Dipablo
Topic Starter
C:\WINDOWS\system32\kaziduwo.dll is one of the files mcafee finds but cannot delete. computer is running horribly slow, redirects webpages. MBAM wont run at all. Mcafee pops up every 2 seconds with the virus detection but cant delete the files. sometimes programs like minitab wont open at all.
again mbam wont open so i dont have that log file but here are the DDS adn the gmer logs.
GMER log
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-09 22:25:26
Windows 5.1.2600 Service Pack 3
Running: pls5rq81.exe; Driver: C:\DOCUME~1\pcarrill\LOCALS~1\Temp\awliapog.sys
GMER
—- System - GMER 1.0.15 —-
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateKey [0xF743BE52]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0xF741CCDE]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0xF741CED0]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteKey [0xF743C640]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteValueKey [0xF743C8F4]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwOpenKey [0xF743AB44]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwRenameKey [0xF743CD60]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwSetValueKey [0xF743C112]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0xF741C984]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0x9AA4322F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0x9AA43285]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0x9AA43243]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0x9AA4329B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0x9AA4326F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
—- Kernel code sections - GMER 1.0.15 —-
.text ntoskrnl.exe!ZwYieldExecution 80515A6A 7 Bytes JMP 9AA43273 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtCreateFile 8057C328 5 Bytes JMP 9AA43233 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnmapViewOfSection 8057DEF1 5 Bytes JMP 9AA4329F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtMapViewOfSection 8057E369 7 Bytes JMP 9AA43289 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwProtectVirtualMemory 80581889 7 Bytes JMP 9AA43247 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
? C:\WINDOWS\system32\drivers\atapi.sys The process cannot access the file because it is being used by another process.
—- User code sections - GMER 1.0.15 —-
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 036E0FEF
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 036E0076
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 036E0065
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 036E0054
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 036E0F97
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 036E001E
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 036E0F55
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 036E009D
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 036E00DD
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 036E0F44
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 036E00F8
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 036E0039
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 036E0FDE
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 036E0F66
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 036E0FB2
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 036E0FC3
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 036E00C2
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 036D0FC3
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 036D0F7C
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 036D000A
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 036D0FD4
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 036D0F8D
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 036D0FE5
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 036D0FA8
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [8D, 8B]
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 036D002F
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 036C0FA6
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] msvcrt.dll!system 77C293C7 5 Bytes JMP 036C0FB7
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 036C0FE3
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] msvcrt.dll!_open 77C2F566 5 Bytes JMP 036C0000
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 036C0FC8
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 036C001D
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] WS2_32.dll!socket 71AB4211 5 Bytes JMP 036A0FEF
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 036B0000
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 036B0FE5
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 036B0011
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 036B0022
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 015A0FEF
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 015A0F66
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 015A0F81
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 015A005B
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 015A004A
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 015A0FC3
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 015A0F38
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 015A0F55
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 015A0F16
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 015A00AF
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 015A00CA
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 015A0FB2
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 015A0FDE
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 015A0080
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 015A002F
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 015A000A
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 015A0F27
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01590FDE
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01590F97
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0159002F
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01590FEF
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01590FA8
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 0159000A
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01590FC3
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [79, 89] {JNS 0xffffffffffffff8b}
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0159004A
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01580FB9
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] msvcrt.dll!system 77C293C7 5 Bytes JMP 01580044
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01580029
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01580FEF
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01580FD4
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01580018
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] WS2_32.dll!socket 71AB4211 5 Bytes JMP 0156000A
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 01570FEF
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 01570014
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 01570025
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 01570040
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01080000
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01080F96
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 0108008B
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0108007A
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01080FBD
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0108004E
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 010800BC
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01080F74
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01080F3E
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 010800D7
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 010800E8
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0108005F
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01080011
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01080F85
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 0108003D
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 0108002C
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01080F59
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01070FCA
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01070F8D
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0107001B
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 0107000A
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01070F9E
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01070FEF
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01070FAF
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [27, 89]
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01070036
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01060FCF
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!system 77C293C7 5 Bytes JMP 0106005A
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0106002E
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01060000
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0106003F
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0106001D
.text C:\WINDOWS\system32\svchost.exe[920] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FF0FE5
.text C:\WINDOWS\system32\svchost.exe[920] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 01050FEF
.text C:\WINDOWS\system32\svchost.exe[920] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 01050000
.text C:\WINDOWS\system32\svchost.exe[920] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 01050011
.text C:\WINDOWS\system32\svchost.exe[920] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 0105002C
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00FD000A
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00FD0F72
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00FD0071
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00FD0054
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00FD0043
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00FD0FA8
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00FD0F35
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00FD0F50
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FD00C7
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FD0F24
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00FD0F13
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00FD0F97
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00FD0FEF
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00FD0F61
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00FD0FB9
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00FD0FDE
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00FD0098
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00070036
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00070F79
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00070FEF
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00070025
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00070F94
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 0007000A
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00070FA5
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [27, 88]
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00070FC0
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00060FBE
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!system 77C293C7 5 Bytes JMP 00060049
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0006001D
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00060FEF
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0006002E
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00060000
.text C:\WINDOWS\system32\services.exe[996] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00040000
.text C:\WINDOWS\system32\services.exe[996] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00050000
.text C:\WINDOWS\system32\services.exe[996] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00050011
.text C:\WINDOWS\system32\services.exe[996] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00050FD1
.text C:\WINDOWS\system32\services.exe[996] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00050022
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 016D0000
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 016D0F79
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 016D0F8A
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 016D0058
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 016D0F9B
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 016D0FCA
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 016D0F37
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 016D0F48
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 016D00AB
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 016D0F1C
