Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Vista Home Premium not connecting to internet


  • Please log in to reply
6 replies to this topic

#1 In-Dell-ible

In-Dell-ible

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:55 AM

Posted 12 October 2011 - 07:36 PM

I have in my possesion a friend's Dell Dimension 4700 desktop. It appears to function fine, except that there is no internet access.

It has Windows Vista Home Premium with SP 2, McAfee AntiVirus Plus Version 11, Build 11.0.586; VirusScan version 15.0, Build 15.0.291; Firewall Version 12.0, Build 12.0.344.
It has been without internet capability for several weeks, so once I got a hold of it I did the following:

  • I tried connecting it via a known working cat 5 to a router. I can ping and tracert via command window, I can see the IP setup, but no internet with either IE 9 or Google Chrome.
  • Reset the Winsock and IPconfig
  • Downloaded and transferred via USB drive the latest definitions for McAfee, ran a full scan with nothing found.
  • Installed Malwarebytes with updated reference file, ran a full scan with nothing found.
  • Internet connection status shows traffic sent and received, but no browser can launch. IPv4 WINS server, IPv6 Default Gateway, and IPv6 DNS Server are all blank.

The trouble apparently started with the last batch of Windows updates, then the computer was turned off. Once it was turned back on, no more internet. It's interesting to note that over the past month, any update for "Definition Update for Microsoft Security Essentials - KB2310138" has failed. I have not done a system cleanup or defrag yet.

I am looking for advice on the next step of troubleshooting. The next step from my point of view is either get a Priest for an exorcism, possibly some mild explosives, or just plain shoot it.

Thank you in advance for your time.

Edited by Budapest, 12 October 2011 - 08:14 PM.
Moved from Vista ~Budapest


BC AdBot (Login to Remove)

 


#2 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,663 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:03:55 AM

Posted 12 October 2011 - 08:10 PM

Welcome aboard Posted Image

Download Security Check from HERE, and save it to your Desktop.

* Double-click SecurityCheck.exe
* Follow the onscreen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt; please post the contents of that document.

=============================================================================

Please download MiniToolBox and run it.

Checkmark following boxes:
  • Report IE Proxy Settings
  • Report FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Users, Partitions and Memory size
Click Go and post the result.

=============================================================================

Download Malwarebytes' Anti-Malware (aka MBAM): https://www.bleepingcomputer.com/download/malwarebytes-anti-malware/ to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform quick scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

Be sure to restart the computer.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

=============================================================================

Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

    Posted Image
  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and be sure to re-enable your anti-virus, Firewall and any other security programs you had disabled.

IMPORTANT! If for some reason GMER refuses to run, try again.
If it still fails, try to UN-check "Devices" in right pane.
If still no joy, try to run it from Safe Mode.

My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#3 In-Dell-ible

In-Dell-ible
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:55 AM

Posted 12 October 2011 - 09:55 PM

HI Broni -

Thank you for the prompt response.


I'm running the requested scans now. The resulting files are quite long, I will post accordingly.

Edited by In-Dell-ible, 12 October 2011 - 10:22 PM.


#4 In-Dell-ible

In-Dell-ible
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:55 AM

Posted 12 October 2011 - 11:23 PM

Broni -

In accordance with Murphy's Law, the computer I am using has decided to no longer allow me to post on this site (I'll start another post later...)

Here are the logs as requested, sent in safe mode from my POS. Hope this works.

Thank you again.

Security Check:

Results of screen317's Security Check version 0.99.7
Windows Vista Service Pack 2 (UAC is enabled)
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Disabled!
McAfee AntiVirus Plus
Microsoft Security Essentials
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
Adobe Flash Player 10.3.181.34
Adobe Reader X (10.1.1)
````````````````````````````````
Process Check:
objlist.exe by Laurent

Windows Defender MSMpEng.exe
Malwarebytes' Anti-Malware mbamservice.exe
Malwarebytes' Anti-Malware mbamgui.exe
mcafee VIRUSS~1 mcvsshld.exe
Microsoft Security Client Antimalware MsMpEng.exe
Microsoft Security Client Antimalware NisSrv.exe
``````````End of Log````````````




MiniToolBox by Farbar
Ran by Vanessa (administrator) on 12-10-2011 at 22:42:32
Windows Vista ™ Home Premium Service Pack 2 (X86)

***************************************************************************

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

========================= FF Proxy Settings: ==============================

========================= Hosts content: =================================

::1 localhost

127.0.0.1 localhost

========================= IP Configuration: ================================

# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset


popd
# End of IPv4 configuration



Windows IP Configuration

Host Name . . . . . . . . . . . . : vanessa
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : Delta

Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . : Delta
Description . . . . . . . . . . . : Intel® PRO/100 VE Network Connection
Physical Address. . . . . . . . . : 00-11-11-C9-F2-85
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::a5ac:cd62:4062:9b34%12(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.2.100(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : Wednesday, October 12, 2011 9:07:45 AM
Lease Expires . . . . . . . . . . : Sunday, November 19, 2147 5:10:48 AM
Default Gateway . . . . . . . . . : 192.168.2.250
DHCP Server . . . . . . . . . . . : 192.168.2.250
DHCPv6 IAID . . . . . . . . . . . : 318771473
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-15-A2-31-D4-00-11-11-C9-F2-85
DNS Servers . . . . . . . . . . . : 192.168.2.250
NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter Local Area Connection*:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 02-00-54-55-4E-01
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv6 Address. . . . . . . . . . . : 2001:0:4137:9e76:2020:15db:3f57:fd9b(Preferred)
Link-local IPv6 Address . . . . . : fe80::2020:15db:3f57:fd9b%8(Preferred)
Default Gateway . . . . . . . . . : ::
NetBIOS over Tcpip. . . . . . . . : Disabled

Tunnel adapter Local Area Connection* 8:

Connection-specific DNS Suffix . : Delta
Description . . . . . . . . . . . : isatap.Delta
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::5efe:192.168.2.100%13(Preferred)
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . : 192.168.2.250
NetBIOS over Tcpip. . . . . . . . : Disabled
DNS request timed out.
timeout was 2 seconds.
Server: UnKnown
Address: 192.168.2.250

DNS request timed out.
timeout was 2 seconds.
Name: google.com
Addresses: 72.14.204.103
72.14.204.147
72.14.204.99
72.14.204.104
72.14.204.105



Pinging google.com [72.14.204.103] with 32 bytes of data:

Reply from 72.14.204.103: bytes=32 time=41ms TTL=52

Reply from 72.14.204.103: bytes=32 time=24ms TTL=52



Ping statistics for 72.14.204.103:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 24ms, Maximum = 41ms, Average = 32ms

Server: UnKnown
Address: 192.168.2.250

DNS request timed out.
timeout was 2 seconds.
Name: yahoo.com.Delta
Address: 92.242.140.1



Pinging yahoo.com [209.191.122.70] with 32 bytes of data:

Reply from 209.191.122.70: bytes=32 time=103ms TTL=49

Reply from 209.191.122.70: bytes=32 time=55ms TTL=49



Ping statistics for 209.191.122.70:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 55ms, Maximum = 103ms, Average = 79ms



Pinging 127.0.0.1 with 32 bytes of data:

Reply from 127.0.0.1: bytes=32 time=8ms TTL=128

Reply from 127.0.0.1: bytes=32 time=2ms TTL=128



Ping statistics for 127.0.0.1:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 2ms, Maximum = 8ms, Average = 5ms

===========================================================================
Interface List
12 ...00 11 11 c9 f2 85 ...... Intel® PRO/100 VE Network Connection
1 ........................... Software Loopback Interface 1
8 ...02 00 54 55 4e 01 ...... Teredo Tunneling Pseudo-Interface
13 ...00 00 00 00 00 00 00 e0 isatap.Delta
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.2.250 192.168.2.100 20
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
192.168.2.0 255.255.255.0 On-link 192.168.2.100 276
192.168.2.100 255.255.255.255 On-link 192.168.2.100 276
192.168.2.255 255.255.255.255 On-link 192.168.2.100 276
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 192.168.2.100 276
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 192.168.2.100 276
===========================================================================
Persistent Routes:
None

IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
8 18 ::/0 On-link
1 306 ::1/128 On-link
8 18 2001::/32 On-link
8 266 2001:0:4137:9e76:2020:15db:3f57:fd9b/128
On-link
12 276 fe80::/64 On-link
8 266 fe80::/64 On-link
13 281 fe80::5efe:192.168.2.100/128
On-link
8 266 fe80::2020:15db:3f57:fd9b/128
On-link
12 276 fe80::a5ac:cd62:4062:9b34/128
On-link
1 306 ff00::/8 On-link
8 266 ff00::/8 On-link
12 276 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\system32\NLAapi.dll [48128] (Microsoft Corporation)
Catalog5 02 C:\Windows\system32\napinsp.dll [50176] (Microsoft Corporation)
Catalog5 03 C:\Windows\system32\pnrpnsp.dll [62464] (Microsoft Corporation)
Catalog5 04 C:\Windows\system32\pnrpnsp.dll [62464] (Microsoft Corporation)
Catalog5 05 C:\Windows\System32\mswsock.dll [223232] (Microsoft Corporation)
Catalog5 06 C:\Windows\System32\winrnr.dll [19968] (Microsoft Corporation)
Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Catalog9 01 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 02 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 03 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 04 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 05 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 06 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 07 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 08 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 09 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 10 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 11 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 12 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 13 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 14 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 15 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 16 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 17 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 18 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 19 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 20 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 21 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)
Catalog9 22 C:\Windows\system32\mswsock.dll [223232] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (10/12/2011 00:05:31 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053"1".
Dependent Assembly Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.4053" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (10/12/2011 08:59:32 AM) (Source: Windows Search Service) (User: )
Description: The entry <C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\MCAFEE\MCAFEE ANTIVIRUS PLUS.LNK> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)

Error: (10/12/2011 08:59:32 AM) (Source: Windows Search Service) (User: )
Description: The entry <C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\MCAFEE\MCAFEE ANTIVIRUS PLUS.LNK> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)

Error: (10/12/2011 08:55:18 AM) (Source: EventSystem) (User: )
Description: The COM+ Event System could not remove the EventSystem.EventSubscription object {CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. The HRESULT was 80070005.

Error: (10/12/2011 08:53:18 AM) (Source: Windows Search Service) (User: )
Description: The entry <C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\MCAFEE\MCAFEE ANTIVIRUS PLUS.LNK> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)

Error: (10/12/2011 08:53:18 AM) (Source: Windows Search Service) (User: )
Description: The entry <C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\MCAFEE\MCAFEE ANTIVIRUS PLUS.LNK> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)

Error: (10/12/2011 07:39:35 AM) (Source: Windows Search Service) (User: )
Description: The entry <C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\MCAFEE\MCAFEE ANTIVIRUS PLUS.LNK> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)

Error: (10/12/2011 07:39:35 AM) (Source: Windows Search Service) (User: )
Description: The entry <C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\MCAFEE\MCAFEE ANTIVIRUS PLUS.LNK> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)

Error: (10/11/2011 10:53:53 PM) (Source: EventSystem) (User: )
Description: The COM+ Event System could not remove the EventSystem.EventSubscription object {CEB8B221-89C5-41A8-98CE-79B413BF150B}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. The HRESULT was 80070005.

Error: (10/11/2011 09:34:13 PM) (Source: Windows Search Service) (User: )
Description: The entry <C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\MCAFEE\MCAFEE ANTIVIRUS PLUS.LNK> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)


System errors:
=============
Error: (10/12/2011 10:36:01 PM) (Source: atikmdag) (User: )
Description: CRT invalid display type

Error: (10/12/2011 10:36:00 PM) (Source: atikmdag) (User: )
Description: CRT invalid display type

Error: (10/12/2011 08:33:31 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.111.2389.0

Update Source: %NT AUTHORITY51

Update Stage: 3.0.8402.00

Source Path: 3.0.8402.01

Signature Type: %NT AUTHORITY602

Update Type: %NT AUTHORITY604

User: NT AUTHORITY\NETWORK SERVICE

Current Engine Version: %NT AUTHORITY605

Previous Engine Version: %NT AUTHORITY606

Error code: %NT AUTHORITY607

Error description: %NT AUTHORITY608

Error: (10/12/2011 08:33:31 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.111.2389.0

Update Source: %NT AUTHORITY51

Update Stage: 3.0.8402.00

Source Path: 3.0.8402.01

Signature Type: %NT AUTHORITY602

Update Type: %NT AUTHORITY604

User: NT AUTHORITY\NETWORK SERVICE

Current Engine Version: %NT AUTHORITY605

Previous Engine Version: %NT AUTHORITY606

Error code: %NT AUTHORITY607

Error description: %NT AUTHORITY608

Error: (10/12/2011 08:33:31 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.111.2389.0

Update Source: %NT AUTHORITY51

Update Stage: 3.0.8402.00

Source Path: 3.0.8402.01

Signature Type: %NT AUTHORITY602

Update Type: %NT AUTHORITY604

User: NT AUTHORITY\NETWORK SERVICE

Current Engine Version: %NT AUTHORITY605

Previous Engine Version: %NT AUTHORITY606

Error code: %NT AUTHORITY607

Error description: %NT AUTHORITY608

Error: (10/12/2011 08:33:31 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.111.2389.0

Update Source: %NT AUTHORITY51

Update Stage: 3.0.8402.00

Source Path: 3.0.8402.01

Signature Type: %NT AUTHORITY602

Update Type: %NT AUTHORITY604

User: NT AUTHORITY\NETWORK SERVICE

Current Engine Version: %NT AUTHORITY605

Previous Engine Version: %NT AUTHORITY606

Error code: %NT AUTHORITY607

Error description: %NT AUTHORITY608

Error: (10/12/2011 08:31:59 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.111.2389.0

Update Source: %NT AUTHORITY51

Update Stage: 3.0.8402.00

Source Path: 3.0.8402.01

Signature Type: %NT AUTHORITY602

Update Type: %NT AUTHORITY604

User: NT AUTHORITY\NETWORK SERVICE

Current Engine Version: %NT AUTHORITY605

Previous Engine Version: %NT AUTHORITY606

Error code: %NT AUTHORITY607

Error description: %NT AUTHORITY608

Error: (10/12/2011 08:31:59 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.111.2389.0

Update Source: %NT AUTHORITY51

Update Stage: 3.0.8402.00

Source Path: 3.0.8402.01

Signature Type: %NT AUTHORITY602

Update Type: %NT AUTHORITY604

User: NT AUTHORITY\NETWORK SERVICE

Current Engine Version: %NT AUTHORITY605

Previous Engine Version: %NT AUTHORITY606

Error code: %NT AUTHORITY607

Error description: %NT AUTHORITY608

Error: (10/12/2011 08:31:59 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.111.2389.0

Update Source: %NT AUTHORITY51

Update Stage: 3.0.8402.00

Source Path: 3.0.8402.01

Signature Type: %NT AUTHORITY602

Update Type: %NT AUTHORITY604

User: NT AUTHORITY\NETWORK SERVICE

Current Engine Version: %NT AUTHORITY605

Previous Engine Version: %NT AUTHORITY606

Error code: %NT AUTHORITY607

Error description: %NT AUTHORITY608

Error: (10/12/2011 08:31:59 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.111.2389.0

