System seems to be running fine. about 2 weeks ago computer would not turn off with out powering down with the button, this past Thursday if started turning off like it should. Google searchs are going where they should. Updated both Adobe and Java. Here is the latest GMER log
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-02-06 23:12:03
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\test\LOCALS~1\Temp\kgpyapod.sys
—- System - GMER 1.0.15 —-
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwCreateKey [0x804D7FCE]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FCE] ZwCreateKey [0x804D7FCE]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwDeleteKey [0x804D7FD8]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FD8] ZwDeleteKey [0x804D7FD8]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwDeleteValueKey [0x804D7FC9]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FC9] ZwDeleteValueKey [0x804D7FC9]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwEnumerateKey [0x804D7FDD]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FDD] ZwEnumerateKey [0x804D7FDD]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwEnumerateValueKey [0x804D7FE2]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FE2] ZwEnumerateValueKey [0x804D7FE2]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwOpenKey [0x804D7FF1]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FF1] ZwOpenKey [0x804D7FF1]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwQueryKey [0x804D7FEC]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FEC] ZwQueryKey [0x804D7FEC]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwQueryValueKey [0x804D7FE7]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FE7] ZwQueryValueKey [0x804D7FE7]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwSetValueKey [0x804D7FD3]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FD3] ZwSetValueKey [0x804D7FD3]
INT 0x03 \WINDOWS\system32\ntkrnlpa.exe[unknown section] 804D7FF6
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xEB6AC78A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xEB6AC738]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xEB6AC74C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xEB6AC7CA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xEB6AC917]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xEB6AC710]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xEB6AC724]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xEB6AC79E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xEB6AC8B9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xEB6AC858]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xEB6AC93F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xEB6AC92B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xEB6AC776]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xEB6AC762]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xEB6AC7F9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xEB6AC901]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xEB6AC7E0]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xEB6AC7B4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess
—- Kernel code sections - GMER 1.0.15 —-
.text ntkrnlpa.exe!ZwYieldExecution 80504AE8 7 Bytes JMP EB6AC7B8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF5BBC360, 0x225D9D, 0xE8000020]
.text C:\WINDOWS\system32\DRIVERS\aksfridge.sys section is writeable [0xB9542000, 0x44527, 0xE0000020]
.init C:\WINDOWS\system32\DRIVERS\aksfridge.sys entry point in ".init" section [0xB9594224]
.init C:\WINDOWS\system32\DRIVERS\aksfridge.sys unknown last code section [0xB9594000, 0x7000, 0xE20000E0]
.text C:\WINDOWS\system32\drivers\hardlock.sys section is writeable [0xB92DF400, 0x88182, 0xE8000020]
.protectÿÿÿÿhardlockentry point in ".protectÿÿÿÿhardlockentry point in ".protectÿÿÿÿhardlockentry point in ".p" section [0xB9383820] C:\WINDOWS\system32\drivers\hardlock.sys entry point in ".protectÿÿÿÿhardlockentry point in ".protectÿÿÿÿhardlockentry point in ".p" section [0xB9383820]
.protectÿÿÿÿhardlockunknown last code section [0xB9383600, 0x50F6, 0xE0000020] C:\WINDOWS\system32\drivers\hardlock.sys unknown last code section [0xB9383600, 0x50F6, 0xE0000020]
—- User code sections - GMER 1.0.15 —-
.text C:\WINDOWS\Explorer.EXE[572] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01320000
.text C:\WINDOWS\Explorer.EXE[572] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 0132006E
.text C:\WINDOWS\Explorer.EXE[572] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01320F79
.text C:\WINDOWS\Explorer.EXE[572] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01320F8A
.text C:\WINDOWS\Explorer.EXE[572] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01320047
.text C:\WINDOWS\Explorer.EXE[572] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01320FAF
.text C:\WINDOWS\Explorer.EXE[572] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01320F4B
.text C:\WINDOWS\Explorer.EXE[572] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01320F5C
.text C:\WINDOWS\Explorer.EXE[572] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01320F29
.text C:\WINDOWS\Explorer.EXE[572] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 013200C2
.text C:\WINDOWS\Explorer.EXE[572] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 013200DD
.text C:\WINDOWS\Explorer.EXE[572] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0132002C
.text C:\WINDOWS\Explorer.EXE[572] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01320FE5
.text C:\WINDOWS\Explorer.EXE[572] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01320093
.text C:\WINDOWS\Explorer.EXE[572] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 0132001B
.text C:\WINDOWS\Explorer.EXE[572] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01320FCA
.text C:\WINDOWS\Explorer.EXE[572] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01320F3A
.text C:\WINDOWS\Explorer.EXE[572] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00D50011
.text C:\WINDOWS\Explorer.EXE[572] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00D50F76
.text C:\WINDOWS\Explorer.EXE[572] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00D50FC0
.text C:\WINDOWS\Explorer.EXE[572] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00D50000
.text C:\WINDOWS\Explorer.EXE[572] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00D50F9B
.text C:\WINDOWS\Explorer.EXE[572] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00D50FEF
.text C:\WINDOWS\Explorer.EXE[572] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00D5003D
.text C:\WINDOWS\Explorer.EXE[572] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00D50022
.text C:\WINDOWS\Explorer.EXE[572] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00D40F90
.text C:\WINDOWS\Explorer.EXE[572] msvcrt.dll!system 77C293C7 5 Bytes JMP 00D40FB5
.text C:\WINDOWS\Explorer.EXE[572] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00D4000A
