Sorry about that. Here it is:
GMER 1.0.15.14972 -
http://www.gmer.net
Rootkit scan 2009-07-12 19:38:34
Windows 6.0.6001 Service Pack 1
—- System - GMER 1.0.15 —-
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwClose [0x8F01B160]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwCreateFile [0x8F01A868]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwCreateKey [0x8F017320]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwCreateProcess [0x8F019E90]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwCreateProcessEx [0x8F019D9C]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwCreateThread [0x8F01A3FC]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwDeleteFile [0x8F01B210]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwDeleteKey [0x8F017786]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwDeleteValueKey [0x8F017846]
SSDT \SystemRoot\system32\drivers\sbhips.sys (Sunbelt Personal Firewall Host Intrusion Prevention Driver/Sunbelt Software, Inc.) ZwLoadDriver [0x8F2BC01C]
SSDT \SystemRoot\system32\drivers\sbhips.sys (Sunbelt Personal Firewall Host Intrusion Prevention Driver/Sunbelt Software, Inc.) ZwMapViewOfSection [0x8F2BC168]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwOpenFile [0x8F01AB54]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwOpenKey [0x8F0175CA]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwResumeThread [0x8F01A4EC]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwSetInformationFile [0x8F01AE8C]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwSetValueKey [0x8F0179BC]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwWriteFile [0x8F01ADE0]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwCreateThreadEx [0x8F01A48E]
SSDT \SystemRoot\system32\drivers\SbFw.sys (Sunbelt Personal Firewall driver/Sunbelt Software, Inc.) ZwCreateUserProcess [0x8F019F82]
—- Kernel code sections - GMER 1.0.15 —-
.text ntkrnlpa.exe!KeSetTimerEx + 3DC 824F19A0 4 Bytes [60, B1, 01, 8F]
.text ntkrnlpa.exe!KeSetTimerEx + 40C 824F19D0 4 Bytes [68, A8, 01, 8F]
.text ntkrnlpa.exe!KeSetTimerEx + 41C 824F19E0 4 Bytes [20, 73, 01, 8F]
.text ntkrnlpa.exe!KeSetTimerEx + 43C 824F1A00 8 Bytes [90, 9E, 01, 8F, 9C, 9D, 01, …] {NOP ; SAHF ; ADD [EDI-0x70fe6264], ECX}
.text ntkrnlpa.exe!KeSetTimerEx + 454 824F1A18 4 Bytes [FC, A3, 01, 8F]
.text …
? C:\Windows\system32\Drivers\PROCEXP90.SYS The system cannot find the file specified. !
? C:\Users\CHRISL~1\AppData\Local\Temp\catchme.sys The system cannot find the file specified. !
—- User code sections - GMER 1.0.15 —-
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[332] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[376] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\Returnil\Returnil.exe[580] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\Returnil\Returnil.exe[580] user32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\Returnil\Returnil.exe[580] user32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\iTunes\iTunesHelper.exe[596] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\iTunes\iTunesHelper.exe[596] WININET.dll!InternetConnectA 779F112E 5 Bytes JMP 00130F54
.text C:\Program Files\iTunes\iTunesHelper.exe[596] WININET.dll!InternetOpenA 77A003ED 5 Bytes JMP 00130D24
.text C:\Program Files\iTunes\iTunesHelper.exe[596] WININET.dll!InternetOpenUrlA 77A020B3 5 Bytes JMP 00130E3C
.text C:\Program Files\iTunes\iTunesHelper.exe[596] WININET.dll!InternetOpenW 77A02A68 5 Bytes JMP 00130DB0
.text C:\Program Files\iTunes\iTunesHelper.exe[596] WININET.dll!InternetConnectW 77A03E11 5 Bytes JMP 00130FE0
.text C:\Program Files\iTunes\iTunesHelper.exe[596] WININET.dll!InternetOpenUrlW 77A4B131 5 Bytes JMP 00130EC8
.text C:\Program Files\iTunes\iTunesHelper.exe[596] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\iTunes\iTunesHelper.exe[596] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\iTunes\iTunesHelper.exe[596] WS2_32.dll!socket 775E36D1 5 Bytes JMP 001308C4
.text C:\Program Files\iTunes\iTunesHelper.exe[596] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00130950
.text C:\Program Files\iTunes\iTunesHelper.exe[596] WS2_32.dll!bind 775E652F 5 Bytes JMP 00130838
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] WS2_32.dll!socket 775E36D1 5 Bytes JMP 001308C4
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00130950
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] WS2_32.dll!bind 775E652F 5 Bytes JMP 00130838
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\Bonjour\mDNSResponder.exe[636] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Windows\system32\csrss.exe[660] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001107AC
.text C:\Windows\system32\csrss.exe[660] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00110720
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001102C0
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00110234
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00110694
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00110090
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001101A8
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001103D8
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0011034C
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!CreateThread 764146C8 5 Bytes JMP 0011057C
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001104F0
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0011011C
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00110004
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!WinExec 764654FF 5 Bytes JMP 00110464
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!SetThreadContext 76467087 5 Bytes JMP 00110608
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000702C0
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00070234
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00070694
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00070090
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000701A8
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000703D8
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0007034C
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0007057C
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000704F0
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0007011C
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00070004
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00070464
.text C:\Windows\system32\svchost.exe[664] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00070608
.text C:\Windows\system32\svchost.exe[664] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000707AC
