This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PING.EXE [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Dear Tech Folks,

My computer recently suffered an attack and am wondering what I can do. The attack occurred mid day on Monday and crashed explorer.exe (which I restarted). In addition, windows defender caught found a "malicious program" which it deleted. In addition a bunch of processes showed up in my task manager including about 100 renditions of internet explorer. I ended the iexplorer processes as well as a few processes with the form "HDtt52.com". I went to the file locations for the HDtt52 processes and scanned them with McAfee, which promptly quarantined them. I ran windows defender on a full scan and found an additional malware entry. I then ran windows defender, spybotSD, and McAfee which came up clean.

However, PING.EXE has been eating up all of my memory and periodically McAfee says that it has stopped my computer from connecting to nefarious IP addresses. I have tried to make all outgoing connections require user approval, but I don't think that it worked.

One final thing, when I tried to download OTL it was "interrupted," which significantly raised my suspicions.

The logs that you requested are below. Thanks.

–David


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:17:35 PM, on 11/23/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe
C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe
C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpy.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\Taskmgr.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\David\Desktop\HiJackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USREL/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.google.com/mail/?hl=en&shva=1#inbox
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:54263
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Comcast Toolbar - {79CEEA4E-C231-4614-9E3B-53B2A02F39B7} - C:\Program Files\comcasttb\comcastdx.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20111115060950.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Comcast Toolbar - {79CEEA4E-C231-4614-9E3B-53B2A02F39B7} - C:\Program Files\comcasttb\comcastdx.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe
O4 - HKLM\..\Run: [SecureUpgrade] "C:\Program Files\Wave Systems Corp\SecureUpgrade.exe"
O4 - HKLM\..\Run: [DellControlPoint] "C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe"
O4 - HKLM\..\Run: [USCService] C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [DellConnectionManager] "C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe"
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Desktop Software] "C:\Program Files\Common Files\SupportSoft\bin\bcont.exe" /ini "C:\Program Files\ComcastUI\Desktop Software\uinstaller.ini" /fromrun /starthidden
O4 - HKCU\..\Run: [ComcastAntispyClient] "C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntispy.exe" /hide
O4 - HKCU\..\Run: [Google Update] "C:\Users\David\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [msraator] rundll32 "C:\Users\David\AppData\Local\Temp\dns-conf.dll",DllGetVersion
O4 - HKCU\..\Run: [Gpilohahozewujo] rundll32.exe "C:\Users\David\AppData\Local\eapcap.dll",Startup
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Privacy Protection] C:\Users\David\AppData\Roaming\privacy.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Dell ControlPoint System Manager.lnk = C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: 55963676-2F5E-4BAF-AC28-CF26AA587566 - vpnweb.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8884D245-DE94-4BB7-AA68-48B5C41ADECE}: NameServer = 128.32.136.9,128.32.136.12,128.32.136.9,128.32.136.12
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~1\mcafee\msc\mcsniepl.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\aestsrv.exe
O23 - Service: Ambient Light Sensor (alssvc) - Dell Inc. - C:\Program Files\Dell\Ambient Light Sensor\AlsSvc.exe
O23 - Service: Comcast AntiSpyware (AntiSpywareService) - Unknown owner - C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Dell ControlPoint Button Service (buttonsvc32) - Dell Inc. - C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe
O23 - Service: Credential Vault Host Control Service - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
O23 - Service: Credential Vault Host Storage - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
O23 - Service: Dell ControlPoint System Manager (dcpsysmgrsvc) - Dell Inc. - C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe
O23 - Service: Smith Micro Connection Manager Service (SMManager) - Smith Micro Software, Inc. - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\STacSV.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: NTRU TSS v1.2.1.29 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
O23 - Service: Cisco AnyConnect VPN Agent (vpnagent) - Cisco Systems, Inc. - C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE

–
End of file - 18947 bytes



.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 15:21:17.06 on Wed 11/23/2011
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.3571.2097 [GMT -8:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\STacSV.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\System32\bcmwltry.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\rundll32.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\aestsrv.exe
C:\Program Files\Dell\Ambient Light Sensor\AlsSvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\Microsoft\BingBar\SeaPort.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe
C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe
C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe
C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpy.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\Steam\SteamService.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\Taskmgr.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\svchost.exe -k SDRSVC
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Program Files\Common Files\McAfee\Core\mchost.exe
C:\Windows\system32\taskeng.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\David\Desktop\dds.scr
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\System32\ping.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://mail.google.com/mail/?hl=en&shva=1#inbox
uWindow Title = Internet Explorer provided by Dell
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = http=127.0.0.1:54263
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Comcast Toolbar: {79ceea4e-c231-4614-9e3b-53b2a02f39b7} - c:\program files\comcasttb\comcastdx.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20111115060950.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll"
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Comcast Toolbar: {79ceea4e-c231-4614-9e3b-53b2a02f39b7} - c:\program files\comcasttb\comcastdx.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll"
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [Desktop Software] "c:\program files\common files\supportsoft\bin\bcont.exe" /ini "c:\program files\comcastui\desktop software\uinstaller.ini" /fromrun /starthidden
uRun: [ComcastAntispyClient] "c:\program files\comcasttb\comcastspywarescan\ComcastAntispy.exe" /hide
uRun: [Google Update] "c:\users\david\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [msraator] rundll32 "c:\users\david\appdata\local\temp\dns-conf.dll",DllGetVersion
uRun: [Gpilohahozewujo] rundll32.exe "c:\users\david\appdata\local\eapcap.dll",Startup
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Steam] "c:\program files\steam\Steam.exe" -silent
uRun: [Privacy Protection] c:\users\david\appdata\roaming\privacy.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [WavXMgr] c:\program files\wave systems corp\services manager\docmgr\bin\WavXDocMgr.exe
mRun: [SecureUpgrade] "c:\program files\wave systems corp\SecureUpgrade.exe"
mRun: [DellControlPoint] "c:\program files\dell\dell controlpoint\Dell.ControlPoint.exe"
mRun: [USCService] c:\program files\dell\dell controlpoint\security manager\BcmDeviceAndTaskStatusService.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [DellConnectionManager] "c:\program files\dell\dell controlpoint\connection manager\Dell.UCM.exe"
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [ddoctorv2] "c:\program files\comcast\desktop doctor\bin\sprtcmd.exe" /P ddoctorv2
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
dRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10b.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\dellco~1.lnk - c:\program files\dell\dell controlpoint\system manager\DCPSysMgr.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
IE: Send image to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mi1933~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: mswsock.dll
DPF: 55963676-2F5E-4BAF-AC28-CF26AA587566 - vpnweb.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: {8884D245-DE94-4BB7-AA68-48B5C41ADECE} = 128.32.136.9,128.32.136.12,128.32.136.9,128.32.136.12
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~1\mcafee\msc\McSnIePl.dll
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
LSA: Authentication Packages = msv1_0 wvauth
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\david\appdata\roaming\mozilla\firefox\profiles\stasjnao.profile1\
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\progra~1\mcafee\msc\npMcSnFFPl.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mcafee\siteadvisor\NPMcFFPlg32.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\david\appdata\local\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\users\david\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\users\david\appdata\roaming\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\users\david\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll
.
—- FIREFOX POLICIES —-
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2010-9-1 464176]
R1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\drivers\mfenlfk.sys [2010-9-1 64880]
R1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2010-9-1 165680]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_820ff26a\AEstSrv.exe [2009-7-15 81920]
R2 alssvc;Ambient Light Sensor;c:\program files\dell\ambient light sensor\AlsSvc.exe [2008-6-3 382232]
R2 AntiSpywareService;Comcast AntiSpyware;c:\program files\comcasttb\comcastspywarescan\ComcastAntiSpyService.exe [2009-5-5 616408]
R2 ASFAgent;ASF Agent;c:\program files\intel\asf agent\ASFAgent.exe [2007-4-19 133968]
R2 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\SeaPort.EXE [2011-6-15 249648]
R2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\dell\dell controlpoint\DCPButtonSvc.exe [2008-12-29 320800]
R2 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\broadcom corporation\broadcom ush host components\cv\bin\HostControlService.exe [2009-1-22 808296]
R2 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\broadcom corporation\broadcom ush host components\cv\bin\HostStorageService.exe [2009-1-22 20840]
R2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\dell\dell controlpoint\system manager\DCPSysMgrSvc.exe [2009-4-9 447264]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-7-23 94880]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-9-1 214904]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-9-1 214904]
R2 McProxy;McAfee Proxy Service;"c:\program files\common files\mcafee\mcsvchost\McSvHost.exe" /McCoreSvc [2010-9-1 214904]
R2 McShield;McAfee McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2010-9-1 166288]
R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2010-9-1 160608]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\common files\mcafee\systemcore\mfevtps.exe [2010-9-1 150856]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-9-28 1153368]
R2 SMManager;Smith Micro Connection Manager Service;c:\program files\dell\dell controlpoint\connection manager\SMManager.exe [2009-4-10 77824]
R2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files\cisco\cisco anyconnect vpn client\vpnagent.exe [2009-12-17 497856]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-9-1 57600]
R3 cvusbdrv;Broadcom USH CV;c:\windows\system32\drivers\cvusbdrv.sys [2009-7-15 32808]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y6032.sys [2009-7-15 224384]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2010-9-1 180816]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2010-9-1 59456]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-9-1 338176]
R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\system32\drivers\OA001Ufd.sys [2009-7-15 133632]
R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\system32\drivers\OA001Vid.sys [2009-7-15 280096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 EZUSB;AnchorChips General Purpose USB Driver (ezusb.sys);c:\windows\system32\drivers\ezusb.sys [2010-1-26 17424]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-3-3 135664]
S3 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-7-7 195336]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2009-7-15 29736]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-3-3 135664]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-9-1 87656]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 rimspci;rimspci;c:\windows\system32\drivers\rimspe86.sys [2009-7-15 45056]
S4 risdpcie;risdpcie;c:\windows\system32\drivers\risdpe86.sys [2009-7-15 48640]
S4 rixdpcie;rixdpcie;c:\windows\system32\drivers\rixdpe86.sys [2009-7-15 38400]
.
=============== Created Last 30 ================
.
2011-11-23 20:20:27 56200 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{04991653-3078-43ba-afba-f62fa6f0008e}\offreg.dll
2011-11-23 20:20:16 6668624 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{04991653-3078-43ba-afba-f62fa6f0008e}\mpengine.dll
2011-11-19 01:37:16 ——– d—–w- c:\users\david\appdata\local\Skyrim
2011-11-16 23:31:59 70992 —-a-w- c:\windows\system32\XAPOFX1_2.dll
2011-11-12 02:54:43 161792 —-a-w- c:\windows\system32\msls31.dll
2011-11-10 18:07:35 ——– d—–w- c:\users\david\appdata\roaming\EFBF5
2011-11-10 18:07:14 ——– d—–w- c:\users\david\appdata\roaming\82CEF
2011-11-09 04:25:56 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat
2011-11-09 04:25:55 905088 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-11-09 04:25:52 707584 —-a-w- c:\program files\common files\system\wab32.dll
2011-10-25 21:53:38 6144 —-a-w- c:\program files\internet explorer\iecompat.dll
.
==================== Find3M ====================
.
2011-11-12 02:45:15 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-06 13:30:12 2043392 —-a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 15:32:30.99 ===============
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———-

**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

It looks as if you have been infected by one of the variants of the ZeroAccess Rootkit. It is an exceptionally nasty piece of malware. As a warning, if you choose to continue with the cleaning we may still need to format and re-install your operating system and it could ruin your internet connection briefly.

If you would like to format and reinstall your Operating System please let me know and I can assist you with that.

If you would like to continue with the cleaning, please continue with the following instructions and I will be more than happy to help. :)
———-

Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Right-click and Run as Administrator GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.
———-
Dear Jeff,

I downloaded GMER and ran it but it seems that my computer shut down/crashed in the running (not sure if it was just windows or something else). So, I ran it again with C:\ unchecked and it completed. Below is that log file (I tried to attach but I seem to lack the permissions to upload that type of file). I will run it again with C:\ checked to see if it completes and then attach that file as well. Thanks.

–David


GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-11-26 14:33:53
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD25 rev.11.0
Running: gmer.exe; Driver: C:\Users\David\AppData\Local\Temp\agloapod.sys


—- System - GMER 1.0.15 —-

Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwMapViewOfSection [0x8BF5F498]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwTerminateProcess [0x8BF5F4C2]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0x8BF5F4AE]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) ZwYieldExecution [0x8BF5F484]
Code \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.) NtMapViewOfSection

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwYieldExecution 82A4A982 5 Bytes JMP 8BF5F488 \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 82C10143 5 Bytes JMP 8BF5F4C6 \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 82C2F89A 7 Bytes JMP 8BF5F49C \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 82C2FB5D 5 Bytes JMP 8BF5F4B2 \SystemRoot\system32\drivers\mfehidk.sys (McAfee Link Driver/McAfee, Inc.)
.text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x9080D340, 0x3EC0F7, 0xE8000020]