Update Source: %NT AUTHORITY51

Update Stage: 3.0.8402.00

Source Path: 3.0.8402.01

Signature Type: %NT AUTHORITY602

Update Type: %NT AUTHORITY604

User: NT AUTHORITY\NETWORK SERVICE

Current Engine Version: %NT AUTHORITY605

Previous Engine Version: %NT AUTHORITY606

Error code: %NT AUTHORITY607

Error description: %NT AUTHORITY608


Microsoft Office Sessions:
=========================

=========================== Installed Programs ============================

32 Bit HP CIO Components Installer (Version: 6.1.2)
Adobe Flash Player 10 ActiveX (Version: 10.0.32.18)
Adobe Flash Player 10 Plugin (Version: 10.3.181.34)
Adobe Help Center 2.1 (Version: 2.1)
Adobe Photoshop Elements 5.0 (Version: 5.0)
Adobe Reader X (10.1.1) (Version: 10.1.1)
B209a-m (Version: 140.0.690.000)
Bonjour (Version: 3.0.0.2)
BufferChm (Version: 140.0.212.000)
Creative Audio Control Panel (Version: 2.56)
Creative MediaSource 5 (Version: 5.26)
Creative Software AutoUpdate (Version: 1.40)
Creative Sound Blaster Properties (Version: 1.02)
Creative WaveStudio 7 (Version: 7.12)
Destinations (Version: 140.0.77.000)
DeviceDiscovery (Version: 140.0.212.000)
Google Chrome (Version: 13.0.782.220)
Google Update Helper (Version: 1.3.21.69)
GPBaseService2 (Version: 140.0.211.000)
HP Imaging Device Functions 14.0 (Version: 14.0)
HP Photo Creations (Version: 1.0.0.2024)
HP Photosmart Plus B209a-m All-in-One Driver Software 14.0 Rel. 6 (Version: 14.0)
HP Smart Web Printing 4.60 (Version: 4.60)
HP Solution Center 14.0 (Version: 14.0)
HP Update (Version: 5.002.002.002)
HPPhotoGadget (Version: 140.0.524.000)
HPProductAssistant (Version: 140.0.212.000)
HPSSupply (Version: 140.0.211.000)
Intel® 537EP V9x DF PCI Modem
Malwarebytes' Anti-Malware version 1.51.2.1300 (Version: 1.51.2.1300)
McAfee AntiVirus Plus (Version: 11.0.586)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft Antimalware (Version: 3.0.8402.2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007 (Version: 12.0.6425.1000)
Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.6425.1000)
Microsoft Office Enterprise 2007 (Version: 12.0.6425.1000)
Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6425.1000)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Groove MUI (English) 2007 (Version: 12.0.6425.1000)
Microsoft Office Groove Setup Metadata MUI (English) 2007 (Version: 12.0.6425.1000)
Microsoft Office InfoPath MUI (English) 2007 (Version: 12.0.6425.1000)
Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6425.1000)
Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6425.1000)
Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6425.1000)
Microsoft Office Proof (English) 2007 (Version: 12.0.6425.1000)
Microsoft Office Proof (French) 2007 (Version: 12.0.6425.1000)
Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6425.1000)
Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.6425.1000)
Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6425.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6425.1000)
Microsoft Office Word MUI (English) 2007 (Version: 12.0.6425.1000)
Microsoft Security Client (Version: 2.1.1116.0)
Microsoft Security Essentials (Version: 2.1.1116.0)
Microsoft Silverlight (Version: 4.0.60531.0)
MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
Network (Version: 140.0.215.000)
PS_AIO_06_B209a-m_SW_Min (Version: 140.0.690.000)
QuickTime (Version: 7.70.80.34)
QuickTransfer (Version: 140.0.98.000)
Scan (Version: 140.0.80.000)
SCRABBLE (Version: 1.0.1.3)
Seagate DiscWizard (Version: 11.0.8326)
Shop for HP Supplies (Version: 14.0)
Skype™ 5.5 (Version: 5.5.114)
SmartWebPrinting (Version: 140.0.186.000)
SolutionCenter (Version: 140.0.213.000)
Status (Version: 140.0.212.000)
Toolbox (Version: 140.0.428.000)
TrayApp (Version: 140.0.212.000)
WebFldrs XP (Version: 9.50.7523)
WebReg (Version: 140.0.212.017)
Yahoo! Toolbar

========================= Memory info: ===================================

Percentage of memory in use: 56%
Total physical RAM: 3069.43 MB
Available physical RAM: 1349.14 MB
Total Pagefile: 12208.44 MB
Available Pagefile: 10737.25 MB
Total Virtual: 2047.88 MB
Available Virtual: 1953.33 MB

========================= Partitions: =====================================

2 Drive c: () (Fixed) (Total:465.75 GB) (Free:369.72 GB) NTFS
5 Drive f: (DEIMOS 2) (Removable) (Total:1.91 GB) (Free:1.14 GB) FAT
6 Drive g: (U3 System) (CDROM) (Total:0.01 GB) (Free:0 GB) CDFS
7 Drive v: (VanessaMedia) (Fixed) (Total:931.51 GB) (Free:810.85 GB) NTFS

========================= Users: ========================================

User accounts for \\VANESSA

Administrator Guest HelpAssistant
SUPPORT_388945a0 Vanessa Vanessa11


**** End of log ****


Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 7622

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

10/12/2011 1:30:37 PM
mbam-log-2011-10-12 (13-30-37).txt

Scan type: Full scan (C:\|V:\|)
Objects scanned: 297109
Time elapsed: 1 hour(s), 9 minute(s), 13 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-10-12 23:05:17
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-2 ST3500413AS rev.JC45
Running: gmer.exe; Driver: C:\Users\Vanessa\AppData\Local\Temp\kwldypow.sys


---- System - GMER 1.0.15 ----

Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0x82C40268]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0x82C40292]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0x82C4027E]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0x82C40254]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!ZwYieldExecution 8202C982 5 Bytes JMP 82C40258 \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 821F2143 5 Bytes JMP 82C40296 \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 8221189A 7 Bytes JMP 82C4026C \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 82211B5D 5 Bytes JMP 82C40282 \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8E402000, 0x205494, 0xE8000020]
init C:\Windows\system32\DRIVERS\mohfilt.sys entry point in "init" section [0x8EBE8720]

