost.exe[3720] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00C40F24
.text C:\WINDOWS\system32\svchost.exe[3720] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00C40F3F
.text C:\WINDOWS\system32\svchost.exe[3720] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C400A2
.text C:\WINDOWS\system32\svchost.exe[3720] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C40087
.text C:\WINDOWS\system32\svchost.exe[3720] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00C400BD
.text C:\WINDOWS\system32\svchost.exe[3720] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00C40FB9
.text C:\WINDOWS\system32\svchost.exe[3720] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00C40FEF
.text C:\WINDOWS\system32\svchost.exe[3720] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00C40F5C
.text C:\WINDOWS\system32\svchost.exe[3720] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00C40FCA
.text C:\WINDOWS\system32\svchost.exe[3720] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00C40025
.text C:\WINDOWS\system32\svchost.exe[3720] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00C40F13
.text C:\WINDOWS\system32\svchost.exe[3720] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[3720] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0070002C
.text C:\WINDOWS\system32\svchost.exe[3720] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00700076
.text C:\WINDOWS\system32\svchost.exe[3720] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00700FDB
.text C:\WINDOWS\system32\svchost.exe[3720] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 0070001B
.text C:\WINDOWS\system32\svchost.exe[3720] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00700FB9
.text C:\WINDOWS\system32\svchost.exe[3720] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 0070000A
.text C:\WINDOWS\system32\svchost.exe[3720] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00700FCA
.text C:\WINDOWS\system32\svchost.exe[3720] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [90, 88]
.text C:\WINDOWS\system32\svchost.exe[3720] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00700051
.text C:\WINDOWS\system32\svchost.exe[3720] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text C:\WINDOWS\system32\svchost.exe[3720] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text C:\WINDOWS\system32\svchost.exe[3720] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text C:\WINDOWS\system32\svchost.exe[3720] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text C:\WINDOWS\system32\svchost.exe[3720] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text C:\WINDOWS\system32\svchost.exe[3720] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text C:\WINDOWS\system32\svchost.exe[3720] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text C:\WINDOWS\system32\svchost.exe[3720] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text C:\WINDOWS\system32\svchost.exe[3720] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text C:\WINDOWS\system32\svchost.exe[3720] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text C:\WINDOWS\system32\svchost.exe[3720] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text C:\WINDOWS\system32\svchost.exe[3720] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text C:\WINDOWS\system32\svchost.exe[3720] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text C:\WINDOWS\system32\svchost.exe[3720] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 006F0F92
.text C:\WINDOWS\system32\svchost.exe[3720] msvcrt.dll!system 77C293C7 5 Bytes JMP 006F0027
.text C:\WINDOWS\system32\svchost.exe[3720] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 006F000C
.text C:\WINDOWS\system32\svchost.exe[3720] msvcrt.dll!_open 77C2F566 5 Bytes JMP 006F0FEF
.text C:\WINDOWS\system32\svchost.exe[3720] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 006F0FAD
.text C:\WINDOWS\system32\svchost.exe[3720] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 006F0FD2
.text C:\WINDOWS\system32\svchost.exe[3720] WININET.dll!InternetOpenA 3D95D690 5 Bytes JMP 006D000A
.text C:\WINDOWS\system32\svchost.exe[3720] WININET.dll!InternetOpenW 3D95DB09 5 Bytes JMP 006D001B
.text C:\WINDOWS\system32\svchost.exe[3720] WININET.dll!InternetOpenUrlA 3D95F3A4 5 Bytes JMP 006D002C
.text C:\WINDOWS\system32\svchost.exe[3720] WININET.dll!InternetOpenUrlW 3D9A6D5F 5 Bytes JMP 006D0047
.text C:\WINDOWS\system32\svchost.exe[3720] WS2_32.dll!socket 71AB4211 5 Bytes JMP 006E0FEF
.text C:\Program Files\Bonjour\mDNSResponder.exe[3760] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8
.text C:\Program Files\Bonjour\mDNSResponder.exe[3760] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\Bonjour\mDNSResponder.exe[3760] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC
.text C:\Program Files\Bonjour\mDNSResponder.exe[3760] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Program Files\Bonjour\mDNSResponder.exe[3760] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014
.text C:\Program Files\Bonjour\mDNSResponder.exe[3760] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804
.text C:\Program Files\Bonjour\mDNSResponder.exe[3760] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08
.text C:\Program Files\Bonjour\mDNSResponder.exe[3760] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C
.text C:\Program Files\Bonjour\mDNSResponder.exe[3760] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10
.text C:\Program Files\Bonjour\mDNSResponder.exe[3760] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8
.text C:\Program Files\Bonjour\mDNSResponder.exe[3760] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC
.text C:\Program Files\Bonjour\mDNSResponder.exe[3760] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600
.text C:\Program Files\Bonjour\mDNSResponder.exe[3760] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A0804
.text C:\Program Files\Bonjour\mDNSResponder.exe[3760] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0A08
.text C:\Program Files\Bonjour\mDNSResponder.exe[3760] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A0600
.text C:\Program Files\Bonjour\mDNSResponder.exe[3760] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A01F8
.text C:\Program Files\Bonjour\mDNSResponder.exe[3760] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A03FC
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[3904] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[3904] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[3904] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[3904] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[3904] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00621014
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[3904] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00620804
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[3904] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00620A08
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[3904] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00620C0C
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[3904] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00620E10
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[3904] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 006201F8
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[3904] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 006203FC
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[3904] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00620600
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[3904] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00630804
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[3904] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00630A08
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[3904] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00630600
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[3904] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 006301F8
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[3904] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 006303FC
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4552] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001601F8
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4552] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4552] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001603FC
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4552] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4552] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A1014
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4552] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A0804
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4552] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0A08
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4552] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A0C0C
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4552] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0E10
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4552] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A01F8
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4552] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A03FC
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4552] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003A0600
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4552] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003B0804
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4552] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003B0A08
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4552] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003B0600
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4552] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003B01F8
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4552] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003B03FC
.text C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe[4868] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8
.text C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe[4868] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe[4868] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC
.text C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe[4868] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe[4868] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A1014
.text C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe[4868] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A0804
.text C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe[4868] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0A08
.text C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe[4868] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A0C0C
.text C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe[4868] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0E10
.text C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe[4868] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A01F8
.text C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe[4868] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A03FC
.text C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe[4868] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003A0600
.text C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe[4868] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003B0804
.text C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe[4868] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003B0A08
.text C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe[4868] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003B0600
.text C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe[4868] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003B01F8
.text C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe[4868] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003B03FC