.text C:\Windows\system32\svchost.exe[664] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00070720
.text C:\Windows\system32\svchost.exe[664] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000708C4
.text C:\Windows\system32\svchost.exe[664] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00070950
.text C:\Windows\system32\svchost.exe[664] WS2_32.dll!bind 775E652F 5 Bytes JMP 00070838
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\wininit.exe[704] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\wininit.exe[704] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\wininit.exe[704] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\wininit.exe[704] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\wininit.exe[704] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\wininit.exe[704] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\system32\csrss.exe[712] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001107AC
.text C:\Windows\system32\csrss.exe[712] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00110720
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001102C0
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00110234
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00110694
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00110090
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001101A8
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001103D8
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0011034C
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!CreateThread 764146C8 5 Bytes JMP 0011057C
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001104F0
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0011011C
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00110004
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!WinExec 764654FF 5 Bytes JMP 00110464
.text C:\Windows\system32\csrss.exe[712] KERNEL32.dll!SetThreadContext 76467087 5 Bytes JMP 00110608
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[752] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\system32\services.exe[756] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\services.exe[756] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\services.exe[756] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\services.exe[756] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\services.exe[756] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\services.exe[756] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\services.exe[756] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\services.exe[756] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\services.exe[756] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\services.exe[756] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\services.exe[756] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\services.exe[756] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\services.exe[756] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\services.exe[756] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\services.exe[756] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\services.exe[756] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\services.exe[756] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\services.exe[756] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\lsass.exe[768] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\lsass.exe[768] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\lsass.exe[768] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\lsass.exe[768] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\lsass.exe[768] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\lsass.exe[768] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\lsm.exe[776] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\lsm.exe[776] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\lsm.exe[776] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\lsm.exe[776] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\lsm.exe[776] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\lsm.exe[776] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe[800] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\winlogon.exe[852] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\winlogon.exe[852] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\winlogon.exe[852] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\winlogon.exe[852] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\winlogon.exe[852] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\winlogon.exe[852] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Windows\system32\dlbccoms.exe[948] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Windows\system32\dlbccoms.exe[948] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Windows\system32\dlbccoms.exe[948] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Windows\system32\dlbccoms.exe[948] ws2_32.dll!socket 775E36D1 5 Bytes JMP 001308C4
.text C:\Windows\system32\dlbccoms.exe[948] ws2_32.dll!connect 775E40D9 5 Bytes JMP 00130950
.text C:\Windows\system32\dlbccoms.exe[948] ws2_32.dll!bind 775E652F 5 Bytes JMP 00130838
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\ehome\ehtray.exe[968] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\ehome\ehtray.exe[968] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\ehome\ehtray.exe[968] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\svchost.exe[1016] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\svchost.exe[1016] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\svchost.exe[1016] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\svchost.exe[1016] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\svchost.exe[1016] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\svchost.exe[1016] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\svchost.exe[1076] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\svchost.exe[1076] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\svchost.exe[1076] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\svchost.exe[1076] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\system32\svchost.exe[1076] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\svchost.exe[1076] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\System32\svchost.exe[1212] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\System32\svchost.exe[1212] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\System32\svchost.exe[1212] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\System32\svchost.exe[1212] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\System32\svchost.exe[1212] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\System32\svchost.exe[1212] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] user32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] user32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] WS2_32.dll!socket 775E36D1 5 Bytes JMP 001308C4