.text C:\WINDOWS\Explorer.EXE[572] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00D40FE3
.text C:\WINDOWS\Explorer.EXE[572] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00D4001B
.text C:\WINDOWS\Explorer.EXE[572] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00D40FD2
.text C:\WINDOWS\Explorer.EXE[572] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 00D20FEF
.text C:\WINDOWS\Explorer.EXE[572] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 00D2000A
.text C:\WINDOWS\Explorer.EXE[572] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 00D20FDE
.text C:\WINDOWS\Explorer.EXE[572] WININET.dll!InternetOpenUrlW 3D998439 5 Bytes JMP 00D20FCD
.text C:\WINDOWS\Explorer.EXE[572] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00D30000
.text C:\WINDOWS\system32\services.exe[1380] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00070FEF
.text C:\WINDOWS\system32\services.exe[1380] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00070F7E
.text C:\WINDOWS\system32\services.exe[1380] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00070073
.text C:\WINDOWS\system32\services.exe[1380] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00070062
.text C:\WINDOWS\system32\services.exe[1380] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00070047
.text C:\WINDOWS\system32\services.exe[1380] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00070FA5
.text C:\WINDOWS\system32\services.exe[1380] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 000700A9
.text C:\WINDOWS\system32\services.exe[1380] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00070F6D
.text C:\WINDOWS\system32\services.exe[1380] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 000700CE
.text C:\WINDOWS\system32\services.exe[1380] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00070F35
.text C:\WINDOWS\system32\services.exe[1380] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00070F1A
.text C:\WINDOWS\system32\services.exe[1380] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00070036
.text C:\WINDOWS\system32\services.exe[1380] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00070FD4
.text C:\WINDOWS\system32\services.exe[1380] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00070098
.text C:\WINDOWS\system32\services.exe[1380] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 0007001B
.text C:\WINDOWS\system32\services.exe[1380] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 0007000A
.text C:\WINDOWS\system32\services.exe[1380] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00070F46
.text C:\WINDOWS\system32\services.exe[1380] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00060FA8
.text C:\WINDOWS\system32\services.exe[1380] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00060043
.text C:\WINDOWS\system32\services.exe[1380] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00060FB9
.text C:\WINDOWS\system32\services.exe[1380] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00060FD4
.text C:\WINDOWS\system32\services.exe[1380] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00060F86
.text C:\WINDOWS\system32\services.exe[1380] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00060FE5
.text C:\WINDOWS\system32\services.exe[1380] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00060028
.text C:\WINDOWS\system32\services.exe[1380] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00060F97
.text C:\WINDOWS\system32\services.exe[1380] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00050FB9
.text C:\WINDOWS\system32\services.exe[1380] msvcrt.dll!system 77C293C7 5 Bytes JMP 00050044
.text C:\WINDOWS\system32\services.exe[1380] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00050FEF
.text C:\WINDOWS\system32\services.exe[1380] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0005000C
.text C:\WINDOWS\system32\services.exe[1380] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00050FD4
.text C:\WINDOWS\system32\services.exe[1380] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0005001D
.text C:\WINDOWS\system32\services.exe[1380] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00040FEF
.text C:\WINDOWS\system32\lsass.exe[1392] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00E90FE5
.text C:\WINDOWS\system32\lsass.exe[1392] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00E9007D
.text C:\WINDOWS\system32\lsass.exe[1392] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00E90F92
.text C:\WINDOWS\system32\lsass.exe[1392] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00E90FA3
.text C:\WINDOWS\system32\lsass.exe[1392] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00E90062
.text C:\WINDOWS\system32\lsass.exe[1392] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00E90047
.text C:\WINDOWS\system32\lsass.exe[1392] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00E900AE
.text C:\WINDOWS\system32\lsass.exe[1392] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00E90F66
.text C:\WINDOWS\system32\lsass.exe[1392] kernel32.dll!CreateProcessW 7C802336 1 Byte [E9]
.text C:\WINDOWS\system32\lsass.exe[1392] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E90F3A
.text C:\WINDOWS\system32\lsass.exe[1392] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E90F55
.text C:\WINDOWS\system32\lsass.exe[1392] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00E900EE
.text C:\WINDOWS\system32\lsass.exe[1392] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00E90FC0
.text C:\WINDOWS\system32\lsass.exe[1392] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00E90000
.text C:\WINDOWS\system32\lsass.exe[1392] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00E90F77
.text C:\WINDOWS\system32\lsass.exe[1392] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00E90036
.text C:\WINDOWS\system32\lsass.exe[1392] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00E90025
.text C:\WINDOWS\system32\lsass.exe[1392] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00E900C9
.text C:\WINDOWS\system32\lsass.exe[1392] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00E80FC0
.text C:\WINDOWS\system32\lsass.exe[1392] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00E80076
.text C:\WINDOWS\system32\lsass.exe[1392] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00E80FE5
.text C:\WINDOWS\system32\lsass.exe[1392] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00E8001B
.text C:\WINDOWS\system32\lsass.exe[1392] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00E80051
.text C:\WINDOWS\system32\lsass.exe[1392] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00E8000A
.text C:\WINDOWS\system32\lsass.exe[1392] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00E80FAF
.text C:\WINDOWS\system32\lsass.exe[1392] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [08, 89]
.text C:\WINDOWS\system32\lsass.exe[1392] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00E8002C
.text C:\WINDOWS\system32\lsass.exe[1392] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00E70FB7