—- User code sections - GMER 1.0.15 —-

.text C:\Windows\system32\svchost.exe[684] ntdll.dll!NtCreateFile 778F4224 5 Bytes JMP 00FB000A
.text C:\Windows\system32\svchost.exe[684] ntdll.dll!NtCreateProcess 778F42E4 5 Bytes JMP 00FB0FDE
.text C:\Windows\system32\svchost.exe[684] ntdll.dll!NtProtectVirtualMemory 778F4B84 5 Bytes JMP 00FB0FEF
.text C:\Windows\system32\svchost.exe[684] kernel32.dll!GetStartupInfoW 76581929 5 Bytes JMP 00FF0F37
.text C:\Windows\system32\svchost.exe[684] kernel32.dll!GetStartupInfoA 765819C9 5 Bytes JMP 00FF0F48
.text C:\Windows\system32\svchost.exe[684] kernel32.dll!CreateProcessW 76581BF3 5 Bytes JMP 00FF00B3
.text C:\Windows\system32\svchost.exe[684] kernel32.dll!CreateProcessA 76581C28 5 Bytes JMP 00FF00A2
.text C:\Windows\system32\svchost.exe[684] kernel32.dll!VirtualProtect 76581DC3 5 Bytes JMP 00FF0F6D
.text C:\Windows\system32\svchost.exe[684] kernel32.dll!CreateNamedPipeA 76582EF5 5 Bytes JMP 00FF0FCA
.text C:\Windows\system32\svchost.exe[684] kernel32.dll!CreateNamedPipeW 76585C0C 5 Bytes JMP 00FF0011
.text C:\Windows\system32\svchost.exe[684] kernel32.dll!CreatePipe 765A8F06 5 Bytes JMP 00FF007D
.text C:\Windows\system32\svchost.exe[684] kernel32.dll!LoadLibraryExW 765A927C 5 Bytes JMP 00FF0051
.text C:\Windows\system32\svchost.exe[684] kernel32.dll!LoadLibraryW 765A9400 5 Bytes JMP 00FF0F94
.text C:\Windows\system32\svchost.exe[684] kernel32.dll!LoadLibraryExA 765A9554 5 Bytes JMP 00FF0040
.text C:\Windows\system32\svchost.exe[684] kernel32.dll!LoadLibraryA 765A957C 5 Bytes JMP 00FF0FA5
.text C:\Windows\system32\svchost.exe[684] kernel32.dll!VirtualProtectEx 765ADC52 5 Bytes JMP 00FF006C
.text C:\Windows\system32\svchost.exe[684] kernel32.dll!GetProcAddress 765C925B 5 Bytes JMP 00FF0EF7
.text C:\Windows\system32\svchost.exe[684] kernel32.dll!CreateFileW 765CB0EB 5 Bytes JMP 00FF0FDB
.text C:\Windows\system32\svchost.exe[684] kernel32.dll!CreateFileA 765CD07F 5 Bytes JMP 00FF0000
.text C:\Windows\system32\svchost.exe[684] kernel32.dll!WinExec 766160CF 5 Bytes JMP 00FF0F26
.text C:\Windows\system32\svchost.exe[684] msvcrt.dll!_wsystem 760C7F2F 5 Bytes JMP 00FE0062
.text C:\Windows\system32\svchost.exe[684] msvcrt.dll!system 760C804B 5 Bytes JMP 00FE0FCD
.text C:\Windows\system32\svchost.exe[684] msvcrt.dll!_creat 760CBBE1 5 Bytes JMP 00FE002C
.text C:\Windows\system32\svchost.exe[684] msvcrt.dll!_open 760CD106 5 Bytes JMP 00FE0000
.text C:\Windows\system32\svchost.exe[684] msvcrt.dll!_wcreat 760CD326 5 Bytes JMP 00FE003D
.text C:\Windows\system32\svchost.exe[684] msvcrt.dll!_wopen 760CD501 5 Bytes JMP 00FE0011
.text C:\Windows\system32\svchost.exe[684] ADVAPI32.dll!RegCreateKeyExA 768039AB 5 Bytes JMP 0160001E
.text C:\Windows\system32\svchost.exe[684] ADVAPI32.dll!RegCreateKeyA 76803BA9 5 Bytes JMP 01600F97
.text C:\Windows\system32\svchost.exe[684] ADVAPI32.dll!RegOpenKeyA 768089C7 5 Bytes JMP 01600FEF
.text C:\Windows\system32\svchost.exe[684] ADVAPI32.dll!RegCreateKeyW 7681391E 5 Bytes JMP 01600F86
.text C:\Windows\system32\svchost.exe[684] ADVAPI32.dll!RegCreateKeyExW 768141F1 5 Bytes JMP 01600F6B
.text C:\Windows\system32\svchost.exe[684] ADVAPI32.dll!RegOpenKeyExA 76817C42 5 Bytes JMP 01600FB9
.text C:\Windows\system32\svchost.exe[684] ADVAPI32.dll!RegOpenKeyW 7681E2B5 5 Bytes JMP 01600FD4
.text C:\Windows\system32\svchost.exe[684] ADVAPI32.dll!RegOpenKeyExW 76827BA1 5 Bytes JMP 01600FA8
.text C:\Windows\system32\svchost.exe[684] WS2_32.dll!socket 75FB36D1 5 Bytes JMP 00210000
.text C:\Windows\system32\services.exe[776] ntdll.dll!NtCreateFile 778F4224 5 Bytes JMP 000A000A
.text C:\Windows\system32\services.exe[776] ntdll.dll!NtCreateProcess 778F42E4 5 Bytes JMP 000A0025
.text C:\Windows\system32\services.exe[776] ntdll.dll!NtProtectVirtualMemory 778F4B84 5 Bytes JMP 000A0FEF
.text C:\Windows\system32\services.exe[776] kernel32.dll!GetStartupInfoW 76581929 5 Bytes JMP 00720FB2
.text C:\Windows\system32\services.exe[776] kernel32.dll!GetStartupInfoA 765819C9 5 Bytes JMP 007200F8
.text C:\Windows\system32\services.exe[776] kernel32.dll!CreateProcessW 76581BF3 5 Bytes JMP 00720F7C
.text C:\Windows\system32\services.exe[776] kernel32.dll!CreateProcessA 76581C28 5 Bytes JMP 00720F97
.text C:\Windows\system32\services.exe[776] kernel32.dll!VirtualProtect 76581DC3 5 Bytes JMP 00720FC3
.text C:\Windows\system32\services.exe[776] kernel32.dll!CreateNamedPipeA 76582EF5 5 Bytes JMP 00720025
.text C:\Windows\system32\services.exe[776] kernel32.dll!CreateNamedPipeW 76585C0C 5 Bytes JMP 0072004A
.text C:\Windows\system32\services.exe[776] kernel32.dll!CreatePipe 765A8F06 5 Bytes JMP 007200D3
.text C:\Windows\system32\services.exe[776] kernel32.dll!LoadLibraryExW 765A927C 5 Bytes JMP 00720091
.text C:\Windows\system32\services.exe[776] kernel32.dll!LoadLibraryW 765A9400 5 Bytes JMP 00720FDE
.text C:\Windows\system32\services.exe[776] kernel32.dll!LoadLibraryExA 765A9554 5 Bytes JMP 00720076
.text C:\Windows\system32\services.exe[776] kernel32.dll!LoadLibraryA 765A957C 5 Bytes JMP 00720065