---- User code sections - GMER 1.0.15 ----

.text C:\Windows\system32\services.exe[816] ntdll.dll!NtCreateFile 775D4224 5 Bytes JMP 007D0000
.text C:\Windows\system32\services.exe[816] ntdll.dll!NtCreateProcess 775D42E4 5 Bytes JMP 007D002C
.text C:\Windows\system32\services.exe[816] ntdll.dll!NtProtectVirtualMemory 775D4B84 5 Bytes JMP 007D001B
.text C:\Windows\system32\services.exe[816] kernel32.dll!GetStartupInfoW 77491929 5 Bytes JMP 002000EB
.text C:\Windows\system32\services.exe[816] kernel32.dll!GetStartupInfoA 774919C9 5 Bytes JMP 002000D0
.text C:\Windows\system32\services.exe[816] kernel32.dll!CreateProcessW 77491BF3 5 Bytes JMP 0020011E
.text C:\Windows\system32\services.exe[816] kernel32.dll!CreateProcessA 77491C28 5 Bytes JMP 0020010D
.text C:\Windows\system32\services.exe[816] kernel32.dll!VirtualProtect 77491DC3 5 Bytes JMP 00200FA5
.text C:\Windows\system32\services.exe[816] kernel32.dll!CreateNamedPipeA 77492EF5 5 Bytes JMP 0020002C
.text C:\Windows\system32\services.exe[816] kernel32.dll!CreateNamedPipeW 77495C0C 5 Bytes JMP 00200047
.text C:\Windows\system32\services.exe[816] kernel32.dll!CreatePipe 774B8F06 5 Bytes JMP 002000AB
.text C:\Windows\system32\services.exe[816] kernel32.dll!LoadLibraryExW 774B927C 5 Bytes JMP 0020007F
.text C:\Windows\system32\services.exe[816] kernel32.dll!LoadLibraryW 774B9400 5 Bytes JMP 00200058
.text C:\Windows\system32\services.exe[816] kernel32.dll!LoadLibraryExA 774B9554 5 Bytes JMP 00200FB6
.text C:\Windows\system32\services.exe[816] kernel32.dll!LoadLibraryA 774B957C 5 Bytes JMP 00200FDB
.text C:\Windows\system32\services.exe[816] kernel32.dll!VirtualProtectEx 774BDC52 5 Bytes JMP 0020009A
.text C:\Windows\system32\services.exe[816] kernel32.dll!GetProcAddress 774D925B 5 Bytes JMP 00200F6C
.text C:\Windows\system32\services.exe[816] kernel32.dll!CreateFileW 774DB0EB 5 Bytes JMP 0020001B
.text C:\Windows\system32\services.exe[816] kernel32.dll!CreateFileA 774DD07F 5 Bytes JMP 00200000
.text C:\Windows\system32\services.exe[816] kernel32.dll!WinExec 775260CF 5 Bytes JMP 002000FC
.text C:\Windows\system32\services.exe[816] ADVAPI32.dll!RegCreateKeyExA 765739AB 5 Bytes JMP 00830FCA
.text C:\Windows\system32\services.exe[816] ADVAPI32.dll!RegCreateKeyA 76573BA9 5 Bytes JMP 0083006C
.text C:\Windows\system32\services.exe[816] ADVAPI32.dll!RegOpenKeyA 765789C7 5 Bytes JMP 0083000A
.text C:\Windows\system32\services.exe[816] ADVAPI32.dll!RegCreateKeyW 7658391E 5 Bytes JMP 00830FE5
.text C:\Windows\system32\services.exe[816] ADVAPI32.dll!RegCreateKeyExW 765841F1 5 Bytes JMP 00830FB9
.text C:\Windows\system32\services.exe[816] ADVAPI32.dll!RegOpenKeyExA 76587C42 5 Bytes JMP 00830040
.text C:\Windows\system32\services.exe[816] ADVAPI32.dll!RegOpenKeyW 7658E2B5 5 Bytes JMP 00830025
.text C:\Windows\system32\services.exe[816] ADVAPI32.dll!RegOpenKeyExW 76597BA1 5 Bytes JMP 0083005B
.text C:\Windows\system32\services.exe[816] msvcrt.dll!_wsystem 76317F2F 5 Bytes JMP 00820FB2
.text C:\Windows\system32\services.exe[816] msvcrt.dll!system 7631804B 5 Bytes JMP 00820FCD
.text C:\Windows\system32\services.exe[816] msvcrt.dll!_creat 7631BBE1 5 Bytes JMP 00820FEF
.text C:\Windows\system32\services.exe[816] msvcrt.dll!_open 7631D106 5 Bytes JMP 0082000C
.text C:\Windows\system32\services.exe[816] msvcrt.dll!_wcreat 7631D326 5 Bytes JMP 00820FDE
.text C:\Windows\system32\services.exe[816] msvcrt.dll!_wopen 7631D501 5 Bytes JMP 00820029
.text C:\Windows\system32\services.exe[816] WS2_32.dll!socket 776A36D1 5 Bytes JMP 00840000
.text C:\Windows\system32\lsass.exe[828] ntdll.dll!NtCreateFile 775D4224 5 Bytes JMP 001D0FE5
.text C:\Windows\system32\lsass.exe[828] ntdll.dll!NtCreateProcess 775D42E4 5 Bytes JMP 001D001B
.text C:\Windows\system32\lsass.exe[828] ntdll.dll!NtProtectVirtualMemory 775D4B84 5 Bytes JMP 001D0000
.text C:\Windows\system32\lsass.exe[828] kernel32.dll!GetStartupInfoW 77491929 5 Bytes JMP 001C0F5E
.text C:\Windows\system32\lsass.exe[828] kernel32.dll!GetStartupInfoA 774919C9 5 Bytes JMP 001C0F6F
.text C:\Windows\system32\lsass.exe[828] kernel32.dll!CreateProcessW 77491BF3 5 Bytes JMP 001C00DA
.text C:\Windows\system32\lsass.exe[828] kernel32.dll!CreateProcessA 77491C28 5 Bytes JMP 001C00BF
.text C:\Windows\system32\lsass.exe[828] kernel32.dll!VirtualProtect 77491DC3 5 Bytes JMP 001C0089
.text C:\Windows\system32\lsass.exe[828] kernel32.dll!CreateNamedPipeA 77492EF5 5 Bytes JMP 001C0FCA
.text C:\Windows\system32\lsass.exe[828] kernel32.dll!CreateNamedPipeW 77495C0C 5 Bytes JMP 001C001B
.text C:\Windows\system32\lsass.exe[828] kernel32.dll!CreatePipe 774B8F06 5 Bytes JMP 001C009A
.text C:\Windows\system32\lsass.exe[828] kernel32.dll!LoadLibraryExW 774B927C 5 Bytes JMP 001C006C
.text C:\Windows\system32\lsass.exe[828] kernel32.dll!LoadLibraryW 774B9400 5 Bytes JMP 001C0FB9
.text C:\Windows\system32\lsass.exe[828] kernel32.dll!LoadLibraryExA 774B9554 5 Bytes JMP 001C005B
.text C:\Windows\system32\lsass.exe[828] kernel32.dll!LoadLibraryA 774B957C 5 Bytes JMP 001C0036
.text C:\Windows\system32\lsass.exe[828] kernel32.dll!VirtualProtectEx 774BDC52 5 Bytes JMP 001C0F8A
.text C:\Windows\system32\lsass.exe[828] kernel32.dll!GetProcAddress 774D925B 5 Bytes JMP 001C00EB
.text C:\Windows\system32\lsass.exe[828] kernel32.dll!CreateFileW 774DB0EB 5 Bytes JMP 001C0000
.text C:\Windows\system32\lsass.exe[828] kernel32.dll!CreateFileA 774DD07F 5 Bytes JMP 001C0FEF
.text C:\Windows\system32\lsass.exe[828] kernel32.dll!WinExec 775260CF 5 Bytes JMP 001C0F43
.text C:\Windows\system32\lsass.exe[828] ADVAPI32.dll!RegCreateKeyExA 765739AB 5 Bytes JMP 008A0F9E
.text C:\Windows\system32\lsass.exe[828] ADVAPI32.dll!RegCreateKeyA 76573BA9 5 Bytes JMP 008A0FB9
.text C:\Windows\system32\lsass.exe[828] ADVAPI32.dll!RegOpenKeyA 765789C7 5 Bytes JMP 008A0000
.text C:\Windows\system32\lsass.exe[828] ADVAPI32.dll!RegCreateKeyW 7658391E 5 Bytes JMP 008A0040
.text C:\Windows\system32\lsass.exe[828] ADVAPI32.dll!RegCreateKeyExW 765841F1 5 Bytes JMP 008A0F8D
.text C:\Windows\system32\lsass.exe[828] ADVAPI32.dll!RegOpenKeyExA 76587C42 5 Bytes JMP 008A0FDE
.text C:\Windows\system32\lsass.exe[828] ADVAPI32.dll!RegOpenKeyW 7658E2B5 5 Bytes JMP 008A0FEF
.text C:\Windows\system32\lsass.exe[828] ADVAPI32.dll!RegOpenKeyExW 76597BA1 5 Bytes JMP 008A002F
.text C:\Windows\system32\lsass.exe[828] msvcrt.dll!_wsystem 76317F2F 5 Bytes JMP 001E0064
.text C:\Windows\system32\lsass.exe[828] msvcrt.dll!system 7631804B 5 Bytes JMP 001E0049
.text C:\Windows\system32\lsass.exe[828] msvcrt.dll!_creat 7631BBE1 5 Bytes JMP 001E0038
.text C:\Windows\system32\lsass.exe[828] msvcrt.dll!_open 7631D106 5 Bytes JMP 001E0000
.text C:\Windows\system32\lsass.exe[828] msvcrt.dll!_wcreat 7631D326 5 Bytes JMP 001E0FD9
.text C:\Windows\system32\lsass.exe[828] msvcrt.dll!_wopen 7631D501 5 Bytes JMP 001E001D
.text C:\Windows\system32\lsass.exe[828] WS2_32.dll!socket 776A36D1 5 Bytes JMP 00C80FEF
.text C:\Windows\system32\svchost.exe[1020] ntdll.dll!NtCreateFile 775D4224 5 Bytes JMP 00810000
.text C:\Windows\system32\svchost.exe[1020] ntdll.dll!NtCreateProcess 775D42E4 5 Bytes JMP 00810025
.text C:\Windows\system32\svchost.exe[1020] ntdll.dll!NtProtectVirtualMemory 775D4B84 5 Bytes JMP 00810FE5
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!GetStartupInfoW 77491929 5 Bytes JMP 001B0F3C
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!GetStartupInfoA 774919C9 5 Bytes JMP 001B0F4D
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!CreateProcessW 77491BF3 5 Bytes JMP 001B00A7
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!CreateProcessA 77491C28 5 Bytes JMP 001B0F10
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!VirtualProtect 77491DC3 5 Bytes JMP 001B0F8A
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!CreateNamedPipeA 77492EF5 5 Bytes JMP 001B002C
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!CreateNamedPipeW 77495C0C 5 Bytes JMP 001B003D
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!CreatePipe 774B8F06 5 Bytes JMP 001B0F68
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!LoadLibraryExW 774B927C 5 Bytes JMP 001B0FA5
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!LoadLibraryW 774B9400 5 Bytes JMP 001B0FC7
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!LoadLibraryExA 774B9554 5 Bytes JMP 001B0FB6
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!LoadLibraryA 774B957C 5 Bytes JMP 001B0058
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!VirtualProtectEx 774BDC52 5 Bytes JMP 001B0F79
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!GetProcAddress 774D925B 5 Bytes JMP 001B00B8
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!CreateFileW 774DB0EB 5 Bytes JMP 001B001B
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!CreateFileA 774DD07F 5 Bytes JMP 001B000A
.text C:\Windows\system32\svchost.exe[1020] kernel32.dll!WinExec 775260CF 5 Bytes JMP 001B0F21
.text C:\Windows\system32\svchost.exe[1020] msvcrt.dll!_wsystem 76317F2F 5 Bytes JMP 00860F77
.text C:\Windows\system32\svchost.exe[1020] msvcrt.dll!system 7631804B 5 Bytes JMP 00860F92
.text C:\Windows\system32\svchost.exe[1020] msvcrt.dll!_creat 7631BBE1 5 Bytes JMP 00860FD2
.text C:\Windows\system32\svchost.exe[1020] msvcrt.dll!_open 7631D106 5 Bytes JMP 00860FE3
.text C:\Windows\system32\svchost.exe[1020] msvcrt.dll!_wcreat 7631D326 5 Bytes JMP 00860FB7
.text C:\Windows\system32\svchost.exe[1020] msvcrt.dll!_wopen 7631D501 5 Bytes JMP 00860000
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!RegCreateKeyExA 765739AB 5 Bytes JMP 00870F8A
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!RegCreateKeyA 76573BA9 5 Bytes JMP 00870FB6
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!RegOpenKeyA 765789C7 5 Bytes JMP 00870FEF
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!RegCreateKeyW 7658391E 5 Bytes JMP 00870F9B
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!RegCreateKeyExW 765841F1 5 Bytes JMP 00870F6F
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!RegOpenKeyExA 76587C42 5 Bytes JMP 00870011
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!RegOpenKeyW 7658E2B5 5 Bytes JMP 00870000
.text C:\Windows\system32\svchost.exe[1020] ADVAPI32.dll!RegOpenKeyExW 76597BA1 5 Bytes JMP 00870022
.text C:\Windows\system32\svchost.exe[1020] WS2_32.dll!socket 776A36D1 5 Bytes JMP 00880000
.text C:\Windows\system32\svchost.exe[1084] ntdll.dll!NtCreateFile 775D4224 5 Bytes JMP 00270FEF
.text C:\Windows\system32\svchost.exe[1084] ntdll.dll!NtCreateProcess 775D42E4 5 Bytes JMP 00270025
.text C:\Windows\system32\svchost.exe[1084] ntdll.dll!NtProtectVirtualMemory 775D4B84 5 Bytes JMP 00270000
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!GetStartupInfoW 77491929 5 Bytes JMP 002600A5
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!GetStartupInfoA 774919C9 5 Bytes JMP 0026008A
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!CreateProcessW 77491BF3 5 Bytes JMP 00260F18
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!CreateProcessA 77491C28 5 Bytes JMP 00260F29
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!VirtualProtect 77491DC3 5 Bytes JMP 00260F95
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!CreateNamedPipeA 77492EF5 5 Bytes JMP 00260025
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!CreateNamedPipeW 77495C0C 5 Bytes JMP 00260040
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!CreatePipe 774B8F06 5 Bytes JMP 00260F69
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!LoadLibraryExW 774B927C 5 Bytes JMP 00260FB2
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!LoadLibraryW 774B9400 5 Bytes JMP 00260FC3
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!LoadLibraryExA 774B9554 5 Bytes JMP 0026006F
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!LoadLibraryA 774B957C 5 Bytes JMP 00260FD4
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!VirtualProtectEx 774BDC52 5 Bytes JMP 00260F84
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!GetProcAddress 774D925B 5 Bytes JMP 002600C0
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!CreateFileW 774DB0EB 5 Bytes JMP 0026000A
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!CreateFileA 774DD07F 5 Bytes JMP 00260FEF
.text C:\Windows\system32\svchost.exe[1084] kernel32.dll!WinExec 775260CF 5 Bytes JMP 00260F44
.text C:\Windows\system32\svchost.exe[1084] msvcrt.dll!_wsystem 76317F2F 5 Bytes JMP 00280053
.text C:\Windows\system32\svchost.exe[1084] msvcrt.dll!system 7631804B 5 Bytes JMP 00280FC8
.text C:\Windows\system32\svchost.exe[1084] msvcrt.dll!_creat 7631BBE1 5 Bytes JMP 0028002E
.text C:\Windows\system32\svchost.exe[1084] msvcrt.dll!_open 7631D106 5 Bytes JMP 00280000
.text C:\Windows\system32\svchost.exe[1084] msvcrt.dll!_wcreat 7631D326 5 Bytes JMP 00280FD9
.text C:\Windows\system32\svchost.exe[1084] msvcrt.dll!_wopen 7631D501 5 Bytes JMP 00280011
.text C:\Windows\system32\svchost.exe[1084] ADVAPI32.dll!RegCreateKeyExA 765739AB 5 Bytes JMP 008F0051
.text C:\Windows\system32\svchost.exe[1084] ADVAPI32.dll!RegCreateKeyA 76573BA9 5 Bytes JMP 008F0FAF
.text C:\Windows\system32\svchost.exe[1084] ADVAPI32.dll!RegOpenKeyA 765789C7 5 Bytes JMP 008F0FEF
.text C:\Windows\system32\svchost.exe[1084] ADVAPI32.dll!RegCreateKeyW 7658391E 5 Bytes JMP 008F0036
.text C:\Windows\system32\svchost.exe[1084] ADVAPI32.dll!RegCreateKeyExW 765841F1 5 Bytes JMP 008F006C
.text C:\Windows\system32\svchost.exe[1084] ADVAPI32.dll!RegOpenKeyExA 76587C42 5 Bytes JMP 008F000A
.text C:\Windows\system32\svchost.exe[1084] ADVAPI32.dll!RegOpenKeyW 7658E2B5 5 Bytes JMP 008F0FD4
.text C:\Windows\system32\svchost.exe[1084] ADVAPI32.dll!RegOpenKeyExW 76597BA1 5 Bytes JMP 008F001B
.text C:\Windows\system32\svchost.exe[1084] WS2_32.dll!socket 776A36D1 5 Bytes JMP 00900FEF
.text C:\Windows\System32\svchost.exe[1172] ntdll.dll!NtCreateFile 775D4224 5 Bytes JMP 006E0000
.text C:\Windows\System32\svchost.exe[1172] ntdll.dll!NtCreateProcess 775D42E4 5 Bytes JMP 006E0025
.text C:\Windows\System32\svchost.exe[1172] ntdll.dll!NtProtectVirtualMemory 775D4B84 5 Bytes JMP 006E0FE5
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!GetStartupInfoW 77491929 5 Bytes JMP 00240F29
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!GetStartupInfoA 774919C9 5 Bytes JMP 00240F3A
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreateProcessW 77491BF3 5 Bytes JMP 002400AC
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreateProcessA 77491C28 5 Bytes JMP 0024009B
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!VirtualProtect 77491DC3 5 Bytes JMP 00240F81
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreateNamedPipeA 77492EF5 5 Bytes JMP 0024000A
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreateNamedPipeW 77495C0C 5 Bytes JMP 00240FB9
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreatePipe 774B8F06 5 Bytes JMP 00240F5F
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!LoadLibraryExW 774B927C 5 Bytes JMP 00240F92
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!LoadLibraryW 774B9400 5 Bytes JMP 00240040
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!LoadLibraryExA 774B9554 5 Bytes JMP 0024005B
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!LoadLibraryA 774B957C 5 Bytes JMP 00240025
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!VirtualProtectEx 774BDC52 5 Bytes JMP 00240F70
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!GetProcAddress 774D925B 5 Bytes JMP 00240EFA
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreateFileW 774DB0EB 5 Bytes JMP 00240FD4
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!CreateFileA 774DD07F 5 Bytes JMP 00240FEF
.text C:\Windows\System32\svchost.exe[1172] kernel32.dll!WinExec 775260CF 5 Bytes JMP 0024008A
.text C:\Windows\System32\svchost.exe[1172] msvcrt.dll!_wsystem 76317F2F 5 Bytes JMP 006F005D
.text C:\Windows\System32\svchost.exe[1172] msvcrt.dll!system 7631804B 5 Bytes JMP 006F004C
.text C:\Windows\System32\svchost.exe[1172] msvcrt.dll!_creat 7631BBE1 5 Bytes JMP 006F0FD2
.text C:\Windows\System32\svchost.exe[1172] msvcrt.dll!_open 7631D106 5 Bytes JMP 006F0000
.text C:\Windows\System32\svchost.exe[1172] msvcrt.dll!_wcreat 7631D326 5 Bytes JMP 006F0027
.text C:\Windows\System32\svchost.exe[1172] msvcrt.dll!_wopen 7631D501 5 Bytes JMP 006F0FE3
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegCreateKeyExA 765739AB 5 Bytes JMP 00700FA8
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegCreateKeyA 76573BA9 5 Bytes JMP 0070002F
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegOpenKeyA 765789C7 5 Bytes JMP 00700FE5
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegCreateKeyW 7658391E 5 Bytes JMP 0070004A
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegCreateKeyExW 765841F1 5 Bytes JMP 0070006F
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegOpenKeyExA 76587C42 5 Bytes JMP 0070000A
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegOpenKeyW 7658E2B5 5 Bytes JMP 00700FCA
