GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-01-03 06:11:43
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.FBEO
Running: 3l9qymr9.exe; Driver: C:\Users\cubstuff\AppData\Local\Temp\kwdyrpog.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0x82B80D48]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0x82B80D72]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0x82B80D5E]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0x82B80D34]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwYieldExecution 82475982 5 Bytes JMP 82B80D38 \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 8263B143 5 Bytes JMP 82B80D76 \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 8265A89A 7 Bytes JMP 82B80D4C \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 8265AB5D 5 Bytes JMP 82B80D62 \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
? System32\drivers\auwmpdyg.sys The system cannot find the path specified. !
.text C:\Windows\system32\DRIVERS\tos_sps32.sys section is writeable [0x88353480, 0x3C939, 0xE8000020]
.dsrt C:\Windows\system32\DRIVERS\tos_sps32.sys unknown last section [0x88394900, 0x3CA, 0x48000040]
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\svchost.exe[752] ntdll.dll!NtCreateFile 77484224 5 Bytes JMP 0095000A
.text C:\Windows\system32\svchost.exe[752] ntdll.dll!NtCreateProcess 774842E4 5 Bytes JMP 00950036
.text C:\Windows\system32\svchost.exe[752] ntdll.dll!NtProtectVirtualMemory 77484B84 5 Bytes JMP 0095001B
.text C:\Windows\system32\svchost.exe[752] kernel32.dll!GetStartupInfoW 75AE1929 5 Bytes JMP 00730084
.text C:\Windows\system32\svchost.exe[752] kernel32.dll!GetStartupInfoA 75AE19C9 5 Bytes JMP 00730073
.text C:\Windows\system32\svchost.exe[752] kernel32.dll!CreateProcessW 75AE1BF3 5 Bytes JMP 007300B0
.text C:\Windows\system32\svchost.exe[752] kernel32.dll!CreateProcessA 75AE1C28 5 Bytes JMP 0073009F
.text C:\Windows\system32\svchost.exe[752] kernel32.dll!VirtualProtect 75AE1DC3 5 Bytes JMP 00730F7E
.text C:\Windows\system32\svchost.exe[752] kernel32.dll!CreateNamedPipeA 75AE2EF5 5 Bytes JMP 00730025
.text C:\Windows\system32\svchost.exe[752] kernel32.dll!CreateNamedPipeW 75AE5C0C 5 Bytes JMP 00730FD4
.text C:\Windows\system32\svchost.exe[752] kernel32.dll!CreatePipe 75B08F06 5 Bytes JMP 00730F52
.text C:\Windows\system32\svchost.exe[752] kernel32.dll!LoadLibraryExW 75B0927C 5 Bytes JMP 00730F9B
.text C:\Windows\system32\svchost.exe[752] kernel32.dll!LoadLibraryW 75B09400 5 Bytes JMP 00730047
.text C:\Windows\system32\svchost.exe[752] kernel32.dll!LoadLibraryExA 75B09554 1 Byte [E9]
.text C:\Windows\system32\svchost.exe[752] kernel32.dll!LoadLibraryExA 75B09554 5 Bytes JMP 00730058
.text C:\Windows\system32\svchost.exe[752] kernel32.dll!LoadLibraryA 75B0957C 5 Bytes JMP 00730036
.text C:\Windows\system32\svchost.exe[752] kernel32.dll!VirtualProtectEx 75B0DC52 5 Bytes JMP 00730F63
.text C:\Windows\system32\svchost.exe[752] kernel32.dll!GetProcAddress 75B2925B 5 Bytes JMP 007300CB
.text C:\Windows\system32\svchost.exe[752] kernel32.dll!CreateFileW 75B2B0EB 1 Byte [E9]
.text C:\Windows\system32\svchost.exe[752] kernel32.dll!CreateFileW 75B2B0EB 5 Bytes JMP 00730FEF
.text C:\Windows\system32\svchost.exe[752] kernel32.dll!CreateFileA 75B2D07F 5 Bytes JMP 00730000
.text C:\Windows\system32\svchost.exe[752] kernel32.dll!WinExec 75B760CF 5 Bytes JMP 00730F23
.text C:\Windows\system32\svchost.exe[752] msvcrt.dll!_wsystem 77627F2F 5 Bytes JMP 00D00FA1
.text C:\Windows\system32\svchost.exe[752] msvcrt.dll!system 7762804B 5 Bytes JMP 00D0002C
.text C:\Windows\system32\svchost.exe[752] msvcrt.dll!_creat 7762BBE1 5 Bytes JMP 00D00FCD
.text C:\Windows\system32\svchost.exe[752] msvcrt.dll!_open 7762D106 5 Bytes JMP 00D00000
.text C:\Windows\system32\svchost.exe[752] msvcrt.dll!_wcreat 7762D326 5 Bytes JMP 00D00FBC
.text C:\Windows\system32\svchost.exe[752] msvcrt.dll!_wopen 7762D501 5 Bytes JMP 00D00011
.text C:\Windows\system32\svchost.exe[752] ADVAPI32.dll!RegCreateKeyExA 75D539AB 5 Bytes JMP 00940051
.text C:\Windows\system32\svchost.exe[752] ADVAPI32.dll!RegCreateKeyA 75D53BA9 5 Bytes JMP 00940025
.text C:\Windows\system32\svchost.exe[752] ADVAPI32.dll!RegOpenKeyA 75D589C7 5 Bytes JMP 00940FE5
.text C:\Windows\system32\svchost.exe[752] ADVAPI32.dll!RegCreateKeyW 75D6391E 5 Bytes JMP 00940040
.text C:\Windows\system32\svchost.exe[752] ADVAPI32.dll!RegCreateKeyExW 75D641F1 5 Bytes JMP 00940062
.text C:\Windows\system32\svchost.exe[752] ADVAPI32.dll!RegOpenKeyExA 75D67C42 5 Bytes JMP 00940014
.text C:\Windows\system32\svchost.exe[752] ADVAPI32.dll!RegOpenKeyW 75D6E2B5 5 Bytes JMP 00940FD4
.text C:\Windows\system32\svchost.exe[752] ADVAPI32.dll!RegOpenKeyExW 75D77BA1 5 Bytes JMP 00940FC3
.text C:\Windows\system32\svchost.exe[752] WS2_32.dll!socket 775A36D1 5 Bytes JMP 00CF0FE5
.text C:\Windows\System32\svchost.exe[776] ntdll.dll!NtCreateFile 77484224 5 Bytes JMP 005A0FE5
.text C:\Windows\System32\svchost.exe[776] ntdll.dll!NtCreateProcess 774842E4 5 Bytes JMP 005A0FAF
.text C:\Windows\System32\svchost.exe[776] ntdll.dll!NtProtectVirtualMemory 77484B84 5 Bytes JMP 005A0FD4
.text C:\Windows\System32\svchost.exe[776] kernel32.dll!GetStartupInfoW 75AE1929 5 Bytes JMP 002D00C1
.text C:\Windows\System32\svchost.exe[776] kernel32.dll!GetStartupInfoA 75AE19C9 5 Bytes JMP 002D0F85
.text C:\Windows\System32\svchost.exe[776] kernel32.dll!CreateProcessW 75AE1BF3 5 Bytes JMP 002D0F45
.text C:\Windows\System32\svchost.exe[776] kernel32.dll!CreateProcessA 75AE1C28 5 Bytes JMP 002D0F56
.text C:\Windows\System32\svchost.exe[776] kernel32.dll!VirtualProtect 75AE1DC3 5 Bytes JMP 002D0FA0
.text C:\Windows\System32\svchost.exe[776] kernel32.dll!CreateNamedPipeA 75AE2EF5 5 Bytes JMP 002D001B
.text C:\Windows\System32\svchost.exe[776] kernel32.dll!CreateNamedPipeW 75AE5C0C 5 Bytes JMP 002D0036
.text C:\Windows\System32\svchost.exe[776] kernel32.dll!CreatePipe 75B08F06 5 Bytes JMP 002D00B0
.text C:\Windows\System32\svchost.exe[776] kernel32.dll!LoadLibraryExW 75B0927C 5 Bytes JMP 002D007A
.text C:\Windows\System32\svchost.exe[776] kernel32.dll!LoadLibraryW 75B09400 5 Bytes JMP 002D0058
.text C:\Windows\System32\svchost.exe[776] kernel32.dll!LoadLibraryExA 75B09554 5 Bytes JMP 002D0069
.text C:\Windows\System32\svchost.exe[776] kernel32.dll!LoadLibraryA 75B0957C 5 Bytes JMP 002D0047
.text C:\Windows\System32\svchost.exe[776] kernel32.dll!VirtualProtectEx 75B0DC52 5 Bytes JMP 002D0095
.text C:\Windows\System32\svchost.exe[776] kernel32.dll!GetProcAddress 75B2925B 5 Bytes JMP 002D0F34
.text C:\Windows\System32\svchost.exe[776] kernel32.dll!CreateFileW 75B2B0EB 5 Bytes JMP 002D000A
.text C:\Windows\System32\svchost.exe[776] kernel32.dll!CreateFileA 75B2D07F 5 Bytes JMP 002D0FEF
.text C:\Windows\System32\svchost.exe[776] kernel32.dll!WinExec 75B760CF 5 Bytes JMP 002D00D2
.text C:\Windows\System32\svchost.exe[776] msvcrt.dll!_wsystem 77627F2F 5 Bytes JMP 005B0F9C
.text C:\Windows\System32\svchost.exe[776] msvcrt.dll!system 7762804B 5 Bytes JMP 005B0FB7
.text C:\Windows\System32\svchost.exe[776] msvcrt.dll!_creat 7762BBE1 5 Bytes JMP 005B0FE3
.text C:\Windows\System32\svchost.exe[776] msvcrt.dll!_open 7762D106 5 Bytes JMP 005B000C
.text C:\Windows\System32\svchost.exe[776] msvcrt.dll!_wcreat 7762D326 5 Bytes JMP 005B0FC8
.text C:\Windows\System32\svchost.exe[776] msvcrt.dll!_wopen 7762D501 5 Bytes JMP 005B001D
.text C:\Windows\System32\svchost.exe[776] ADVAPI32.dll!RegCreateKeyExA 75D539AB 5 Bytes JMP 002E0076