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 016D00C6
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 016D0047
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 016D001B
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 016D007F
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 016D0FDB
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 016D002C
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 016D009A
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 016C002C
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 016C0FA8
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 016C001B
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 016C0FE5
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 016C0FB9
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 016C0000
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 016C0051
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 016C0FCA
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 016B003D
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!system 77C293C7 5 Bytes JMP 016B002C
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 016B0FC6
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!_open 77C2F566 5 Bytes JMP 016B0000
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 016B001B
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 016B0FE3
.text C:\WINDOWS\system32\lsass.exe[1008] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01690FE5
.text C:\WINDOWS\system32\lsass.exe[1008] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 016A0FEF
.text C:\WINDOWS\system32\lsass.exe[1008] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 016A000A
.text C:\WINDOWS\system32\lsass.exe[1008] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 016A0025
.text C:\WINDOWS\system32\lsass.exe[1008] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 016A0FD4
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 0109000A
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01090F61
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01090F7C
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0109004A
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01090F8D
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01090FB9
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01090F35
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01090F46
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01090098
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01090F09
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01090EE4
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01090FA8
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0109001B
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01090071
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01090FD4
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01090FEF
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01090F24
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01080FC0
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01080F8A
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01080011
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01080000
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01080047
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01080FE5
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 01080036
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01080FAF
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01070FA6
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!system 77C293C7 5 Bytes JMP 01070FB7
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01070FE3
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01070000
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01070FC8
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0107001D
.text C:\WINDOWS\system32\svchost.exe[1188] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01050FE5
.text C:\WINDOWS\system32\svchost.exe[1188] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 01060000
.text C:\WINDOWS\system32\svchost.exe[1188] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 01060FEF
.text C:\WINDOWS\system32\svchost.exe[1188] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 01060025
.text C:\WINDOWS\system32\svchost.exe[1188] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 01060036
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 011B0000
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 011B0F66
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 011B005B
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 011B004A
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 011B0F8D
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 011B0F9E
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 011B0087
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 011B0F4B
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 011B00C7
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 011B00A2
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 011B00D8
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 011B002F
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 011B0FE5
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 011B0076
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 011B0FAF
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 011B0FD4
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 011B0F24
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0112002F
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01120F83
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01120FD4
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01120FEF
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01120F9E
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01120000
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 01120040
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01120FC3
.text C:\WINDOWS\system32\svchost.exe[1264] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01110FA8
.text C:\WINDOWS\system32\svchost.exe[1264] msvcrt.dll!system 77C293C7 5 Bytes JMP 01110033
.text C:\WINDOWS\system32\svchost.exe[1264] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01110018
.text C:\WINDOWS\system32\svchost.exe[1264] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01110FEF
.text C:\WINDOWS\system32\svchost.exe[1264] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01110FC3
.text C:\WINDOWS\system32\svchost.exe[1264] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01110FDE
.text C:\WINDOWS\system32\svchost.exe[1264] WS2_32.dll!socket 71AB4211 5 Bytes JMP 010F0FE5
.text C:\WINDOWS\system32\svchost.exe[1264] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 01100000
.text C:\WINDOWS\system32\svchost.exe[1264] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 0110001B
.text C:\WINDOWS\system32\svchost.exe[1264] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 01100036
.text C:\WINDOWS\system32\svchost.exe[1264] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 01100FEF
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02C20FEF
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02C20062
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02C2003D
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02C20F63
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02C2002C
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02C20FAF
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02C20F2B
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02C2007D
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02C20EEB
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 02C2008E
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02C2009F
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02C20F94
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02C20FD4
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02C20F52
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02C2001B
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02C2000A
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 02C20F1A
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01DD002C
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01DD0062
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01DD0FDB
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01DD0011
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01DD0051
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01DD0000
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01DD0FAF
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [FD, 89]
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01DD0FCA
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01DC0F8B
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!system 77C293C7 5 Bytes JMP 01DC0F9C
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01DC0FC8
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01DC0000
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01DC0FB7
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01DC0FE3
.text C:\WINDOWS\System32\svchost.exe[1312] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01DA0FE5
.text C:\WINDOWS\System32\svchost.exe[1312] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 01DB0000
.text C:\WINDOWS\System32\svchost.exe[1312] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 01DB0FE5
.text C:\WINDOWS\System32\svchost.exe[1312] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 01DB0011
.text C:\WINDOWS\System32\svchost.exe[1312] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 01DB0022
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00E00FE5
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00E00F4B
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00E00036
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00E00F5C
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00E00F79
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00E00025
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00E00F0E
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00E00F1F
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E00067
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E00ECE
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00E00078
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00E00F9E
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00E0000A
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00E00F3A
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00E00FB9
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00E00FD4
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00E00EE9
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00DF0F9E
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00DF0F68
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00DF0FB9
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00DF0FCA
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00DF0025
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00DF0FEF
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00DF0F83
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [FF, 88]
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00DF000A
.text C:\WINDOWS\system32\svchost.exe[1392] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 00F6000A
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00DE0F8B
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!system 77C293C7 5 Bytes JMP 00DE0FA6
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00DE0FD2
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00DE0000
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00DE0FB7
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00DE0FE3
.text C:\WINDOWS\system32\svchost.exe[1392] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00DC0FEF
.text C:\WINDOWS\system32\svchost.exe[1392] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00DD0000
.text C:\WINDOWS\system32\svchost.exe[1392] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00DD0FEF
.text C:\WINDOWS\system32\svchost.exe[1392] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00DD0FCA
.text C:\WINDOWS\system32\svchost.exe[1392] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00DD0FB9
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F20FEF
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F2008C
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F2007B
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F20FA1
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F20FBC
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F20FCD
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F20F5F
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F200A7
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F20F29
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F20F44