.text C:\WINDOWS\system32\lsass.exe[1392] msvcrt.dll!system 77C293C7 5 Bytes JMP 00E70FC8
.text C:\WINDOWS\system32\lsass.exe[1392] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00E7002E
.text C:\WINDOWS\system32\lsass.exe[1392] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00E70000
.text C:\WINDOWS\system32\lsass.exe[1392] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00E70FD9
.text C:\WINDOWS\system32\lsass.exe[1392] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00E7001D
.text C:\WINDOWS\system32\lsass.exe[1392] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00C30000
.text C:\WINDOWS\system32\svchost.exe[1560] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02530FEF
.text C:\WINDOWS\system32\svchost.exe[1560] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02530F9B
.text C:\WINDOWS\system32\svchost.exe[1560] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02530FB6
.text C:\WINDOWS\system32\svchost.exe[1560] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02530084
.text C:\WINDOWS\system32\svchost.exe[1560] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02530073
.text C:\WINDOWS\system32\svchost.exe[1560] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02530051
.text C:\WINDOWS\system32\svchost.exe[1560] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 025300D9
.text C:\WINDOWS\system32\svchost.exe[1560] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 025300C8
.text C:\WINDOWS\system32\svchost.exe[1560] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02530F4A
.text C:\WINDOWS\system32\svchost.exe[1560] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 02530F5B
.text C:\WINDOWS\system32\svchost.exe[1560] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02530F39
.text C:\WINDOWS\system32\svchost.exe[1560] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02530062
.text C:\WINDOWS\system32\svchost.exe[1560] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0253000A
.text C:\WINDOWS\system32\svchost.exe[1560] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 025300AB
.text C:\WINDOWS\system32\svchost.exe[1560] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02530040
.text C:\WINDOWS\system32\svchost.exe[1560] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02530025
.text C:\WINDOWS\system32\svchost.exe[1560] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 02530F6C
.text C:\WINDOWS\system32\svchost.exe[1560] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 02520011
.text C:\WINDOWS\system32\svchost.exe[1560] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 02520022
.text C:\WINDOWS\system32\svchost.exe[1560] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 02520FCA
.text C:\WINDOWS\system32\svchost.exe[1560] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 02520FDB
.text C:\WINDOWS\system32\svchost.exe[1560] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 02520F6F
.text C:\WINDOWS\system32\svchost.exe[1560] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 02520000
.text C:\WINDOWS\system32\svchost.exe[1560] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 02520F80
.text C:\WINDOWS\system32\svchost.exe[1560] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [72, 8A] {JB 0xffffffffffffff8c}
.text C:\WINDOWS\system32\svchost.exe[1560] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 02520F9B
.text C:\WINDOWS\system32\svchost.exe[1560] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 02510FAD
.text C:\WINDOWS\system32\svchost.exe[1560] msvcrt.dll!system 77C293C7 5 Bytes JMP 02510038
.text C:\WINDOWS\system32\svchost.exe[1560] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0251001D
.text C:\WINDOWS\system32\svchost.exe[1560] msvcrt.dll!_open 77C2F566 5 Bytes JMP 02510FEF
.text C:\WINDOWS\system32\svchost.exe[1560] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 02510FC8
.text C:\WINDOWS\system32\svchost.exe[1560] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0251000C
.text C:\WINDOWS\system32\svchost.exe[1560] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FF000A
.text C:\WINDOWS\system32\svchost.exe[1608] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00DD0FEF
.text C:\WINDOWS\system32\svchost.exe[1608] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00DD0093
.text C:\WINDOWS\system32\svchost.exe[1608] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00DD0078
.text C:\WINDOWS\system32\svchost.exe[1608] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00DD0F9E
.text C:\WINDOWS\system32\svchost.exe[1608] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00DD0051
.text C:\WINDOWS\system32\svchost.exe[1608] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00DD0FB9
.text C:\WINDOWS\system32\svchost.exe[1608] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00DD00AE
.text C:\WINDOWS\system32\svchost.exe[1608] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00DD0F68
.text C:\WINDOWS\system32\svchost.exe[1608] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00DD0F4B
.text C:\WINDOWS\system32\svchost.exe[1608] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00DD00E4
.text C:\WINDOWS\system32\svchost.exe[1608] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00DD0F3A
.text C:\WINDOWS\system32\svchost.exe[1608] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00DD0040
.text C:\WINDOWS\system32\svchost.exe[1608] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00DD0FDE
.text C:\WINDOWS\system32\svchost.exe[1608] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00DD0F79
.text C:\WINDOWS\system32\svchost.exe[1608] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00DD0025
.text C:\WINDOWS\system32\svchost.exe[1608] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00DD0014
.text C:\WINDOWS\system32\svchost.exe[1608] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00DD00BF
.text C:\WINDOWS\system32\svchost.exe[1608] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00DC0025
.text C:\WINDOWS\system32\svchost.exe[1608] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00DC006C
.text C:\WINDOWS\system32\svchost.exe[1608] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00DC0FDE
.text C:\WINDOWS\system32\svchost.exe[1608] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00DC0FEF
.text C:\WINDOWS\system32\svchost.exe[1608] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00DC0FAF
.text C:\WINDOWS\system32\svchost.exe[1608] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00DC0000
.text C:\WINDOWS\system32\svchost.exe[1608] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00DC0051
.text C:\WINDOWS\system32\svchost.exe[1608] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00DC0036
.text C:\WINDOWS\system32\svchost.exe[1608] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00DB005D
.text C:\WINDOWS\system32\svchost.exe[1608] msvcrt.dll!system 77C293C7 5 Bytes JMP 00DB0FC8
.text C:\WINDOWS\system32\svchost.exe[1608] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00DB0027