.text C:\Windows\System32\svchost.exe[776] ADVAPI32.dll!RegCreateKeyA 75D53BA9 5 Bytes JMP 002E0040
.text C:\Windows\System32\svchost.exe[776] ADVAPI32.dll!RegOpenKeyA 75D589C7 5 Bytes JMP 002E0000
.text C:\Windows\System32\svchost.exe[776] ADVAPI32.dll!RegCreateKeyW 75D6391E 5 Bytes JMP 002E0065
.text C:\Windows\System32\svchost.exe[776] ADVAPI32.dll!RegCreateKeyExW 75D641F1 5 Bytes JMP 002E0FB9
.text C:\Windows\System32\svchost.exe[776] ADVAPI32.dll!RegOpenKeyExA 75D67C42 5 Bytes JMP 002E0FE5
.text C:\Windows\System32\svchost.exe[776] ADVAPI32.dll!RegOpenKeyW 75D6E2B5 5 Bytes JMP 002E001B
.text C:\Windows\System32\svchost.exe[776] ADVAPI32.dll!RegOpenKeyExW 75D77BA1 5 Bytes JMP 002E0FD4
.text C:\Windows\system32\services.exe[784] ntdll.dll!NtCreateFile 77484224 5 Bytes JMP 00320FEF
.text C:\Windows\system32\services.exe[784] ntdll.dll!NtCreateProcess 774842E4 5 Bytes JMP 00320FC3
.text C:\Windows\system32\services.exe[784] ntdll.dll!NtProtectVirtualMemory 77484B84 5 Bytes JMP 00320FD4
.text C:\Windows\system32\services.exe[784] kernel32.dll!GetStartupInfoW 75AE1929 5 Bytes JMP 00310F6D
.text C:\Windows\system32\services.exe[784] kernel32.dll!GetStartupInfoA 75AE19C9 5 Bytes JMP 003100BD
.text C:\Windows\system32\services.exe[784] kernel32.dll!CreateProcessW 75AE1BF3 5 Bytes JMP 00310F4B
.text C:\Windows\system32\services.exe[784] kernel32.dll!CreateProcessA 75AE1C28 5 Bytes JMP 00310F5C
.text C:\Windows\system32\services.exe[784] kernel32.dll!VirtualProtect 75AE1DC3 5 Bytes JMP 00310F9C
.text C:\Windows\system32\services.exe[784] kernel32.dll!CreateNamedPipeA 75AE2EF5 5 Bytes JMP 0031000A
.text C:\Windows\system32\services.exe[784] kernel32.dll!CreateNamedPipeW 75AE5C0C 5 Bytes JMP 00310FB9
.text C:\Windows\system32\services.exe[784] kernel32.dll!CreatePipe 75B08F06 5 Bytes JMP 003100A2
.text C:\Windows\system32\services.exe[784] kernel32.dll!LoadLibraryExW 75B0927C 5 Bytes JMP 00310076
.text C:\Windows\system32\services.exe[784] kernel32.dll!LoadLibraryW 75B09400 5 Bytes JMP 0031004A
.text C:\Windows\system32\services.exe[784] kernel32.dll!LoadLibraryExA 75B09554 5 Bytes JMP 0031005B
.text C:\Windows\system32\services.exe[784] kernel32.dll!LoadLibraryA 75B0957C 5 Bytes JMP 0031002F
.text C:\Windows\system32\services.exe[784] kernel32.dll!VirtualProtectEx 75B0DC52 5 Bytes JMP 00310091
.text C:\Windows\system32\services.exe[784] kernel32.dll!GetProcAddress 75B2925B 5 Bytes JMP 00310F30
.text C:\Windows\system32\services.exe[784] kernel32.dll!CreateFileW 75B2B0EB 5 Bytes JMP 00310FD4
.text C:\Windows\system32\services.exe[784] kernel32.dll!CreateFileA 75B2D07F 5 Bytes JMP 00310FE5
.text C:\Windows\system32\services.exe[784] kernel32.dll!WinExec 75B760CF 5 Bytes JMP 003100CE
.text C:\Windows\system32\services.exe[784] ADVAPI32.dll!RegCreateKeyExA 75D539AB 5 Bytes JMP 00330040
.text C:\Windows\system32\services.exe[784] ADVAPI32.dll!RegCreateKeyA 75D53BA9 5 Bytes JMP 00330F9E
.text C:\Windows\system32\services.exe[784] ADVAPI32.dll!RegOpenKeyA 75D589C7 5 Bytes JMP 00330FEF
.text C:\Windows\system32\services.exe[784] ADVAPI32.dll!RegCreateKeyW 75D6391E 5 Bytes JMP 00330025
.text C:\Windows\system32\services.exe[784] ADVAPI32.dll!RegCreateKeyExW 75D641F1 5 Bytes JMP 00330051
.text C:\Windows\system32\services.exe[784] ADVAPI32.dll!RegOpenKeyExA 75D67C42 5 Bytes JMP 00330FB9
.text C:\Windows\system32\services.exe[784] ADVAPI32.dll!RegOpenKeyW 75D6E2B5 5 Bytes JMP 00330FD4
.text C:\Windows\system32\services.exe[784] ADVAPI32.dll!RegOpenKeyExW 75D77BA1 5 Bytes JMP 0033000A
.text C:\Windows\system32\services.exe[784] msvcrt.dll!_wsystem 77627F2F 5 Bytes JMP 00360029
.text C:\Windows\system32\services.exe[784] msvcrt.dll!system 7762804B 5 Bytes JMP 00360FA8
.text C:\Windows\system32\services.exe[784] msvcrt.dll!_creat 7762BBE1 5 Bytes JMP 00360FDE
.text C:\Windows\system32\services.exe[784] msvcrt.dll!_open 7762D106 5 Bytes JMP 00360FEF
.text C:\Windows\system32\services.exe[784] msvcrt.dll!_wcreat 7762D326 5 Bytes JMP 00360FB9
.text C:\Windows\system32\services.exe[784] msvcrt.dll!_wopen 7762D501 5 Bytes JMP 00360018
.text C:\Windows\system32\services.exe[784] WS2_32.dll!socket 775A36D1 5 Bytes JMP 00350000
.text C:\Windows\system32\services.exe[784] WININET.dll!InternetOpenA 75E34E3C 5 Bytes JMP 00340000
.text C:\Windows\system32\services.exe[784] WININET.dll!InternetOpenUrlA 75E3BFDE 5 Bytes JMP 00340FDB
.text C:\Windows\system32\services.exe[784] WININET.dll!InternetOpenW 75E6C126 5 Bytes JMP 00340011
.text C:\Windows\system32\services.exe[784] WININET.dll!InternetOpenUrlW 75E9D8D2 5 Bytes JMP 00340FCA
.text C:\Windows\system32\lsass.exe[796] ntdll.dll!NtCreateFile 77484224 5 Bytes JMP 001F0000
.text C:\Windows\system32\lsass.exe[796] ntdll.dll!NtCreateProcess 774842E4 5 Bytes JMP 001F002C
.text C:\Windows\system32\lsass.exe[796] ntdll.dll!NtProtectVirtualMemory 77484B84 5 Bytes JMP 001F001B
.text C:\Windows\system32\lsass.exe[796] kernel32.dll!GetStartupInfoW 75AE1929 5 Bytes JMP 001E0F50
.text C:\Windows\system32\lsass.exe[796] kernel32.dll!GetStartupInfoA 75AE19C9 5 Bytes JMP 001E0F61
.text C:\Windows\system32\lsass.exe[796] kernel32.dll!CreateProcessW 75AE1BF3 5 Bytes JMP 001E0F2E
.text C:\Windows\system32\lsass.exe[796] kernel32.dll!CreateProcessA 75AE1C28 5 Bytes JMP 001E0F3F
.text C:\Windows\system32\lsass.exe[796] kernel32.dll!VirtualProtect 75AE1DC3 5 Bytes JMP 001E0F94
.text C:\Windows\system32\lsass.exe[796] kernel32.dll!CreateNamedPipeA 75AE2EF5 5 Bytes JMP 001E001B
.text C:\Windows\system32\lsass.exe[796] kernel32.dll!CreateNamedPipeW 75AE5C0C 5 Bytes JMP 001E0FCA
.text C:\Windows\system32\lsass.exe[796] kernel32.dll!CreatePipe 75B08F06 5 Bytes JMP 001E0F72
.text C:\Windows\system32\lsass.exe[796] kernel32.dll!LoadLibraryExW 75B0927C 5 Bytes JMP 001E0FAF
.text C:\Windows\system32\lsass.exe[796] kernel32.dll!LoadLibraryW 75B09400 5 Bytes JMP 001E005B
.text C:\Windows\system32\lsass.exe[796] kernel32.dll!LoadLibraryExA 75B09554 5 Bytes JMP 001E006C
.text C:\Windows\system32\lsass.exe[796] kernel32.dll!LoadLibraryA 75B0957C 5 Bytes JMP 001E0036
.text C:\Windows\system32\lsass.exe[796] kernel32.dll!VirtualProtectEx 75B0DC52 5 Bytes JMP 001E0F83
.text C:\Windows\system32\lsass.exe[796] kernel32.dll!GetProcAddress 75B2925B 5 Bytes JMP 001E0F1D
.text C:\Windows\system32\lsass.exe[796] kernel32.dll!CreateFileW 75B2B0EB 5 Bytes JMP 001E0000
.text C:\Windows\system32\lsass.exe[796] kernel32.dll!CreateFileA 75B2D07F 5 Bytes JMP 001E0FEF
.text C:\Windows\system32\lsass.exe[796] kernel32.dll!WinExec 75B760CF 5 Bytes JMP 001E00B1
.text C:\Windows\system32\lsass.exe[796] ADVAPI32.dll!RegCreateKeyExA 75D539AB 1 Byte [E9]
.text C:\Windows\system32\lsass.exe[796] ADVAPI32.dll!RegCreateKeyExA 75D539AB 5 Bytes JMP 00200FAF
.text C:\Windows\system32\lsass.exe[796] ADVAPI32.dll!RegCreateKeyA 75D53BA9 5 Bytes JMP 00200040
.text C:\Windows\system32\lsass.exe[796] ADVAPI32.dll!RegOpenKeyA 75D589C7 5 Bytes JMP 00200FEF
.text C:\Windows\system32\lsass.exe[796] ADVAPI32.dll!RegCreateKeyW 75D6391E 5 Bytes JMP 00200051
.text C:\Windows\system32\lsass.exe[796] ADVAPI32.dll!RegCreateKeyExW 75D641F1 5 Bytes JMP 00200F94
.text C:\Windows\system32\lsass.exe[796] ADVAPI32.dll!RegOpenKeyExA 75D67C42 5 Bytes JMP 0020001B
.text C:\Windows\system32\lsass.exe[796] ADVAPI32.dll!RegOpenKeyW 75D6E2B5 5 Bytes JMP 0020000A
.text C:\Windows\system32\lsass.exe[796] ADVAPI32.dll!RegOpenKeyExW 75D77BA1 5 Bytes JMP 00200FCA
.text C:\Windows\system32\lsass.exe[796] msvcrt.dll!_wsystem 77627F2F 5 Bytes JMP 00950053