.text C:\Windows\System32\svchost.exe[1172] ADVAPI32.dll!RegOpenKeyExW 76597BA1 5 Bytes JMP 00700FB9
.text C:\Windows\System32\svchost.exe[1172] WS2_32.dll!socket 776A36D1 5 Bytes JMP 00710FEF
.text C:\Windows\System32\svchost.exe[1172] WININET.dll!InternetOpenA 75D74E33 5 Bytes JMP 00720FEF
.text C:\Windows\System32\svchost.exe[1172] WININET.dll!InternetOpenUrlA 75D7BFCE 5 Bytes JMP 00720FD4
.text C:\Windows\System32\svchost.exe[1172] WININET.dll!InternetOpenW 75DAC02E 5 Bytes JMP 0072000A
.text C:\Windows\System32\svchost.exe[1172] WININET.dll!InternetOpenUrlW 75DDD70A 5 Bytes JMP 00720FAF
.text C:\Windows\System32\svchost.exe[1340] ntdll.dll!NtCreateFile 775D4224 5 Bytes JMP 00E4000A
.text C:\Windows\System32\svchost.exe[1340] ntdll.dll!NtCreateProcess 775D42E4 5 Bytes JMP 00E4002C
.text C:\Windows\System32\svchost.exe[1340] ntdll.dll!NtProtectVirtualMemory 775D4B84 5 Bytes JMP 00E4001B
.text C:\Windows\System32\svchost.exe[1340] kernel32.dll!GetStartupInfoW 77491929 5 Bytes JMP 00E30F72
.text C:\Windows\System32\svchost.exe[1340] kernel32.dll!GetStartupInfoA 774919C9 5 Bytes JMP 00E300C2
.text C:\Windows\System32\svchost.exe[1340] kernel32.dll!CreateProcessW 77491BF3 5 Bytes JMP 00E30F46
.text C:\Windows\System32\svchost.exe[1340] kernel32.dll!CreateProcessA 77491C28 5 Bytes JMP 00E300DD
.text C:\Windows\System32\svchost.exe[1340] kernel32.dll!VirtualProtect 77491DC3 5 Bytes JMP 00E30082
.text C:\Windows\System32\svchost.exe[1340] kernel32.dll!CreateNamedPipeA 77492EF5 5 Bytes JMP 00E30025
.text C:\Windows\System32\svchost.exe[1340] kernel32.dll!CreateNamedPipeW 77495C0C 5 Bytes JMP 00E30040
.text C:\Windows\System32\svchost.exe[1340] kernel32.dll!CreatePipe 774B8F06 5 Bytes JMP 00E30F8D
.text C:\Windows\System32\svchost.exe[1340] kernel32.dll!LoadLibraryExW 774B927C 5 Bytes JMP 00E30FA8
.text C:\Windows\System32\svchost.exe[1340] kernel32.dll!LoadLibraryW 774B9400 5 Bytes JMP 00E30FCA
.text C:\Windows\System32\svchost.exe[1340] kernel32.dll!LoadLibraryExA 774B9554 5 Bytes JMP 00E30FB9
.text C:\Windows\System32\svchost.exe[1340] kernel32.dll!LoadLibraryA 774B957C 5 Bytes JMP 00E30051
.text C:\Windows\System32\svchost.exe[1340] kernel32.dll!VirtualProtectEx 774BDC52 5 Bytes JMP 00E30093
.text C:\Windows\System32\svchost.exe[1340] kernel32.dll!GetProcAddress 774D925B 5 Bytes JMP 00E300F8
.text C:\Windows\System32\svchost.exe[1340] kernel32.dll!CreateFileW 774DB0EB 1 Byte [E9]
.text C:\Windows\System32\svchost.exe[1340] kernel32.dll!CreateFileW 774DB0EB 5 Bytes JMP 00E30FEF
.text C:\Windows\System32\svchost.exe[1340] kernel32.dll!CreateFileA 774DD07F 5 Bytes JMP 00E3000A
.text C:\Windows\System32\svchost.exe[1340] kernel32.dll!WinExec 775260CF 5 Bytes JMP 00E30F61
.text C:\Windows\System32\svchost.exe[1340] msvcrt.dll!_wsystem 76317F2F 5 Bytes JMP 00E50053
.text C:\Windows\System32\svchost.exe[1340] msvcrt.dll!system 7631804B 5 Bytes JMP 00E5002E
.text C:\Windows\System32\svchost.exe[1340] msvcrt.dll!_creat 7631BBE1 5 Bytes JMP 00E50FD2
.text C:\Windows\System32\svchost.exe[1340] msvcrt.dll!_open 7631D106 5 Bytes JMP 00E50000
.text C:\Windows\System32\svchost.exe[1340] msvcrt.dll!_wcreat 7631D326 5 Bytes JMP 00E5001D
.text C:\Windows\System32\svchost.exe[1340] msvcrt.dll!_wopen 7631D501 5 Bytes JMP 00E50FE3
.text C:\Windows\System32\svchost.exe[1340] ADVAPI32.dll!RegCreateKeyExA 765739AB 5 Bytes JMP 00E60054
.text C:\Windows\System32\svchost.exe[1340] ADVAPI32.dll!RegCreateKeyA 76573BA9 5 Bytes JMP 00E6002F
.text C:\Windows\System32\svchost.exe[1340] ADVAPI32.dll!RegOpenKeyA 765789C7 5 Bytes JMP 00E60FEF
.text C:\Windows\System32\svchost.exe[1340] ADVAPI32.dll!RegCreateKeyW 7658391E 5 Bytes JMP 00E60FB2
.text C:\Windows\System32\svchost.exe[1340] ADVAPI32.dll!RegCreateKeyExW 765841F1 5 Bytes JMP 00E6006F
.text C:\Windows\System32\svchost.exe[1340] ADVAPI32.dll!RegOpenKeyExA 76587C42 5 Bytes JMP 00E60FDE
.text C:\Windows\System32\svchost.exe[1340] ADVAPI32.dll!RegOpenKeyW 7658E2B5 5 Bytes JMP 00E60014
.text C:\Windows\System32\svchost.exe[1340] ADVAPI32.dll!RegOpenKeyExW 76597BA1 5 Bytes JMP 00E60FC3
.text C:\Windows\System32\svchost.exe[1340] WS2_32.dll!socket 776A36D1 5 Bytes JMP 00E8000A
.text C:\Windows\System32\svchost.exe[1376] ntdll.dll!NtCreateFile 775D4224 5 Bytes JMP 00DD0FEF
.text C:\Windows\System32\svchost.exe[1376] ntdll.dll!NtCreateProcess 775D42E4 5 Bytes JMP 00DD001B
.text C:\Windows\System32\svchost.exe[1376] ntdll.dll!NtProtectVirtualMemory 775D4B84 5 Bytes JMP 00DD000A
.text C:\Windows\System32\svchost.exe[1376] kernel32.dll!GetStartupInfoW 77491929 5 Bytes JMP 00C800A2
.text C:\Windows\System32\svchost.exe[1376] kernel32.dll!GetStartupInfoA 774919C9 5 Bytes JMP 00C80F52
.text C:\Windows\System32\svchost.exe[1376] kernel32.dll!CreateProcessW 77491BF3 5 Bytes JMP 00C800D8
.text C:\Windows\System32\svchost.exe[1376] kernel32.dll!CreateProcessA 77491C28 5 Bytes JMP 00C80F37
.text C:\Windows\System32\svchost.exe[1376] kernel32.dll!VirtualProtect 77491DC3 5 Bytes JMP 00C80062
.text C:\Windows\System32\svchost.exe[1376] kernel32.dll!CreateNamedPipeA 77492EF5 5 Bytes JMP 00C80FCA
.text C:\Windows\System32\svchost.exe[1376] kernel32.dll!CreateNamedPipeW 77495C0C 5 Bytes JMP 00C80FB9
.text C:\Windows\System32\svchost.exe[1376] kernel32.dll!CreatePipe 774B8F06 5 Bytes JMP 00C80F63
.text C:\Windows\System32\svchost.exe[1376] kernel32.dll!LoadLibraryExW 774B927C 5 Bytes JMP 00C80051
.text C:\Windows\System32\svchost.exe[1376] kernel32.dll!LoadLibraryW 774B9400 5 Bytes JMP 00C80025
.text C:\Windows\System32\svchost.exe[1376] kernel32.dll!LoadLibraryExA 774B9554 5 Bytes JMP 00C80040
.text C:\Windows\System32\svchost.exe[1376] kernel32.dll!LoadLibraryA 774B957C 5 Bytes JMP 00C80F9E
.text C:\Windows\System32\svchost.exe[1376] kernel32.dll!VirtualProtectEx 774BDC52 5 Bytes JMP 00C8007D
.text C:\Windows\System32\svchost.exe[1376] kernel32.dll!GetProcAddress 774D925B 5 Bytes JMP 00C80F1C
.text C:\Windows\System32\svchost.exe[1376] kernel32.dll!CreateFileW 774DB0EB 5 Bytes JMP 00C80000
.text C:\Windows\System32\svchost.exe[1376] kernel32.dll!CreateFileA 774DD07F 5 Bytes JMP 00C80FEF
.text C:\Windows\System32\svchost.exe[1376] kernel32.dll!WinExec 775260CF 5 Bytes JMP 00C800B3
.text C:\Windows\System32\svchost.exe[1376] msvcrt.dll!_wsystem 76317F2F 5 Bytes JMP 00DE0049
.text C:\Windows\System32\svchost.exe[1376] msvcrt.dll!system 7631804B 5 Bytes JMP 00DE002E
.text C:\Windows\System32\svchost.exe[1376] msvcrt.dll!_creat 7631BBE1 5 Bytes JMP 00DE0FC8
.text C:\Windows\System32\svchost.exe[1376] msvcrt.dll!_open 7631D106 5 Bytes JMP 00DE0FEF
.text C:\Windows\System32\svchost.exe[1376] msvcrt.dll!_wcreat 7631D326 5 Bytes JMP 00DE001D
.text C:\Windows\System32\svchost.exe[1376] msvcrt.dll!_wopen 7631D501 5 Bytes JMP 00DE000C
.text C:\Windows\System32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyExA 765739AB 5 Bytes JMP 00E00F65
.text C:\Windows\System32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyA 76573BA9 5 Bytes JMP 00E00F94
.text C:\Windows\System32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyA 765789C7 5 Bytes JMP 00E00FEF
.text C:\Windows\System32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyW 7658391E 5 Bytes JMP 00E00011
.text C:\Windows\System32\svchost.exe[1376] ADVAPI32.dll!RegCreateKeyExW 765841F1 5 Bytes JMP 00E00022
.text C:\Windows\System32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyExA 76587C42 5 Bytes JMP 00E00FC0
.text C:\Windows\System32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyW 7658E2B5 5 Bytes JMP 00E00000
.text C:\Windows\System32\svchost.exe[1376] ADVAPI32.dll!RegOpenKeyExW 76597BA1 5 Bytes JMP 00E00FAF
.text C:\Windows\System32\svchost.exe[1376] WS2_32.dll!socket 776A36D1 5 Bytes JMP 00E10FE5
.text C:\Windows\System32\svchost.exe[1376] WININET.dll!InternetOpenA 75D74E33 5 Bytes JMP 00DA0FEF
.text C:\Windows\System32\svchost.exe[1376] WININET.dll!InternetOpenUrlA 75D7BFCE 5 Bytes JMP 00DA0FCD
.text C:\Windows\System32\svchost.exe[1376] WININET.dll!InternetOpenW 75DAC02E 5 Bytes JMP 00DA0FDE
.text C:\Windows\System32\svchost.exe[1376] WININET.dll!InternetOpenUrlW 75DDD70A 5 Bytes JMP 00DA001E
.text C:\Windows\system32\svchost.exe[1396] ntdll.dll!NtCreateFile 775D4224 5 Bytes JMP 00D30000
.text C:\Windows\system32\svchost.exe[1396] ntdll.dll!NtCreateProcess 775D42E4 5 Bytes JMP 00D30025
.text C:\Windows\system32\svchost.exe[1396] ntdll.dll!NtProtectVirtualMemory 775D4B84 5 Bytes JMP 00D30FEF
.text C:\Windows\system32\svchost.exe[1396] kernel32.dll!GetStartupInfoW 77491929 5 Bytes JMP 00CE00C1
.text C:\Windows\system32\svchost.exe[1396] kernel32.dll!GetStartupInfoA 774919C9 5 Bytes JMP 00CE00B0
.text C:\Windows\system32\svchost.exe[1396] kernel32.dll!CreateProcessW 77491BF3 5 Bytes JMP 00CE0F3B
.text C:\Windows\system32\svchost.exe[1396] kernel32.dll!CreateProcessA 77491C28 5 Bytes JMP 00CE0F56
.text C:\Windows\system32\svchost.exe[1396] kernel32.dll!VirtualProtect 77491DC3 5 Bytes JMP 00CE0084
.text C:\Windows\system32\svchost.exe[1396] kernel32.dll!CreateNamedPipeA 77492EF5 5 Bytes JMP 00CE0FDB
.text C:\Windows\system32\svchost.exe[1396] kernel32.dll!CreateNamedPipeW 77495C0C 5 Bytes JMP 00CE0022
.text C:\Windows\system32\svchost.exe[1396] kernel32.dll!CreatePipe 774B8F06 5 Bytes JMP 00CE009F
.text C:\Windows\system32\svchost.exe[1396] kernel32.dll!LoadLibraryExW 774B927C 5 Bytes JMP 00CE0073
.text C:\Windows\system32\svchost.exe[1396] kernel32.dll!LoadLibraryW 774B9400 5 Bytes JMP 00CE0058
.text C:\Windows\system32\svchost.exe[1396] kernel32.dll!LoadLibraryExA 774B9554 5 Bytes JMP 00CE0FB6
.text C:\Windows\system32\svchost.exe[1396] kernel32.dll!LoadLibraryA 774B957C 5 Bytes JMP 00CE0033
.text C:\Windows\system32\svchost.exe[1396] kernel32.dll!VirtualProtectEx 774BDC52 5 Bytes JMP 00CE0F8F
.text C:\Windows\system32\svchost.exe[1396] kernel32.dll!GetProcAddress 774D925B 5 Bytes JMP 00CE00F7
.text C:\Windows\system32\svchost.exe[1396] kernel32.dll!CreateFileW 774DB0EB 5 Bytes JMP 00CE0011
.text C:\Windows\system32\svchost.exe[1396] kernel32.dll!CreateFileA 774DD07F 5 Bytes JMP 00CE0000
.text C:\Windows\system32\svchost.exe[1396] kernel32.dll!WinExec 775260CF 5 Bytes JMP 00CE00DC
.text C:\Windows\system32\svchost.exe[1396] msvcrt.dll!_wsystem 76317F2F 5 Bytes JMP 00D80F9F
.text C:\Windows\system32\svchost.exe[1396] msvcrt.dll!system 7631804B 5 Bytes JMP 00D80FB0
.text C:\Windows\system32\svchost.exe[1396] msvcrt.dll!_creat 7631BBE1 5 Bytes JMP 00D8000C
.text C:\Windows\system32\svchost.exe[1396] msvcrt.dll!_open 7631D106 5 Bytes JMP 00D80FEF
.text C:\Windows\system32\svchost.exe[1396] msvcrt.dll!_wcreat 7631D326 5 Bytes JMP 00D80FC1
.text C:\Windows\system32\svchost.exe[1396] msvcrt.dll!_wopen 7631D501 5 Bytes JMP 00D80FD2
.text C:\Windows\system32\svchost.exe[1396] ADVAPI32.dll!RegCreateKeyExA 765739AB 1 Byte [E9]
.text C:\Windows\system32\svchost.exe[1396] ADVAPI32.dll!RegCreateKeyExA 765739AB 5 Bytes JMP 00D90FAF
.text C:\Windows\system32\svchost.exe[1396] ADVAPI32.dll!RegCreateKeyA 76573BA9 5 Bytes JMP 00D90047
.text C:\Windows\system32\svchost.exe[1396] ADVAPI32.dll!RegOpenKeyA 765789C7 5 Bytes JMP 00D90000
.text C:\Windows\system32\svchost.exe[1396] ADVAPI32.dll!RegCreateKeyW 7658391E 5 Bytes JMP 00D90FCA
.text C:\Windows\system32\svchost.exe[1396] ADVAPI32.dll!RegCreateKeyExW 765841F1 5 Bytes JMP 00D90F94
.text C:\Windows\system32\svchost.exe[1396] ADVAPI32.dll!RegOpenKeyExA 76587C42 5 Bytes JMP 00D9002C
.text C:\Windows\system32\svchost.exe[1396] ADVAPI32.dll!RegOpenKeyW 7658E2B5 5 Bytes JMP 00D90011
.text C:\Windows\system32\svchost.exe[1396] ADVAPI32.dll!RegOpenKeyExW 76597BA1 5 Bytes JMP 00D90FDB
.text C:\Windows\system32\svchost.exe[1396] WS2_32.dll!socket 776A36D1 5 Bytes JMP 00DA0FEF
.text C:\Windows\system32\svchost.exe[1536] ntdll.dll!NtCreateFile 775D4224 5 Bytes JMP 00090FEF
.text C:\Windows\system32\svchost.exe[1536] ntdll.dll!NtCreateProcess 775D42E4 5 Bytes JMP 00090FD4
.text C:\Windows\system32\svchost.exe[1536] ntdll.dll!NtProtectVirtualMemory 775D4B84 5 Bytes JMP 0009000A
.text C:\Windows\system32\svchost.exe[1536] kernel32.dll!GetStartupInfoW 77491929 5 Bytes JMP 000800C2
.text C:\Windows\system32\svchost.exe[1536] kernel32.dll!GetStartupInfoA 774919C9 5 Bytes JMP 000800A7
.text C:\Windows\system32\svchost.exe[1536] kernel32.dll!CreateProcessW 77491BF3 5 Bytes JMP 00080109
.text C:\Windows\system32\svchost.exe[1536] kernel32.dll!CreateProcessA 77491C28 5 Bytes JMP 000800EE
.text C:\Windows\system32\svchost.exe[1536] kernel32.dll!VirtualProtect 77491DC3 5 Bytes JMP 00080071
.text C:\Windows\system32\svchost.exe[1536] kernel32.dll!CreateNamedPipeA 77492EF5 5 Bytes JMP 00080FEF
.text C:\Windows\system32\svchost.exe[1536] kernel32.dll!CreateNamedPipeW 77495C0C 5 Bytes JMP 00080FDE
.text C:\Windows\system32\svchost.exe[1536] kernel32.dll!CreatePipe 774B8F06 5 Bytes JMP 00080096
.text C:\Windows\system32\svchost.exe[1536] kernel32.dll!LoadLibraryExW 774B927C 5 Bytes JMP 00080054
.text C:\Windows\system32\svchost.exe[1536] kernel32.dll!LoadLibraryW 774B9400 5 Bytes JMP 00080FA8
.text C:\Windows\system32\svchost.exe[1536] kernel32.dll!LoadLibraryExA 774B9554 5 Bytes JMP 00080F97
.text C:\Windows\system32\svchost.exe[1536] kernel32.dll!LoadLibraryA 774B957C 5 Bytes JMP 00080FC3
.text C:\Windows\system32\svchost.exe[1536] kernel32.dll!VirtualProtectEx 774BDC52 5 Bytes JMP 00080F86
.text C:\Windows\system32\svchost.exe[1536] kernel32.dll!GetProcAddress 774D925B 5 Bytes JMP 00080F57
.text C:\Windows\system32\svchost.exe[1536] kernel32.dll!CreateFileW 774DB0EB 5 Bytes JMP 0008001B
.text C:\Windows\system32\svchost.exe[1536] kernel32.dll!CreateFileA 774DD07F 5 Bytes JMP 0008000A
.text C:\Windows\system32\svchost.exe[1536] kernel32.dll!WinExec 775260CF 1 Byte [E9]
.text C:\Windows\system32\svchost.exe[1536] kernel32.dll!WinExec 775260CF 5 Bytes JMP 000800D3
.text C:\Windows\system32\svchost.exe[1536] msvcrt.dll!_wsystem 76317F2F 5 Bytes JMP 000A001B
.text C:\Windows\system32\svchost.exe[1536] msvcrt.dll!system 7631804B 5 Bytes JMP 000A0000
.text C:\Windows\system32\svchost.exe[1536] msvcrt.dll!_creat 7631BBE1 5 Bytes JMP 000A0FAB
.text C:\Windows\system32\svchost.exe[1536] msvcrt.dll!_open 7631D106 5 Bytes JMP 000A0FEF
.text C:\Windows\system32\svchost.exe[1536] msvcrt.dll!_wcreat 7631D326 5 Bytes JMP 000A0F9A
.text C:\Windows\system32\svchost.exe[1536] msvcrt.dll!_wopen 7631D501 5 Bytes JMP 000A0FC6
.text C:\Windows\system32\svchost.exe[1536] ADVAPI32.dll!RegCreateKeyExA 765739AB 5 Bytes JMP 000B0FA5
.text C:\Windows\system32\svchost.exe[1536] ADVAPI32.dll!RegCreateKeyA 76573BA9 5 Bytes JMP 000B002C
.text C:\Windows\system32\svchost.exe[1536] ADVAPI32.dll!RegOpenKeyA 765789C7 5 Bytes JMP 000B0000
.text C:\Windows\system32\svchost.exe[1536] ADVAPI32.dll!RegCreateKeyW 7658391E 5 Bytes JMP 000B0047
.text C:\Windows\system32\svchost.exe[1536] ADVAPI32.dll!RegCreateKeyExW 765841F1 5 Bytes JMP 000B0F94
.text C:\Windows\system32\svchost.exe[1536] ADVAPI32.dll!RegOpenKeyExA 76587C42 5 Bytes JMP 000B0FCA
.text C:\Windows\system32\svchost.exe[1536] ADVAPI32.dll!RegOpenKeyW 7658E2B5 5 Bytes JMP 000B0FDB
.text C:\Windows\system32\svchost.exe[1536] ADVAPI32.dll!RegOpenKeyExW 76597BA1 5 Bytes JMP 000B001B
.text C:\Windows\system32\svchost.exe[1536] WS2_32.dll!socket 776A36D1 5 Bytes JMP 001D0000
.text C:\Windows\system32\svchost.exe[1568] ntdll.dll!NtCreateFile 775D4224 5 Bytes JMP 00750000
.text C:\Windows\system32\svchost.exe[1568] ntdll.dll!NtCreateProcess 775D42E4 5 Bytes JMP 0075002C
.text C:\Windows\system32\svchost.exe[1568] ntdll.dll!NtProtectVirtualMemory 775D4B84 5 Bytes JMP 0075001B
.text C:\Windows\system32\svchost.exe[1568] kernel32.dll!GetStartupInfoW 77491929 5 Bytes JMP 007400DA
.text C:\Windows\system32\svchost.exe[1568] kernel32.dll!GetStartupInfoA 774919C9 5 Bytes JMP 00740F9E
.text C:\Windows\system32\svchost.exe[1568] kernel32.dll!CreateProcessW 77491BF3 5 Bytes JMP 00740F57
.text C:\Windows\system32\svchost.exe[1568] kernel32.dll!CreateProcessA 77491C28 5 Bytes JMP 00740F68
.text C:\Windows\system32\svchost.exe[1568] kernel32.dll!VirtualProtect 77491DC3 5 Bytes JMP 00740093
.text C:\Windows\system32\svchost.exe[1568] kernel32.dll!CreateNamedPipeA 77492EF5 5 Bytes JMP 00740000
.text C:\Windows\system32\svchost.exe[1568] kernel32.dll!CreateNamedPipeW 77495C0C 5 Bytes JMP 00740FB9
.text C:\Windows\system32\svchost.exe[1568] kernel32.dll!CreatePipe 774B8F06 5 Bytes JMP 007400C9
.text C:\Windows\system32\svchost.exe[1568] kernel32.dll!LoadLibraryExW 774B927C 3 Bytes JMP 00740082
.text C:\Windows\system32\svchost.exe[1568] kernel32.dll!LoadLibraryExW + 4 774B9280 1 Byte [89]
.text C:\Windows\system32\svchost.exe[1568] kernel32.dll!LoadLibraryW 774B9400 5 Bytes JMP 00740040
.text C:\Windows\system32\svchost.exe[1568] kernel32.dll!LoadLibraryExA 774B9554 5 Bytes JMP 0074005B
.text C:\Windows\system32\svchost.exe[1568] kernel32.dll!LoadLibraryA 774B957C 5 Bytes JMP 0074002F