.text C:\Windows\system32\services.exe[776] kernel32.dll!VirtualProtectEx 765ADC52 5 Bytes JMP 007200B8
.text C:\Windows\system32\services.exe[776] kernel32.dll!GetProcAddress 765C925B 5 Bytes JMP 0072012E
.text C:\Windows\system32\services.exe[776] kernel32.dll!CreateFileW 765CB0EB 5 Bytes JMP 0072000A
.text C:\Windows\system32\services.exe[776] kernel32.dll!CreateFileA 765CD07F 5 Bytes JMP 00720FEF
.text C:\Windows\system32\services.exe[776] kernel32.dll!WinExec 766160CF 5 Bytes JMP 00720113
.text C:\Windows\system32\services.exe[776] ADVAPI32.dll!RegCreateKeyExA 768039AB 5 Bytes JMP 00730091
.text C:\Windows\system32\services.exe[776] ADVAPI32.dll!RegCreateKeyA 76803BA9 5 Bytes JMP 00730065
.text C:\Windows\system32\services.exe[776] ADVAPI32.dll!RegOpenKeyA 768089C7 5 Bytes JMP 0073000A
.text C:\Windows\system32\services.exe[776] ADVAPI32.dll!RegCreateKeyW 7681391E 5 Bytes JMP 00730080
.text C:\Windows\system32\services.exe[776] ADVAPI32.dll!RegCreateKeyExW 768141F1 5 Bytes JMP 007300A2
.text C:\Windows\system32\services.exe[776] ADVAPI32.dll!RegOpenKeyExA 76817C42 5 Bytes JMP 00730FEF
.text C:\Windows\system32\services.exe[776] ADVAPI32.dll!RegOpenKeyW 7681E2B5 5 Bytes JMP 0073001B
.text C:\Windows\system32\services.exe[776] ADVAPI32.dll!RegOpenKeyExW 76827BA1 5 Bytes JMP 00730040
.text C:\Windows\system32\services.exe[776] msvcrt.dll!_wsystem 760C7F2F 5 Bytes JMP 001D0F9C
.text C:\Windows\system32\services.exe[776] msvcrt.dll!system 760C804B 5 Bytes JMP 001D0FAD
.text C:\Windows\system32\services.exe[776] msvcrt.dll!_creat 760CBBE1 5 Bytes JMP 001D001D
.text C:\Windows\system32\services.exe[776] msvcrt.dll!_open 760CD106 5 Bytes JMP 001D0000
.text C:\Windows\system32\services.exe[776] msvcrt.dll!_wcreat 760CD326 5 Bytes JMP 001D0FBE
.text C:\Windows\system32\services.exe[776] msvcrt.dll!_wopen 760CD501 5 Bytes JMP 001D0FE3
.text C:\Windows\system32\services.exe[776] WS2_32.dll!socket 75FB36D1 5 Bytes JMP 000B0000
.text C:\Windows\system32\services.exe[776] WININET.dll!InternetOpenA 775D4E33 5 Bytes JMP 0096000A
.text C:\Windows\system32\services.exe[776] WININET.dll!InternetOpenUrlA 775DBFCE 5 Bytes JMP 00960FDE
.text C:\Windows\system32\services.exe[776] WININET.dll!InternetOpenW 7760C02E 5 Bytes JMP 00960FEF
.text C:\Windows\system32\services.exe[776] WININET.dll!InternetOpenUrlW 7763D70A 5 Bytes JMP 00960FCD
.text C:\Windows\system32\lsass.exe[788] ntdll.dll!NtCreateFile 778F4224 5 Bytes JMP 00200FEF
.text C:\Windows\system32\lsass.exe[788] ntdll.dll!NtCreateProcess 778F42E4 5 Bytes JMP 00200025
.text C:\Windows\system32\lsass.exe[788] ntdll.dll!NtProtectVirtualMemory 778F4B84 5 Bytes JMP 00200014
.text C:\Windows\system32\lsass.exe[788] kernel32.dll!GetStartupInfoW 76581929 5 Bytes JMP 00A4009A
.text C:\Windows\system32\lsass.exe[788] kernel32.dll!GetStartupInfoA 765819C9 5 Bytes JMP 00A40089
.text C:\Windows\system32\lsass.exe[788] kernel32.dll!CreateProcessW 76581BF3 5 Bytes JMP 00A40F0D
.text C:\Windows\system32\lsass.exe[788] kernel32.dll!CreateProcessA 76581C28 5 Bytes JMP 00A40F28
.text C:\Windows\system32\lsass.exe[788] kernel32.dll!VirtualProtect 76581DC3 5 Bytes JMP 00A4005A
.text C:\Windows\system32\lsass.exe[788] kernel32.dll!CreateNamedPipeA 76582EF5 5 Bytes JMP 00A40FD1
.text C:\Windows\system32\lsass.exe[788] kernel32.dll!CreateNamedPipeW 76585C0C 5 Bytes JMP 00A40FB6
.text C:\Windows\system32\lsass.exe[788] kernel32.dll!CreatePipe 765A8F06 5 Bytes JMP 00A40F5E
.text C:\Windows\system32\lsass.exe[788] kernel32.dll!LoadLibraryExW 765A927C 5 Bytes JMP 00A40F80
.text C:\Windows\system32\lsass.exe[788] kernel32.dll!LoadLibraryW 765A9400 5 Bytes JMP 00A40022
.text C:\Windows\system32\lsass.exe[788] kernel32.dll!LoadLibraryExA 765A9554 5 Bytes JMP 00A4003D
.text C:\Windows\system32\lsass.exe[788] kernel32.dll!LoadLibraryA 765A957C 5 Bytes JMP 00A40FA5
.text C:\Windows\system32\lsass.exe[788] kernel32.dll!VirtualProtectEx 765ADC52 5 Bytes JMP 00A40F6F
.text C:\Windows\system32\lsass.exe[788] kernel32.dll!GetProcAddress 765C925B 5 Bytes JMP 00A400BF
.text C:\Windows\system32\lsass.exe[788] kernel32.dll!CreateFileW 765CB0EB 5 Bytes JMP 00A40011
.text C:\Windows\system32\lsass.exe[788] kernel32.dll!CreateFileA 765CD07F 5 Bytes JMP 00A40000
.text C:\Windows\system32\lsass.exe[788] kernel32.dll!WinExec 766160CF 5 Bytes JMP 00A40F39
.text C:\Windows\system32\lsass.exe[788] ADVAPI32.dll!RegCreateKeyExA 768039AB 5 Bytes JMP 00A50051
.text C:\Windows\system32\lsass.exe[788] ADVAPI32.dll!RegCreateKeyA 76803BA9 5 Bytes JMP 00A50025
.text C:\Windows\system32\lsass.exe[788] ADVAPI32.dll!RegOpenKeyA 768089C7 5 Bytes JMP 00A50FEF
.text C:\Windows\system32\lsass.exe[788] ADVAPI32.dll!RegCreateKeyW 7681391E 5 Bytes JMP 00A50036
.text C:\Windows\system32\lsass.exe[788] ADVAPI32.dll!RegCreateKeyExW 768141F1 5 Bytes JMP 00A50F94
.text C:\Windows\system32\lsass.exe[788] ADVAPI32.dll!RegOpenKeyExA 76817C42 5 Bytes JMP 00A50FCD
.text C:\Windows\system32\lsass.exe[788] ADVAPI32.dll!RegOpenKeyW 7681E2B5 5 Bytes JMP 00A50FDE