.text C:\Windows\system32\lsass.exe[796] msvcrt.dll!system 7762804B 5 Bytes JMP 00950042
.text C:\Windows\system32\lsass.exe[796] msvcrt.dll!_creat 7762BBE1 5 Bytes JMP 00950FD2
.text C:\Windows\system32\lsass.exe[796] msvcrt.dll!_open 7762D106 5 Bytes JMP 00950FEF
.text C:\Windows\system32\lsass.exe[796] msvcrt.dll!_wcreat 7762D326 5 Bytes JMP 00950027
.text C:\Windows\system32\lsass.exe[796] msvcrt.dll!_wopen 7762D501 5 Bytes JMP 0095000C
.text C:\Windows\system32\lsass.exe[796] WS2_32.dll!socket 775A36D1 5 Bytes JMP 00940FE5
.text C:\Windows\system32\lsass.exe[796] WININET.dll!InternetOpenA 75E34E3C 5 Bytes JMP 00540000
.text C:\Windows\system32\lsass.exe[796] WININET.dll!InternetOpenUrlA 75E3BFDE 5 Bytes JMP 00540025
.text C:\Windows\system32\lsass.exe[796] WININET.dll!InternetOpenW 75E6C126 5 Bytes JMP 00540FE5
.text C:\Windows\system32\lsass.exe[796] WININET.dll!InternetOpenUrlW 75E9D8D2 5 Bytes JMP 00540FD4
.text C:\Windows\system32\svchost.exe[996] ntdll.dll!NtCreateFile 77484224 5 Bytes JMP 001D0FEF
.text C:\Windows\system32\svchost.exe[996] ntdll.dll!NtCreateProcess 774842E4 5 Bytes JMP 001D0FCA
.text C:\Windows\system32\svchost.exe[996] ntdll.dll!NtProtectVirtualMemory 77484B84 5 Bytes JMP 001D0000
.text C:\Windows\system32\svchost.exe[996] kernel32.dll!GetStartupInfoW 75AE1929 5 Bytes JMP 001C007D
.text C:\Windows\system32\svchost.exe[996] kernel32.dll!GetStartupInfoA 75AE19C9 5 Bytes JMP 001C0062
.text C:\Windows\system32\svchost.exe[996] kernel32.dll!CreateProcessW 75AE1BF3 5 Bytes JMP 001C0F01
.text C:\Windows\system32\svchost.exe[996] kernel32.dll!CreateProcessA 75AE1C28 5 Bytes JMP 001C0F1C
.text C:\Windows\system32\svchost.exe[996] kernel32.dll!VirtualProtect 75AE1DC3 5 Bytes JMP 001C0F41
.text C:\Windows\system32\svchost.exe[996] kernel32.dll!CreateNamedPipeA 75AE2EF5 5 Bytes JMP 001C0000
.text C:\Windows\system32\svchost.exe[996] kernel32.dll!CreateNamedPipeW 75AE5C0C 5 Bytes JMP 001C0FAF
.text C:\Windows\system32\svchost.exe[996] kernel32.dll!CreatePipe 75B08F06 5 Bytes JMP 001C0051
.text C:\Windows\system32\svchost.exe[996] kernel32.dll!LoadLibraryExW 75B0927C 5 Bytes JMP 001C0F68
.text C:\Windows\system32\svchost.exe[996] kernel32.dll!LoadLibraryW 75B09400 5 Bytes JMP 001C0F83
.text C:\Windows\system32\svchost.exe[996] kernel32.dll!LoadLibraryExA 75B09554 5 Bytes JMP 001C0025
.text C:\Windows\system32\svchost.exe[996] kernel32.dll!LoadLibraryA 75B0957C 5 Bytes JMP 001C0F94
.text C:\Windows\system32\svchost.exe[996] kernel32.dll!VirtualProtectEx 75B0DC52 5 Bytes JMP 001C0036
.text C:\Windows\system32\svchost.exe[996] kernel32.dll!GetProcAddress 75B2925B 5 Bytes JMP 001C0EF0
.text C:\Windows\system32\svchost.exe[996] kernel32.dll!CreateFileW 75B2B0EB 5 Bytes JMP 001C0FD4
.text C:\Windows\system32\svchost.exe[996] kernel32.dll!CreateFileA 75B2D07F 5 Bytes JMP 001C0FEF
.text C:\Windows\system32\svchost.exe[996] kernel32.dll!WinExec 75B760CF 5 Bytes JMP 001C0098
.text C:\Windows\system32\svchost.exe[996] msvcrt.dll!_wsystem 77627F2F 5 Bytes JMP 002C0038
.text C:\Windows\system32\svchost.exe[996] msvcrt.dll!system 7762804B 5 Bytes JMP 002C0027
.text C:\Windows\system32\svchost.exe[996] msvcrt.dll!_creat 7762BBE1 5 Bytes JMP 002C0FD2
.text C:\Windows\system32\svchost.exe[996] msvcrt.dll!_open 7762D106 5 Bytes JMP 002C0FEF
.text C:\Windows\system32\svchost.exe[996] msvcrt.dll!_wcreat 7762D326 5 Bytes JMP 002C0FB7
.text C:\Windows\system32\svchost.exe[996] msvcrt.dll!_wopen 7762D501 5 Bytes JMP 002C000C
.text C:\Windows\system32\svchost.exe[996] ADVAPI32.dll!RegCreateKeyExA 75D539AB 5 Bytes JMP 001E006C
.text C:\Windows\system32\svchost.exe[996] ADVAPI32.dll!RegCreateKeyA 75D53BA9 5 Bytes JMP 001E0FD4
.text C:\Windows\system32\svchost.exe[996] ADVAPI32.dll!RegOpenKeyA 75D589C7 5 Bytes JMP 001E0FE5
.text C:\Windows\system32\svchost.exe[996] ADVAPI32.dll!RegCreateKeyW 75D6391E 5 Bytes JMP 001E0051
.text C:\Windows\system32\svchost.exe[996] ADVAPI32.dll!RegCreateKeyExW 75D641F1 5 Bytes JMP 001E007D
.text C:\Windows\system32\svchost.exe[996] ADVAPI32.dll!RegOpenKeyExA 75D67C42 5 Bytes JMP 001E001B
.text C:\Windows\system32\svchost.exe[996] ADVAPI32.dll!RegOpenKeyW 75D6E2B5 5 Bytes JMP 001E000A
.text C:\Windows\system32\svchost.exe[996] ADVAPI32.dll!RegOpenKeyExW 75D77BA1 5 Bytes JMP 001E0040
.text C:\Windows\system32\svchost.exe[996] WS2_32.dll!socket 775A36D1 5 Bytes JMP 002B000A
.text C:\Windows\system32\svchost.exe[1092] ntdll.dll!NtCreateFile 77484224 5 Bytes JMP 00750FEF
.text C:\Windows\system32\svchost.exe[1092] ntdll.dll!NtCreateProcess 774842E4 5 Bytes JMP 00750FCA
.text C:\Windows\system32\svchost.exe[1092] ntdll.dll!NtProtectVirtualMemory 77484B84 5 Bytes JMP 0075000A
.text C:\Windows\system32\svchost.exe[1092] kernel32.dll!GetStartupInfoW 75AE1929 5 Bytes JMP 00740087
.text C:\Windows\system32\svchost.exe[1092] kernel32.dll!GetStartupInfoA 75AE19C9 5 Bytes JMP 00740076
.text C:\Windows\system32\svchost.exe[1092] kernel32.dll!CreateProcessW 75AE1BF3 5 Bytes JMP 007400B3
.text C:\Windows\system32\svchost.exe[1092] kernel32.dll!CreateProcessA 75AE1C28 5 Bytes JMP 00740F1C
.text C:\Windows\system32\svchost.exe[1092] kernel32.dll!VirtualProtect 75AE1DC3 5 Bytes JMP 00740F6D
.text C:\Windows\system32\svchost.exe[1092] kernel32.dll!CreateNamedPipeA 75AE2EF5 5 Bytes JMP 0074000A
.text C:\Windows\system32\svchost.exe[1092] kernel32.dll!CreateNamedPipeW 75AE5C0C 5 Bytes JMP 00740FB9
.text C:\Windows\system32\svchost.exe[1092] kernel32.dll!CreatePipe 75B08F06 5 Bytes JMP 00740F41
.text C:\Windows\system32\svchost.exe[1092] kernel32.dll!LoadLibraryExW 75B0927C 5 Bytes JMP 00740051
.text C:\Windows\system32\svchost.exe[1092] kernel32.dll!LoadLibraryW 75B09400 5 Bytes JMP 0074001B
.text C:\Windows\system32\svchost.exe[1092] kernel32.dll!LoadLibraryExA 75B09554 5 Bytes JMP 00740036
.text C:\Windows\system32\svchost.exe[1092] kernel32.dll!LoadLibraryA 75B0957C 5 Bytes JMP 00740F9E
.text C:\Windows\system32\svchost.exe[1092] kernel32.dll!VirtualProtectEx 75B0DC52 5 Bytes JMP 00740F5C
.text C:\Windows\system32\svchost.exe[1092] kernel32.dll!GetProcAddress 75B2925B 5 Bytes JMP 007400D8
.text C:\Windows\system32\svchost.exe[1092] kernel32.dll!CreateFileW 75B2B0EB 5 Bytes JMP 00740FD4
.text C:\Windows\system32\svchost.exe[1092] kernel32.dll!CreateFileA 75B2D07F 5 Bytes JMP 00740FE5
.text C:\Windows\system32\svchost.exe[1092] kernel32.dll!WinExec 75B760CF 5 Bytes JMP 00740098
.text C:\Windows\system32\svchost.exe[1092] msvcrt.dll!_wsystem 77627F2F 5 Bytes JMP 00A8002F
.text C:\Windows\system32\svchost.exe[1092] msvcrt.dll!system 7762804B 5 Bytes JMP 00A80F9A
.text C:\Windows\system32\svchost.exe[1092] msvcrt.dll!_creat 7762BBE1 5 Bytes JMP 00A80FC6
.text C:\Windows\system32\svchost.exe[1092] msvcrt.dll!_open 7762D106 5 Bytes JMP 00A80000
.text C:\Windows\system32\svchost.exe[1092] msvcrt.dll!_wcreat 7762D326 5 Bytes JMP 00A80FB5
.text C:\Windows\system32\svchost.exe[1092] msvcrt.dll!_wopen 7762D501 5 Bytes JMP 00A80FE3
.text C:\Windows\system32\svchost.exe[1092] ADVAPI32.dll!RegCreateKeyExA 75D539AB 5 Bytes JMP 00760062
.text C:\Windows\system32\svchost.exe[1092] ADVAPI32.dll!RegCreateKeyA 75D53BA9 5 Bytes JMP 00760FCA
.text C:\Windows\system32\svchost.exe[1092] ADVAPI32.dll!RegOpenKeyA 75D589C7 5 Bytes JMP 00760FEF
.text C:\Windows\system32\svchost.exe[1092] ADVAPI32.dll!RegCreateKeyW 75D6391E 5 Bytes JMP 00760051
.text C:\Windows\system32\svchost.exe[1092] ADVAPI32.dll!RegCreateKeyExW 75D641F1 5 Bytes JMP 00760073