.text C:\Windows\system32\svchost.exe[1568] kernel32.dll!VirtualProtectEx 774BDC52 5 Bytes JMP 007400A4
.text C:\Windows\system32\svchost.exe[1568] kernel32.dll!GetProcAddress 774D925B 5 Bytes JMP 00740F46
.text C:\Windows\system32\svchost.exe[1568] kernel32.dll!CreateFileW 774DB0EB 5 Bytes JMP 00740FCA
.text C:\Windows\system32\svchost.exe[1568] kernel32.dll!CreateFileA 774DD07F 5 Bytes JMP 00740FEF
.text C:\Windows\system32\svchost.exe[1568] kernel32.dll!WinExec 775260CF 5 Bytes JMP 00740F79
.text C:\Windows\system32\svchost.exe[1568] msvcrt.dll!_wsystem 76317F2F 5 Bytes JMP 00760FB4
.text C:\Windows\system32\svchost.exe[1568] msvcrt.dll!system 7631804B 5 Bytes JMP 0076003F
.text C:\Windows\system32\svchost.exe[1568] msvcrt.dll!_creat 7631BBE1 5 Bytes JMP 00760FE3
.text C:\Windows\system32\svchost.exe[1568] msvcrt.dll!_open 7631D106 5 Bytes JMP 0076000C
.text C:\Windows\system32\svchost.exe[1568] msvcrt.dll!_wcreat 7631D326 5 Bytes JMP 0076002E
.text C:\Windows\system32\svchost.exe[1568] msvcrt.dll!_wopen 7631D501 5 Bytes JMP 0076001D
.text C:\Windows\system32\svchost.exe[1568] ADVAPI32.dll!RegCreateKeyExA 765739AB 5 Bytes JMP 00670047
.text C:\Windows\system32\svchost.exe[1568] ADVAPI32.dll!RegCreateKeyA 76573BA9 5 Bytes JMP 0067001B
.text C:\Windows\system32\svchost.exe[1568] ADVAPI32.dll!RegOpenKeyA 765789C7 5 Bytes JMP 00670FE5
.text C:\Windows\system32\svchost.exe[1568] ADVAPI32.dll!RegCreateKeyW 7658391E 5 Bytes JMP 00670036
.text C:\Windows\system32\svchost.exe[1568] ADVAPI32.dll!RegCreateKeyExW 765841F1 5 Bytes JMP 00670058
.text C:\Windows\system32\svchost.exe[1568] ADVAPI32.dll!RegOpenKeyExA 76587C42 5 Bytes JMP 00670FB9
.text C:\Windows\system32\svchost.exe[1568] ADVAPI32.dll!RegOpenKeyW 7658E2B5 5 Bytes JMP 00670FCA
.text C:\Windows\system32\svchost.exe[1568] ADVAPI32.dll!RegOpenKeyExW 76597BA1 5 Bytes JMP 0067000A
.text C:\Windows\system32\svchost.exe[1600] ntdll.dll!NtCreateFile 775D4224 5 Bytes JMP 00EC000A
.text C:\Windows\system32\svchost.exe[1600] ntdll.dll!NtCreateProcess 775D42E4 5 Bytes JMP 00EC0FDE
.text C:\Windows\system32\svchost.exe[1600] ntdll.dll!NtProtectVirtualMemory 775D4B84 5 Bytes JMP 00EC0FEF
.text C:\Windows\system32\svchost.exe[1600] kernel32.dll!GetStartupInfoW 77491929 5 Bytes JMP 001F00AE
.text C:\Windows\system32\svchost.exe[1600] kernel32.dll!GetStartupInfoA 774919C9 5 Bytes JMP 001F0F5E
.text C:\Windows\system32\svchost.exe[1600] kernel32.dll!CreateProcessW 77491BF3 5 Bytes JMP 001F00C9
.text C:\Windows\system32\svchost.exe[1600] kernel32.dll!CreateProcessA 77491C28 5 Bytes JMP 001F0F32
.text C:\Windows\system32\svchost.exe[1600] kernel32.dll!VirtualProtect 77491DC3 5 Bytes JMP 001F006E
.text C:\Windows\system32\svchost.exe[1600] kernel32.dll!CreateNamedPipeA 77492EF5 5 Bytes JMP 001F000A
.text C:\Windows\system32\svchost.exe[1600] kernel32.dll!CreateNamedPipeW 77495C0C 5 Bytes JMP 001F001B
.text C:\Windows\system32\svchost.exe[1600] kernel32.dll!CreatePipe 774B8F06 5 Bytes JMP 001F0F79
.text C:\Windows\system32\svchost.exe[1600] kernel32.dll!LoadLibraryExW 774B927C 5 Bytes JMP 001F0051
.text C:\Windows\system32\svchost.exe[1600] kernel32.dll!LoadLibraryW 774B9400 5 Bytes JMP 001F0F94
.text C:\Windows\system32\svchost.exe[1600] kernel32.dll!LoadLibraryExA 774B9554 5 Bytes JMP 001F0040
.text C:\Windows\system32\svchost.exe[1600] kernel32.dll!LoadLibraryA 774B957C 5 Bytes JMP 001F0FB9
.text C:\Windows\system32\svchost.exe[1600] kernel32.dll!VirtualProtectEx 774BDC52 5 Bytes JMP 001F0089
.text C:\Windows\system32\svchost.exe[1600] kernel32.dll!GetProcAddress 774D925B 5 Bytes JMP 001F00EE
.text C:\Windows\system32\svchost.exe[1600] kernel32.dll!CreateFileW 774DB0EB 5 Bytes JMP 001F0FDE
.text C:\Windows\system32\svchost.exe[1600] kernel32.dll!CreateFileA 774DD07F 5 Bytes JMP 001F0FEF
.text C:\Windows\system32\svchost.exe[1600] kernel32.dll!WinExec 775260CF 5 Bytes JMP 001F0F43
.text C:\Windows\system32\svchost.exe[1600] msvcrt.dll!_wsystem 76317F2F 5 Bytes JMP 01320F86
.text C:\Windows\system32\svchost.exe[1600] msvcrt.dll!system 7631804B 5 Bytes JMP 01320FA1
.text C:\Windows\system32\svchost.exe[1600] msvcrt.dll!_creat 7631BBE1 5 Bytes JMP 01320FC3
.text C:\Windows\system32\svchost.exe[1600] msvcrt.dll!_open 7631D106 5 Bytes JMP 01320FEF
.text C:\Windows\system32\svchost.exe[1600] msvcrt.dll!_wcreat 7631D326 5 Bytes JMP 01320FB2
.text C:\Windows\system32\svchost.exe[1600] msvcrt.dll!_wopen 7631D501 5 Bytes JMP 01320FDE
.text C:\Windows\system32\svchost.exe[1600] ADVAPI32.dll!RegCreateKeyExA 765739AB 5 Bytes JMP 0133007D
.text C:\Windows\system32\svchost.exe[1600] ADVAPI32.dll!RegCreateKeyA 76573BA9 5 Bytes JMP 01330051
.text C:\Windows\system32\svchost.exe[1600] ADVAPI32.dll!RegOpenKeyA 765789C7 5 Bytes JMP 01330FEF
.text C:\Windows\system32\svchost.exe[1600] ADVAPI32.dll!RegCreateKeyW 7658391E 5 Bytes JMP 0133006C
.text C:\Windows\system32\svchost.exe[1600] ADVAPI32.dll!RegCreateKeyExW 765841F1 5 Bytes JMP 01330098
.text C:\Windows\system32\svchost.exe[1600] ADVAPI32.dll!RegOpenKeyExA 76587C42 5 Bytes JMP 01330025
.text C:\Windows\system32\svchost.exe[1600] ADVAPI32.dll!RegOpenKeyW 7658E2B5 5 Bytes JMP 0133000A
.text C:\Windows\system32\svchost.exe[1600] ADVAPI32.dll!RegOpenKeyExW 76597BA1 5 Bytes JMP 01330036
.text C:\Windows\system32\svchost.exe[1600] WS2_32.dll!socket 776A36D1 5 Bytes JMP 01400000
.text C:\Windows\system32\svchost.exe[1600] WININET.dll!InternetOpenA 75D74E33 5 Bytes JMP 00ED0000
.text C:\Windows\system32\svchost.exe[1600] WININET.dll!InternetOpenUrlA 75D7BFCE 5 Bytes JMP 00ED0025
.text C:\Windows\system32\svchost.exe[1600] WININET.dll!InternetOpenW 75DAC02E 5 Bytes JMP 00ED0FE5
.text C:\Windows\system32\svchost.exe[1600] WININET.dll!InternetOpenUrlW 75DDD70A 5 Bytes JMP 00ED0036
.text C:\Windows\system32\svchost.exe[1808] ntdll.dll!NtCreateFile 775D4224 5 Bytes JMP 00910FEF
.text C:\Windows\system32\svchost.exe[1808] ntdll.dll!NtCreateProcess 775D42E4 5 Bytes JMP 00910014
.text C:\Windows\system32\svchost.exe[1808] ntdll.dll!NtProtectVirtualMemory 775D4B84 5 Bytes JMP 00910FDE
.text C:\Windows\system32\svchost.exe[1808] kernel32.dll!GetStartupInfoW 77491929 5 Bytes JMP 00900F8C
.text C:\Windows\system32\svchost.exe[1808] kernel32.dll!GetStartupInfoA 774919C9 5 Bytes JMP 009000D2
.text C:\Windows\system32\svchost.exe[1808] kernel32.dll!CreateProcessW 77491BF3 5 Bytes JMP 00900108
.text C:\Windows\system32\svchost.exe[1808] kernel32.dll!CreateProcessA 77491C28 5 Bytes JMP 00900F71
.text C:\Windows\system32\svchost.exe[1808] kernel32.dll!VirtualProtect 77491DC3 5 Bytes JMP 0090008B
.text C:\Windows\system32\svchost.exe[1808] kernel32.dll!CreateNamedPipeA 77492EF5 5 Bytes JMP 0090002C
.text C:\Windows\system32\svchost.exe[1808] kernel32.dll!CreateNamedPipeW 77495C0C 5 Bytes JMP 00900047
.text C:\Windows\system32\svchost.exe[1808] kernel32.dll!CreatePipe 774B8F06 5 Bytes JMP 009000B7
.text C:\Windows\system32\svchost.exe[1808] kernel32.dll!LoadLibraryExW 774B927C 5 Bytes JMP 0090007A
.text C:\Windows\system32\svchost.exe[1808] kernel32.dll!LoadLibraryW 774B9400 5 Bytes JMP 00900FD1
.text C:\Windows\system32\svchost.exe[1808] kernel32.dll!LoadLibraryExA 774B9554 5 Bytes JMP 00900069
.text C:\Windows\system32\svchost.exe[1808] kernel32.dll!LoadLibraryA 774B957C 5 Bytes JMP 00900058
.text C:\Windows\system32\svchost.exe[1808] kernel32.dll!VirtualProtectEx 774BDC52 5 Bytes JMP 0090009C
.text C:\Windows\system32\svchost.exe[1808] kernel32.dll!GetProcAddress 774D925B 5 Bytes JMP 00900F56
.text C:\Windows\system32\svchost.exe[1808] kernel32.dll!CreateFileW 774DB0EB 5 Bytes JMP 0090001B
.text C:\Windows\system32\svchost.exe[1808] kernel32.dll!CreateFileA 774DD07F 5 Bytes JMP 0090000A
.text C:\Windows\system32\svchost.exe[1808] kernel32.dll!WinExec 775260CF 5 Bytes JMP 009000E3
.text C:\Windows\system32\svchost.exe[1808] msvcrt.dll!_wsystem 76317F2F 5 Bytes JMP 00920049
.text C:\Windows\system32\svchost.exe[1808] msvcrt.dll!system 7631804B 5 Bytes JMP 00920FBE
.text C:\Windows\system32\svchost.exe[1808] msvcrt.dll!_creat 7631BBE1 5 Bytes JMP 0092001D
.text C:\Windows\system32\svchost.exe[1808] msvcrt.dll!_open 7631D106 5 Bytes JMP 00920000
.text C:\Windows\system32\svchost.exe[1808] msvcrt.dll!_wcreat 7631D326 5 Bytes JMP 00920038
.text C:\Windows\system32\svchost.exe[1808] msvcrt.dll!_wopen 7631D501 5 Bytes JMP 00920FE3
.text C:\Windows\system32\svchost.exe[1808] ADVAPI32.dll!RegCreateKeyExA 765739AB 5 Bytes JMP 008B0062
.text C:\Windows\system32\svchost.exe[1808] ADVAPI32.dll!RegCreateKeyA 76573BA9 5 Bytes JMP 008B0FCA
.text C:\Windows\system32\svchost.exe[1808] ADVAPI32.dll!RegOpenKeyA 765789C7 5 Bytes JMP 008B0000
.text C:\Windows\system32\svchost.exe[1808] ADVAPI32.dll!RegCreateKeyW 7658391E 5 Bytes JMP 008B0047
.text C:\Windows\system32\svchost.exe[1808] ADVAPI32.dll!RegCreateKeyExW 765841F1 5 Bytes JMP 008B0073
.text C:\Windows\system32\svchost.exe[1808] ADVAPI32.dll!RegOpenKeyExA 76587C42 5 Bytes JMP 008B002C
.text C:\Windows\system32\svchost.exe[1808] ADVAPI32.dll!RegOpenKeyW 7658E2B5 5 Bytes JMP 008B0011
.text C:\Windows\system32\svchost.exe[1808] ADVAPI32.dll!RegOpenKeyExW 76597BA1 5 Bytes JMP 008B0FDB
.text C:\Windows\system32\svchost.exe[1808] WS2_32.dll!socket 776A36D1 5 Bytes JMP 00930000
.text C:\Windows\system32\svchost.exe[2036] ntdll.dll!NtCreateFile 775D4224 5 Bytes JMP 008F0FEF
.text C:\Windows\system32\svchost.exe[2036] ntdll.dll!NtCreateProcess 775D42E4 5 Bytes JMP 008F0FCA
.text C:\Windows\system32\svchost.exe[2036] ntdll.dll!NtProtectVirtualMemory 775D4B84 5 Bytes JMP 008F000A
.text C:\Windows\system32\svchost.exe[2036] kernel32.dll!GetStartupInfoW 77491929 5 Bytes JMP 008E0F1A
.text C:\Windows\system32\svchost.exe[2036] kernel32.dll!GetStartupInfoA 774919C9 5 Bytes JMP 008E0F2B
.text C:\Windows\system32\svchost.exe[2036] kernel32.dll!CreateProcessW 77491BF3 5 Bytes JMP 008E009D
.text C:\Windows\system32\svchost.exe[2036] kernel32.dll!CreateProcessA 77491C28 5 Bytes JMP 008E008C
.text C:\Windows\system32\svchost.exe[2036] kernel32.dll!VirtualProtect 77491DC3 5 Bytes JMP 008E0042
.text C:\Windows\system32\svchost.exe[2036] kernel32.dll!CreateNamedPipeA 77492EF5 5 Bytes JMP 008E0FB9
.text C:\Windows\system32\svchost.exe[2036] kernel32.dll!CreateNamedPipeW 77495C0C 5 Bytes JMP 008E0014
.text C:\Windows\system32\svchost.exe[2036] kernel32.dll!CreatePipe 774B8F06 5 Bytes JMP 008E0F3C
.text C:\Windows\system32\svchost.exe[2036] kernel32.dll!LoadLibraryExW 774B927C 5 Bytes JMP 008E0F68
.text C:\Windows\system32\svchost.exe[2036] kernel32.dll!LoadLibraryW 774B9400 5 Bytes JMP 008E0025
.text C:\Windows\system32\svchost.exe[2036] kernel32.dll!LoadLibraryExA 774B9554 5 Bytes JMP 008E0F79
.text C:\Windows\system32\svchost.exe[2036] kernel32.dll!LoadLibraryA 774B957C 5 Bytes JMP 008E0F9E
.text C:\Windows\system32\svchost.exe[2036] kernel32.dll!VirtualProtectEx 774BDC52 5 Bytes JMP 008E0F4D
.text C:\Windows\system32\svchost.exe[2036] kernel32.dll!GetProcAddress 774D925B 5 Bytes JMP 008E00B8
.text C:\Windows\system32\svchost.exe[2036] kernel32.dll!CreateFileW 774DB0EB 5 Bytes JMP 008E0FD4
.text C:\Windows\system32\svchost.exe[2036] kernel32.dll!CreateFileA 774DD07F 5 Bytes JMP 008E0FEF
.text C:\Windows\system32\svchost.exe[2036] kernel32.dll!WinExec 775260CF 5 Bytes JMP 008E007B
.text C:\Windows\system32\svchost.exe[2036] msvcrt.dll!_wsystem 76317F2F 5 Bytes JMP 00900084
.text C:\Windows\system32\svchost.exe[2036] msvcrt.dll!system 7631804B 5 Bytes JMP 0090005F
.text C:\Windows\system32\svchost.exe[2036] msvcrt.dll!_creat 7631BBE1 5 Bytes JMP 0090003A
.text C:\Windows\system32\svchost.exe[2036] msvcrt.dll!_open 7631D106 5 Bytes JMP 00900000
.text C:\Windows\system32\svchost.exe[2036] msvcrt.dll!_wcreat 7631D326 5 Bytes JMP 00900FEF
.text C:\Windows\system32\svchost.exe[2036] msvcrt.dll!_wopen 7631D501 5 Bytes JMP 0090001D
.text C:\Windows\system32\svchost.exe[2036] ADVAPI32.dll!RegCreateKeyExA 765739AB 5 Bytes JMP 00770F9B
.text C:\Windows\system32\svchost.exe[2036] ADVAPI32.dll!RegCreateKeyA 76573BA9 5 Bytes JMP 00770FB6
.text C:\Windows\system32\svchost.exe[2036] ADVAPI32.dll!RegOpenKeyA 765789C7 5 Bytes JMP 00770000
.text C:\Windows\system32\svchost.exe[2036] ADVAPI32.dll!RegCreateKeyW 7658391E 5 Bytes JMP 0077003D
.text C:\Windows\system32\svchost.exe[2036] ADVAPI32.dll!RegCreateKeyExW 765841F1 5 Bytes JMP 00770058
.text C:\Windows\system32\svchost.exe[2036] ADVAPI32.dll!RegOpenKeyExA 76587C42 5 Bytes JMP 00770011
.text C:\Windows\system32\svchost.exe[2036] ADVAPI32.dll!RegOpenKeyW 7658E2B5 5 Bytes JMP 00770FDB
.text C:\Windows\system32\svchost.exe[2036] ADVAPI32.dll!RegOpenKeyExW 76597BA1 5 Bytes JMP 0077002C
.text C:\Windows\system32\svchost.exe[2036] WS2_32.dll!socket 776A36D1 5 Bytes JMP 00A50FE5
.text C:\Windows\system32\svchost.exe[2264] ntdll.dll!NtCreateFile 775D4224 5 Bytes JMP 008E0FE5
.text C:\Windows\system32\svchost.exe[2264] ntdll.dll!NtCreateProcess 775D42E4 5 Bytes JMP 008E0014
.text C:\Windows\system32\svchost.exe[2264] ntdll.dll!NtProtectVirtualMemory 775D4B84 5 Bytes JMP 008E0FD4
.text C:\Windows\system32\svchost.exe[2264] kernel32.dll!GetStartupInfoW 77491929 5 Bytes JMP 00260085
.text C:\Windows\system32\svchost.exe[2264] kernel32.dll!GetStartupInfoA 774919C9 5 Bytes JMP 00260074
.text C:\Windows\system32\svchost.exe[2264] kernel32.dll!CreateProcessW 77491BF3 5 Bytes JMP 00260F13
.text C:\Windows\system32\svchost.exe[2264] kernel32.dll!CreateProcessA 77491C28 5 Bytes JMP 00260F24
.text C:\Windows\system32\svchost.exe[2264] kernel32.dll!VirtualProtect 77491DC3 5 Bytes JMP 00260F6B
.text C:\Windows\system32\svchost.exe[2264] kernel32.dll!CreateNamedPipeA 77492EF5 5 Bytes JMP 00260FD4
.text C:\Windows\system32\svchost.exe[2264] kernel32.dll!CreateNamedPipeW 77495C0C 5 Bytes JMP 0026001B
.text C:\Windows\system32\svchost.exe[2264] kernel32.dll!CreatePipe 774B8F06 5 Bytes JMP 00260F3F
.text C:\Windows\system32\svchost.exe[2264] kernel32.dll!LoadLibraryExW 774B927C 5 Bytes JMP 00260F86
.text C:\Windows\system32\svchost.exe[2264] kernel32.dll!LoadLibraryW 774B9400 5 Bytes JMP 00260FA8
.text C:\Windows\system32\svchost.exe[2264] kernel32.dll!LoadLibraryExA 774B9554 5 Bytes JMP 00260F97
.text C:\Windows\system32\svchost.exe[2264] kernel32.dll!LoadLibraryA 774B957C 5 Bytes JMP 00260FB9
.text C:\Windows\system32\svchost.exe[2264] kernel32.dll!VirtualProtectEx 774BDC52 5 Bytes JMP 00260F5A
.text C:\Windows\system32\svchost.exe[2264] kernel32.dll!GetProcAddress 774D925B 5 Bytes JMP 00260F02
.text C:\Windows\system32\svchost.exe[2264] kernel32.dll!CreateFileW 774DB0EB 5 Bytes JMP 0026000A
.text C:\Windows\system32\svchost.exe[2264] kernel32.dll!CreateFileA 774DD07F 5 Bytes JMP 00260FEF
.text C:\Windows\system32\svchost.exe[2264] kernel32.dll!WinExec 775260CF 5 Bytes JMP 002600A0
.text C:\Windows\system32\svchost.exe[2264] msvcrt.dll!_wsystem 76317F2F 5 Bytes JMP 00930FC1
.text C:\Windows\system32\svchost.exe[2264] msvcrt.dll!system 7631804B 5 Bytes JMP 0093004C
.text C:\Windows\system32\svchost.exe[2264] msvcrt.dll!_creat 7631BBE1 5 Bytes JMP 00930FD2
.text C:\Windows\system32\svchost.exe[2264] msvcrt.dll!_open 7631D106 5 Bytes JMP 00930FEF
.text C:\Windows\system32\svchost.exe[2264] msvcrt.dll!_wcreat 7631D326 5 Bytes JMP 00930027
.text C:\Windows\system32\svchost.exe[2264] msvcrt.dll!_wopen 7631D501 5 Bytes JMP 0093000C
.text C:\Windows\system32\svchost.exe[2264] ADVAPI32.dll!RegCreateKeyExA 765739AB 5 Bytes JMP 001D0F9E
.text C:\Windows\system32\svchost.exe[2264] ADVAPI32.dll!RegCreateKeyA 76573BA9 5 Bytes JMP 001D0036
.text C:\Windows\system32\svchost.exe[2264] ADVAPI32.dll!RegOpenKeyA 765789C7 5 Bytes JMP 001D0FEF
.text C:\Windows\system32\svchost.exe[2264] ADVAPI32.dll!RegCreateKeyW 7658391E 5 Bytes JMP 001D0FAF
.text C:\Windows\system32\svchost.exe[2264] ADVAPI32.dll!RegCreateKeyExW 765841F1 5 Bytes JMP 001D005B
.text C:\Windows\system32\svchost.exe[2264] ADVAPI32.dll!RegOpenKeyExA 76587C42 5 Bytes JMP 001D0014
.text C:\Windows\system32\svchost.exe[2264] ADVAPI32.dll!RegOpenKeyW 7658E2B5 5 Bytes JMP 001D0FDE
.text C:\Windows\system32\svchost.exe[2264] ADVAPI32.dll!RegOpenKeyExW 76597BA1 5 Bytes JMP 001D0025
.text C:\Windows\system32\svchost.exe[2264] WS2_32.dll!socket 776A36D1 5 Bytes JMP 00940FE5
.text C:\Windows\system32\svchost.exe[2332] ntdll.dll!NtCreateFile 775D4224 5 Bytes JMP 00FE0FE5
.text C:\Windows\system32\svchost.exe[2332] ntdll.dll!NtCreateProcess 775D42E4 5 Bytes JMP 00FE001B
.text C:\Windows\system32\svchost.exe[2332] ntdll.dll!NtProtectVirtualMemory 775D4B84 5 Bytes JMP 00FE0000
.text C:\Windows\system32\svchost.exe[2332] kernel32.dll!GetStartupInfoW 77491929 5 Bytes JMP 00FD0F4B
.text C:\Windows\system32\svchost.exe[2332] kernel32.dll!GetStartupInfoA 774919C9 5 Bytes JMP 00FD0091
.text C:\Windows\system32\svchost.exe[2332] kernel32.dll!CreateProcessW 77491BF3 5 Bytes JMP 00FD00C7
.text C:\Windows\system32\svchost.exe[2332] kernel32.dll!CreateProcessA 77491C28 5 Bytes JMP 00FD0F30
.text C:\Windows\system32\svchost.exe[2332] kernel32.dll!VirtualProtect 77491DC3 5 Bytes JMP 00FD0F92