.text C:\Windows\system32\lsass.exe[788] ADVAPI32.dll!RegOpenKeyExW 76827BA1 5 Bytes JMP 00A50014
.text C:\Windows\system32\lsass.exe[788] msvcrt.dll!_wsystem 760C7F2F 5 Bytes JMP 00210FBE
.text C:\Windows\system32\lsass.exe[788] msvcrt.dll!system 760C804B 5 Bytes JMP 00210053
.text C:\Windows\system32\lsass.exe[788] msvcrt.dll!_creat 760CBBE1 5 Bytes JMP 0021001D
.text C:\Windows\system32\lsass.exe[788] msvcrt.dll!_open 760CD106 5 Bytes JMP 0021000C
.text C:\Windows\system32\lsass.exe[788] msvcrt.dll!_wcreat 760CD326 5 Bytes JMP 00210038
.text C:\Windows\system32\lsass.exe[788] msvcrt.dll!_wopen 760CD501 5 Bytes JMP 00210FEF
.text C:\Windows\system32\lsass.exe[788] WS2_32.dll!socket 75FB36D1 5 Bytes JMP 001F0FEF
.text C:\Windows\system32\lsass.exe[788] WININET.dll!InternetOpenA 775D4E33 5 Bytes JMP 00AA000A
.text C:\Windows\system32\lsass.exe[788] WININET.dll!InternetOpenUrlA 775DBFCE 5 Bytes JMP 00AA0FD4
.text C:\Windows\system32\lsass.exe[788] WININET.dll!InternetOpenW 7760C02E 5 Bytes JMP 00AA0FEF
.text C:\Windows\system32\lsass.exe[788] WININET.dll!InternetOpenUrlW 7763D70A 5 Bytes JMP 00AA0FC3
.text C:\Windows\system32\svchost.exe[948] ntdll.dll!NtCreateFile 778F4224 5 Bytes JMP 00720000
.text C:\Windows\system32\svchost.exe[948] ntdll.dll!NtCreateProcess 778F42E4 5 Bytes JMP 0072002C
.text C:\Windows\system32\svchost.exe[948] ntdll.dll!NtProtectVirtualMemory 778F4B84 5 Bytes JMP 0072001B
.text C:\Windows\system32\svchost.exe[948] kernel32.dll!GetStartupInfoW 76581929 5 Bytes JMP 00750F0B
.text C:\Windows\system32\svchost.exe[948] kernel32.dll!GetStartupInfoA 765819C9 5 Bytes JMP 0075005B
.text C:\Windows\system32\svchost.exe[948] kernel32.dll!CreateProcessW 76581BF3 5 Bytes JMP 00750EBA
.text C:\Windows\system32\svchost.exe[948] kernel32.dll!CreateProcessA 76581C28 5 Bytes JMP 00750ED5
.text C:\Windows\system32\svchost.exe[948] kernel32.dll!VirtualProtect 76581DC3 5 Bytes JMP 00750F5C
.text C:\Windows\system32\svchost.exe[948] kernel32.dll!CreateNamedPipeA 76582EF5 5 Bytes JMP 00750FCA
.text C:\Windows\system32\svchost.exe[948] kernel32.dll!CreateNamedPipeW 76585C0C 5 Bytes JMP 0075001B
.text C:\Windows\system32\svchost.exe[948] kernel32.dll!CreatePipe 765A8F06 5 Bytes JMP 00750F30
.text C:\Windows\system32\svchost.exe[948] kernel32.dll!LoadLibraryExW 765A927C 5 Bytes JMP 00750040
.text C:\Windows\system32\svchost.exe[948] kernel32.dll!LoadLibraryW 765A9400 5 Bytes JMP 00750F9E
.text C:\Windows\system32\svchost.exe[948] kernel32.dll!LoadLibraryExA 765A9554 5 Bytes JMP 00750F8D
.text C:\Windows\system32\svchost.exe[948] kernel32.dll!LoadLibraryA 765A957C 5 Bytes JMP 00750FB9
.text C:\Windows\system32\svchost.exe[948] kernel32.dll!VirtualProtectEx 765ADC52 5 Bytes JMP 00750F4B
.text C:\Windows\system32\svchost.exe[948] kernel32.dll!GetProcAddress 765C925B 5 Bytes JMP 00750EA9
.text C:\Windows\system32\svchost.exe[948] kernel32.dll!CreateFileW 765CB0EB 5 Bytes JMP 00750FDB
.text C:\Windows\system32\svchost.exe[948] kernel32.dll!CreateFileA 765CD07F 5 Bytes JMP 00750000
.text C:\Windows\system32\svchost.exe[948] kernel32.dll!WinExec 766160CF 5 Bytes JMP 00750EF0
.text C:\Windows\system32\svchost.exe[948] msvcrt.dll!_wsystem 760C7F2F 5 Bytes JMP 0074001D
.text C:\Windows\system32\svchost.exe[948] msvcrt.dll!system 760C804B 5 Bytes JMP 00740F9C
.text C:\Windows\system32\svchost.exe[948] msvcrt.dll!_creat 760CBBE1 5 Bytes JMP 0074000C
.text C:\Windows\system32\svchost.exe[948] msvcrt.dll!_open 760CD106 5 Bytes JMP 00740FEF
.text C:\Windows\system32\svchost.exe[948] msvcrt.dll!_wcreat 760CD326 5 Bytes JMP 00740FAD
.text C:\Windows\system32\svchost.exe[948] msvcrt.dll!_wopen 760CD501 5 Bytes JMP 00740FD2
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!RegCreateKeyExA 768039AB 5 Bytes JMP 007A0062
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!RegCreateKeyA 76803BA9 5 Bytes JMP 007A0047
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!RegOpenKeyA 768089C7 5 Bytes JMP 007A0000
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!RegCreateKeyW 7681391E 5 Bytes JMP 007A0FCA
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!RegCreateKeyExW 768141F1 5 Bytes JMP 007A0073
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!RegOpenKeyExA 76817C42 5 Bytes JMP 007A0022
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!RegOpenKeyW 7681E2B5 5 Bytes JMP 007A0011
.text C:\Windows\system32\svchost.exe[948] ADVAPI32.dll!RegOpenKeyExW 76827BA1 5 Bytes JMP 007A0FDB
.text C:\Windows\system32\svchost.exe[948] WS2_32.dll!socket 75FB36D1 5 Bytes JMP 00730FEF
.text C:\Windows\system32\svchost.exe[1024] ntdll.dll!NtCreateFile 778F4224 5 Bytes JMP 0023000A
.text C:\Windows\system32\svchost.exe[1024] ntdll.dll!NtCreateProcess 778F42E4 5 Bytes JMP 00230FEF
.text C:\Windows\system32\svchost.exe[1024] ntdll.dll!NtProtectVirtualMemory 778F4B84 5 Bytes JMP 0023001B
.text C:\Windows\system32\svchost.exe[1024] kernel32.dll!GetStartupInfoW 76581929 5 Bytes JMP 002A00AB