.text C:\Windows\system32\svchost.exe[1092] ADVAPI32.dll!RegOpenKeyExA 75D67C42 5 Bytes JMP 00760011
.text C:\Windows\system32\svchost.exe[1092] ADVAPI32.dll!RegOpenKeyW 75D6E2B5 5 Bytes JMP 00760000
.text C:\Windows\system32\svchost.exe[1092] ADVAPI32.dll!RegOpenKeyExW 75D77BA1 5 Bytes JMP 0076002C
.text C:\Windows\system32\svchost.exe[1092] WS2_32.dll!socket 775A36D1 5 Bytes JMP 00A70000
.text C:\Windows\system32\svchost.exe[1092] WININET.dll!InternetOpenA 75E34E3C 5 Bytes JMP 00770000
.text C:\Windows\system32\svchost.exe[1092] WININET.dll!InternetOpenUrlA 75E3BFDE 5 Bytes JMP 00770025
.text C:\Windows\system32\svchost.exe[1092] WININET.dll!InternetOpenW 75E6C126 5 Bytes JMP 00770FE5
.text C:\Windows\system32\svchost.exe[1092] WININET.dll!InternetOpenUrlW 75E9D8D2 5 Bytes JMP 00770040
.text C:\Windows\System32\svchost.exe[1128] ntdll.dll!NtCreateFile 77484224 5 Bytes JMP 00FE0000
.text C:\Windows\System32\svchost.exe[1128] ntdll.dll!NtCreateProcess 774842E4 5 Bytes JMP 00FE0FCA
.text C:\Windows\System32\svchost.exe[1128] ntdll.dll!NtProtectVirtualMemory 77484B84 5 Bytes JMP 00FE0FE5
.text C:\Windows\System32\svchost.exe[1128] kernel32.dll!GetStartupInfoW 75AE1929 5 Bytes JMP 00B200A4
.text C:\Windows\System32\svchost.exe[1128] kernel32.dll!GetStartupInfoA 75AE19C9 5 Bytes JMP 00B20089
.text C:\Windows\System32\svchost.exe[1128] kernel32.dll!CreateProcessW 75AE1BF3 5 Bytes JMP 00B20F28
.text C:\Windows\System32\svchost.exe[1128] kernel32.dll!CreateProcessA 75AE1C28 5 Bytes JMP 00B20F39
.text C:\Windows\System32\svchost.exe[1128] kernel32.dll!VirtualProtect 75AE1DC3 5 Bytes JMP 00B20064
.text C:\Windows\System32\svchost.exe[1128] kernel32.dll!CreateNamedPipeA 75AE2EF5 5 Bytes JMP 00B20011
.text C:\Windows\System32\svchost.exe[1128] kernel32.dll!CreateNamedPipeW 75AE5C0C 5 Bytes JMP 00B20FB6
.text C:\Windows\System32\svchost.exe[1128] kernel32.dll!CreatePipe 75B08F06 5 Bytes JMP 00B20F54
.text C:\Windows\System32\svchost.exe[1128] kernel32.dll!LoadLibraryExW 75B0927C 5 Bytes JMP 00B20F80
.text C:\Windows\System32\svchost.exe[1128] kernel32.dll!LoadLibraryW 75B09400 5 Bytes JMP 00B20F9B
.text C:\Windows\System32\svchost.exe[1128] kernel32.dll!LoadLibraryExA 75B09554 5 Bytes JMP 00B20033
.text C:\Windows\System32\svchost.exe[1128] kernel32.dll!LoadLibraryA 75B0957C 5 Bytes JMP 00B20022
.text C:\Windows\System32\svchost.exe[1128] kernel32.dll!VirtualProtectEx 75B0DC52 5 Bytes JMP 00B20F6F
.text C:\Windows\System32\svchost.exe[1128] kernel32.dll!GetProcAddress 75B2925B 5 Bytes JMP 00B200DA
.text C:\Windows\System32\svchost.exe[1128] kernel32.dll!CreateFileW 75B2B0EB 5 Bytes JMP 00B20000
.text C:\Windows\System32\svchost.exe[1128] kernel32.dll!CreateFileA 75B2D07F 5 Bytes JMP 00B20FE5
.text C:\Windows\System32\svchost.exe[1128] kernel32.dll!WinExec 75B760CF 5 Bytes JMP 00B200B5
.text C:\Windows\System32\svchost.exe[1128] msvcrt.dll!_wsystem 77627F2F 5 Bytes JMP 01FA003B
.text C:\Windows\System32\svchost.exe[1128] msvcrt.dll!system 7762804B 5 Bytes JMP 01FA0020
.text C:\Windows\System32\svchost.exe[1128] msvcrt.dll!_creat 7762BBE1 5 Bytes JMP 01FA0FC1
.text C:\Windows\System32\svchost.exe[1128] msvcrt.dll!_open 7762D106 5 Bytes JMP 01FA0FEF
.text C:\Windows\System32\svchost.exe[1128] msvcrt.dll!_wcreat 7762D326 5 Bytes JMP 01FA0FA6
.text C:\Windows\System32\svchost.exe[1128] msvcrt.dll!_wopen 7762D501 5 Bytes JMP 01FA0FD2
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!RegCreateKeyExA 75D539AB 5 Bytes JMP 00FF004A
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!RegCreateKeyA 75D53BA9 5 Bytes JMP 00FF0FCD
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!RegOpenKeyA 75D589C7 5 Bytes JMP 00FF000A
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!RegCreateKeyW 75D6391E 5 Bytes JMP 00FF0FA8
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!RegCreateKeyExW 75D641F1 5 Bytes JMP 00FF005B
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!RegOpenKeyExA 75D67C42 5 Bytes JMP 00FF0FEF
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!RegOpenKeyW 75D6E2B5 5 Bytes JMP 00FF001B
.text C:\Windows\System32\svchost.exe[1128] ADVAPI32.dll!RegOpenKeyExW 75D77BA1 5 Bytes JMP 00FF0FDE
.text C:\Windows\System32\svchost.exe[1128] WS2_32.dll!socket 775A36D1 5 Bytes JMP 01F90000
.text C:\Windows\System32\svchost.exe[1128] WININET.dll!InternetOpenA 75E34E3C 5 Bytes JMP 01F00FEF
.text C:\Windows\System32\svchost.exe[1128] WININET.dll!InternetOpenUrlA 75E3BFDE 5 Bytes JMP 01F00FB9
.text C:\Windows\System32\svchost.exe[1128] WININET.dll!InternetOpenW 75E6C126 5 Bytes JMP 01F00FCA
.text C:\Windows\System32\svchost.exe[1128] WININET.dll!InternetOpenUrlW 75E9D8D2 5 Bytes JMP 01F00000
.text C:\Windows\System32\svchost.exe[1232] ntdll.dll!NtCreateFile 77484224 5 Bytes JMP 01020FE5
.text C:\Windows\System32\svchost.exe[1232] ntdll.dll!NtCreateProcess 774842E4 5 Bytes JMP 01020011
.text C:\Windows\System32\svchost.exe[1232] ntdll.dll!NtProtectVirtualMemory 77484B84 5 Bytes JMP 01020000
.text C:\Windows\System32\svchost.exe[1232] kernel32.dll!GetStartupInfoW 75AE1929 5 Bytes JMP 00D5007D
.text C:\Windows\System32\svchost.exe[1232] kernel32.dll!GetStartupInfoA 75AE19C9 5 Bytes JMP 00D5006C
.text C:\Windows\System32\svchost.exe[1232] kernel32.dll!CreateProcessW 75AE1BF3 5 Bytes JMP 00D50F12
.text C:\Windows\System32\svchost.exe[1232] kernel32.dll!CreateProcessA 75AE1C28 5 Bytes JMP 00D500A9
.text C:\Windows\System32\svchost.exe[1232] kernel32.dll!VirtualProtect 75AE1DC3 5 Bytes JMP 00D50F5C
.text C:\Windows\System32\svchost.exe[1232] kernel32.dll!CreateNamedPipeA 75AE2EF5 5 Bytes JMP 00D50FD4
.text C:\Windows\System32\svchost.exe[1232] kernel32.dll!CreateNamedPipeW 75AE5C0C 5 Bytes JMP 00D50FB9
.text C:\Windows\System32\svchost.exe[1232] kernel32.dll!CreatePipe 75B08F06 5 Bytes JMP 00D50051
.text C:\Windows\System32\svchost.exe[1232] kernel32.dll!LoadLibraryExW 75B0927C 5 Bytes JMP 00D50040
.text C:\Windows\System32\svchost.exe[1232] kernel32.dll!LoadLibraryW 75B09400 5 Bytes JMP 00D50F8D
.text C:\Windows\System32\svchost.exe[1232] kernel32.dll!LoadLibraryExA 75B09554 5 Bytes JMP 00D50025
.text C:\Windows\System32\svchost.exe[1232] kernel32.dll!LoadLibraryA 75B0957C 5 Bytes JMP 00D50FA8
.text C:\Windows\System32\svchost.exe[1232] kernel32.dll!VirtualProtectEx 75B0DC52 5 Bytes JMP 00D50F4B
.text C:\Windows\System32\svchost.exe[1232] kernel32.dll!GetProcAddress 75B2925B 5 Bytes JMP 00D50F01
.text C:\Windows\System32\svchost.exe[1232] kernel32.dll!CreateFileW 75B2B0EB 5 Bytes JMP 00D5000A
.text C:\Windows\System32\svchost.exe[1232] kernel32.dll!CreateFileA 75B2D07F 5 Bytes JMP 00D50FEF
.text C:\Windows\System32\svchost.exe[1232] kernel32.dll!WinExec 75B760CF 5 Bytes JMP 00D5008E
.text C:\Windows\System32\svchost.exe[1232] msvcrt.dll!_wsystem 77627F2F 5 Bytes JMP 0160005D
.text C:\Windows\System32\svchost.exe[1232] msvcrt.dll!system 7762804B 5 Bytes JMP 0160004C
.text C:\Windows\System32\svchost.exe[1232] msvcrt.dll!_creat 7762BBE1 5 Bytes JMP 01600027
.text C:\Windows\System32\svchost.exe[1232] msvcrt.dll!_open 7762D106 5 Bytes JMP 01600000
.text C:\Windows\System32\svchost.exe[1232] msvcrt.dll!_wcreat 7762D326 5 Bytes JMP 01600FD2
.text C:\Windows\System32\svchost.exe[1232] msvcrt.dll!_wopen 7762D501 5 Bytes JMP 01600FEF
.text C:\Windows\System32\svchost.exe[1232] ADVAPI32.dll!RegCreateKeyExA 75D539AB 5 Bytes JMP 01590039
.text C:\Windows\System32\svchost.exe[1232] ADVAPI32.dll!RegCreateKeyA 75D53BA9 5 Bytes JMP 01590FB2
.text C:\Windows\System32\svchost.exe[1232] ADVAPI32.dll!RegOpenKeyA 75D589C7 5 Bytes JMP 0159000A