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F200DD
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F2005E
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F2000A
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F20F7C
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F2002F
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F20FDE
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F200B8
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00F10FEF
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00F1006C
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00F10040
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00F10025
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00F10FB9
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00F10000
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00F10FD4
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [11, 89]
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00F1005B
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00F00FAB
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!system 77C293C7 5 Bytes JMP 00F00FBC
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00F00FCD
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00F00FEF
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00F00022
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00F00FDE
.text C:\WINDOWS\system32\svchost.exe[1524] WS2_32.dll!socket 71AB4211 5 Bytes JMP 001B0000
.text C:\WINDOWS\system32\svchost.exe[1524] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00EF0000
.text C:\WINDOWS\system32\svchost.exe[1524] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00EF0011
.text C:\WINDOWS\system32\svchost.exe[1524] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00EF0022
.text C:\WINDOWS\system32\svchost.exe[1524] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00EF0FD1
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F80FEF
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F800A1
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F80086
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F80069
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F80058
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F8002C
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F80F7E
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F80F8F
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F80F48
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F800E1
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F80F37
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F8003D
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F80FDE
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F800BC
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F8001B
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F8000A
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F80F59
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00EA0025
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00EA005B
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00EA0014
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00EA0FDE
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00EA0040
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00EA0FEF
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00EA0F9E
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [0A, 89]
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00EA0FAF
.text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00E90FCA
.text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!system 77C293C7 5 Bytes JMP 00E90055
.text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00E90029
.text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00E90000
.text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00E9003A
.text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00E90FEF
.text C:\WINDOWS\system32\svchost.exe[1956] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00E70000
.text C:\WINDOWS\system32\svchost.exe[1956] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00E80000
.text C:\WINDOWS\system32\svchost.exe[1956] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00E80FEF
.text C:\WINDOWS\system32\svchost.exe[1956] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00E80FD4
.text C:\WINDOWS\system32\svchost.exe[1956] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00E80025
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01360FE5
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01360049
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01360038
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01360F5E
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0136001B
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01360F94
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01360089
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 0136006E
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01360F01
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01360F1C
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01360EF0
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01360F79
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01360FD4
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreatePipe 7C81D83F 1 Byte [E9]
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01360F43
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01360FA5
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01360000
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 0136009A
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01350040
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01350087
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01350025
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 0135000A
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01350076
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01350FEF
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01350FCA
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [55, 89]
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0135005B
.text C:\WINDOWS\System32\svchost.exe[3528] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00FF0F92
.text C:\WINDOWS\System32\svchost.exe[3528] msvcrt.dll!system 77C293C7 5 Bytes JMP 00FF001D
.text C:\WINDOWS\System32\svchost.exe[3528] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00FF0FC8
.text C:\WINDOWS\System32\svchost.exe[3528] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00FF0000
.text C:\WINDOWS\System32\svchost.exe[3528] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00FF0FB7
.text C:\WINDOWS\System32\svchost.exe[3528] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00FF0FE3
.text C:\WINDOWS\System32\svchost.exe[3528] WS2_32.dll!socket 71AB4211 5 Bytes JMP 001A0000
.text C:\WINDOWS\System32\svchost.exe[3528] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 001B0000
.text C:\WINDOWS\System32\svchost.exe[3528] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 001B0011
.text C:\WINDOWS\System32\svchost.exe[3528] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 001B0022
.text C:\WINDOWS\System32\svchost.exe[3528] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 001B0FD1
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02A80FEF
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02A8004D
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02A80F58
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02A80F69
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02A80F86
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02A80FA8
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02A80F36
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02A80F47
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02A80EF6
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02A80F97
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02A80FD4
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02A80068
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02A8000A
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02A80FB9
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 02A80099
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 02A70FE5
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 02A70FAF
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 02A70036
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 02A7001B
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 02A70FC0
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 02A7000A
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 02A70062
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 02A70047
.text C:\WINDOWS\Explorer.EXE[3836] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 02A6005A
.text C:\WINDOWS\Explorer.EXE[3836] msvcrt.dll!system 77C293C7 5 Bytes JMP 02A60049
.text C:\WINDOWS\Explorer.EXE[3836] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 02A60FD9
.text C:\WINDOWS\Explorer.EXE[3836] msvcrt.dll!_open 77C2F566 5 Bytes JMP 02A60000
.text C:\WINDOWS\Explorer.EXE[3836] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 02A60038
.text C:\WINDOWS\Explorer.EXE[3836] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 02A6001D
.text C:\WINDOWS\Explorer.EXE[3836] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 02A50FEF
.text C:\WINDOWS\Explorer.EXE[3836] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 02A50FCA
.text C:\WINDOWS\Explorer.EXE[3836] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 02A50FB9
.text C:\WINDOWS\Explorer.EXE[3836] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 02A50014
.text C:\WINDOWS\Explorer.EXE[3836] WS2_32.dll!socket 71AB4211 5 Bytes JMP 02A40FE5
—- User IAT/EAT - GMER 1.0.15 —-
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [7C88420A] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [7C88420A] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [7C88420A] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [7C88420A] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [7C88420A] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [7C88420A] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [7C88420A] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\Explorer.EXE [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
—- Registry - GMER 1.0.15 —-
Reg HKLM\SOFTWARE\Classes\CLSID\{6CB39D60-4086-B7F8-381D8F903EAF6AF0}\{AFC2635D-FADA-3E20-D0B5B6B6E250D71B}\{28C204A2-D9FA-6C6E-1B551E281BAD6C81}
Reg HKLM\SOFTWARE\Classes\CLSID\{6CB39D60-4086-B7F8-381D8F903EAF6AF0}\{AFC2635D-FADA-3E20-D0B5B6B6E250D71B}\{28C204A2-D9FA-6C6E-1B551E281BAD6C81}@{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1 0x01 0x00 0x01 0x00 …
Reg HKLM\SOFTWARE\Classes\CLSID\{A1146105-B145-D547-791CC80E83BF21B6}\{DC78455E-4161-0768-1856DB98A0FFD8AF}\{619B65F9-9B50-CD99-3F29A63495E25D6C}
Reg HKLM\SOFTWARE\Classes\CLSID\{A1146105-B145-D547-791CC80E83BF21B6}\{DC78455E-4161-0768-1856DB98A0FFD8AF}\{619B65F9-9B50-CD99-3F29A63495E25D6C}@RA4KGUJC6T6LBNJRIDQ63C2L6C1 0x01 0x00 0x01 0x00 …
—- EOF - GMER 1.0.15 —-
DDS log
DDS (Ver_09-12-01.01) - NTFSx86 NETWORK
Run by [removed] at 6:28:29.32 on Wed 02/10/2010
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3536.2827 [GMT -7:00]
AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\pcarrill\Desktop\dds.pif
============== Pseudo HJT Report ===============
uWindow Title = Windows Internet Explorer provided by Mosaic
uStart Page = hxxp://employee.mosaicco.com/
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_11\bin\ssv.dll
BHO: ADC PlugIn: {77dc0baa-3235-4ba9-8be8-aa9eb678fa02} - c:\program files\adc32.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan enterprise\scriptcl.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
uRun: [ISUSPM] "c:\documents and settings\all users\application data\macrovision\flexnet connect\6\ISUSPM.exe" -scheduler
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE
mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\UdaterUI.exe" /StartedFromRunKey
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
mRun: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Sfopikoq] rundll32.exe "c:\windows\ohivukov.dll",Startup
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [milepihew] Rundll32.exe "c:\windows\system32\pokitiwi.dll",a
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
dRun: [Communicator] "c:\program files\microsoft office communicator\Communicator.exe"
mPolicies-explorer: NoWelcomeScreen = 1 (0x1)
mPolicies-system: EnableLUA = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_11\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: buy-internet-security10.com
Trusted Zone: buy-internetsecurity10.com
Trusted Zone: buy-is2010.com
Trusted Zone: cargill.com\hrdirect
Trusted Zone: cargill.com\smaccess.ds
Trusted Zone: is-soft-download.com
Trusted Zone: is-software-download.com
Trusted Zone: is10-soft-download.com