.text C:\WINDOWS\system32\svchost.exe[1608] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00DB0000
.text C:\WINDOWS\system32\svchost.exe[1608] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00DB0038
.text C:\WINDOWS\system32\svchost.exe[1608] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00DB0FE3
.text C:\WINDOWS\system32\svchost.exe[1608] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00DA0000
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 05FB0000
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 05FB0F70
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 05FB0F8B
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 05FB0F9C
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 05FB005B
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 05FB0FB9
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 05FB0F2E
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 05FB0F3F
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 05FB0F02
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 05FB0F1D
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 05FB0EF1
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 05FB004A
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 05FB001B
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 05FB0076
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 05FB0FCA
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 05FB0FDB
.text C:\WINDOWS\System32\svchost.exe[1648] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 05FB0091
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 05FA0FC3
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 05FA0F8D
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 05FA0FD4
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 05FA0000
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 05FA0F9E
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 05FA0FEF
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 05FA004A
.text C:\WINDOWS\System32\svchost.exe[1648] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 05FA0025
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 0335004B
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!system 77C293C7 5 Bytes JMP 0335003A
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 03350029
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!_open 77C2F566 5 Bytes JMP 03350FEF
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 03350FCA
.text C:\WINDOWS\System32\svchost.exe[1648] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0335000C
.text C:\WINDOWS\System32\svchost.exe[1648] WS2_32.dll!socket 71AB4211 5 Bytes JMP 03340FEF
.text C:\WINDOWS\System32\svchost.exe[1648] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 03330FEF
.text C:\WINDOWS\System32\svchost.exe[1648] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 03330FD4
.text C:\WINDOWS\System32\svchost.exe[1648] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 03330FB9
.text C:\WINDOWS\System32\svchost.exe[1648] WININET.dll!InternetOpenUrlW 3D998439 5 Bytes JMP 03330FA8
.text C:\WINDOWS\system32\svchost.exe[1800] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00D9000A
.text C:\WINDOWS\system32\svchost.exe[1800] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00D90F68
.text C:\WINDOWS\system32\svchost.exe[1800] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00D9005D
.text C:\WINDOWS\system32\svchost.exe[1800] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00D90F83
.text C:\WINDOWS\system32\svchost.exe[1800] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00D90040
.text C:\WINDOWS\system32\svchost.exe[1800] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00D90FAF
.text C:\WINDOWS\system32\svchost.exe[1800] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00D90098
.text C:\WINDOWS\system32\svchost.exe[1800] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00D90F46
.text C:\WINDOWS\system32\svchost.exe[1800] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D90F24
.text C:\WINDOWS\system32\svchost.exe[1800] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D90F35
.text C:\WINDOWS\system32\svchost.exe[1800] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00D900E2
.text C:\WINDOWS\system32\svchost.exe[1800] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00D90F9E
.text C:\WINDOWS\system32\svchost.exe[1800] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00D90FEF
.text C:\WINDOWS\system32\svchost.exe[1800] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00D90F57
.text C:\WINDOWS\system32\svchost.exe[1800] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00D90FCA
.text C:\WINDOWS\system32\svchost.exe[1800] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00D9001B
.text C:\WINDOWS\system32\svchost.exe[1800] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00D900B3
.text C:\WINDOWS\system32\svchost.exe[1800] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00D80FB9
.text C:\WINDOWS\system32\svchost.exe[1800] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00D8004A
.text C:\WINDOWS\system32\svchost.exe[1800] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00D80FD4
.text C:\WINDOWS\system32\svchost.exe[1800] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00D80FE5
.text C:\WINDOWS\system32\svchost.exe[1800] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00D80F8D
.text C:\WINDOWS\system32\svchost.exe[1800] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00D80000
.text C:\WINDOWS\system32\svchost.exe[1800] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00D80FA8
.text C:\WINDOWS\system32\svchost.exe[1800] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [F8, 88]
.text C:\WINDOWS\system32\svchost.exe[1800] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00D8002F
.text C:\WINDOWS\system32\svchost.exe[1800] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00D70F9C
.text C:\WINDOWS\system32\svchost.exe[1800] msvcrt.dll!system 77C293C7 5 Bytes JMP 00D70FB7
.text C:\WINDOWS\system32\svchost.exe[1800] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00D70FD2
.text C:\WINDOWS\system32\svchost.exe[1800] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00D70FEF
.text C:\WINDOWS\system32\svchost.exe[1800] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00D70027
.text C:\WINDOWS\system32\svchost.exe[1800] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00D7000C
.text C:\WINDOWS\system32\svchost.exe[1800] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00D60FEF
.text C:\WINDOWS\system32\svchost.exe[1828] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00D8000A
.text C:\WINDOWS\system32\svchost.exe[1828] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00D8007B
.text C:\WINDOWS\system32\svchost.exe[1828] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00D80F90
.text C:\WINDOWS\system32\svchost.exe[1828] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00D8005E