.text C:\Windows\system32\svchost.exe[2332] kernel32.dll!CreateNamedPipeA 77492EF5 5 Bytes JMP 00FD0FD4
.text C:\Windows\system32\svchost.exe[2332] kernel32.dll!CreateNamedPipeW 77495C0C 5 Bytes JMP 00FD0FB9
.text C:\Windows\system32\svchost.exe[2332] kernel32.dll!CreatePipe 774B8F06 5 Bytes JMP 00FD0F70
.text C:\Windows\system32\svchost.exe[2332] kernel32.dll!LoadLibraryExW 774B927C 5 Bytes JMP 00FD006C
.text C:\Windows\system32\svchost.exe[2332] kernel32.dll!LoadLibraryW 774B9400 5 Bytes JMP 00FD0040
.text C:\Windows\system32\svchost.exe[2332] kernel32.dll!LoadLibraryExA 774B9554 5 Bytes JMP 00FD0051
.text C:\Windows\system32\svchost.exe[2332] kernel32.dll!LoadLibraryA 774B957C 5 Bytes JMP 00FD0025
.text C:\Windows\system32\svchost.exe[2332] kernel32.dll!VirtualProtectEx 774BDC52 5 Bytes JMP 00FD0F81
.text C:\Windows\system32\svchost.exe[2332] kernel32.dll!GetProcAddress 774D925B 5 Bytes JMP 00FD0F1F
.text C:\Windows\system32\svchost.exe[2332] kernel32.dll!CreateFileW 774DB0EB 5 Bytes JMP 00FD0FE5
.text C:\Windows\system32\svchost.exe[2332] kernel32.dll!CreateFileA 774DD07F 5 Bytes JMP 00FD0000
.text C:\Windows\system32\svchost.exe[2332] kernel32.dll!WinExec 775260CF 5 Bytes JMP 00FD00B6
.text C:\Windows\system32\svchost.exe[2332] msvcrt.dll!_wsystem 76317F2F 5 Bytes JMP 01000038
.text C:\Windows\system32\svchost.exe[2332] msvcrt.dll!system 7631804B 5 Bytes JMP 0100001D
.text C:\Windows\system32\svchost.exe[2332] msvcrt.dll!_creat 7631BBE1 5 Bytes JMP 01000FD2
.text C:\Windows\system32\svchost.exe[2332] msvcrt.dll!_open 7631D106 5 Bytes JMP 01000000
.text C:\Windows\system32\svchost.exe[2332] msvcrt.dll!_wcreat 7631D326 5 Bytes JMP 01000FB7
.text C:\Windows\system32\svchost.exe[2332] msvcrt.dll!_wopen 7631D501 5 Bytes JMP 01000FE3
.text C:\Windows\system32\svchost.exe[2332] ADVAPI32.dll!RegCreateKeyExA 765739AB 5 Bytes JMP 00FC0040
.text C:\Windows\system32\svchost.exe[2332] ADVAPI32.dll!RegCreateKeyA 76573BA9 5 Bytes JMP 00FC0025
.text C:\Windows\system32\svchost.exe[2332] ADVAPI32.dll!RegOpenKeyA 765789C7 5 Bytes JMP 00FC0FEF
.text C:\Windows\system32\svchost.exe[2332] ADVAPI32.dll!RegCreateKeyW 7658391E 5 Bytes JMP 00FC0F9E
.text C:\Windows\system32\svchost.exe[2332] ADVAPI32.dll!RegCreateKeyExW 765841F1 5 Bytes JMP 00FC0F83
.text C:\Windows\system32\svchost.exe[2332] ADVAPI32.dll!RegOpenKeyExA 76587C42 5 Bytes JMP 00FC000A
.text C:\Windows\system32\svchost.exe[2332] ADVAPI32.dll!RegOpenKeyW 7658E2B5 5 Bytes JMP 00FC0FD4
.text C:\Windows\system32\svchost.exe[2332] ADVAPI32.dll!RegOpenKeyExW 76597BA1 5 Bytes JMP 00FC0FB9
.text C:\Windows\system32\svchost.exe[2332] WS2_32.dll!socket 776A36D1 5 Bytes JMP 01010FEF
.text C:\Windows\System32\svchost.exe[2368] ntdll.dll!NtCreateFile 775D4224 5 Bytes JMP 00070000
.text C:\Windows\System32\svchost.exe[2368] ntdll.dll!NtCreateProcess 775D42E4 5 Bytes JMP 00070FE5
.text C:\Windows\System32\svchost.exe[2368] ntdll.dll!NtProtectVirtualMemory 775D4B84 5 Bytes JMP 0007001B
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!GetStartupInfoW 77491929 5 Bytes JMP 00060F4D
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!GetStartupInfoA 774919C9 5 Bytes JMP 00060093
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!CreateProcessW 77491BF3 5 Bytes JMP 000600C9
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!CreateProcessA 77491C28 5 Bytes JMP 00060F3C
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!VirtualProtect 77491DC3 5 Bytes JMP 00060F68
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!CreateNamedPipeA 77492EF5 5 Bytes JMP 0006002C
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!CreateNamedPipeW 77495C0C 5 Bytes JMP 00060FD1
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!CreatePipe 774B8F06 5 Bytes JMP 00060078
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!LoadLibraryExW 774B927C 5 Bytes JMP 00060F83
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!LoadLibraryW 774B9400 5 Bytes JMP 00060FA5
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!LoadLibraryExA 774B9554 5 Bytes JMP 00060F94
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!LoadLibraryA 774B957C 5 Bytes JMP 00060FC0
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!VirtualProtectEx 774BDC52 5 Bytes JMP 0006005D
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!GetProcAddress 774D925B 5 Bytes JMP 00060F17
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!CreateFileW 774DB0EB 5 Bytes JMP 00060011
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!CreateFileA 774DD07F 5 Bytes JMP 00060000
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!WinExec 775260CF 5 Bytes JMP 000600B8
.text C:\Windows\System32\svchost.exe[2368] msvcrt.dll!_wsystem 76317F2F 5 Bytes JMP 00080031
.text C:\Windows\System32\svchost.exe[2368] msvcrt.dll!system 7631804B 5 Bytes JMP 00080FA6
.text C:\Windows\System32\svchost.exe[2368] msvcrt.dll!_creat 7631BBE1 5 Bytes JMP 00080FC8
.text C:\Windows\System32\svchost.exe[2368] msvcrt.dll!_open 7631D106 5 Bytes JMP 00080FEF
.text C:\Windows\System32\svchost.exe[2368] msvcrt.dll!_wcreat 7631D326 5 Bytes JMP 00080FB7
.text C:\Windows\System32\svchost.exe[2368] msvcrt.dll!_wopen 7631D501 5 Bytes JMP 0008000C
.text C:\Windows\System32\svchost.exe[2368] ADVAPI32.dll!RegCreateKeyExA 765739AB 5 Bytes JMP 00050F97
.text C:\Windows\System32\svchost.exe[2368] ADVAPI32.dll!RegCreateKeyA 76573BA9 5 Bytes JMP 00050FB2
.text C:\Windows\System32\svchost.exe[2368] ADVAPI32.dll!RegOpenKeyA 765789C7 5 Bytes JMP 00050FEF
.text C:\Windows\System32\svchost.exe[2368] ADVAPI32.dll!RegCreateKeyW 7658391E 5 Bytes JMP 00050043
.text C:\Windows\System32\svchost.exe[2368] ADVAPI32.dll!RegCreateKeyExW 765841F1 5 Bytes JMP 00050F86
.text C:\Windows\System32\svchost.exe[2368] ADVAPI32.dll!RegOpenKeyExA 76587C42 5 Bytes JMP 00050FD4
.text C:\Windows\System32\svchost.exe[2368] ADVAPI32.dll!RegOpenKeyW 7658E2B5 5 Bytes JMP 0005000A
.text C:\Windows\System32\svchost.exe[2368] ADVAPI32.dll!RegOpenKeyExW 76597BA1 5 Bytes JMP 00050FC3
.text C:\Windows\System32\svchost.exe[2368] WS2_32.dll!socket 776A36D1 5 Bytes JMP 00100000
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[2628] kernel32.dll!LoadLibraryW 774B9400 5 Bytes JMP 702E9A63 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[2628] kernel32.dll!LoadLibraryA 774B957C 5 Bytes JMP 702E99A1 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Windows\system32\svchost.exe[2948] ntdll.dll!NtCreateFile 775D4224 5 Bytes JMP 001B0FEF
.text C:\Windows\system32\svchost.exe[2948] ntdll.dll!NtCreateProcess 775D42E4 5 Bytes JMP 001B0FD4
.text C:\Windows\system32\svchost.exe[2948] ntdll.dll!NtProtectVirtualMemory 775D4B84 5 Bytes JMP 001B000A
.text C:\Windows\system32\svchost.exe[2948] kernel32.dll!GetStartupInfoW 77491929 5 Bytes JMP 001A0F7A
.text C:\Windows\system32\svchost.exe[2948] kernel32.dll!GetStartupInfoA 774919C9 5 Bytes JMP 001A0F8B
.text C:\Windows\system32\svchost.exe[2948] kernel32.dll!CreateProcessW 77491BF3 5 Bytes JMP 001A00E5
.text C:\Windows\system32\svchost.exe[2948] kernel32.dll!CreateProcessA 77491C28 5 Bytes JMP 001A0F4E
.text C:\Windows\system32\svchost.exe[2948] kernel32.dll!VirtualProtect 77491DC3 5 Bytes JMP 001A008A
.text C:\Windows\system32\svchost.exe[2948] kernel32.dll!CreateNamedPipeA 77492EF5 5 Bytes JMP 001A0014
.text C:\Windows\system32\svchost.exe[2948] kernel32.dll!CreateNamedPipeW 77495C0C 5 Bytes JMP 001A002F
.text C:\Windows\system32\svchost.exe[2948] kernel32.dll!CreatePipe 774B8F06 5 Bytes JMP 001A00B6
.text C:\Windows\system32\svchost.exe[2948] kernel32.dll!LoadLibraryExW 774B927C 5 Bytes JMP 001A0FA6
.text C:\Windows\system32\svchost.exe[2948] kernel32.dll!LoadLibraryW 774B9400 5 Bytes JMP 001A0065
.text C:\Windows\system32\svchost.exe[2948] kernel32.dll!LoadLibraryExA 774B9554 5 Bytes JMP 001A0FC3
.text C:\Windows\system32\svchost.exe[2948] kernel32.dll!LoadLibraryA 774B957C 5 Bytes JMP 001A0040
.text C:\Windows\system32\svchost.exe[2948] kernel32.dll!VirtualProtectEx 774BDC52 5 Bytes JMP 001A00A5
.text C:\Windows\system32\svchost.exe[2948] kernel32.dll!GetProcAddress 774D925B 5 Bytes JMP 001A0F33
.text C:\Windows\system32\svchost.exe[2948] kernel32.dll!CreateFileW 774DB0EB 5 Bytes JMP 001A0FD4
.text C:\Windows\system32\svchost.exe[2948] kernel32.dll!CreateFileA 774DD07F 5 Bytes JMP 001A0FEF
.text C:\Windows\system32\svchost.exe[2948] kernel32.dll!WinExec 775260CF 5 Bytes JMP 001A0F69
.text C:\Windows\system32\svchost.exe[2948] msvcrt.dll!_wsystem 76317F2F 5 Bytes JMP 00170047
.text C:\Windows\system32\svchost.exe[2948] msvcrt.dll!system 7631804B 5 Bytes JMP 00170FBC
.text C:\Windows\system32\svchost.exe[2948] msvcrt.dll!_creat 7631BBE1 5 Bytes JMP 00170FCD
.text C:\Windows\system32\svchost.exe[2948] msvcrt.dll!_open 7631D106 5 Bytes JMP 00170FEF
.text C:\Windows\system32\svchost.exe[2948] msvcrt.dll!_wcreat 7631D326 5 Bytes JMP 0017002C
.text C:\Windows\system32\svchost.exe[2948] msvcrt.dll!_wopen 7631D501 5 Bytes JMP 00170FDE
.text C:\Windows\system32\svchost.exe[2948] ADVAPI32.dll!RegCreateKeyExA 765739AB 5 Bytes JMP 00180054
.text C:\Windows\system32\svchost.exe[2948] ADVAPI32.dll!RegCreateKeyA 76573BA9 5 Bytes JMP 0018002F
.text C:\Windows\system32\svchost.exe[2948] ADVAPI32.dll!RegOpenKeyA 765789C7 5 Bytes JMP 00180FEF
.text C:\Windows\system32\svchost.exe[2948] ADVAPI32.dll!RegCreateKeyW 7658391E 5 Bytes JMP 00180FB2
.text C:\Windows\system32\svchost.exe[2948] ADVAPI32.dll!RegCreateKeyExW 765841F1 5 Bytes JMP 00180FA1
.text C:\Windows\system32\svchost.exe[2948] ADVAPI32.dll!RegOpenKeyExA 76587C42 5 Bytes JMP 00180FCD
.text C:\Windows\system32\svchost.exe[2948] ADVAPI32.dll!RegOpenKeyW 7658E2B5 5 Bytes JMP 00180FDE
.text C:\Windows\system32\svchost.exe[2948] ADVAPI32.dll!RegOpenKeyExW 76597BA1 5 Bytes JMP 0018001E
.text C:\Windows\system32\svchost.exe[2948] WS2_32.dll!socket 776A36D1 5 Bytes JMP 001F0000
.text C:\Windows\system32\svchost.exe[3568] ntdll.dll!NtCreateFile 775D4224 5 Bytes JMP 00040FEF
.text C:\Windows\system32\svchost.exe[3568] ntdll.dll!NtCreateProcess 775D42E4 5 Bytes JMP 00040FC0
.text C:\Windows\system32\svchost.exe[3568] ntdll.dll!NtProtectVirtualMemory 775D4B84 5 Bytes JMP 00040000
.text C:\Windows\system32\svchost.exe[3568] kernel32.dll!GetStartupInfoW 77491929 5 Bytes JMP 00010F06
.text C:\Windows\system32\svchost.exe[3568] kernel32.dll!GetStartupInfoA 774919C9 5 Bytes JMP 00010056
.text C:\Windows\system32\svchost.exe[3568] kernel32.dll!CreateProcessW 77491BF3 5 Bytes JMP 00010EE4
.text C:\Windows\system32\svchost.exe[3568] kernel32.dll!CreateProcessA 77491C28 5 Bytes JMP 00010071
.text C:\Windows\system32\svchost.exe[3568] kernel32.dll!VirtualProtect 77491DC3 5 Bytes JMP 00010016
.text C:\Windows\system32\svchost.exe[3568] kernel32.dll!CreateNamedPipeA 77492EF5 5 Bytes JMP 00010FB9
.text C:\Windows\system32\svchost.exe[3568] kernel32.dll!CreateNamedPipeW 77495C0C 5 Bytes JMP 00010F9E
.text C:\Windows\system32\svchost.exe[3568] kernel32.dll!CreatePipe 774B8F06 5 Bytes JMP 00010045
.text C:\Windows\system32\svchost.exe[3568] kernel32.dll!LoadLibraryExW 774B927C 5 Bytes JMP 00010F3C
.text C:\Windows\system32\svchost.exe[3568] kernel32.dll!LoadLibraryW 774B9400 5 Bytes JMP 00010F68
.text C:\Windows\system32\svchost.exe[3568] kernel32.dll!LoadLibraryExA 774B9554 5 Bytes JMP 00010F4D
.text C:\Windows\system32\svchost.exe[3568] kernel32.dll!LoadLibraryA 774B957C 5 Bytes JMP 00010F83
.text C:\Windows\system32\svchost.exe[3568] kernel32.dll!VirtualProtectEx 774BDC52 5 Bytes JMP 00010F2B
.text C:\Windows\system32\svchost.exe[3568] kernel32.dll!GetProcAddress 774D925B 5 Bytes JMP 00010ED3
.text C:\Windows\system32\svchost.exe[3568] kernel32.dll!CreateFileW 774DB0EB 5 Bytes JMP 00010FD4
.text C:\Windows\system32\svchost.exe[3568] kernel32.dll!CreateFileA 774DD07F 5 Bytes JMP 00010FEF
.text C:\Windows\system32\svchost.exe[3568] kernel32.dll!WinExec 775260CF 5 Bytes JMP 00010EF5
.text C:\Windows\system32\svchost.exe[3568] msvcrt.dll!_wsystem 76317F2F 5 Bytes JMP 00060FAD
.text C:\Windows\system32\svchost.exe[3568] msvcrt.dll!system 7631804B 5 Bytes JMP 00060042
.text C:\Windows\system32\svchost.exe[3568] msvcrt.dll!_creat 7631BBE1 5 Bytes JMP 0006001D
.text C:\Windows\system32\svchost.exe[3568] msvcrt.dll!_open 7631D106 5 Bytes JMP 0006000C
.text C:\Windows\system32\svchost.exe[3568] msvcrt.dll!_wcreat 7631D326 5 Bytes JMP 00060FC8
.text C:\Windows\system32\svchost.exe[3568] msvcrt.dll!_wopen 7631D501 5 Bytes JMP 00060FE3
.text C:\Windows\system32\svchost.exe[3568] ADVAPI32.dll!RegCreateKeyExA 765739AB 5 Bytes JMP 00070F8A
.text C:\Windows\system32\svchost.exe[3568] ADVAPI32.dll!RegCreateKeyA 76573BA9 5 Bytes JMP 00070FB6
.text C:\Windows\system32\svchost.exe[3568] ADVAPI32.dll!RegOpenKeyA 765789C7 5 Bytes JMP 00070000
.text C:\Windows\system32\svchost.exe[3568] ADVAPI32.dll!RegCreateKeyW 7658391E 5 Bytes JMP 00070FA5
.text C:\Windows\system32\svchost.exe[3568] ADVAPI32.dll!RegCreateKeyExW 765841F1 5 Bytes JMP 00070F79
.text C:\Windows\system32\svchost.exe[3568] ADVAPI32.dll!RegOpenKeyExA 76587C42 5 Bytes JMP 00070011
.text C:\Windows\system32\svchost.exe[3568] ADVAPI32.dll!RegOpenKeyW 7658E2B5 5 Bytes JMP 00070FE5
.text C:\Windows\system32\svchost.exe[3568] ADVAPI32.dll!RegOpenKeyExW 76597BA1 5 Bytes JMP 00070022
.text C:\Windows\system32\svchost.exe[3568] WS2_32.dll!socket 776A36D1 5 Bytes JMP 00080FEF
.text C:\Windows\Explorer.EXE[4032] ntdll.dll!NtCreateFile 775D4224 5 Bytes JMP 00040000
.text C:\Windows\Explorer.EXE[4032] ntdll.dll!NtCreateProcess 775D42E4 5 Bytes JMP 00040FE5
.text C:\Windows\Explorer.EXE[4032] ntdll.dll!NtProtectVirtualMemory 775D4B84 5 Bytes JMP 00040011
.text C:\Windows\Explorer.EXE[4032] kernel32.dll!GetStartupInfoW 77491929 5 Bytes JMP 00010F1F
.text C:\Windows\Explorer.EXE[4032] kernel32.dll!GetStartupInfoA 774919C9 5 Bytes JMP 00010F3A
.text C:\Windows\Explorer.EXE[4032] kernel32.dll!CreateProcessW 77491BF3 5 Bytes JMP 00010091
.text C:\Windows\Explorer.EXE[4032] kernel32.dll!CreateProcessA 77491C28 5 Bytes JMP 00010080
.text C:\Windows\Explorer.EXE[4032] kernel32.dll!VirtualProtect 77491DC3 5 Bytes JMP 00010F81
.text C:\Windows\Explorer.EXE[4032] kernel32.dll!CreateNamedPipeA 77492EF5 5 Bytes JMP 0001000A
.text C:\Windows\Explorer.EXE[4032] kernel32.dll!CreateNamedPipeW 77495C0C 5 Bytes JMP 00010025
.text C:\Windows\Explorer.EXE[4032] kernel32.dll!CreatePipe 774B8F06 5 Bytes JMP 00010F55
.text C:\Windows\Explorer.EXE[4032] kernel32.dll!LoadLibraryExW 774B927C 5 Bytes JMP 00010065
.text C:\Windows\Explorer.EXE[4032] kernel32.dll!LoadLibraryW 774B9400 5 Bytes JMP 00010054
.text C:\Windows\Explorer.EXE[4032] kernel32.dll!LoadLibraryExA 774B9554 5 Bytes JMP 00010FB2
.text C:\Windows\Explorer.EXE[4032] kernel32.dll!LoadLibraryA 774B957C 5 Bytes JMP 00010FC3
.text C:\Windows\Explorer.EXE[4032] kernel32.dll!VirtualProtectEx 774BDC52 5 Bytes JMP 00010F66
.text C:\Windows\Explorer.EXE[4032] kernel32.dll!GetProcAddress 774D925B 5 Bytes JMP 00010EDF
.text C:\Windows\Explorer.EXE[4032] kernel32.dll!CreateFileW 774DB0EB 5 Bytes JMP 00010FD4
.text C:\Windows\Explorer.EXE[4032] kernel32.dll!CreateFileA 774DD07F 5 Bytes JMP 00010FEF
.text C:\Windows\Explorer.EXE[4032] kernel32.dll!WinExec 775260CF 5 Bytes JMP 00010EFA
.text C:\Windows\Explorer.EXE[4032] ADVAPI32.dll!RegCreateKeyExA 765739AB 5 Bytes JMP 00060FA5
.text C:\Windows\Explorer.EXE[4032] ADVAPI32.dll!RegCreateKeyA 76573BA9 5 Bytes JMP 00060FC0
.text C:\Windows\Explorer.EXE[4032] ADVAPI32.dll!RegOpenKeyA 765789C7 5 Bytes JMP 00060000
.text C:\Windows\Explorer.EXE[4032] ADVAPI32.dll!RegCreateKeyW 7658391E 5 Bytes JMP 00060047
.text C:\Windows\Explorer.EXE[4032] ADVAPI32.dll!RegCreateKeyExW 765841F1 5 Bytes JMP 00060062
.text C:\Windows\Explorer.EXE[4032] ADVAPI32.dll!RegOpenKeyExA 76587C42 5 Bytes JMP 00060FE5
.text C:\Windows\Explorer.EXE[4032] ADVAPI32.dll!RegOpenKeyW 7658E2B5 5 Bytes JMP 00060011
.text C:\Windows\Explorer.EXE[4032] ADVAPI32.dll!RegOpenKeyExW 76597BA1 5 Bytes JMP 00060036
.text C:\Windows\Explorer.EXE[4032] msvcrt.dll!_wsystem 76317F2F 5 Bytes JMP 00070F8B
.text C:\Windows\Explorer.EXE[4032] msvcrt.dll!system 7631804B 5 Bytes JMP 00070F9C
.text C:\Windows\Explorer.EXE[4032] msvcrt.dll!_creat 7631BBE1 5 Bytes JMP 00070FD2
.text C:\Windows\Explorer.EXE[4032] msvcrt.dll!_open 7631D106 5 Bytes JMP 00070FEF
.text C:\Windows\Explorer.EXE[4032] msvcrt.dll!_wcreat 7631D326 5 Bytes JMP 00070FB7
.text C:\Windows\Explorer.EXE[4032] msvcrt.dll!_wopen 7631D501 5 Bytes JMP 0007000C
.text C:\Windows\Explorer.EXE[4032] WININET.dll!InternetOpenA 75D74E33 5 Bytes JMP 01DE0FEF
.text C:\Windows\Explorer.EXE[4032] WININET.dll!InternetOpenUrlA 75D7BFCE 5 Bytes JMP 01DE0FD4
.text C:\Windows\Explorer.EXE[4032] WININET.dll!InternetOpenW 75DAC02E 5 Bytes JMP 01DE000A
.text C:\Windows\Explorer.EXE[4032] WININET.dll!InternetOpenUrlW 75DDD70A 5 Bytes JMP 01DE0FB9
.text C:\Windows\Explorer.EXE[4032] WS2_32.dll!socket 776A36D1 5 Bytes JMP 0397000A