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00130950
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] WS2_32.dll!bind 775E652F 5 Bytes JMP 00130838
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] wininet.dll!InternetConnectA 779F112E 5 Bytes JMP 00130F54
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] wininet.dll!InternetOpenA 77A003ED 5 Bytes JMP 00130D24
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] wininet.dll!InternetOpenUrlA 77A020B3 5 Bytes JMP 00130E3C
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] wininet.dll!InternetOpenW 77A02A68 5 Bytes JMP 00130DB0
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] wininet.dll!InternetConnectW 77A03E11 5 Bytes JMP 00130FE0
.text C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe[1220] wininet.dll!InternetOpenUrlW 77A4B131 5 Bytes JMP 00130EC8
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\System32\svchost.exe[1252] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\System32\svchost.exe[1252] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\System32\svchost.exe[1252] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\System32\svchost.exe[1252] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\System32\svchost.exe[1252] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\System32\svchost.exe[1252] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\svchost.exe[1284] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\svchost.exe[1284] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\svchost.exe[1284] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\svchost.exe[1284] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\svchost.exe[1284] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\svchost.exe[1284] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\AUDIODG.EXE[1352] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\AUDIODG.EXE[1352] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\AUDIODG.EXE[1352] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\AUDIODG.EXE[1352] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\AUDIODG.EXE[1352] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\AUDIODG.EXE[1352] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\svchost.exe[1468] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\svchost.exe[1468] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\svchost.exe[1468] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\svchost.exe[1468] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\svchost.exe[1468] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\svchost.exe[1468] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1548] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] WININET.dll!InternetConnectA 779F112E 5 Bytes JMP 00130F54
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] WININET.dll!InternetOpenA 77A003ED 5 Bytes JMP 00130D24
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] WININET.dll!InternetOpenUrlA 77A020B3 5 Bytes JMP 00130E3C
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] WININET.dll!InternetOpenW 77A02A68 5 Bytes JMP 00130DB0
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] WININET.dll!InternetConnectW 77A03E11 5 Bytes JMP 00130FE0
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] WININET.dll!InternetOpenUrlW 77A4B131 5 Bytes JMP 00130EC8
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] WS2_32.dll!socket 775E36D1 5 Bytes JMP 001308C4
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00130950
.text C:\Program Files\Creative\SBAudigy\Volume Panel\VolPanlu.exe[1560] WS2_32.dll!bind 775E652F 5 Bytes JMP 00130838
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] WS2_32.dll!socket 775E36D1 5 Bytes JMP 001308C4
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00130950
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[1568] WS2_32.dll!bind 775E652F 5 Bytes JMP 00130838
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\svchost.exe[1616] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\svchost.exe[1616] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\svchost.exe[1616] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\svchost.exe[1616] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\svchost.exe[1616] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\svchost.exe[1616] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Windows\System32\WLTRYSVC.EXE[1724] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Windows\System32\WLTRYSVC.EXE[1724] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Windows\System32\WLTRYSVC.EXE[1724] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\WLANExt.exe[1732] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\WLANExt.exe[1732] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\WLANExt.exe[1732] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\WLANExt.exe[1732] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\WLANExt.exe[1732] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\WLANExt.exe[1732] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Windows\System32\bcmwltry.exe[1744] KERNEL32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Windows\System32\bcmwltry.exe[1744] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Windows\System32\bcmwltry.exe[1744] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Windows\System32\bcmwltry.exe[1744] WININET.dll!InternetConnectA 779F112E 5 Bytes JMP 00130F54
.text C:\Windows\System32\bcmwltry.exe[1744] WININET.dll!InternetOpenA 77A003ED 5 Bytes JMP 00130D24
.text C:\Windows\System32\bcmwltry.exe[1744] WININET.dll!InternetOpenUrlA 77A020B3 5 Bytes JMP 00130E3C
.text C:\Windows\System32\bcmwltry.exe[1744] WININET.dll!InternetOpenW 77A02A68 5 Bytes JMP 00130DB0
.text C:\Windows\System32\bcmwltry.exe[1744] WININET.dll!InternetConnectW 77A03E11 5 Bytes JMP 00130FE0
.text C:\Windows\System32\bcmwltry.exe[1744] WININET.dll!InternetOpenUrlW 77A4B131 5 Bytes JMP 00130EC8
.text C:\Windows\System32\bcmwltry.exe[1744] WS2_32.dll!socket 775E36D1 5 Bytes JMP 001308C4
.text C:\Windows\System32\bcmwltry.exe[1744] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00130950
.text C:\Windows\System32\bcmwltry.exe[1744] WS2_32.dll!bind 775E652F 5 Bytes JMP 00130838
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] WS2_32.dll!socket 775E36D1 5 Bytes JMP 001308C4