.text C:\WINDOWS\system32\svchost.exe[1828] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00D80FA1
.text C:\WINDOWS\system32\svchost.exe[1828] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00D80FBC
.text C:\WINDOWS\system32\svchost.exe[1828] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00D80096
.text C:\WINDOWS\system32\svchost.exe[1828] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00D80F5A
.text C:\WINDOWS\system32\svchost.exe[1828] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D80F1B
.text C:\WINDOWS\system32\svchost.exe[1828] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D80F2C
.text C:\WINDOWS\system32\svchost.exe[1828] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00D800C5
.text C:\WINDOWS\system32\svchost.exe[1828] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00D80039
.text C:\WINDOWS\system32\svchost.exe[1828] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00D80FEF
.text C:\WINDOWS\system32\svchost.exe[1828] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00D80F75
.text C:\WINDOWS\system32\svchost.exe[1828] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00D80FCD
.text C:\WINDOWS\system32\svchost.exe[1828] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00D80FDE
.text C:\WINDOWS\system32\svchost.exe[1828] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00D80F3D
.text C:\WINDOWS\system32\svchost.exe[1828] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00D70FAF
.text C:\WINDOWS\system32\svchost.exe[1828] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00D70F79
.text C:\WINDOWS\system32\svchost.exe[1828] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00D70FC0
.text C:\WINDOWS\system32\svchost.exe[1828] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00D70FE5
.text C:\WINDOWS\system32\svchost.exe[1828] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00D7002C
.text C:\WINDOWS\system32\svchost.exe[1828] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00D70000
.text C:\WINDOWS\system32\svchost.exe[1828] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00D70F94
.text C:\WINDOWS\system32\svchost.exe[1828] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [F7, 88]
.text C:\WINDOWS\system32\svchost.exe[1828] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00D7001B
.text C:\WINDOWS\system32\svchost.exe[1828] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00D60FC3
.text C:\WINDOWS\system32\svchost.exe[1828] msvcrt.dll!system 77C293C7 5 Bytes JMP 00D60FD4
.text C:\WINDOWS\system32\svchost.exe[1828] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00D60029
.text C:\WINDOWS\system32\svchost.exe[1828] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00D6000C
.text C:\WINDOWS\system32\svchost.exe[1828] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00D60044
.text C:\WINDOWS\system32\svchost.exe[1828] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00D60FEF
.text C:\WINDOWS\system32\svchost.exe[1828] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00D50FEF
.text C:\WINDOWS\system32\svchost.exe[1828] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 00F60FE5
.text C:\WINDOWS\system32\svchost.exe[1828] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 00F60FD4
.text C:\WINDOWS\system32\svchost.exe[1828] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 00F6000A
.text C:\WINDOWS\system32\svchost.exe[1828] WININET.dll!InternetOpenUrlW 3D998439 5 Bytes JMP 00F6001B
.text C:\WINDOWS\system32\svchost.exe[2032] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BE0FEF
.text C:\WINDOWS\system32\svchost.exe[2032] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BE009A
.text C:\WINDOWS\system32\svchost.exe[2032] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BE0FAF
.text C:\WINDOWS\system32\svchost.exe[2032] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BE007D
.text C:\WINDOWS\system32\svchost.exe[2032] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BE006C
.text C:\WINDOWS\system32\svchost.exe[2032] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BE0040
.text C:\WINDOWS\system32\svchost.exe[2032] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BE0F52
.text C:\WINDOWS\system32\svchost.exe[2032] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BE0F63
.text C:\WINDOWS\system32\svchost.exe[2032] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BE0F26
.text C:\WINDOWS\system32\svchost.exe[2032] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BE0F37
.text C:\WINDOWS\system32\svchost.exe[2032] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BE0F0B
.text C:\WINDOWS\system32\svchost.exe[2032] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BE0051
.text C:\WINDOWS\system32\svchost.exe[2032] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BE000A
.text C:\WINDOWS\system32\svchost.exe[2032] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BE0F8A
.text C:\WINDOWS\system32\svchost.exe[2032] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BE0FD4
.text C:\WINDOWS\system32\svchost.exe[2032] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BE002F
.text C:\WINDOWS\system32\svchost.exe[2032] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BE00B5
.text C:\WINDOWS\system32\svchost.exe[2032] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00660047
.text C:\WINDOWS\system32\svchost.exe[2032] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00660FBD
.text C:\WINDOWS\system32\svchost.exe[2032] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0066002C
.text C:\WINDOWS\system32\svchost.exe[2032] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 0066001B
.text C:\WINDOWS\system32\svchost.exe[2032] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00660084
.text C:\WINDOWS\system32\svchost.exe[2032] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00660000
.text C:\WINDOWS\system32\svchost.exe[2032] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00660073
.text C:\WINDOWS\system32\svchost.exe[2032] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00660058
.text C:\WINDOWS\system32\svchost.exe[2032] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00650FB7
.text C:\WINDOWS\system32\svchost.exe[2032] msvcrt.dll!system 77C293C7 5 Bytes JMP 00650042
.text C:\WINDOWS\system32\svchost.exe[2032] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00650FD2
.text C:\WINDOWS\system32\svchost.exe[2032] msvcrt.dll!_open 77C2F566 5 Bytes JMP 0065000C
.text C:\WINDOWS\system32\svchost.exe[2032] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00650027
.text C:\WINDOWS\system32\svchost.exe[2032] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00650FE3
.text C:\WINDOWS\system32\svchost.exe[2032] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 00630FEF
.text C:\WINDOWS\system32\svchost.exe[2032] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 00630FDE
.text C:\WINDOWS\system32\svchost.exe[2032] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 00630FCD