.text C:\Windows\System32\svchost.exe[1232] ADVAPI32.dll!RegCreateKeyW 75D6391E 5 Bytes JMP 01590F97
.text C:\Windows\System32\svchost.exe[1232] ADVAPI32.dll!RegCreateKeyExW 75D641F1 5 Bytes JMP 01590F7C
.text C:\Windows\System32\svchost.exe[1232] ADVAPI32.dll!RegOpenKeyExA 75D67C42 5 Bytes JMP 01590FDE
.text C:\Windows\System32\svchost.exe[1232] ADVAPI32.dll!RegOpenKeyW 75D6E2B5 5 Bytes JMP 01590FEF
.text C:\Windows\System32\svchost.exe[1232] ADVAPI32.dll!RegOpenKeyExW 75D77BA1 5 Bytes JMP 01590FCD
.text C:\Windows\System32\svchost.exe[1232] WS2_32.dll!socket 775A36D1 5 Bytes JMP 015F000A
.text C:\Windows\System32\svchost.exe[1232] WININET.dll!InternetOpenA 75E34E3C 5 Bytes JMP 015E0FEF
.text C:\Windows\System32\svchost.exe[1232] WININET.dll!InternetOpenUrlA 75E3BFDE 5 Bytes JMP 015E002F
.text C:\Windows\System32\svchost.exe[1232] WININET.dll!InternetOpenW 75E6C126 5 Bytes JMP 015E0014
.text C:\Windows\System32\svchost.exe[1232] WININET.dll!InternetOpenUrlW 75E9D8D2 5 Bytes JMP 015E0FDE
.text C:\Windows\system32\svchost.exe[1256] ntdll.dll!NtCreateFile 77484224 5 Bytes JMP 014C0000
.text C:\Windows\system32\svchost.exe[1256] ntdll.dll!NtCreateProcess 774842E4 5 Bytes JMP 014C0FE5
.text C:\Windows\system32\svchost.exe[1256] ntdll.dll!NtProtectVirtualMemory 77484B84 5 Bytes JMP 014C001B
.text C:\Windows\system32\svchost.exe[1256] ntdll.dll!NtWriteVirtualMemory 774854C4 5 Bytes JMP 00D6000A
.text C:\Windows\system32\svchost.exe[1256] ntdll.dll!KiUserExceptionDispatcher 77485BF8 5 Bytes JMP 0097000A
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!GetStartupInfoW 75AE1929 5 Bytes JMP 01470071
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!GetStartupInfoA 75AE19C9 5 Bytes JMP 01470F2B
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!CreateProcessW 75AE1BF3 5 Bytes JMP 01470EF5
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!CreateProcessA 75AE1C28 5 Bytes JMP 01470F06
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!VirtualProtect 75AE1DC3 5 Bytes JMP 01470F72
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!CreateNamedPipeA 75AE2EF5 5 Bytes JMP 0147000A
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!CreateNamedPipeW 75AE5C0C 5 Bytes JMP 01470FB9
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!CreatePipe 75B08F06 5 Bytes JMP 01470F3C
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!LoadLibraryExW 75B0927C 5 Bytes JMP 01470F83
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!LoadLibraryW 75B09400 5 Bytes JMP 0147002F
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!LoadLibraryExA 75B09554 5 Bytes JMP 01470040
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!LoadLibraryA 75B0957C 5 Bytes JMP 01470FA8
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!VirtualProtectEx 75B0DC52 5 Bytes JMP 01470F57
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!GetProcAddress 75B2925B 5 Bytes JMP 01470EDA
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!CreateFileW 75B2B0EB 5 Bytes JMP 01470FD4
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!CreateFileA 75B2D07F 5 Bytes JMP 01470FEF
.text C:\Windows\system32\svchost.exe[1256] kernel32.dll!WinExec 75B760CF 5 Bytes JMP 01470082
.text C:\Windows\system32\svchost.exe[1256] msvcrt.dll!_wsystem 77627F2F 5 Bytes JMP 01540FBE
.text C:\Windows\system32\svchost.exe[1256] msvcrt.dll!system 7762804B 5 Bytes JMP 0154003F
.text C:\Windows\system32\svchost.exe[1256] msvcrt.dll!_creat 7762BBE1 5 Bytes JMP 01540FD9
.text C:\Windows\system32\svchost.exe[1256] msvcrt.dll!_open 7762D106 5 Bytes JMP 01540000
.text C:\Windows\system32\svchost.exe[1256] msvcrt.dll!_wcreat 7762D326 5 Bytes JMP 0154002E
.text C:\Windows\system32\svchost.exe[1256] msvcrt.dll!_wopen 7762D501 5 Bytes JMP 0154001D
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegCreateKeyExA 75D539AB 5 Bytes JMP 014D0047
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegCreateKeyA 75D53BA9 5 Bytes JMP 014D0036
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegOpenKeyA 75D589C7 5 Bytes JMP 014D0FE5
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegCreateKeyW 75D6391E 5 Bytes JMP 014D0FA5
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegCreateKeyExW 75D641F1 5 Bytes JMP 014D0062
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegOpenKeyExA 75D67C42 5 Bytes JMP 014D001B
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegOpenKeyW 75D6E2B5 5 Bytes JMP 014D0000
.text C:\Windows\system32\svchost.exe[1256] ADVAPI32.dll!RegOpenKeyExW 75D77BA1 5 Bytes JMP 014D0FC0
.text C:\Windows\system32\svchost.exe[1256] WS2_32.dll!socket 775A36D1 5 Bytes JMP 01530FEF
.text C:\Windows\system32\svchost.exe[1256] WININET.dll!InternetOpenA 75E34E3C 5 Bytes JMP 0152000A
.text C:\Windows\system32\svchost.exe[1256] WININET.dll!InternetOpenUrlA 75E3BFDE 5 Bytes JMP 01520036
.text C:\Windows\system32\svchost.exe[1256] WININET.dll!InternetOpenW 75E6C126 5 Bytes JMP 0152001B
.text C:\Windows\system32\svchost.exe[1256] WININET.dll!InternetOpenUrlW 75E9D8D2 5 Bytes JMP 01520FE5
.text C:\Windows\system32\svchost.exe[1400] ntdll.dll!NtCreateFile 77484224 5 Bytes JMP 00120000
.text C:\Windows\system32\svchost.exe[1400] ntdll.dll!NtCreateProcess 774842E4 5 Bytes JMP 00120FDE
.text C:\Windows\system32\svchost.exe[1400] ntdll.dll!NtProtectVirtualMemory 77484B84 5 Bytes JMP 00120FEF
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!GetStartupInfoW 75AE1929 5 Bytes JMP 000F0084
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!GetStartupInfoA 75AE19C9 5 Bytes JMP 000F0073
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreateProcessW 75AE1BF3 1 Byte [E9]
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreateProcessW 75AE1BF3 5 Bytes JMP 000F0EF7
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreateProcessA 75AE1C28 5 Bytes JMP 000F0F08
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!VirtualProtect 75AE1DC3 5 Bytes JMP 000F003D
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreateNamedPipeA 75AE2EF5 5 Bytes JMP 000F0FCA
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreateNamedPipeW 75AE5C0C 5 Bytes JMP 000F001B
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreatePipe 75B08F06 5 Bytes JMP 000F0058
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!LoadLibraryExW 75B0927C 5 Bytes JMP 000F0F63
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!LoadLibraryW 75B09400 5 Bytes JMP 000F0F8A
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!LoadLibraryExA 75B09554 5 Bytes JMP 000F002C
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!LoadLibraryA 75B0957C 5 Bytes JMP 000F0FA5
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!VirtualProtectEx 75B0DC52 5 Bytes JMP 000F0F48
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!GetProcAddress 75B2925B 5 Bytes JMP 000F0EDC
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreateFileW 75B2B0EB 1 Byte [E9]
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreateFileW 75B2B0EB 5 Bytes JMP 000F0FEF
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!CreateFileA 75B2D07F 5 Bytes JMP 000F000A
.text C:\Windows\system32\svchost.exe[1400] kernel32.dll!WinExec 75B760CF 5 Bytes JMP 000F0F19
.text C:\Windows\system32\svchost.exe[1400] msvcrt.dll!_wsystem 77627F2F 5 Bytes JMP 00140FA6
.text C:\Windows\system32\svchost.exe[1400] msvcrt.dll!system 7762804B 5 Bytes JMP 00140FB7
.text C:\Windows\system32\svchost.exe[1400] msvcrt.dll!_creat 7762BBE1 5 Bytes JMP 00140FD2