.text C:\Windows\system32\svchost.exe[1024] kernel32.dll!GetStartupInfoA 765819C9 5 Bytes JMP 002A009A
.text C:\Windows\system32\svchost.exe[1024] kernel32.dll!CreateProcessW 76581BF3 5 Bytes JMP 002A0F2F
.text C:\Windows\system32\svchost.exe[1024] kernel32.dll!CreateProcessA 76581C28 5 Bytes JMP 002A0F4A
.text C:\Windows\system32\svchost.exe[1024] kernel32.dll!VirtualProtect 76581DC3 5 Bytes JMP 002A0067
.text C:\Windows\system32\svchost.exe[1024] kernel32.dll!CreateNamedPipeA 76582EF5 5 Bytes JMP 002A001B
.text C:\Windows\system32\svchost.exe[1024] kernel32.dll!CreateNamedPipeW 76585C0C 5 Bytes JMP 002A0FCA
.text C:\Windows\system32\svchost.exe[1024] kernel32.dll!CreatePipe 765A8F06 5 Bytes JMP 002A0089
.text C:\Windows\system32\svchost.exe[1024] kernel32.dll!LoadLibraryExW 765A927C 5 Bytes JMP 002A0F8D
.text C:\Windows\system32\svchost.exe[1024] kernel32.dll!LoadLibraryW 765A9400 5 Bytes JMP 002A0040
.text C:\Windows\system32\svchost.exe[1024] kernel32.dll!LoadLibraryExA 765A9554 5 Bytes JMP 002A0F9E
.text C:\Windows\system32\svchost.exe[1024] kernel32.dll!LoadLibraryA 765A957C 5 Bytes JMP 002A0FB9
.text C:\Windows\system32\svchost.exe[1024] kernel32.dll!VirtualProtectEx 765ADC52 5 Bytes JMP 002A0078
.text C:\Windows\system32\svchost.exe[1024] kernel32.dll!GetProcAddress 765C925B 5 Bytes JMP 002A0F14
.text C:\Windows\system32\svchost.exe[1024] kernel32.dll!CreateFileW 765CB0EB 5 Bytes JMP 002A000A
.text C:\Windows\system32\svchost.exe[1024] kernel32.dll!CreateFileA 765CD07F 5 Bytes JMP 002A0FEF
.text C:\Windows\system32\svchost.exe[1024] kernel32.dll!WinExec 766160CF 5 Bytes JMP 002A00C6
.text C:\Windows\system32\svchost.exe[1024] msvcrt.dll!_wsystem 760C7F2F 5 Bytes JMP 00250FAD
.text C:\Windows\system32\svchost.exe[1024] msvcrt.dll!system 760C804B 5 Bytes JMP 0025002E
.text C:\Windows\system32\svchost.exe[1024] msvcrt.dll!_creat 760CBBE1 5 Bytes JMP 00250FD2
.text C:\Windows\system32\svchost.exe[1024] msvcrt.dll!_open 760CD106 5 Bytes JMP 00250000
.text C:\Windows\system32\svchost.exe[1024] msvcrt.dll!_wcreat 760CD326 5 Bytes JMP 0025001D
.text C:\Windows\system32\svchost.exe[1024] msvcrt.dll!_wopen 760CD501 5 Bytes JMP 00250FE3
.text C:\Windows\system32\svchost.exe[1024] ADVAPI32.dll!RegCreateKeyExA 768039AB 5 Bytes JMP 002F0051
.text C:\Windows\system32\svchost.exe[1024] ADVAPI32.dll!RegCreateKeyA 76803BA9 5 Bytes JMP 002F0FC0
.text C:\Windows\system32\svchost.exe[1024] ADVAPI32.dll!RegOpenKeyA 768089C7 5 Bytes JMP 002F0000
.text C:\Windows\system32\svchost.exe[1024] ADVAPI32.dll!RegCreateKeyW 7681391E 5 Bytes JMP 002F0FA5
.text C:\Windows\system32\svchost.exe[1024] ADVAPI32.dll!RegCreateKeyExW 768141F1 5 Bytes JMP 002F006C
.text C:\Windows\system32\svchost.exe[1024] ADVAPI32.dll!RegOpenKeyExA 76817C42 5 Bytes JMP 002F0011
.text C:\Windows\system32\svchost.exe[1024] ADVAPI32.dll!RegOpenKeyW 7681E2B5 5 Bytes JMP 002F0FE5
.text C:\Windows\system32\svchost.exe[1024] ADVAPI32.dll!RegOpenKeyExW 76827BA1 5 Bytes JMP 002F002C
.text C:\Windows\system32\svchost.exe[1024] WS2_32.dll!socket 75FB36D1 5 Bytes JMP 00240000
.text C:\Windows\system32\svchost.exe[1024] WININET.dll!InternetOpenA 775D4E33 5 Bytes JMP 00960000
.text C:\Windows\system32\svchost.exe[1024] WININET.dll!InternetOpenUrlA 775DBFCE 5 Bytes JMP 00960FCA
.text C:\Windows\system32\svchost.exe[1024] WININET.dll!InternetOpenW 7760C02E 5 Bytes JMP 00960FE5
.text C:\Windows\system32\svchost.exe[1024] WININET.dll!InternetOpenUrlW 7763D70A 5 Bytes JMP 00960011
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateFile 778F4224 5 Bytes JMP 001D0000
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcess 778F42E4 5 Bytes JMP 001D0FE5
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtProtectVirtualMemory 778F4B84 5 Bytes JMP 001D0011
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!GetStartupInfoW 76581929 5 Bytes JMP 00AF00DD
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!GetStartupInfoA 765819C9 5 Bytes JMP 00AF0F97
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!CreateProcessW 76581BF3 5 Bytes JMP 00AF0F68
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!CreateProcessA 76581C28 5 Bytes JMP 00AF0109
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!VirtualProtect 76581DC3 5 Bytes JMP 00AF0FD4
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!CreateNamedPipeA 76582EF5 5 Bytes JMP 00AF0FEF
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!CreateNamedPipeW 76585C0C 5 Bytes JMP 00AF0040
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!CreatePipe 765A8F06 5 Bytes JMP 00AF0FB2
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!LoadLibraryExW 765A927C 5 Bytes JMP 00AF00B8
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!LoadLibraryW 765A9400 5 Bytes JMP 00AF0080
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!LoadLibraryExA 765A9554 5 Bytes JMP 00AF0091
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!LoadLibraryA 765A957C 5 Bytes JMP 00AF005B
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!VirtualProtectEx 765ADC52 5 Bytes JMP 00AF0FC3