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\WINDOWS\system32\services.exe[1512] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 005E0002
IAT C:\WINDOWS\system32\services.exe[1512] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 005E0000
IAT C:\WINDOWS\system32\mfevtps.exe[2604] @ C:\WINDOWS\system32\CRYPT32.dll [ADVAPI32.dll!RegQueryValueExW] [00407740] C:\WINDOWS\system32\mfevtps.exe (McAfee Process Validation Service/McAfee, Inc.)
IAT C:\WINDOWS\system32\mfevtps.exe[2604] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [004077A0] C:\WINDOWS\system32\mfevtps.exe (McAfee Process Validation Service/McAfee, Inc.)

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/AVAST Software)

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software)
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Ntfs \Ntfs MOBK.sys (Mozy Change Monitor Filter Driver/Mozy, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\Ip mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\Udp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdi2k.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)

Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device 9BFD9D20

AttachedDevice fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
AttachedDevice MOBK.sys (Mozy Change Monitor Filter Driver/Mozy, Inc.)

Device Fs_Rec.SYS (File System Recognizer Driver/Microsoft Corporation)

---- Threads - GMER 1.0.15 ----

Thread System [4:5668] 9C190730

---- EOF - GMER 1.0.15 ----

#6 cryptodan

cryptodan

    Bleepin Madman


  • Members
  • 21,868 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Catonsville, Md
  • Local time:06:45 PM

Posted 22 May 2011 - 01:42 PM

Please Update Malwarebytes, and rerun the scans.

#7 ayamcd

ayamcd
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:45 PM

Posted 22 May 2011 - 05:03 PM

I tried but the thing would get to 100% then say update failed. I will try again.

#8 ayamcd

ayamcd
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:45 PM

Posted 22 May 2011 - 07:31 PM

got it updated here is the log

Malwarebytes' Anti-Malware 1.51.0.600
www.malwarebytes.org

Database version: 6644

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

5/22/2011 7:24:59 PM
mbam-log-2011-05-22 (19-24-59).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 293529
Time elapsed: 1 hour(s), 24 minute(s), 21 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

#9 cryptodan

cryptodan

    Bleepin Madman


  • Members
  • 21,868 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Catonsville, Md
  • Local time:06:45 PM

Posted 24 May 2011 - 04:59 PM

How is the PC running now?

#10 ayamcd

ayamcd
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:01:45 PM

Posted 24 May 2011 - 08:06 PM

It is still slow and my antivirus keeps getting turned off. not the avast the mcafee

#11 cryptodan

cryptodan

    Bleepin Madman


  • Members
  • 21,868 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Catonsville, Md
  • Local time:06:45 PM

Posted 24 May 2011 - 08:10 PM

Remove one and keep the other. Thats why it is slow.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users