Trusted Zone: mosaicco.com\alsharepoint
Trusted Zone: mosaicco.com\it
Trusted Zone: mosaicco.com\mgts
Trusted Zone: mosaicco.com\ps1.pmo
Trusted Zone: mosaicco.com\sites.project
Trusted Zone: mosaicco.com\wdsharepoint
Trusted Zone: mosaicco.com\webmail
Trusted Zone: mosaicco.com\www.pmo
Trusted Zone: wdwebprd2
Trusted Zone: buy-internet-security10.com
Trusted Zone: buy-internetsecurity10.com
Trusted Zone: buy-is2010.com
Trusted Zone: cargill.com\hrdirect
Trusted Zone: cargill.com\smaccess.ds
Trusted Zone: mosaicco.com\alsharepoint
Trusted Zone: mosaicco.com\it
Trusted Zone: mosaicco.com\mgts
Trusted Zone: mosaicco.com\ps1.pmo
Trusted Zone: mosaicco.com\sites.project
Trusted Zone: mosaicco.com\wdsharepoint
Trusted Zone: mosaicco.com\webmail
Trusted Zone: mosaicco.com\www.pmo
Trusted Zone: wdwebprd2
DPF: {2BCDB465-81F9-41CB-832C-8037A4064446} - hxxps://vpn2.mosaicco.com/vdesk/terminal/urxvpn.cab#version=6031,2009,1010,313
DPF: {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} - hxxps://vpn2.mosaicco.com/vdesk/terminal/f5tunsrv.cab#version=6031,2009,1010,310
DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} - hxxps://vpn2.mosaicco.com/vdesk/terminal/InstallerControl.cab#version=6031,2009,1010,0312
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1243366726630
DPF: {6C275925-A1ED-4DD2-9CEE-9823F5FDAA10} - hxxps://vpn1.mosaicco.com/vdesk/terminal/urTermProxy.cab#version=6020,2007,1001,2136
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1243366697098
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} - hxxps://vpn2.mosaicco.com/vdesk/terminal/urxshost.cab#version=6031,2009,1010,308
DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} - hxxps://vpn2.mosaicco.com/vdesk/terminal/urxhost.cab#version=6031,2009,1010,304
Handler: saphtmlp - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\program files\sap\frontend\sapgui\SAPHTMLP.DLL
Handler: sapr3 - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\program files\sap\frontend\sapgui\SAPHTMLP.DLL
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\windows\system32\tusugemo.dll kaziduwo.dll c:\windows\system32\pokitiwi.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: penedahet - {7d7e192b-e486-4107-a9c0-ec81e981a533} - c:\windows\system32\tusugemo.dll
SSODL: vajazozoh - {76c938f6-8593-41a0-ac23-5fa8d8ddf15f} - c:\windows\system32\pokitiwi.dll
STS: mujuzedij: {7d7e192b-e486-4107-a9c0-ec81e981a533} - c:\windows\system32\tusugemo.dll
STS: tokatiluy: {76c938f6-8593-41a0-ac23-5fa8d8ddf15f} - c:\windows\system32\pokitiwi.dll
LSA: Notification Packages = scecli deqmabFi.dll jivobumo.dll
Hosts: 216.203.33.144 vpn1.mosaicco.com #ADDED BY F5 NETWORKS SSL TUNNEL - ORIGINAL RECORD#
Hosts: [removed] vpn1 #ADDED BY F5 NETWORKS SSL TUNNEL - ORIGINAL RECORD#
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\pcarrill\applic~1\mozilla\firefox\profiles\xia7xztq.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://mail.live.com/default.aspx?wa=wsignin1.0
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - prefs.js: network.proxy.type - 2
FF - plugin: c:\documents and settings\pcarrill\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\pcarrill\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJava11.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJava12.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJava13.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJava14.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJava32.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJPI150_11.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPOJI610.dll
FF - HiddenExtension: XULRunner: {70660533-012F-4BC3-A5DA-BA8C628D8037} - c:\documents and settings\pcarrill\local settings\application data\{70660533-012F-4BC3-A5DA-BA8C628D8037}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-2-1 207792]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [2008-12-31 244368]
R3 urvpndrv;F5 Networks VPN Adapter;c:\windows\system32\drivers\covpndrv.sys [2009-10-9 33920]
S1 mferkdk;VSCore mferkdk;c:\program files\mcafee\virusscan enterprise\mferkdk.sys [2009-1-27 31848]
S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\spyware doctor\bdt\BDTUpdateService.exe [2010-2-1 112592]
S2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2008-9-25 103744]
S2 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\Mcshield.exe [2009-1-27 144704]
S2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\VsTskMgr.exe [2009-1-27 54608]
S3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [2009-11-16 108160]
S3 cvusbdrv;Broadcom USH CV;c:\windows\system32\drivers\cvusbdrv.sys [2008-12-31 32808]
S3 f5ipfw;F5 Networks StoneWall Filter;c:\windows\system32\drivers\urfltw2k.sys [2009-12-2 10752]
S3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2009-11-16 110080]
S3 mfeavfk;McAfee Inc.;c:\windows\system32\drivers\mfeavfk.sys [2008-9-25 73512]
S3 mfebopk;McAfee Inc.;c:\windows\system32\drivers\mfebopk.sys [2008-9-25 34408]
S3 mfehidk;McAfee Inc.;c:\windows\system32\drivers\mfehidk.sys [2008-9-25 177864]
S3 OracleOraHome81ClientCache;OracleOraHome81ClientCache;c:\oracle\ora81\bin\onrsd.exe –> c:\oracle\ora81\bin\ONRSD.EXE [?]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2010-2-1 359624]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2010-2-1 1141712]
=============== Created Last 30 ================
2010-02-08 13:37:25 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-08 13:37:24 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-08 13:37:24 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-07 17:21:04 0 —-a-w- c:\windows\Yfezuqol.bin
2010-02-07 17:21:02 120 —-a-w- c:\windows\Twefoboxebod.dat
2010-02-07 13:13:03 0 d—–w- c:\program files\schtml
2010-02-07 13:08:35 962560 —-a-w- c:\program files\adc32.dll
2010-02-07 13:08:33 56 —-a-w- c:\program files\wp4.dat
2010-02-07 13:08:33 4 —-a-w- c:\program files\wp3.dat
2010-02-07 13:08:33 36 —-a-w- c:\program files\skynet.dat
2010-02-07 13:08:25 0 d—–w- c:\program files\Your PC Protector
2010-02-02 18:56:16 0 —-a-w- c:\windows\system32\29358.exe
2010-02-02 18:36:15 0 —-a-w- c:\windows\system32\11478.exe
2010-02-02 18:16:14 0 —-a-w- c:\windows\system32\15724.exe
2010-02-02 17:56:13 0 —-a-w- c:\windows\system32\19169.exe
2010-02-02 04:31:07 767952 —-a-w- c:\windows\BDTSupport.dll
2010-02-02 04:31:06 882 —-a-w- c:\windows\RegSDImport.xml
2010-02-02 04:31:06 879 —-a-w- c:\windows\RegISSImport.xml
2010-02-02 04:31:06 165840 —-a-w- c:\windows\PCTBDRes.dll
2010-02-02 04:31:06 1652688 —-a-w- c:\windows\PCTBDCore.dll
2010-02-02 04:31:06 1640400 —-a-w- c:\windows\PCTBDCore.dll.old
2010-02-02 04:31:06 149456 —-a-w- c:\windows\SGDetectionTool.dll
2010-02-02 04:31:06 131 —-a-w- c:\windows\IDB.zip
2010-02-02 04:31:06 1152444 —-a-w- c:\windows\UDB.zip
2010-02-02 04:29:09 7387 —-a-w- c:\windows\system32\drivers\pctgntdi.cat
2010-02-02 04:29:09 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-02-02 04:29:07 7412 —-a-w- c:\windows\system32\drivers\PCTAppEvent.cat
2010-02-02 04:29:07 7383 —-a-w- c:\windows\system32\drivers\pctcore.cat
2010-02-02 04:29:07 207792 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2010-02-02 04:29:06 87784 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-02-02 04:29:00 7383 —-a-w- c:\windows\system32\drivers\pctplsg.cat
2010-02-02 04:29:00 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2010-02-02 04:28:46 0 d—–w- c:\program files\Spyware Doctor
2010-02-02 04:28:46 0 d—–w- c:\program files\common files\PC Tools
2010-02-02 04:28:46 0 d—–w- c:\docume~1\pcarrill\applic~1\PC Tools
2010-02-02 04:28:46 0 d—–w- c:\docume~1\alluse~1\applic~1\PC Tools
2010-02-02 04:01:35 0 —-a-w- c:\windows\system32\26500.exe
2010-02-02 03:41:34 0 —-a-w- c:\windows\system32\6334.exe
2010-02-02 03:21:34 0 —-a-w- c:\windows\system32\18467.exe
2010-02-02 03:01:33 0 —-a-w- c:\windows\system32\41.exe
2010-01-26 16:00:34 0 d—–w- c:\docume~1\pcarrill\applic~1\Macrovision
2010-01-25 20:15:02 0 d—–w- c:\windows\system32\E177E04D548C4006A465EEB92D3DE021
2010-01-25 20:14:56 65 —-a-w- c:\windows\minitab.ini
2010-01-25 20:14:05 0 d—–w- c:\program files\Minitab 15
2010-01-21 21:04:40 0 d—–w- c:\windows\system32\rc
2010-01-21 20:42:38 0 d—–w- c:\docume~1\pcarrill\applic~1\Malwarebytes
2010-01-21 19:07:21 0 d—–w- c:\program files\Microsoft Visual Studio 8
2010-01-21 18:59:57 79872 -c—-w- c:\windows\system32\dllcache\raschap.dll
2010-01-21 18:59:57 66560 -c–a-w- c:\windows\system32\dllcache\tdc.ocx
2010-01-21 18:59:57 149504 -c—-w- c:\windows\system32\dllcache\rastls.dll
2010-01-21 18:59:55 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2010-01-21 18:59:54 270336 -c—-w- c:\windows\system32\dllcache\oakley.dll
2010-01-21 04:57:21 0 d—–w- c:\program files\uTorrent
2010-01-21 04:57:14 0 d—–w- c:\docume~1\pcarrill\applic~1\uTorrent
2010-01-20 23:58:10 0 d—–w- c:\program files\True Sword 5
2010-01-20 21:52:11 0 d—–w- c:\program files\RADO Removal Tool[1]
2010-01-14 05:50:17 79040 —ha-w- c:\windows\system32\mlfcache.dat
==================== Find3M ====================
2010-02-07 13:08:54 9 —-a-w- c:\program files\nuar.old
2010-01-26 15:57:47 2725698 —ha-w- c:\docume~1\pcarrill\applic~1\logs.dat
2010-01-10 02:55:10 21928 —-a-w- c:\windows\fonts\Princess_Sparkle_Font_by_darnfancylettuce.ttf
2010-01-10 02:52:17 7808 —-a-w- c:\windows\fonts\meow_font_by_pinktooney7.ttf
2009-12-27 04:07:48 126148 —-a-w- c:\windows\fonts\Sony_Sketch_Bold_205.ttf
2009-12-16 04:58:38 50772 —-a-w- c:\windows\fonts\sunshineinmysoul.ttf
2009-12-06 16:09:14 17680 —-a-w- c:\windows\fonts\heyyyy.ttf
2009-11-16 20:49:08 402006 —-a-w- c:\windows\system32\ScreenSaverMosaic.scr
1601-01-01 00:03:28 93696 –sha-w- c:\windows\system32\duzurosa.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\fivajubu.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\fivefoda.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\fodituva.dll
1601-01-01 00:03:28 93696 –sha-w- c:\windows\system32\gedoneno.dll
1601-01-01 00:03:52 53760 –sha-w- c:\windows\system32\jivobumo.dll
1601-01-01 00:03:52 53760 –sha-w- c:\windows\system32\kaziduwo.dll
1601-01-01 00:03:28 94208 –sha-w- c:\windows\system32\kiwatehu.dll
1601-01-01 00:03:28 93184 –sha-w- c:\windows\system32\lemutuja.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\nepihene.dll
1601-01-01 00:03:28 93696 –sha-w- c:\windows\system32\pokitiwi.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\pubonepo.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\selulisa.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\telariva.dll
1601-01-01 00:03:28 42496 –sha-w- c:\windows\system32\tesegigo.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\tifunalo.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\wopeneda.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\yehuruma.dll
============= FINISH: 6:30:09.85 ===============
thank you very much for you help.
again mbam wont open so i dont have that log file but here are the DDS adn the gmer logs.
GMER log
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-09 22:25:26
Windows 5.1.2600 Service Pack 3
Running: pls5rq81.exe; Driver: C:\DOCUME~1\pcarrill\LOCALS~1\Temp\awliapog.sys
GMER
—- System - GMER 1.0.15 —-
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateKey [0xF743BE52]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0xF741CCDE]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0xF741CED0]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteKey [0xF743C640]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteValueKey [0xF743C8F4]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwOpenKey [0xF743AB44]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwRenameKey [0xF743CD60]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwSetValueKey [0xF743C112]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0xF741C984]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0x9AA4322F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0x9AA43285]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0x9AA43243]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0x9AA4329B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0x9AA4326F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
—- Kernel code sections - GMER 1.0.15 —-
.text ntoskrnl.exe!ZwYieldExecution 80515A6A 7 Bytes JMP 9AA43273 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtCreateFile 8057C328 5 Bytes JMP 9AA43233 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwUnmapViewOfSection 8057DEF1 5 Bytes JMP 9AA4329F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!NtMapViewOfSection 8057E369 7 Bytes JMP 9AA43289 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntoskrnl.exe!ZwProtectVirtualMemory 80581889 7 Bytes JMP 9AA43247 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
? C:\WINDOWS\system32\drivers\atapi.sys The process cannot access the file because it is being used by another process.