.text C:\WINDOWS\system32\svchost.exe[2032] WININET.dll!InternetOpenUrlW 3D998439 5 Bytes JMP 00630FBC
.text C:\WINDOWS\system32\svchost.exe[2032] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00640FEF
.text C:\WINDOWS\System32\svchost.exe[2212] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F80000
.text C:\WINDOWS\System32\svchost.exe[2212] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F80073
.text C:\WINDOWS\System32\svchost.exe[2212] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F80F7E
.text C:\WINDOWS\System32\svchost.exe[2212] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F80058
.text C:\WINDOWS\System32\svchost.exe[2212] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F80F9B
.text C:\WINDOWS\System32\svchost.exe[2212] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F80FC0
.text C:\WINDOWS\System32\svchost.exe[2212] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F800B2
.text C:\WINDOWS\System32\svchost.exe[2212] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F800A1
.text C:\WINDOWS\System32\svchost.exe[2212] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F80F23
.text C:\WINDOWS\System32\svchost.exe[2212] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F80F3E
.text C:\WINDOWS\System32\svchost.exe[2212] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F800D7
.text C:\WINDOWS\System32\svchost.exe[2212] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F80047
.text C:\WINDOWS\System32\svchost.exe[2212] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F80FE5
.text C:\WINDOWS\System32\svchost.exe[2212] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F80084
.text C:\WINDOWS\System32\svchost.exe[2212] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F8002C
.text C:\WINDOWS\System32\svchost.exe[2212] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F80011
.text C:\WINDOWS\System32\svchost.exe[2212] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F80F4F
.text C:\WINDOWS\System32\svchost.exe[2212] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00F70051
.text C:\WINDOWS\System32\svchost.exe[2212] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00F70FAF
.text C:\WINDOWS\System32\svchost.exe[2212] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00F70036
.text C:\WINDOWS\System32\svchost.exe[2212] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00F70025
.text C:\WINDOWS\System32\svchost.exe[2212] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00F70FCA
.text C:\WINDOWS\System32\svchost.exe[2212] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00F7000A
.text C:\WINDOWS\System32\svchost.exe[2212] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00F70FDB
.text C:\WINDOWS\System32\svchost.exe[2212] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [17, 89]
.text C:\WINDOWS\System32\svchost.exe[2212] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00F70062
.text C:\WINDOWS\System32\svchost.exe[2212] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 006C0F90
.text C:\WINDOWS\System32\svchost.exe[2212] msvcrt.dll!system 77C293C7 5 Bytes JMP 006C001B
.text C:\WINDOWS\System32\svchost.exe[2212] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 006C0FB5
.text C:\WINDOWS\System32\svchost.exe[2212] msvcrt.dll!_open 77C2F566 5 Bytes JMP 006C0FEF
.text C:\WINDOWS\System32\svchost.exe[2212] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 006C000A
.text C:\WINDOWS\System32\svchost.exe[2212] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 006C0FC6
.text C:\WINDOWS\System32\svchost.exe[2212] WS2_32.dll!socket 71AB4211 5 Bytes JMP 006B0FEF
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2716] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0041C130 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2716] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0041C1B0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\system32\dllhost.exe[3168] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F10000
.text C:\WINDOWS\system32\dllhost.exe[3168] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F10FAC
.text C:\WINDOWS\system32\dllhost.exe[3168] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F100AB
.text C:\WINDOWS\system32\dllhost.exe[3168] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F1008E
.text C:\WINDOWS\system32\dllhost.exe[3168] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F1007D
.text C:\WINDOWS\system32\dllhost.exe[3168] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F10FE5
.text C:\WINDOWS\system32\dllhost.exe[3168] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F10F80
.text C:\WINDOWS\system32\dllhost.exe[3168] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F100C6
.text C:\WINDOWS\system32\dllhost.exe[3168] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F10F39
.text C:\WINDOWS\system32\dllhost.exe[3168] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F10F54
.text C:\WINDOWS\system32\dllhost.exe[3168] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F100ED
.text C:\WINDOWS\system32\dllhost.exe[3168] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F1006C
.text C:\WINDOWS\system32\dllhost.exe[3168] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F1001B
.text C:\WINDOWS\system32\dllhost.exe[3168] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F10F9B
.text C:\WINDOWS\system32\dllhost.exe[3168] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F10051
.text C:\WINDOWS\system32\dllhost.exe[3168] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F10040
.text C:\WINDOWS\system32\dllhost.exe[3168] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F10F65
.text C:\WINDOWS\system32\dllhost.exe[3168] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00EF0F9C
.text C:\WINDOWS\system32\dllhost.exe[3168] msvcrt.dll!system 77C293C7 5 Bytes JMP 00EF0FB7
.text C:\WINDOWS\system32\dllhost.exe[3168] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00EF000C
.text C:\WINDOWS\system32\dllhost.exe[3168] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00EF0FEF
.text C:\WINDOWS\system32\dllhost.exe[3168] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00EF0027
.text C:\WINDOWS\system32\dllhost.exe[3168] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00EF0FD2
.text C:\WINDOWS\system32\dllhost.exe[3168] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00F00036
.text C:\WINDOWS\system32\dllhost.exe[3168] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00F00F9E
.text C:\WINDOWS\system32\dllhost.exe[3168] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00F0001B
.text C:\WINDOWS\system32\dllhost.exe[3168] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00F00FEF
.text C:\WINDOWS\system32\dllhost.exe[3168] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00F00FAF
.text C:\WINDOWS\system32\dllhost.exe[3168] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00F0000A
.text C:\WINDOWS\system32\dllhost.exe[3168] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00F00051