.text C:\Windows\system32\svchost.exe[1400] msvcrt.dll!_open 7762D106 5 Bytes JMP 00140FEF
.text C:\Windows\system32\svchost.exe[1400] msvcrt.dll!_wcreat 7762D326 5 Bytes JMP 00140027
.text C:\Windows\system32\svchost.exe[1400] msvcrt.dll!_wopen 7762D501 5 Bytes JMP 0014000C
.text C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyExA 75D539AB 5 Bytes JMP 00110098
.text C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyA 75D53BA9 5 Bytes JMP 00110058
.text C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyA 75D589C7 5 Bytes JMP 00110000
.text C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyW 75D6391E 5 Bytes JMP 0011007D
.text C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyExW 75D641F1 5 Bytes JMP 00110FDB
.text C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyExA 75D67C42 5 Bytes JMP 0011002C
.text C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyW 75D6E2B5 5 Bytes JMP 00110011
.text C:\Windows\system32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyExW 75D77BA1 5 Bytes JMP 00110047
.text C:\Windows\system32\svchost.exe[1400] WS2_32.dll!socket 775A36D1 5 Bytes JMP 00130000
.text C:\Windows\system32\svchost.exe[1464] ntdll.dll!NtCreateFile 77484224 5 Bytes JMP 00910FEF
.text C:\Windows\system32\svchost.exe[1464] ntdll.dll!NtCreateProcess 774842E4 5 Bytes JMP 0091001B
.text C:\Windows\system32\svchost.exe[1464] ntdll.dll!NtProtectVirtualMemory 77484B84 5 Bytes JMP 0091000A
.text C:\Windows\system32\svchost.exe[1464] kernel32.dll!GetStartupInfoW 75AE1929 5 Bytes JMP 008F0F36
.text C:\Windows\system32\svchost.exe[1464] kernel32.dll!GetStartupInfoA 75AE19C9 5 Bytes JMP 008F007C
.text C:\Windows\system32\svchost.exe[1464] kernel32.dll!CreateProcessW 75AE1BF3 5 Bytes JMP 008F00BC
.text C:\Windows\system32\svchost.exe[1464] kernel32.dll!CreateProcessA 75AE1C28 5 Bytes JMP 008F0F25
.text C:\Windows\system32\svchost.exe[1464] kernel32.dll!VirtualProtect 75AE1DC3 5 Bytes JMP 008F0F80
.text C:\Windows\system32\svchost.exe[1464] kernel32.dll!CreateNamedPipeA 75AE2EF5 5 Bytes JMP 008F0022
.text C:\Windows\system32\svchost.exe[1464] kernel32.dll!CreateNamedPipeW 75AE5C0C 5 Bytes JMP 008F0FC7
.text C:\Windows\system32\svchost.exe[1464] kernel32.dll!CreatePipe 75B08F06 5 Bytes JMP 008F006B
.text C:\Windows\system32\svchost.exe[1464] kernel32.dll!LoadLibraryExW 75B0927C 5 Bytes JMP 008F005A
.text C:\Windows\system32\svchost.exe[1464] kernel32.dll!LoadLibraryW 75B09400 5 Bytes JMP 008F0FA2
.text C:\Windows\system32\svchost.exe[1464] kernel32.dll!LoadLibraryExA 75B09554 5 Bytes JMP 008F0F91
.text C:\Windows\system32\svchost.exe[1464] kernel32.dll!LoadLibraryA 75B0957C 5 Bytes JMP 008F0033
.text C:\Windows\system32\svchost.exe[1464] kernel32.dll!VirtualProtectEx 75B0DC52 5 Bytes JMP 008F0F65
.text C:\Windows\system32\svchost.exe[1464] kernel32.dll!GetProcAddress 75B2925B 5 Bytes JMP 008F0F0A
.text C:\Windows\system32\svchost.exe[1464] kernel32.dll!CreateFileW 75B2B0EB 5 Bytes JMP 008F0011
.text C:\Windows\system32\svchost.exe[1464] kernel32.dll!CreateFileA 75B2D07F 5 Bytes JMP 008F0000
.text C:\Windows\system32\svchost.exe[1464] kernel32.dll!WinExec 75B760CF 5 Bytes JMP 008F00A1
.text C:\Windows\system32\svchost.exe[1464] msvcrt.dll!_wsystem 77627F2F 5 Bytes JMP 00DB0073
.text C:\Windows\system32\svchost.exe[1464] msvcrt.dll!system 7762804B 5 Bytes JMP 00DB0062
.text C:\Windows\system32\svchost.exe[1464] msvcrt.dll!_creat 7762BBE1 5 Bytes JMP 00DB002C
.text C:\Windows\system32\svchost.exe[1464] msvcrt.dll!_open 7762D106 5 Bytes JMP 00DB0000
.text C:\Windows\system32\svchost.exe[1464] msvcrt.dll!_wcreat 7762D326 5 Bytes JMP 00DB0047
.text C:\Windows\system32\svchost.exe[1464] msvcrt.dll!_wopen 7762D501 5 Bytes JMP 00DB0011
.text C:\Windows\system32\svchost.exe[1464] ADVAPI32.dll!RegCreateKeyExA 75D539AB 5 Bytes JMP 00900047
.text C:\Windows\system32\svchost.exe[1464] ADVAPI32.dll!RegCreateKeyA 75D53BA9 5 Bytes JMP 00900FC0
.text C:\Windows\system32\svchost.exe[1464] ADVAPI32.dll!RegOpenKeyA 75D589C7 5 Bytes JMP 00900000
.text C:\Windows\system32\svchost.exe[1464] ADVAPI32.dll!RegCreateKeyW 75D6391E 5 Bytes JMP 00900FA5
.text C:\Windows\system32\svchost.exe[1464] ADVAPI32.dll!RegCreateKeyExW 75D641F1 5 Bytes JMP 00900062
.text C:\Windows\system32\svchost.exe[1464] ADVAPI32.dll!RegOpenKeyExA 75D67C42 5 Bytes JMP 0090002C
.text C:\Windows\system32\svchost.exe[1464] ADVAPI32.dll!RegOpenKeyW 75D6E2B5 5 Bytes JMP 0090001B
.text C:\Windows\system32\svchost.exe[1464] ADVAPI32.dll!RegOpenKeyExW 75D77BA1 5 Bytes JMP 00900FE5
.text C:\Windows\system32\svchost.exe[1464] WS2_32.dll!socket 775A36D1 5 Bytes JMP 00930000
.text C:\Windows\system32\svchost.exe[1464] WININET.dll!InternetOpenA 75E34E3C 5 Bytes JMP 00920FE5
.text C:\Windows\system32\svchost.exe[1464] WININET.dll!InternetOpenUrlA 75E3BFDE 5 Bytes JMP 00920FB9
.text C:\Windows\system32\svchost.exe[1464] WININET.dll!InternetOpenW 75E6C126 5 Bytes JMP 00920FD4
.text C:\Windows\system32\svchost.exe[1464] WININET.dll!InternetOpenUrlW 75E9D8D2 5 Bytes JMP 00920FA8
.text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtCreateFile 77484224 5 Bytes JMP 00F90000
.text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtCreateProcess 774842E4 5 Bytes JMP 00F9001B
.text C:\Windows\system32\svchost.exe[1588] ntdll.dll!NtProtectVirtualMemory 77484B84 5 Bytes JMP 00F90FE5
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!GetStartupInfoW 75AE1929 5 Bytes JMP 00F70F18
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!GetStartupInfoA 75AE19C9 5 Bytes JMP 00F70F29
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateProcessW 75AE1BF3 5 Bytes JMP 00F70EF3
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateProcessA 75AE1C28 5 Bytes JMP 00F7008A
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!VirtualProtect 75AE1DC3 5 Bytes JMP 00F70040
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateNamedPipeA 75AE2EF5 5 Bytes JMP 00F70FD4
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateNamedPipeW 75AE5C0C 5 Bytes JMP 00F70FB9
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreatePipe 75B08F06 5 Bytes JMP 00F70F3A
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!LoadLibraryExW 75B0927C 5 Bytes JMP 00F70F72
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!LoadLibraryW 75B09400 5 Bytes JMP 00F7002F
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!LoadLibraryExA 75B09554 5 Bytes JMP 00F70F83
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!LoadLibraryA 75B0957C 5 Bytes JMP 00F70FA8
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!VirtualProtectEx 75B0DC52 5 Bytes JMP 00F70F4B
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!GetProcAddress 75B2925B 5 Bytes JMP 00F700A5
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateFileW 75B2B0EB 1 Byte [E9]
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateFileW 75B2B0EB 5 Bytes JMP 00F70FEF
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!CreateFileA 75B2D07F 5 Bytes JMP 00F7000A
.text C:\Windows\system32\svchost.exe[1588] kernel32.dll!WinExec 75B760CF 5 Bytes JMP 00F70079
.text C:\Windows\system32\svchost.exe[1588] msvcrt.dll!_wsystem 77627F2F 5 Bytes JMP 028F0FEF
.text C:\Windows\system32\svchost.exe[1588] msvcrt.dll!system 7762804B 5 Bytes JMP 028F007A
.text C:\Windows\system32\svchost.exe[1588] msvcrt.dll!_creat 7762BBE1 5 Bytes JMP 028F003A
.text C:\Windows\system32\svchost.exe[1588] msvcrt.dll!_open 7762D106 5 Bytes JMP 028F000C