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\Windows\system32\mfevtps.exe[1744] @ C:\Windows\system32\CRYPT32.dll [ADVAPI32.dll!RegQueryValueExW] [0115A4B0] C:\Windows\system32\mfevtps.exe (McAfee Process Validation Service/McAfee, Inc.)
IAT C:\Windows\system32\mfevtps.exe[1744] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [0115A510] C:\Windows\system32\mfevtps.exe (McAfee Process Validation Service/McAfee, Inc.)
IAT C:\Windows\Explorer.EXE[4032] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [74397817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4032] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [743EA86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4032] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7439BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4032] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [7438F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4032] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [743975E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4032] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [7438E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4032] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [743C8395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4032] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [7439DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4032] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [7438FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4032] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [7438FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4032] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [743871CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4032] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [7441CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4032] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [743BC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4032] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [7438D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4032] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [74386853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4032] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [7438687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[4032] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74392AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18342_none_9e54f8aaca13c773\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\Tcp mfewfpk.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 tdrpman.sys (Acronis Try&Decide and Restore Points Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 timntr.sys (Acronis True Image Backup Archive Explorer/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 tdrpman.sys (Acronis Try&Decide and Restore Points Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 timntr.sys (Acronis True Image Backup Archive Explorer/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 tdrpman.sys (Acronis Try&Decide and Restore Points Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 timntr.sys (Acronis True Image Backup Archive Explorer/Acronis)
AttachedDevice \Driver\tdx \Device\Udp mfewfpk.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat mfehidk.sys (McAfee Link Driver/McAfee, Inc.)