—- User code sections - GMER 1.0.15 —-
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 036E0FEF
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 036E0076
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 036E0065
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 036E0054
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 036E0F97
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 036E001E
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 036E0F55
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 036E009D
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 036E00DD
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 036E0F44
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 036E00F8
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 036E0039
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 036E0FDE
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 036E0F66
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 036E0FB2
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 036E0FC3
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 036E00C2
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 036D0FC3
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 036D0F7C
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 036D000A
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 036D0FD4
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 036D0F8D
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 036D0FE5
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 036D0FA8
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [8D, 8B]
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 036D002F
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 036C0FA6
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] msvcrt.dll!system 77C293C7 5 Bytes JMP 036C0FB7
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 036C0FE3
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] msvcrt.dll!_open 77C2F566 5 Bytes JMP 036C0000
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 036C0FC8
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 036C001D
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] WS2_32.dll!socket 71AB4211 5 Bytes JMP 036A0FEF
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 036B0000
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 036B0FE5
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 036B0011
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[332] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 036B0022
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 015A0FEF
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 015A0F66
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 015A0F81
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 015A005B
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 015A004A
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 015A0FC3
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 015A0F38
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 015A0F55
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 015A0F16
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 015A00AF
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 015A00CA
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 015A0FB2
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 015A0FDE
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 015A0080
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 015A002F
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 015A000A
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 015A0F27
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01590FDE
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01590F97
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0159002F
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01590FEF
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01590FA8
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 0159000A
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01590FC3
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [79, 89] {JNS 0xffffffffffffff8b}
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0159004A
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01580FB9
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] msvcrt.dll!system 77C293C7 5 Bytes JMP 01580044
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01580029
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01580FEF
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01580FD4
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01580018
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] WS2_32.dll!socket 71AB4211 5 Bytes JMP 0156000A
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 01570FEF
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 01570014
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 01570025
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[672] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 01570040
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01080000
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01080F96
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 0108008B
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0108007A
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01080FBD
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0108004E
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 010800BC
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01080F74
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01080F3E
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 010800D7
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 010800E8
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 0108005F
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01080011
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01080F85
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 0108003D
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 0108002C
.text C:\WINDOWS\system32\svchost.exe[920] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01080F59
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01070FCA
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01070F8D
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0107001B
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 0107000A
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01070F9E
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01070FEF
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01070FAF
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [27, 89]
.text C:\WINDOWS\system32\svchost.exe[920] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01070036
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01060FCF
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!system 77C293C7 5 Bytes JMP 0106005A
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0106002E
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01060000
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0106003F
.text C:\WINDOWS\system32\svchost.exe[920] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0106001D
.text C:\WINDOWS\system32\svchost.exe[920] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FF0FE5
.text C:\WINDOWS\system32\svchost.exe[920] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 01050FEF
.text C:\WINDOWS\system32\svchost.exe[920] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 01050000
.text C:\WINDOWS\system32\svchost.exe[920] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 01050011
.text C:\WINDOWS\system32\svchost.exe[920] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 0105002C
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00FD000A
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00FD0F72
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00FD0071
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00FD0054
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00FD0043
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00FD0FA8
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00FD0F35
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00FD0F50
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FD00C7
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FD0F24
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00FD0F13
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00FD0F97
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00FD0FEF
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00FD0F61
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00FD0FB9
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00FD0FDE
.text C:\WINDOWS\system32\services.exe[996] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00FD0098
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00070036
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00070F79
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00070FEF
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00070025
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00070F94
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 0007000A
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00070FA5
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [27, 88]
.text C:\WINDOWS\system32\services.exe[996] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00070FC0
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00060FBE
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!system 77C293C7 5 Bytes JMP 00060049
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0006001D
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00060FEF
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0006002E
.text C:\WINDOWS\system32\services.exe[996] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00060000
.text C:\WINDOWS\system32\services.exe[996] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00040000
.text C:\WINDOWS\system32\services.exe[996] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00050000
.text C:\WINDOWS\system32\services.exe[996] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00050011
.text C:\WINDOWS\system32\services.exe[996] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00050FD1
.text C:\WINDOWS\system32\services.exe[996] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00050022
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 016D0000
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 016D0F79
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 016D0F8A
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 016D0058
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 016D0F9B
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 016D0FCA
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 016D0F37
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 016D0F48
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 016D00AB
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 016D0F1C
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 016D00C6
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 016D0047
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 016D001B
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 016D007F
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 016D0FDB
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 016D002C
.text C:\WINDOWS\system32\lsass.exe[1008] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 016D009A
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 016C002C
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 016C0FA8
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 016C001B
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 016C0FE5
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 016C0FB9
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 016C0000
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 016C0051
.text C:\WINDOWS\system32\lsass.exe[1008] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 016C0FCA
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 016B003D
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!system 77C293C7 5 Bytes JMP 016B002C
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 016B0FC6
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!_open 77C2F566 5 Bytes JMP 016B0000
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 016B001B
.text C:\WINDOWS\system32\lsass.exe[1008] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 016B0FE3