.text C:\Windows\system32\svchost.exe[1588] msvcrt.dll!_wcreat 7762D326 5 Bytes JMP 028F0055
.text C:\Windows\system32\svchost.exe[1588] msvcrt.dll!_wopen 7762D501 5 Bytes JMP 028F001D
.text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegCreateKeyExA 75D539AB 5 Bytes JMP 00F8002C
.text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegCreateKeyA 75D53BA9 5 Bytes JMP 00F80FA5
.text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegOpenKeyA 75D589C7 5 Bytes JMP 00F80000
.text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegCreateKeyW 75D6391E 5 Bytes JMP 00F80F8A
.text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegCreateKeyExW 75D641F1 5 Bytes JMP 00F80F65
.text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegOpenKeyExA 75D67C42 5 Bytes JMP 00F80FCA
.text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegOpenKeyW 75D6E2B5 5 Bytes JMP 00F80FDB
.text C:\Windows\system32\svchost.exe[1588] ADVAPI32.dll!RegOpenKeyExW 75D77BA1 5 Bytes JMP 00F8001B
.text C:\Windows\system32\svchost.exe[1588] WS2_32.dll!socket 775A36D1 5 Bytes JMP 02880FEF
.text C:\Windows\system32\svchost.exe[1588] WININET.dll!InternetOpenA 75E34E3C 5 Bytes JMP 00FA0000
.text C:\Windows\system32\svchost.exe[1588] WININET.dll!InternetOpenUrlA 75E3BFDE 5 Bytes JMP 00FA001B
.text C:\Windows\system32\svchost.exe[1588] WININET.dll!InternetOpenW 75E6C126 5 Bytes JMP 00FA0FE5
.text C:\Windows\system32\svchost.exe[1588] WININET.dll!InternetOpenUrlW 75E9D8D2 5 Bytes JMP 00FA0FCA
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[1984] kernel32.dll!LoadLibraryW 75B09400 5 Bytes JMP 6D789AE2 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[1984] kernel32.dll!LoadLibraryA 75B0957C 5 Bytes JMP 6D789A20 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Windows\System32\svchost.exe[2368] ntdll.dll!NtCreateFile 77484224 5 Bytes JMP 000B0FEF
.text C:\Windows\System32\svchost.exe[2368] ntdll.dll!NtCreateProcess 774842E4 5 Bytes JMP 000B0FC3
.text C:\Windows\System32\svchost.exe[2368] ntdll.dll!NtProtectVirtualMemory 77484B84 5 Bytes JMP 000B0FDE
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!GetStartupInfoW 75AE1929 5 Bytes JMP 000500A4
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!GetStartupInfoA 75AE19C9 5 Bytes JMP 00050089
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!CreateProcessW 75AE1BF3 5 Bytes JMP 00050F25
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!CreateProcessA 75AE1C28 5 Bytes JMP 000500C6
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!VirtualProtect 75AE1DC3 5 Bytes JMP 0005005D
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!CreateNamedPipeA 75AE2EF5 5 Bytes JMP 00050FCA
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!CreateNamedPipeW 75AE5C0C 5 Bytes JMP 00050FAF
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!CreatePipe 75B08F06 5 Bytes JMP 00050F68
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!LoadLibraryExW 75B0927C 5 Bytes JMP 0005004C
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!LoadLibraryW 75B09400 5 Bytes JMP 00050F8D
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!LoadLibraryExA 75B09554 5 Bytes JMP 0005002F
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!LoadLibraryA 75B0957C 5 Bytes JMP 00050F9E
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!VirtualProtectEx 75B0DC52 5 Bytes JMP 0005006E
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!GetProcAddress 75B2925B 5 Bytes JMP 00050F14
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!CreateFileW 75B2B0EB 5 Bytes JMP 00050FE5
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!CreateFileA 75B2D07F 5 Bytes JMP 00050000
.text C:\Windows\System32\svchost.exe[2368] kernel32.dll!WinExec 75B760CF 5 Bytes JMP 000500B5
.text C:\Windows\System32\svchost.exe[2368] msvcrt.dll!_wsystem 77627F2F 5 Bytes JMP 000D0F81
.text C:\Windows\System32\svchost.exe[2368] msvcrt.dll!system 7762804B 5 Bytes JMP 000D0F9C
.text C:\Windows\System32\svchost.exe[2368] msvcrt.dll!_creat 7762BBE1 5 Bytes JMP 000D000C
.text C:\Windows\System32\svchost.exe[2368] msvcrt.dll!_open 7762D106 5 Bytes JMP 000D0FEF
.text C:\Windows\System32\svchost.exe[2368] msvcrt.dll!_wcreat 7762D326 5 Bytes JMP 000D0FAD
.text C:\Windows\System32\svchost.exe[2368] msvcrt.dll!_wopen 7762D501 5 Bytes JMP 000D0FDE
.text C:\Windows\System32\svchost.exe[2368] ADVAPI32.dll!RegCreateKeyExA 75D539AB 5 Bytes JMP 000A0F7C
.text C:\Windows\System32\svchost.exe[2368] ADVAPI32.dll!RegCreateKeyA 75D53BA9 5 Bytes JMP 000A0F97
.text C:\Windows\System32\svchost.exe[2368] ADVAPI32.dll!RegOpenKeyA 75D589C7 5 Bytes JMP 000A0FE5
.text C:\Windows\System32\svchost.exe[2368] ADVAPI32.dll!RegCreateKeyW 75D6391E 5 Bytes JMP 000A001E
.text C:\Windows\System32\svchost.exe[2368] ADVAPI32.dll!RegCreateKeyExW 75D641F1 5 Bytes JMP 000A0039
.text C:\Windows\System32\svchost.exe[2368] ADVAPI32.dll!RegOpenKeyExA 75D67C42 5 Bytes JMP 000A0FC3
.text C:\Windows\System32\svchost.exe[2368] ADVAPI32.dll!RegOpenKeyW 75D6E2B5 5 Bytes JMP 000A0FD4
.text C:\Windows\System32\svchost.exe[2368] ADVAPI32.dll!RegOpenKeyExW 75D77BA1 5 Bytes JMP 000A0FA8
.text C:\Windows\Explorer.EXE[3328] ntdll.dll!NtCreateFile 77484224 5 Bytes JMP 02740000
.text C:\Windows\Explorer.EXE[3328] ntdll.dll!NtCreateProcess 774842E4 5 Bytes JMP 02740036
.text C:\Windows\Explorer.EXE[3328] ntdll.dll!NtProtectVirtualMemory 77484B84 5 Bytes JMP 02740011
.text C:\Windows\Explorer.EXE[3328] kernel32.dll!GetStartupInfoW 75AE1929 5 Bytes JMP 02640F1C
.text C:\Windows\Explorer.EXE[3328] kernel32.dll!GetStartupInfoA 75AE19C9 5 Bytes JMP 02640062
.text C:\Windows\Explorer.EXE[3328] kernel32.dll!CreateProcessW 75AE1BF3 5 Bytes JMP 02640EF0
.text C:\Windows\Explorer.EXE[3328] kernel32.dll!CreateProcessA 75AE1C28 5 Bytes JMP 02640087
.text C:\Windows\Explorer.EXE[3328] kernel32.dll!VirtualProtect 75AE1DC3 5 Bytes JMP 02640F52
.text C:\Windows\Explorer.EXE[3328] kernel32.dll!CreateNamedPipeA 75AE2EF5 5 Bytes JMP 02640FE5
.text C:\Windows\Explorer.EXE[3328] kernel32.dll!CreateNamedPipeW 75AE5C0C 5 Bytes JMP 02640FCA
.text C:\Windows\Explorer.EXE[3328] kernel32.dll!CreatePipe 75B08F06 5 Bytes JMP 02640047
.text C:\Windows\Explorer.EXE[3328] kernel32.dll!LoadLibraryExW 75B0927C 5 Bytes JMP 02640F6F
.text C:\Windows\Explorer.EXE[3328] kernel32.dll!LoadLibraryW 75B09400 5 Bytes JMP 0264002C
.text C:\Windows\Explorer.EXE[3328] kernel32.dll!LoadLibraryExA 75B09554 5 Bytes JMP 02640F8A
.text C:\Windows\Explorer.EXE[3328] kernel32.dll!LoadLibraryA 75B0957C 5 Bytes JMP 02640FA5
.text C:\Windows\Explorer.EXE[3328] kernel32.dll!VirtualProtectEx 75B0DC52 5 Bytes JMP 02640F37
.text C:\Windows\Explorer.EXE[3328] kernel32.dll!GetProcAddress 75B2925B 5 Bytes JMP 026400AC
.text C:\Windows\Explorer.EXE[3328] kernel32.dll!CreateFileW 75B2B0EB 5 Bytes JMP 0264001B
.text C:\Windows\Explorer.EXE[3328] kernel32.dll!CreateFileA 75B2D07F 5 Bytes JMP 02640000
.text C:\Windows\Explorer.EXE[3328] kernel32.dll!WinExec 75B760CF 5 Bytes JMP 02640F0B
.text C:\Windows\Explorer.EXE[3328] ADVAPI32.dll!RegCreateKeyExA 75D539AB 5 Bytes JMP 02720039
.text C:\Windows\Explorer.EXE[3328] ADVAPI32.dll!RegCreateKeyA 75D53BA9 5 Bytes JMP 02720FA8
.text C:\Windows\Explorer.EXE[3328] ADVAPI32.dll!RegOpenKeyA 75D589C7 5 Bytes JMP 02720FEF
.text C:\Windows\Explorer.EXE[3328] ADVAPI32.dll!RegCreateKeyW 75D6391E 5 Bytes JMP 02720F97
.text C:\Windows\Explorer.EXE[3328] ADVAPI32.dll!RegCreateKeyExW 75D641F1 5 Bytes JMP 02720054
.text C:\Windows\Explorer.EXE[3328] ADVAPI32.dll!RegOpenKeyExA 75D67C42 5 Bytes JMP 0272000A