---- EOF - GMER 1.0.15 ----

Edited by In-Dell-ible, 12 October 2011 - 11:26 PM.


#5 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,663 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:03:55 AM

Posted 13 October 2011 - 12:11 AM

You're running two AV programs:
McAfee AntiVirus Plus
Microsoft Security Essentials

One of them has to go.
If McAfee, make sure to use this tool to uninstall it: http://www.softpedia.com/get/Tweak/Uninstallers/McAfee-Consumer-Product-Removal-Tool.shtml

Your connection is fine (ping works), but you seem to have DNS issue.

Make sure, your computer is set to obtain IP address automatically.
1. Go Start>Settings>Control Panel (Vista/7 users: Start>Control Panel)
2. Double click Network Connections (Vista/7 users: Network and Sharing Center)
3. Vista/7 users - From the list of tasks on the left, click Manage network connections.
4. For a wired network connection, right-click Local Area Connection, and then select Properties.
For a wireless network connection, right-click Wireless Network Connection, and then select Properties.
5. From the General tab (Vista/7 users: Networking tab), click Internet Protocol (TCP/IP), make sure it is checked, and then click Properties
6. Click Obtain an IP Address Automatically, and then click OK.

If that doesn't work...
Turn off computer. Disconnect router, and modem from power source for 1 minute. At the same time disconnect ethernet cable as well.
Reconnect everything.
Restart computer.

If that doesn't work, bypass router, and connect computer straight to the modem.

If that doesn't work...
Go Start>Run (Start search in Vista), type in:
cmd
Click OK (in Vista and 7, while holding CTRL, and SHIFT, press Enter).

In Command Prompt window, type in following commands, and hit Enter after each one:
ipconfig /flushdns
ipconfig /registerdns
ipconfig /release
ipconfig /renew
net stop "dns client"
net start "dns client"


Restart computer.

If that doesn't work...
Go Start>Run (Start search in Vista and 7), type in:
cmd
Click OK (in Vista, while holding CTRL, and SHIFT, press Enter).

At Command Prompt, type in:
netsh int ip reset reset.log
Hit Enter.
Type in:
netsh winsock reset catalog
Hit Enter.

Restart computer.

My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#6 In-Dell-ible

In-Dell-ible
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:55 AM

Posted 13 October 2011 - 12:59 AM

Broni -

The 2 AV programs... That was it. I disabled the windows one for now, and poof, I have internet. Thank you for that.

It's not my computer, but I am not a fan of McAfee. It takes almost exactly 5 minutes for it to come online and actively protect the computer - the whole time the internet is connected with traffic. Maybe a Remove and re-install for it might help, but I don't know for sure. For the moment, I would like to consider removing McAfee completely, let Windows guard the gate for the interim, and choose another program. Any input about that?

Thank you for you help thus far.

#7 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,663 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:03:55 AM

Posted 13 October 2011 - 03:12 PM

Good news :)
I'm not a bog fan of McAfee either.

My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users