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00130950
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[1768] WS2_32.dll!bind 775E652F 5 Bytes JMP 00130838
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\System32\spoolsv.exe[1844] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\System32\spoolsv.exe[1844] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\System32\spoolsv.exe[1844] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\System32\spoolsv.exe[1844] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\System32\spoolsv.exe[1844] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\System32\spoolsv.exe[1844] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Windows\system32\igfxsrvc.exe[1852] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Windows\system32\igfxsrvc.exe[1852] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Windows\system32\igfxsrvc.exe[1852] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Windows\system32\igfxsrvc.exe[1852] WS2_32.dll!socket 775E36D1 5 Bytes JMP 001308C4
.text C:\Windows\system32\igfxsrvc.exe[1852] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00130950
.text C:\Windows\system32\igfxsrvc.exe[1852] WS2_32.dll!bind 775E652F 5 Bytes JMP 00130838
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\svchost.exe[1896] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\svchost.exe[1896] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\svchost.exe[1896] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\svchost.exe[1896] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\svchost.exe[1896] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\svchost.exe[1896] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe[1992] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\DellTPad\Apoint.exe[2004] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\DellTPad\Apoint.exe[2004] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\DellTPad\Apoint.exe[2004] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] WININET.dll!InternetConnectA 779F112E 5 Bytes JMP 00130F54
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] WININET.dll!InternetOpenA 77A003ED 5 Bytes JMP 00130D24
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] WININET.dll!InternetOpenUrlA 77A020B3 5 Bytes JMP 00130E3C
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] WININET.dll!InternetOpenW 77A02A68 5 Bytes JMP 00130DB0
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] WININET.dll!InternetConnectW 77A03E11 5 Bytes JMP 00130FE0
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] WININET.dll!InternetOpenUrlW 77A4B131 5 Bytes JMP 00130EC8
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] ws2_32.dll!socket 775E36D1 5 Bytes JMP 001308C4
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] ws2_32.dll!connect 775E40D9 5 Bytes JMP 00130950
.text C:\Program Files\Java\jre6\bin\jusched.exe[2016] ws2_32.dll!bind 775E652F 5 Bytes JMP 00130838
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] wininet.dll!InternetConnectA 779F112E 5 Bytes JMP 00130F54
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] wininet.dll!InternetOpenA 77A003ED 5 Bytes JMP 00130D24
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] wininet.dll!InternetOpenUrlA 77A020B3 5 Bytes JMP 00130E3C
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] wininet.dll!InternetOpenW 77A02A68 5 Bytes JMP 00130DB0
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] wininet.dll!InternetConnectW 77A03E11 5 Bytes JMP 00130FE0
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2044] wininet.dll!InternetOpenUrlW 77A4B131 5 Bytes JMP 00130EC8
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 000302C0
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00030234
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00030694
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00030090
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 000301A8
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 000303D8
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0003034C
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0003057C
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 000304F0
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0003011C
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00030004
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00030464
.text C:\Windows\system32\svchost.exe[2088] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00030608
.text C:\Windows\system32\svchost.exe[2088] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 000307AC
.text C:\Windows\system32\svchost.exe[2088] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00030720
.text C:\Windows\system32\svchost.exe[2088] WS2_32.dll!socket 775E36D1 5 Bytes JMP 000308C4
.text C:\Windows\system32\svchost.exe[2088] WS2_32.dll!connect 775E40D9 5 Bytes JMP 00030950
.text C:\Windows\system32\svchost.exe[2088] WS2_32.dll!bind 775E652F 5 Bytes JMP 00030838
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] USER32.dll!SetWindowsHookExW 77417B69 5 Bytes JMP 001307AC
.text C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe[2132] USER32.dll!SetWindowsHookExA 7743BB0E 5 Bytes JMP 00130720
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2204] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!CreateProcessW 763D1C01 5 Bytes JMP 001302C0
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!CreateProcessA 763D1C36 5 Bytes JMP 00130234
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!WriteProcessMemory 763D1CC6 5 Bytes JMP 00130694
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!VirtualProtect 763D1DD1 5 Bytes JMP 00130090
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!VirtualProtectEx 763F8D7E 5 Bytes JMP 001301A8
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!CreateProcessInternalW 763F98DD 5 Bytes JMP 001303D8
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!CreateProcessInternalA 764003CD 5 Bytes JMP 0013034C
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!CreateThread 764146C8 5 Bytes JMP 0013057C
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!CreateRemoteThread 764146EF 5 Bytes JMP 001304F0
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!VirtualAllocEx 7641B816 5 Bytes JMP 0013011C
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!VirtualAlloc 7641B86F 5 Bytes JMP 00130004
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!WinExec 764654FF 5 Bytes JMP 00130464
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2216] kernel32.dll!SetThreadContext 76467087 5 Bytes JMP 00130608