.text C:\Windows\Explorer.EXE[3328] ADVAPI32.dll!RegOpenKeyW 75D6E2B5 5 Bytes JMP 02720FDE
.text C:\Windows\Explorer.EXE[3328] ADVAPI32.dll!RegOpenKeyExW 75D77BA1 5 Bytes JMP 02720FB9
.text C:\Windows\Explorer.EXE[3328] msvcrt.dll!_wsystem 77627F2F 5 Bytes JMP 02780FBE
.text C:\Windows\Explorer.EXE[3328] msvcrt.dll!system 7762804B 5 Bytes JMP 02780FD9
.text C:\Windows\Explorer.EXE[3328] msvcrt.dll!_creat 7762BBE1 5 Bytes JMP 0278002E
.text C:\Windows\Explorer.EXE[3328] msvcrt.dll!_open 7762D106 5 Bytes JMP 0278000C
.text C:\Windows\Explorer.EXE[3328] msvcrt.dll!_wcreat 7762D326 5 Bytes JMP 02780049
.text C:\Windows\Explorer.EXE[3328] msvcrt.dll!_wopen 7762D501 5 Bytes JMP 0278001D
.text C:\Windows\Explorer.EXE[3328] WININET.dll!InternetOpenA 75E34E3C 5 Bytes JMP 02730000
.text C:\Windows\Explorer.EXE[3328] WININET.dll!InternetOpenUrlA 75E3BFDE 5 Bytes JMP 0273001B
.text C:\Windows\Explorer.EXE[3328] WININET.dll!InternetOpenW 75E6C126 5 Bytes JMP 02730FE5
.text C:\Windows\Explorer.EXE[3328] WININET.dll!InternetOpenUrlW 75E9D8D2 5 Bytes JMP 0273002C
.text C:\Windows\Explorer.EXE[3328] WS2_32.dll!socket 775A36D1 5 Bytes JMP 02750FE5
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] ntdll.dll!NtCreateFile 77484224 5 Bytes JMP 00880000
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] ntdll.dll!NtCreateProcess 774842E4 5 Bytes JMP 00880FDB
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] ntdll.dll!NtProtectVirtualMemory 77484B84 5 Bytes JMP 00880011
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] kernel32.dll!GetStartupInfoW 75AE1929 5 Bytes JMP 00020F30
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] kernel32.dll!GetStartupInfoA 75AE19C9 5 Bytes JMP 00020076
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] kernel32.dll!CreateProcessW 75AE1BF3 5 Bytes JMP 00020F15
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] kernel32.dll!CreateProcessA 75AE1C28 5 Bytes JMP 000200AC
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] kernel32.dll!VirtualProtect 75AE1DC3 5 Bytes JMP 0002005B
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] kernel32.dll!CreateNamedPipeA 75AE2EF5 5 Bytes JMP 0002001B
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] kernel32.dll!CreateNamedPipeW 75AE5C0C 5 Bytes JMP 00020FCA
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] kernel32.dll!CreatePipe 75B08F06 5 Bytes JMP 00020F41
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] kernel32.dll!LoadLibraryExW 75B0927C 5 Bytes JMP 00020F81
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] kernel32.dll!LoadLibraryW 75B09400 5 Bytes JMP 00020FAF
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] kernel32.dll!LoadLibraryExA 75B09554 5 Bytes JMP 00020F9E
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] kernel32.dll!LoadLibraryA 75B0957C 5 Bytes JMP 00020036
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] kernel32.dll!VirtualProtectEx 75B0DC52 5 Bytes JMP 00020F66
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] kernel32.dll!GetProcAddress 75B2925B 5 Bytes JMP 000200BD
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] kernel32.dll!CreateFileW 75B2B0EB 5 Bytes JMP 0002000A
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] kernel32.dll!CreateFileA 75B2D07F 5 Bytes JMP 00020FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] kernel32.dll!WinExec 75B760CF 5 Bytes JMP 00020091
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] ADVAPI32.dll!RegCreateKeyExA 75D539AB 5 Bytes JMP 00860065
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] ADVAPI32.dll!RegCreateKeyA 75D53BA9 5 Bytes JMP 00860FD4
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] ADVAPI32.dll!RegOpenKeyA 75D589C7 5 Bytes JMP 0086000A
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] ADVAPI32.dll!RegCreateKeyW 75D6391E 5 Bytes JMP 00860FC3
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] ADVAPI32.dll!RegCreateKeyExW 75D641F1 5 Bytes JMP 00860076
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] ADVAPI32.dll!RegOpenKeyExA 75D67C42 5 Bytes JMP 00860025
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] ADVAPI32.dll!RegOpenKeyW 75D6E2B5 5 Bytes JMP 00860FE5
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] ADVAPI32.dll!RegOpenKeyExW 75D77BA1 5 Bytes JMP 00860040
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] USER32.dll!EnableWindow 75F3CD8B 5 Bytes JMP 6A979A14 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] USER32.dll!DialogBoxParamW 75F610B0 5 Bytes JMP 6A8D170B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] USER32.dll!DialogBoxIndirectParamW 75F62EF5 5 Bytes JMP 6AAC62BE C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] USER32.dll!DialogBoxParamA 75F78152 5 Bytes JMP 6AAC6259 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] USER32.dll!DialogBoxIndirectParamA 75F7847D 5 Bytes JMP 6AAC6323 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] USER32.dll!MessageBoxIndirectA 75F8D4D9 5 Bytes JMP 6AAC61E0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] USER32.dll!MessageBoxIndirectW 75F8D5D3 5 Bytes JMP 6AAC6167 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] USER32.dll!MessageBoxExA 75F8D639 5 Bytes JMP 6AAC6103 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] USER32.dll!MessageBoxExW 75F8D65D 5 Bytes JMP 6AAC609F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] msvcrt.dll!_wsystem 77627F2F 5 Bytes JMP 009C004A
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] msvcrt.dll!system 7762804B 5 Bytes JMP 009C0FB5
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] msvcrt.dll!_creat 7762BBE1 5 Bytes JMP 009C0011
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] msvcrt.dll!_open 7762D106 5 Bytes JMP 009C0FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] msvcrt.dll!_wcreat 7762D326 5 Bytes JMP 009C0FC6
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] msvcrt.dll!_wopen 7762D501 5 Bytes JMP 009C0000
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] WININET.dll!InternetOpenA 75E34E3C 5 Bytes JMP 00870000
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] WININET.dll!InternetOpenUrlA 75E3BFDE 5 Bytes JMP 00870040
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] WININET.dll!InternetOpenW 75E6C126 5 Bytes JMP 0087001B
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] WININET.dll!InternetOpenUrlW 75E9D8D2 5 Bytes JMP 00870051
.text C:\Program Files\Internet Explorer\iexplore.exe[4500] WS2_32.dll!socket 775A36D1 5 Bytes JMP 0089000A
.text C:\Windows\system32\svchost.exe[4520] ntdll.dll!NtCreateFile 77484224 5 Bytes JMP 00330000
.text C:\Windows\system32\svchost.exe[4520] ntdll.dll!NtCreateProcess 774842E4 5 Bytes JMP 00330022
.text C:\Windows\system32\svchost.exe[4520] ntdll.dll!NtProtectVirtualMemory 77484B84 5 Bytes JMP 00330011
.text C:\Windows\system32\svchost.exe[4520] kernel32.dll!GetStartupInfoW 75AE1929 5 Bytes JMP 00020F5F
.text C:\Windows\system32\svchost.exe[4520] kernel32.dll!GetStartupInfoA 75AE19C9 5 Bytes JMP 000200A5
.text C:\Windows\system32\svchost.exe[4520] kernel32.dll!CreateProcessW 75AE1BF3 5 Bytes JMP 00020F1F
.text C:\Windows\system32\svchost.exe[4520] kernel32.dll!CreateProcessA 75AE1C28 5 Bytes JMP 000200B6
.text C:\Windows\system32\svchost.exe[4520] kernel32.dll!VirtualProtect 75AE1DC3 5 Bytes JMP 0002008A
.text C:\Windows\system32\svchost.exe[4520] kernel32.dll!CreateNamedPipeA 75AE2EF5 5 Bytes JMP 0002002F
.text C:\Windows\system32\svchost.exe[4520] kernel32.dll!CreateNamedPipeW