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!GetProcAddress 765C925B 5 Bytes JMP 00AF0F57
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!CreateFileW 765CB0EB 5 Bytes JMP 00AF001B
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!CreateFileA 765CD07F 5 Bytes JMP 00AF0000
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!WinExec 766160CF 5 Bytes JMP 00AF00EE
.text C:\Windows\System32\svchost.exe[1064] msvcrt.dll!_wsystem 760C7F2F 5 Bytes JMP 00AE0070
.text C:\Windows\System32\svchost.exe[1064] msvcrt.dll!system 760C804B 5 Bytes JMP 00AE005F
.text C:\Windows\System32\svchost.exe[1064] msvcrt.dll!_creat 760CBBE1 5 Bytes JMP 00AE003A
.text C:\Windows\System32\svchost.exe[1064] msvcrt.dll!_open 760CD106 5 Bytes JMP 00AE000C
.text C:\Windows\System32\svchost.exe[1064] msvcrt.dll!_wcreat 760CD326 5 Bytes JMP 00AE0FEF
.text C:\Windows\System32\svchost.exe[1064] msvcrt.dll!_wopen 760CD501 5 Bytes JMP 00AE001D
.text C:\Windows\System32\svchost.exe[1064] ADVAPI32.dll!RegCreateKeyExA 768039AB 5 Bytes JMP 00B00F9B
.text C:\Windows\System32\svchost.exe[1064] ADVAPI32.dll!RegCreateKeyA 76803BA9 5 Bytes JMP 00B00022
.text C:\Windows\System32\svchost.exe[1064] ADVAPI32.dll!RegOpenKeyA 768089C7 5 Bytes JMP 00B00FEF
.text C:\Windows\System32\svchost.exe[1064] ADVAPI32.dll!RegCreateKeyW 7681391E 5 Bytes JMP 00B0003D
.text C:\Windows\System32\svchost.exe[1064] ADVAPI32.dll!RegCreateKeyExW 768141F1 5 Bytes JMP 00B00F8A
.text C:\Windows\System32\svchost.exe[1064] ADVAPI32.dll!RegOpenKeyExA 76817C42 5 Bytes JMP 00B00011
.text C:\Windows\System32\svchost.exe[1064] ADVAPI32.dll!RegOpenKeyW 7681E2B5 5 Bytes JMP 00B00000
.text C:\Windows\System32\svchost.exe[1064] ADVAPI32.dll!RegOpenKeyExW 76827BA1 5 Bytes JMP 00B00FB6
.text C:\Windows\System32\svchost.exe[1064] WS2_32.dll!socket 75FB36D1 5 Bytes JMP 00990000
.text C:\Windows\System32\svchost.exe[1064] WININET.dll!InternetOpenA 775D4E33 5 Bytes JMP 00BA0FEF
.text C:\Windows\System32\svchost.exe[1064] WININET.dll!InternetOpenUrlA 775DBFCE 5 Bytes JMP 00BA0011
.text C:\Windows\System32\svchost.exe[1064] WININET.dll!InternetOpenW 7760C02E 5 Bytes JMP 00BA0000
.text C:\Windows\System32\svchost.exe[1064] WININET.dll!InternetOpenUrlW 7763D70A 5 Bytes JMP 00BA002C
.text C:\Windows\System32\svchost.exe[1116] ntdll.dll!NtCreateFile 778F4224 5 Bytes JMP 00B50FEF
.text C:\Windows\System32\svchost.exe[1116] ntdll.dll!NtCreateProcess 778F42E4 5 Bytes JMP 00B5002F
.text C:\Windows\System32\svchost.exe[1116] ntdll.dll!NtProtectVirtualMemory 778F4B84 5 Bytes JMP 00B5000A
.text C:\Windows\System32\svchost.exe[1116] kernel32.dll!GetStartupInfoW 76581929 5 Bytes JMP 00F500ED
.text C:\Windows\System32\svchost.exe[1116] kernel32.dll!GetStartupInfoA 765819C9 5 Bytes JMP 00F500D2
.text C:\Windows\System32\svchost.exe[1116] kernel32.dll!CreateProcessW 76581BF3 5 Bytes JMP 00F50134
.text C:\Windows\System32\svchost.exe[1116] kernel32.dll!CreateProcessA 76581C28 5 Bytes JMP 00F50123
.text C:\Windows\System32\svchost.exe[1116] kernel32.dll!VirtualProtect 76581DC3 5 Bytes JMP 00F5009F
.text C:\Windows\System32\svchost.exe[1116] kernel32.dll!CreateNamedPipeA 76582EF5 5 Bytes JMP 00F50FD1
.text C:\Windows\System32\svchost.exe[1116] kernel32.dll!CreateNamedPipeW 76585C0C 5 Bytes JMP 00F50022
.text C:\Windows\System32\svchost.exe[1116] kernel32.dll!CreatePipe 765A8F06 5 Bytes JMP 00F500C1
.text C:\Windows\System32\svchost.exe[1116] kernel32.dll!LoadLibraryExW 765A927C 5 Bytes JMP 00F50084
.text C:\Windows\System32\svchost.exe[1116] kernel32.dll!LoadLibraryW 765A9400 5 Bytes JMP 00F50058
.text C:\Windows\System32\svchost.exe[1116] kernel32.dll!LoadLibraryExA 765A9554 5 Bytes JMP 00F50069
.text C:\Windows\System32\svchost.exe[1116] kernel32.dll!LoadLibraryA 765A957C 5 Bytes JMP 00F50047
.text C:\Windows\System32\svchost.exe[1116] kernel32.dll!VirtualProtectEx 765ADC52 5 Bytes JMP 00F500B0
.text C:\Windows\System32\svchost.exe[1116] kernel32.dll!GetProcAddress 765C925B 5 Bytes JMP 00F50F82
.text C:\Windows\System32\svchost.exe[1116] kernel32.dll!CreateFileW 765CB0EB 5 Bytes JMP 00F50011
.text C:\Windows\System32\svchost.exe[1116] kernel32.dll!CreateFileA 765CD07F 5 Bytes JMP 00F50000
.text C:\Windows\System32\svchost.exe[1116] kernel32.dll!WinExec 766160CF 5 Bytes JMP 00F50108
.text C:\Windows\System32\svchost.exe[1116] msvcrt.dll!_wsystem 760C7F2F 5 Bytes JMP 00F40FCD
.text C:\Windows\System32\svchost.exe[1116] msvcrt.dll!system 760C804B 5 Bytes JMP 00F40FDE
.text C:\Windows\System32\svchost.exe[1116] msvcrt.dll!_creat 760CBBE1 5 Bytes JMP 00F40029
.text C:\Windows\System32\svchost.exe[1116] msvcrt.dll!_open 760CD106 5 Bytes JMP 00F4000C
.text C:\Windows\System32\svchost.exe[1116] msvcrt.dll!_wcreat 760CD326 5 Bytes JMP 00F4004E
.text C:\Windows\System32\svchost.exe[1116] msvcrt.dll!_wopen 760CD501 5 Bytes JMP 00F40FEF
.text C:\Windows\System32\svchost.exe[1116] ADVAPI32.dll!RegCreateKeyExA 768039AB 5 Bytes JMP 00F60022
.text C:\Windows\System32\svchost.exe[1116] ADVAPI32.dll!RegCreateKeyA 76803BA9 5 Bytes JMP 00F60011