.text C:\WINDOWS\system32\dllhost.exe[3168] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00F00FCA
.text C:\WINDOWS\system32\dllhost.exe[3168] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00EE0000
.text C:\WINDOWS\system32\svchost.exe[3384] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00CA0FEF
.text C:\WINDOWS\system32\svchost.exe[3384] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00CA0082
.text C:\WINDOWS\system32\svchost.exe[3384] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00CA0F97
.text C:\WINDOWS\system32\svchost.exe[3384] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00CA0071
.text C:\WINDOWS\system32\svchost.exe[3384] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00CA0FA8
.text C:\WINDOWS\system32\svchost.exe[3384] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00CA002F
.text C:\WINDOWS\system32\svchost.exe[3384] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00CA0F57
.text C:\WINDOWS\system32\svchost.exe[3384] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00CA009D
.text C:\WINDOWS\system32\svchost.exe[3384] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00CA0F17
.text C:\WINDOWS\system32\svchost.exe[3384] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00CA00BA
.text C:\WINDOWS\system32\svchost.exe[3384] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00CA00CB
.text C:\WINDOWS\system32\svchost.exe[3384] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00CA0040
.text C:\WINDOWS\system32\svchost.exe[3384] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00CA0FD4
.text C:\WINDOWS\system32\svchost.exe[3384] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00CA0F72
.text C:\WINDOWS\system32\svchost.exe[3384] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00CA0014
.text C:\WINDOWS\system32\svchost.exe[3384] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00CA0FC3
.text C:\WINDOWS\system32\svchost.exe[3384] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00CA0F3C
.text C:\WINDOWS\system32\svchost.exe[3384] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00C90025
.text C:\WINDOWS\system32\svchost.exe[3384] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00C9006C
.text C:\WINDOWS\system32\svchost.exe[3384] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00C90FD4
.text C:\WINDOWS\system32\svchost.exe[3384] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00C9000A
.text C:\WINDOWS\system32\svchost.exe[3384] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00C9005B
.text C:\WINDOWS\system32\svchost.exe[3384] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00C90FE5
.text C:\WINDOWS\system32\svchost.exe[3384] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00C90FAF
.text C:\WINDOWS\system32\svchost.exe[3384] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes JMP C89FEDE5
.text C:\WINDOWS\system32\svchost.exe[3384] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00C90036
.text C:\WINDOWS\system32\svchost.exe[3384] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00C80042
.text C:\WINDOWS\system32\svchost.exe[3384] msvcrt.dll!system 77C293C7 5 Bytes JMP 00C80FB7
.text C:\WINDOWS\system32\svchost.exe[3384] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00C80FE3
.text C:\WINDOWS\system32\svchost.exe[3384] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00C8000C
.text C:\WINDOWS\system32\svchost.exe[3384] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00C80FC8
.text C:\WINDOWS\system32\svchost.exe[3384] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00C8001D
.text C:\WINDOWS\system32\svchost.exe[3384] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00C70FE5
.text C:\WINDOWS\system32\svchost.exe[3396] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BD0FE5
.text C:\WINDOWS\system32\svchost.exe[3396] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BD0F54
.text C:\WINDOWS\system32\svchost.exe[3396] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BD0053
.text C:\WINDOWS\system32\svchost.exe[3396] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BD0F79
.text C:\WINDOWS\system32\svchost.exe[3396] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BD0F8A
.text C:\WINDOWS\system32\svchost.exe[3396] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BD0FA5
.text C:\WINDOWS\system32\svchost.exe[3396] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BD008B
.text C:\WINDOWS\system32\svchost.exe[3396] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BD0F43
.text C:\WINDOWS\system32\svchost.exe[3396] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BD00C1
.text C:\WINDOWS\system32\svchost.exe[3396] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BD0F28
.text C:\WINDOWS\system32\svchost.exe[3396] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BD0F0D
.text C:\WINDOWS\system32\svchost.exe[3396] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BD002C
.text C:\WINDOWS\system32\svchost.exe[3396] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BD0000
.text C:\WINDOWS\system32\svchost.exe[3396] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BD0064
.text C:\WINDOWS\system32\svchost.exe[3396] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BD0FC0
.text C:\WINDOWS\system32\svchost.exe[3396] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BD0011
.text C:\WINDOWS\system32\svchost.exe[3396] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BD00A6
.text C:\WINDOWS\system32\svchost.exe[3396] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00BC0FD4
.text C:\WINDOWS\system32\svchost.exe[3396] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00BC0F8D
.text C:\WINDOWS\system32\svchost.exe[3396] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00BC0FEF
.text C:\WINDOWS\system32\svchost.exe[3396] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00BC001B
.text C:\WINDOWS\system32\svchost.exe[3396] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00BC0054
.text C:\WINDOWS\system32\svchost.exe[3396] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00BC0000
.text C:\WINDOWS\system32\svchost.exe[3396] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00BC0FB2
.text C:\WINDOWS\system32\svchost.exe[3396] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [DC, 88]
.text C:\WINDOWS\system32\svchost.exe[3396] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00BC0FC3
.text C:\WINDOWS\system32\svchost.exe[3396] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00BB0FCF
.text C:\WINDOWS\system32\svchost.exe[3396] msvcrt.dll!system 77C293C7 5 Bytes JMP 00BB005A
.text C:\WINDOWS\system32\svchost.exe[3396] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00BB002E
.text C:\WINDOWS\system32\svchost.exe[3396] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00BB0000
.text C:\WINDOWS\system32\svchost.exe[3396] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00BB0049
.text C:\WINDOWS\system32\svchost.exe[3396] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00BB0011