.text C:\WINDOWS\system32\lsass.exe[1008] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01690FE5
.text C:\WINDOWS\system32\lsass.exe[1008] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 016A0FEF
.text C:\WINDOWS\system32\lsass.exe[1008] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 016A000A
.text C:\WINDOWS\system32\lsass.exe[1008] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 016A0025
.text C:\WINDOWS\system32\lsass.exe[1008] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 016A0FD4
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 0109000A
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01090F61
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01090F7C
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0109004A
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01090F8D
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01090FB9
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01090F35
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01090F46
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01090098
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01090F09
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01090EE4
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01090FA8
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0109001B
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01090071
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01090FD4
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01090FEF
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01090F24
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01080FC0
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01080F8A
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01080011
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01080000
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01080047
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01080FE5
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 01080036
.text C:\WINDOWS\system32\svchost.exe[1188] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01080FAF
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01070FA6
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!system 77C293C7 5 Bytes JMP 01070FB7
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01070FE3
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01070000
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01070FC8
.text C:\WINDOWS\system32\svchost.exe[1188] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 0107001D
.text C:\WINDOWS\system32\svchost.exe[1188] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01050FE5
.text C:\WINDOWS\system32\svchost.exe[1188] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 01060000
.text C:\WINDOWS\system32\svchost.exe[1188] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 01060FEF
.text C:\WINDOWS\system32\svchost.exe[1188] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 01060025
.text C:\WINDOWS\system32\svchost.exe[1188] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 01060036
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 011B0000
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 011B0F66
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 011B005B
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 011B004A
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 011B0F8D
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 011B0F9E
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 011B0087
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 011B0F4B
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 011B00C7
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 011B00A2
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 011B00D8
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 011B002F
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 011B0FE5
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 011B0076
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 011B0FAF
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 011B0FD4
.text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 011B0F24
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0112002F
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01120F83
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01120FD4
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01120FEF
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01120F9E
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01120000
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 01120040
.text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01120FC3
.text C:\WINDOWS\system32\svchost.exe[1264] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01110FA8
.text C:\WINDOWS\system32\svchost.exe[1264] msvcrt.dll!system 77C293C7 5 Bytes JMP 01110033
.text C:\WINDOWS\system32\svchost.exe[1264] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01110018
.text C:\WINDOWS\system32\svchost.exe[1264] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01110FEF
.text C:\WINDOWS\system32\svchost.exe[1264] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01110FC3
.text C:\WINDOWS\system32\svchost.exe[1264] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01110FDE
.text C:\WINDOWS\system32\svchost.exe[1264] WS2_32.dll!socket 71AB4211 5 Bytes JMP 010F0FE5
.text C:\WINDOWS\system32\svchost.exe[1264] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 01100000
.text C:\WINDOWS\system32\svchost.exe[1264] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 0110001B
.text C:\WINDOWS\system32\svchost.exe[1264] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 01100036
.text C:\WINDOWS\system32\svchost.exe[1264] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 01100FEF
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02C20FEF
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02C20062
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02C2003D
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02C20F63
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02C2002C
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02C20FAF
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02C20F2B
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02C2007D
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02C20EEB
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 02C2008E
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02C2009F
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02C20F94
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02C20FD4
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02C20F52
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02C2001B
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02C2000A
.text C:\WINDOWS\System32\svchost.exe[1312] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 02C20F1A
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01DD002C
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01DD0062
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01DD0FDB
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01DD0011
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01DD0051
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01DD0000
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01DD0FAF
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [FD, 89]
.text C:\WINDOWS\System32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01DD0FCA
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01DC0F8B
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!system 77C293C7 5 Bytes JMP 01DC0F9C
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01DC0FC8
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01DC0000
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01DC0FB7
.text C:\WINDOWS\System32\svchost.exe[1312] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01DC0FE3
.text C:\WINDOWS\System32\svchost.exe[1312] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01DA0FE5
.text C:\WINDOWS\System32\svchost.exe[1312] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 01DB0000
.text C:\WINDOWS\System32\svchost.exe[1312] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 01DB0FE5
.text C:\WINDOWS\System32\svchost.exe[1312] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 01DB0011
.text C:\WINDOWS\System32\svchost.exe[1312] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 01DB0022
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00E00FE5
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00E00F4B
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00E00036
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00E00F5C
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00E00F79
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00E00025
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00E00F0E
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00E00F1F
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E00067
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E00ECE
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00E00078
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00E00F9E
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00E0000A
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00E00F3A
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00E00FB9
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00E00FD4
.text C:\WINDOWS\system32\svchost.exe[1392] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00E00EE9
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00DF0F9E
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00DF0F68
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00DF0FB9
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00DF0FCA
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00DF0025
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00DF0FEF
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00DF0F83
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [FF, 88]
.text C:\WINDOWS\system32\svchost.exe[1392] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00DF000A
.text C:\WINDOWS\system32\svchost.exe[1392] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 00F6000A
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00DE0F8B
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!system 77C293C7 5 Bytes JMP 00DE0FA6
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00DE0FD2
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00DE0000
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00DE0FB7
.text C:\WINDOWS\system32\svchost.exe[1392] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00DE0FE3
.text C:\WINDOWS\system32\svchost.exe[1392] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00DC0FEF
.text C:\WINDOWS\system32\svchost.exe[1392] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00DD0000
.text C:\WINDOWS\system32\svchost.exe[1392] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00DD0FEF
.text C:\WINDOWS\system32\svchost.exe[1392] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00DD0FCA
.text C:\WINDOWS\system32\svchost.exe[1392] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00DD0FB9
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F20FEF
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F2008C
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F2007B
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F20FA1
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F20FBC
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F20FCD
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F20F5F
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F200A7
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F20F29
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F20F44
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F200DD
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F2005E
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F2000A
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F20F7C
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F2002F
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F20FDE
.text C:\WINDOWS\system32\svchost.exe[1524] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F200B8
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00F10FEF
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00F1006C
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00F10040
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00F10025