.text C:\WINDOWS\system32\svchost.exe[3572] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01480FE5
.text C:\WINDOWS\system32\svchost.exe[3572] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01480F94
.text C:\WINDOWS\system32\svchost.exe[3572] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01480FA5
.text C:\WINDOWS\system32\svchost.exe[3572] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01480089
.text C:\WINDOWS\system32\svchost.exe[3572] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0148006C
.text C:\WINDOWS\system32\svchost.exe[3572] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01480036
.text C:\WINDOWS\system32\svchost.exe[3572] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 014800B5
.text C:\WINDOWS\system32\svchost.exe[3572] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 0148009A
.text C:\WINDOWS\system32\svchost.exe[3572] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01480F1C
.text C:\WINDOWS\system32\svchost.exe[3572] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01480F2D
.text C:\WINDOWS\system32\svchost.exe[3572] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01480F0B
.text C:\WINDOWS\system32\svchost.exe[3572] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01480051
.text C:\WINDOWS\system32\svchost.exe[3572] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01480FD4
.text C:\WINDOWS\system32\svchost.exe[3572] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01480F6F
.text C:\WINDOWS\system32\svchost.exe[3572] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01480025
.text C:\WINDOWS\system32\svchost.exe[3572] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 0148000A
.text C:\WINDOWS\system32\svchost.exe[3572] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01480F52
.text C:\WINDOWS\system32\svchost.exe[3572] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01470FB9
.text C:\WINDOWS\system32\svchost.exe[3572] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01470F83
.text C:\WINDOWS\system32\svchost.exe[3572] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0147000A
.text C:\WINDOWS\system32\svchost.exe[3572] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01470FDE
.text C:\WINDOWS\system32\svchost.exe[3572] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01470040
.text C:\WINDOWS\system32\svchost.exe[3572] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01470FEF
.text C:\WINDOWS\system32\svchost.exe[3572] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 0147002F
.text C:\WINDOWS\system32\svchost.exe[3572] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01470F9E
.text C:\WINDOWS\system32\svchost.exe[3572] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01460FAD
.text C:\WINDOWS\system32\svchost.exe[3572] msvcrt.dll!system 77C293C7 5 Bytes JMP 01460FD2
.text C:\WINDOWS\system32\svchost.exe[3572] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01460027
.text C:\WINDOWS\system32\svchost.exe[3572] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01460000
.text C:\WINDOWS\system32\svchost.exe[3572] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01460042
.text C:\WINDOWS\system32\svchost.exe[3572] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01460FE3
.text C:\WINDOWS\system32\svchost.exe[3572] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01450000
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00260FEF
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00260F88
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00260FA3
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00260087
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00260FCA
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0026005B
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 002600BF
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00260F77
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00260F26
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00260F41
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 002600DA
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0026006C
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0026000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00260098
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00260036
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00260025
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00260F52
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00350FB9
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00350058
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00350FD4
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00350FE5
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00350047
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 0035000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00350036
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00350025
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E1DF4B9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E352046 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E351FC7 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E35200B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E351F53 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E351F8D C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] USER32.dll!DialogBoxIndirectParamA 7E456D7D 1 Byte [E9]
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E352081 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E2017EA C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00360044
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] msvcrt.dll!system 77C293C7 5 Bytes JMP 00360033
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00360FD4
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00360FEF
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00360FC3
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00360018
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] ole32.dll!OleLoadFromStream 77529C85 5 Bytes JMP 3E352243 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] WININET.dll!InternetOpenA 3D953081 5 Bytes JMP 01CF000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] WININET.dll!InternetOpenW 3D9536B1 5 Bytes JMP 01CF001B
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] WININET.dll!InternetOpenUrlA 3D956F5A 5 Bytes JMP 01CF0FE5
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] WININET.dll!InternetOpenUrlW 3D998439 5 Bytes JMP 01CF0036
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[6048] ws2_32.dll!socket 71AB4211 5 Bytes JMP 02980FE5
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 eabfiltr.sys (QLB PS/2 Keyboard filter driver/Hewlett-Packard Development Company, L.P.)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
Device \Driver\Disk \Device\Harddisk0\DR0 aksfridge.sys (Ancillary Function Driver/Aladdin Knowledge Systems Ltd.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
—- EOF - GMER 1.0.15 —-