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00F10FB9
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00F10000
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00F10FD4
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [11, 89]
.text C:\WINDOWS\system32\svchost.exe[1524] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00F1005B
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00F00FAB
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!system 77C293C7 5 Bytes JMP 00F00FBC
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00F00FCD
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00F00FEF
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00F00022
.text C:\WINDOWS\system32\svchost.exe[1524] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00F00FDE
.text C:\WINDOWS\system32\svchost.exe[1524] WS2_32.dll!socket 71AB4211 5 Bytes JMP 001B0000
.text C:\WINDOWS\system32\svchost.exe[1524] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00EF0000
.text C:\WINDOWS\system32\svchost.exe[1524] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00EF0011
.text C:\WINDOWS\system32\svchost.exe[1524] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00EF0022
.text C:\WINDOWS\system32\svchost.exe[1524] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00EF0FD1
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F80FEF
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F800A1
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F80086
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F80069
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F80058
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F8002C
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F80F7E
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F80F8F
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F80F48
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F800E1
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F80F37
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F8003D
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F80FDE
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F800BC
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F8001B
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F8000A
.text C:\WINDOWS\system32\svchost.exe[1956] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F80F59
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00EA0025
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00EA005B
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00EA0014
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00EA0FDE
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00EA0040
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00EA0FEF
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00EA0F9E
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [0A, 89]
.text C:\WINDOWS\system32\svchost.exe[1956] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00EA0FAF
.text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00E90FCA
.text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!system 77C293C7 5 Bytes JMP 00E90055
.text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00E90029
.text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00E90000
.text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00E9003A
.text C:\WINDOWS\system32\svchost.exe[1956] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00E90FEF
.text C:\WINDOWS\system32\svchost.exe[1956] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00E70000
.text C:\WINDOWS\system32\svchost.exe[1956] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 00E80000
.text C:\WINDOWS\system32\svchost.exe[1956] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 00E80FEF
.text C:\WINDOWS\system32\svchost.exe[1956] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 00E80FD4
.text C:\WINDOWS\system32\svchost.exe[1956] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 00E80025
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01360FE5
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01360049
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01360038
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01360F5E
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0136001B
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01360F94
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01360089
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 0136006E
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01360F01
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01360F1C
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01360EF0
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01360F79
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01360FD4
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreatePipe 7C81D83F 1 Byte [E9]
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01360F43
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01360FA5
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01360000
.text C:\WINDOWS\System32\svchost.exe[3528] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 0136009A
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01350040
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01350087
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01350025
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 0135000A
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01350076
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01350FEF
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01350FCA
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [55, 89]
.text C:\WINDOWS\System32\svchost.exe[3528] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0135005B
.text C:\WINDOWS\System32\svchost.exe[3528] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00FF0F92
.text C:\WINDOWS\System32\svchost.exe[3528] msvcrt.dll!system 77C293C7 5 Bytes JMP 00FF001D
.text C:\WINDOWS\System32\svchost.exe[3528] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00FF0FC8
.text C:\WINDOWS\System32\svchost.exe[3528] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00FF0000
.text C:\WINDOWS\System32\svchost.exe[3528] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00FF0FB7
.text C:\WINDOWS\System32\svchost.exe[3528] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00FF0FE3
.text C:\WINDOWS\System32\svchost.exe[3528] WS2_32.dll!socket 71AB4211 5 Bytes JMP 001A0000
.text C:\WINDOWS\System32\svchost.exe[3528] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 001B0000
.text C:\WINDOWS\System32\svchost.exe[3528] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 001B0011
.text C:\WINDOWS\System32\svchost.exe[3528] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 001B0022
.text C:\WINDOWS\System32\svchost.exe[3528] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 001B0FD1
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02A80FEF
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02A8004D
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02A80F58
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02A80F69
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02A80F86
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02A80FA8
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02A80F36
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02A80F47
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 02A80EF6
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02A80F97
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 02A80FD4
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02A80068
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02A8000A
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02A80FB9
.text C:\WINDOWS\Explorer.EXE[3836] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 02A80099
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 02A70FE5
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 02A70FAF
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 02A70036
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 02A7001B
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 02A70FC0
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 02A7000A
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 02A70062
.text C:\WINDOWS\Explorer.EXE[3836] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 02A70047
.text C:\WINDOWS\Explorer.EXE[3836] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 02A6005A
.text C:\WINDOWS\Explorer.EXE[3836] msvcrt.dll!system 77C293C7 5 Bytes JMP 02A60049
.text C:\WINDOWS\Explorer.EXE[3836] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 02A60FD9
.text C:\WINDOWS\Explorer.EXE[3836] msvcrt.dll!_open 77C2F566 5 Bytes JMP 02A60000
.text C:\WINDOWS\Explorer.EXE[3836] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 02A60038
.text C:\WINDOWS\Explorer.EXE[3836] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 02A6001D
.text C:\WINDOWS\Explorer.EXE[3836] WININET.dll!InternetOpenA 771CA6DD 5 Bytes JMP 02A50FEF
.text C:\WINDOWS\Explorer.EXE[3836] WININET.dll!InternetOpenW 771CAFC2 5 Bytes JMP 02A50FCA
.text C:\WINDOWS\Explorer.EXE[3836] WININET.dll!InternetOpenUrlA 771CC8BD 5 Bytes JMP 02A50FB9
.text C:\WINDOWS\Explorer.EXE[3836] WININET.dll!InternetOpenUrlW 77215A51 5 Bytes JMP 02A50014
.text C:\WINDOWS\Explorer.EXE[3836] WS2_32.dll!socket 71AB4211 5 Bytes JMP 02A40FE5
—- User IAT/EAT - GMER 1.0.15 —-
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apntex.exe[792] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxpers.exe[888] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\McTray.exe[1876] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\IDT\WDM\sttray.exe[2076] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe[2500] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\ctfmon.exe[2520] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\WLTRAY.exe[2556] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [7C88420A] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\AESTFltr.exe[3212] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [7C88420A] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\DellTPad\ApMsgFwd.exe[3244] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [7C88420A] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [7C88420A] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [7C88420A] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Documents and Settings\pcarrill\Desktop\pls5rq81.exe[3284] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [7C88420A] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\DellTPad\Apoint.exe[3420] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [7C88420A] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\Explorer.EXE [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\USERENV.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\Explorer.EXE[3836] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\Program Files\McAfee\Common Framework\UdaterUI.exe[4056] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\SHELL32.dll [ADVAPI32.dll!CreateProcessAsUserW] [77E45600] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [7C884205] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [7C884200] C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
IAT C:\WINDOWS\system32\igfxtray.exe[4088] @ C:\WINDOWS\system32\WININET.dll [ADVAPI32.dll!CreateProcessAsUserA] [77E45605] C:\WINDOWS\system32\ADVAPI32.dll (Advanced Windows 32 Base API/Microsoft Corporation)
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
—- Registry - GMER 1.0.15 —-
Reg HKLM\SOFTWARE\Classes\CLSID\{6CB39D60-4086-B7F8-381D8F903EAF6AF0}\{AFC2635D-FADA-3E20-D0B5B6B6E250D71B}\{28C204A2-D9FA-6C6E-1B551E281BAD6C81}
Reg HKLM\SOFTWARE\Classes\CLSID\{6CB39D60-4086-B7F8-381D8F903EAF6AF0}\{AFC2635D-FADA-3E20-D0B5B6B6E250D71B}\{28C204A2-D9FA-6C6E-1B551E281BAD6C81}@{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1 0x01 0x00 0x01 0x00 …
Reg HKLM\SOFTWARE\Classes\CLSID\{A1146105-B145-D547-791CC80E83BF21B6}\{DC78455E-4161-0768-1856DB98A0FFD8AF}\{619B65F9-9B50-CD99-3F29A63495E25D6C}
Reg HKLM\SOFTWARE\Classes\CLSID\{A1146105-B145-D547-791CC80E83BF21B6}\{DC78455E-4161-0768-1856DB98A0FFD8AF}\{619B65F9-9B50-CD99-3F29A63495E25D6C}@RA4KGUJC6T6LBNJRIDQ63C2L6C1 0x01 0x00 0x01 0x00 …
—- EOF - GMER 1.0.15 —-
DDS log
DDS (Ver_09-12-01.01) - NTFSx86 NETWORK
Run by [removed] at 6:28:29.32 on Wed 02/10/2010
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3536.2827 [GMT -7:00]
AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\pcarrill\Desktop\dds.pif
============== Pseudo HJT Report ===============
uWindow Title = Windows Internet Explorer provided by Mosaic
uStart Page = hxxp://employee.mosaicco.com/
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_11\bin\ssv.dll
BHO: ADC PlugIn: {77dc0baa-3235-4ba9-8be8-aa9eb678fa02} - c:\program files\adc32.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan enterprise\scriptcl.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
uRun: [ISUSPM] "c:\documents and settings\all users\application data\macrovision\flexnet connect\6\ISUSPM.exe" -scheduler
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE
mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\UdaterUI.exe" /StartedFromRunKey
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
mRun: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Sfopikoq] rundll32.exe "c:\windows\ohivukov.dll",Startup
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [milepihew] Rundll32.exe "c:\windows\system32\pokitiwi.dll",a
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
dRun: [Communicator] "c:\program files\microsoft office communicator\Communicator.exe"
mPolicies-explorer: NoWelcomeScreen = 1 (0x1)
mPolicies-system: EnableLUA = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_11\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: buy-internet-security10.com
Trusted Zone: buy-internetsecurity10.com
Trusted Zone: buy-is2010.com
Trusted Zone: cargill.com\hrdirect
Trusted Zone: cargill.com\smaccess.ds
Trusted Zone: is-soft-download.com
Trusted Zone: is-software-download.com
Trusted Zone: is10-soft-download.com
Trusted Zone: mosaicco.com\alsharepoint
Trusted Zone: mosaicco.com\it
Trusted Zone: mosaicco.com\mgts
Trusted Zone: mosaicco.com\ps1.pmo
Trusted Zone: mosaicco.com\sites.project
Trusted Zone: mosaicco.com\wdsharepoint
Trusted Zone: mosaicco.com\webmail
Trusted Zone: mosaicco.com\www.pmo
Trusted Zone: wdwebprd2
Trusted Zone: buy-internet-security10.com
Trusted Zone: buy-internetsecurity10.com
Trusted Zone: buy-is2010.com
Trusted Zone: cargill.com\hrdirect
Trusted Zone: cargill.com\smaccess.ds
Trusted Zone: mosaicco.com\alsharepoint
Trusted Zone: mosaicco.com\it
Trusted Zone: mosaicco.com\mgts
Trusted Zone: mosaicco.com\ps1.pmo
Trusted Zone: mosaicco.com\sites.project
Trusted Zone: mosaicco.com\wdsharepoint
Trusted Zone: mosaicco.com\webmail
Trusted Zone: mosaicco.com\www.pmo
Trusted Zone: wdwebprd2
DPF: {2BCDB465-81F9-41CB-832C-8037A4064446} - hxxps://vpn2.mosaicco.com/vdesk/terminal/urxvpn.cab#version=6031,2009,1010,313
DPF: {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} - hxxps://vpn2.mosaicco.com/vdesk/terminal/f5tunsrv.cab#version=6031,2009,1010,310
DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} - hxxps://vpn2.mosaicco.com/vdesk/terminal/InstallerControl.cab#version=6031,2009,1010,0312
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1243366726630
DPF: {6C275925-A1ED-4DD2-9CEE-9823F5FDAA10} - hxxps://vpn1.mosaicco.com/vdesk/terminal/urTermProxy.cab#version=6020,2007,1001,2136
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1243366697098
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} - hxxps://vpn2.mosaicco.com/vdesk/terminal/urxshost.cab#version=6031,2009,1010,308
DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} - hxxps://vpn2.mosaicco.com/vdesk/terminal/urxhost.cab#version=6031,2009,1010,304
Handler: saphtmlp - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\program files\sap\frontend\sapgui\SAPHTMLP.DLL
Handler: sapr3 - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\program files\sap\frontend\sapgui\SAPHTMLP.DLL
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\windows\system32\tusugemo.dll kaziduwo.dll c:\windows\system32\pokitiwi.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: penedahet - {7d7e192b-e486-4107-a9c0-ec81e981a533} - c:\windows\system32\tusugemo.dll
SSODL: vajazozoh - {76c938f6-8593-41a0-ac23-5fa8d8ddf15f} - c:\windows\system32\pokitiwi.dll
STS: mujuzedij: {7d7e192b-e486-4107-a9c0-ec81e981a533} - c:\windows\system32\tusugemo.dll
STS: tokatiluy: {76c938f6-8593-41a0-ac23-5fa8d8ddf15f} - c:\windows\system32\pokitiwi.dll
LSA: Notification Packages = scecli deqmabFi.dll jivobumo.dll
Hosts: 216.203.33.144 vpn1.mosaicco.com #ADDED BY F5 NETWORKS SSL TUNNEL - ORIGINAL RECORD#
Hosts: [removed] vpn1 #ADDED BY F5 NETWORKS SSL TUNNEL - ORIGINAL RECORD#
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\pcarrill\applic~1\mozilla\firefox\profiles\xia7xztq.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://mail.live.com/default.aspx?wa=wsignin1.0
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - prefs.js: network.proxy.type - 2
FF - plugin: c:\documents and settings\pcarrill\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\pcarrill\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJava11.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJava12.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJava13.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJava14.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJava32.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPJPI150_11.dll
FF - plugin: c:\program files\java\jre1.5.0_11\bin\NPOJI610.dll
FF - HiddenExtension: XULRunner: {70660533-012F-4BC3-A5DA-BA8C628D8037} - c:\documents and settings\pcarrill\local settings\application data\{70660533-012F-4BC3-A5DA-BA8C628D8037}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-2-1 207792]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [2008-12-31 244368]
R3 urvpndrv;F5 Networks VPN Adapter;c:\windows\system32\drivers\covpndrv.sys [2009-10-9 33920]
S1 mferkdk;VSCore mferkdk;c:\program files\mcafee\virusscan enterprise\mferkdk.sys [2009-1-27 31848]
S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\spyware doctor\bdt\BDTUpdateService.exe [2010-2-1 112592]
S2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2008-9-25 103744]
S2 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\Mcshield.exe [2009-1-27 144704]
S2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\VsTskMgr.exe [2009-1-27 54608]
S3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [2009-11-16 108160]
S3 cvusbdrv;Broadcom USH CV;c:\windows\system32\drivers\cvusbdrv.sys [2008-12-31 32808]
S3 f5ipfw;F5 Networks StoneWall Filter;c:\windows\system32\drivers\urfltw2k.sys [2009-12-2 10752]
S3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2009-11-16 110080]
S3 mfeavfk;McAfee Inc.;c:\windows\system32\drivers\mfeavfk.sys [2008-9-25 73512]
S3 mfebopk;McAfee Inc.;c:\windows\system32\drivers\mfebopk.sys [2008-9-25 34408]
S3 mfehidk;McAfee Inc.;c:\windows\system32\drivers\mfehidk.sys [2008-9-25 177864]
S3 OracleOraHome81ClientCache;OracleOraHome81ClientCache;c:\oracle\ora81\bin\onrsd.exe –> c:\oracle\ora81\bin\ONRSD.EXE [?]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2010-2-1 359624]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2010-2-1 1141712]
=============== Created Last 30 ================
2010-02-08 13:37:25 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-08 13:37:24 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-08 13:37:24 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-07 17:21:04 0 —-a-w- c:\windows\Yfezuqol.bin
2010-02-07 17:21:02 120 —-a-w- c:\windows\Twefoboxebod.dat
2010-02-07 13:13:03 0 d—–w- c:\program files\schtml
2010-02-07 13:08:35 962560 —-a-w- c:\program files\adc32.dll
2010-02-07 13:08:33 56 —-a-w- c:\program files\wp4.dat
2010-02-07 13:08:33 4 —-a-w- c:\program files\wp3.dat
2010-02-07 13:08:33 36 —-a-w- c:\program files\skynet.dat
2010-02-07 13:08:25 0 d—–w- c:\program files\Your PC Protector
2010-02-02 18:56:16 0 —-a-w- c:\windows\system32\29358.exe
2010-02-02 18:36:15 0 —-a-w- c:\windows\system32\11478.exe
2010-02-02 18:16:14 0 —-a-w- c:\windows\system32\15724.exe
2010-02-02 17:56:13 0 —-a-w- c:\windows\system32\19169.exe
2010-02-02 04:31:07 767952 —-a-w- c:\windows\BDTSupport.dll
2010-02-02 04:31:06 882 —-a-w- c:\windows\RegSDImport.xml
2010-02-02 04:31:06 879 —-a-w- c:\windows\RegISSImport.xml
2010-02-02 04:31:06 165840 —-a-w- c:\windows\PCTBDRes.dll
2010-02-02 04:31:06 1652688 —-a-w- c:\windows\PCTBDCore.dll
2010-02-02 04:31:06 1640400 —-a-w- c:\windows\PCTBDCore.dll.old
2010-02-02 04:31:06 149456 —-a-w- c:\windows\SGDetectionTool.dll
2010-02-02 04:31:06 131 —-a-w- c:\windows\IDB.zip
2010-02-02 04:31:06 1152444 —-a-w- c:\windows\UDB.zip
2010-02-02 04:29:09 7387 —-a-w- c:\windows\system32\drivers\pctgntdi.cat
2010-02-02 04:29:09 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-02-02 04:29:07 7412 —-a-w- c:\windows\system32\drivers\PCTAppEvent.cat
2010-02-02 04:29:07 7383 —-a-w- c:\windows\system32\drivers\pctcore.cat
2010-02-02 04:29:07 207792 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2010-02-02 04:29:06 87784 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-02-02 04:29:00 7383 —-a-w- c:\windows\system32\drivers\pctplsg.cat
2010-02-02 04:29:00 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2010-02-02 04:28:46 0 d—–w- c:\program files\Spyware Doctor
2010-02-02 04:28:46 0 d—–w- c:\program files\common files\PC Tools
2010-02-02 04:28:46 0 d—–w- c:\docume~1\pcarrill\applic~1\PC Tools
2010-02-02 04:28:46 0 d—–w- c:\docume~1\alluse~1\applic~1\PC Tools
2010-02-02 04:01:35 0 —-a-w- c:\windows\system32\26500.exe
2010-02-02 03:41:34 0 —-a-w- c:\windows\system32\6334.exe
2010-02-02 03:21:34 0 —-a-w- c:\windows\system32\18467.exe
2010-02-02 03:01:33 0 —-a-w- c:\windows\system32\41.exe
2010-01-26 16:00:34 0 d—–w- c:\docume~1\pcarrill\applic~1\Macrovision
2010-01-25 20:15:02 0 d—–w- c:\windows\system32\E177E04D548C4006A465EEB92D3DE021
2010-01-25 20:14:56 65 —-a-w- c:\windows\minitab.ini
2010-01-25 20:14:05 0 d—–w- c:\program files\Minitab 15
2010-01-21 21:04:40 0 d—–w- c:\windows\system32\rc
2010-01-21 20:42:38 0 d—–w- c:\docume~1\pcarrill\applic~1\Malwarebytes
2010-01-21 19:07:21 0 d—–w- c:\program files\Microsoft Visual Studio 8
2010-01-21 18:59:57 79872 -c—-w- c:\windows\system32\dllcache\raschap.dll
2010-01-21 18:59:57 66560 -c–a-w- c:\windows\system32\dllcache\tdc.ocx
2010-01-21 18:59:57 149504 -c—-w- c:\windows\system32\dllcache\rastls.dll
2010-01-21 18:59:55 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2010-01-21 18:59:54 270336 -c—-w- c:\windows\system32\dllcache\oakley.dll
2010-01-21 04:57:21 0 d—–w- c:\program files\uTorrent
2010-01-21 04:57:14 0 d—–w- c:\docume~1\pcarrill\applic~1\uTorrent
2010-01-20 23:58:10 0 d—–w- c:\program files\True Sword 5
2010-01-20 21:52:11 0 d—–w- c:\program files\RADO Removal Tool[1]
2010-01-14 05:50:17 79040 —ha-w- c:\windows\system32\mlfcache.dat
==================== Find3M ====================
2010-02-07 13:08:54 9 —-a-w- c:\program files\nuar.old
2010-01-26 15:57:47 2725698 —ha-w- c:\docume~1\pcarrill\applic~1\logs.dat
2010-01-10 02:55:10 21928 —-a-w- c:\windows\fonts\Princess_Sparkle_Font_by_darnfancylettuce.ttf
2010-01-10 02:52:17 7808 —-a-w- c:\windows\fonts\meow_font_by_pinktooney7.ttf
2009-12-27 04:07:48 126148 —-a-w- c:\windows\fonts\Sony_Sketch_Bold_205.ttf
2009-12-16 04:58:38 50772 —-a-w- c:\windows\fonts\sunshineinmysoul.ttf
2009-12-06 16:09:14 17680 —-a-w- c:\windows\fonts\heyyyy.ttf
2009-11-16 20:49:08 402006 —-a-w- c:\windows\system32\ScreenSaverMosaic.scr
1601-01-01 00:03:28 93696 –sha-w- c:\windows\system32\duzurosa.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\fivajubu.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\fivefoda.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\fodituva.dll
1601-01-01 00:03:28 93696 –sha-w- c:\windows\system32\gedoneno.dll
1601-01-01 00:03:52 53760 –sha-w- c:\windows\system32\jivobumo.dll
1601-01-01 00:03:52 53760 –sha-w- c:\windows\system32\kaziduwo.dll
1601-01-01 00:03:28 94208 –sha-w- c:\windows\system32\kiwatehu.dll
1601-01-01 00:03:28 93184 –sha-w- c:\windows\system32\lemutuja.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\nepihene.dll
1601-01-01 00:03:28 93696 –sha-w- c:\windows\system32\pokitiwi.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\pubonepo.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\selulisa.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\telariva.dll
1601-01-01 00:03:28 42496 –sha-w- c:\windows\system32\tesegigo.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\tifunalo.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\wopeneda.dll
1601-01-01 00:03:28 39424 –sha-w- c:\windows\system32\yehuruma.dll
============= FINISH: 6:30:09.85 ===============
thank you very much for you help.