.text C:\Windows\System32\svchost.exe[1116] ADVAPI32.dll!RegOpenKeyA 768089C7 5 Bytes JMP 00F60FE5
.text C:\Windows\System32\svchost.exe[1116] ADVAPI32.dll!RegCreateKeyW 7681391E 5 Bytes JMP 00F60F8A
.text C:\Windows\System32\svchost.exe[1116] ADVAPI32.dll!RegCreateKeyExW 768141F1 5 Bytes JMP 00F6003D
.text C:\Windows\System32\svchost.exe[1116] ADVAPI32.dll!RegOpenKeyExA 76817C42 5 Bytes JMP 00F60000
.text C:\Windows\System32\svchost.exe[1116] ADVAPI32.dll!RegOpenKeyW 7681E2B5 5 Bytes JMP 00F60FD4
.text C:\Windows\System32\svchost.exe[1116] ADVAPI32.dll!RegOpenKeyExW 76827BA1 1 Byte [E9]
.text C:\Windows\System32\svchost.exe[1116] ADVAPI32.dll!RegOpenKeyExW 76827BA1 5 Bytes JMP 00F60FA5
.text C:\Windows\System32\svchost.exe[1116] WS2_32.dll!socket 75FB36D1 5 Bytes JMP 00B60FE5
.text C:\Windows\System32\svchost.exe[1116] WININET.dll!InternetOpenA 775D4E33 5 Bytes JMP 00FF0FEF
.text C:\Windows\System32\svchost.exe[1116] WININET.dll!InternetOpenUrlA 775DBFCE 5 Bytes JMP 00FF001B
.text C:\Windows\System32\svchost.exe[1116] WININET.dll!InternetOpenW 7760C02E 5 Bytes JMP 00FF0000
.text C:\Windows\System32\svchost.exe[1116] WININET.dll!InternetOpenUrlW 7763D70A 5 Bytes JMP 00FF0FCA
.text C:\Windows\System32\svchost.exe[1152] ntdll.dll!NtCreateFile 778F4224 5 Bytes JMP 00B7000A
.text C:\Windows\System32\svchost.exe[1152] ntdll.dll!NtCreateProcess 778F42E4 5 Bytes JMP 00B70FD4
.text C:\Windows\System32\svchost.exe[1152] ntdll.dll!NtProtectVirtualMemory 778F4B84 5 Bytes JMP 00B70FEF
.text C:\Windows\System32\svchost.exe[1152] kernel32.dll!GetStartupInfoW 76581929 5 Bytes JMP 00F400BF
.text C:\Windows\System32\svchost.exe[1152] kernel32.dll!GetStartupInfoA 765819C9 5 Bytes JMP 00F400A4
.text C:\Windows\System32\svchost.exe[1152] kernel32.dll!CreateProcessW 76581BF3 5 Bytes JMP 00F40F4A
.text C:\Windows\System32\svchost.exe[1152] kernel32.dll!CreateProcessA 76581C28 5 Bytes JMP 00F400EB
.text C:\Windows\System32\svchost.exe[1152] kernel32.dll!VirtualProtect 76581DC3 5 Bytes JMP 00F4006E
.text C:\Windows\System32\svchost.exe[1152] kernel32.dll!CreateNamedPipeA 76582EF5 5 Bytes JMP 00F40014
.text C:\Windows\System32\svchost.exe[1152] kernel32.dll!CreateNamedPipeW 76585C0C 5 Bytes JMP 00F40FC3
.text C:\Windows\System32\svchost.exe[1152] kernel32.dll!CreatePipe 765A8F06 5 Bytes JMP 00F40089
.text C:\Windows\System32\svchost.exe[1152] kernel32.dll!LoadLibraryExW 765A927C 5 Bytes JMP 00F40F94
.text C:\Windows\System32\svchost.exe[1152] kernel32.dll!LoadLibraryW 765A9400 5 Bytes JMP 00F40040
.text C:\Windows\System32\svchost.exe[1152] kernel32.dll!LoadLibraryExA 765A9554 5 Bytes JMP 00F40051
.text C:\Windows\System32\svchost.exe[1152] kernel32.dll!LoadLibraryA 765A957C 5 Bytes JMP 00F40025
.text C:\Windows\System32\svchost.exe[1152] kernel32.dll!VirtualProtectEx 765ADC52 5 Bytes JMP 00F40F79
.text C:\Windows\System32\svchost.exe[1152] kernel32.dll!GetProcAddress 765C925B 5 Bytes JMP 00F40F39
.text C:\Windows\System32\svchost.exe[1152] kernel32.dll!CreateFileW 765CB0EB 5 Bytes JMP 00F40FDE
.text C:\Windows\System32\svchost.exe[1152] kernel32.dll!CreateFileA 765CD07F 5 Bytes JMP 00F40FEF
.text C:\Windows\System32\svchost.exe[1152] kernel32.dll!WinExec 766160CF 5 Bytes JMP 00F400DA
.text C:\Windows\System32\svchost.exe[1152] msvcrt.dll!_wsystem 760C7F2F 5 Bytes JMP 00BA004E
.text C:\Windows\System32\svchost.exe[1152] msvcrt.dll!system 760C804B 5 Bytes JMP 00BA003D
.text C:\Windows\System32\svchost.exe[1152] msvcrt.dll!_creat 760CBBE1 5 Bytes JMP 00BA0FD7
.text C:\Windows\System32\svchost.exe[1152] msvcrt.dll!_open 760CD106 5 Bytes JMP 00BA0000
.text C:\Windows\System32\svchost.exe[1152] msvcrt.dll!_wcreat 760CD326 5 Bytes JMP 00BA002C
.text C:\Windows\System32\svchost.exe[1152] msvcrt.dll!_wopen 760CD501 5 Bytes JMP 00BA0011
.text C:\Windows\System32\svchost.exe[1152] ADVAPI32.dll!RegCreateKeyExA 768039AB 5 Bytes JMP 00F50F97
.text C:\Windows\System32\svchost.exe[1152] ADVAPI32.dll!RegCreateKeyA 76803BA9 5 Bytes JMP 00F5002F
.text C:\Windows\System32\svchost.exe[1152] ADVAPI32.dll!RegOpenKeyA 768089C7 5 Bytes JMP 00F50FE5
.text C:\Windows\System32\svchost.exe[1152] ADVAPI32.dll!RegCreateKeyW 7681391E 5 Bytes JMP 00F50FA8
.text C:\Windows\System32\svchost.exe[1152] ADVAPI32.dll!RegCreateKeyExW 768141F1 5 Bytes JMP 00F5004A
.text C:\Windows\System32\svchost.exe[1152] ADVAPI32.dll!RegOpenKeyExA 76817C42 5 Bytes JMP 00F50FC3
.text C:\Windows\System32\svchost.exe[1152] ADVAPI32.dll!RegOpenKeyW 7681E2B5 5 Bytes JMP 00F50FD4
.text C:\Windows\System32\svchost.exe[1152] ADVAPI32.dll!RegOpenKeyExW 76827BA1 5 Bytes JMP 00F5000A
.text C:\Windows\System32\svchost.exe[1152] WS2_32.dll!socket 75FB36D1 5 Bytes JMP 00B80000
.text C:\Windows\System32\svchost.exe[1152] WININET.dll!InternetOpenA 775D4E33 5 Bytes JMP 01600FE5
.text C:\Windows\System32\svchost.exe[1152] WININET.dll!InternetOpenUrlA 775DBFCE 5 Bytes JMP 0160001B
.text C:\Windows\System32\svchost.exe[1152] WININET.dll!InternetOpenW 7760C02E 5 Bytes JMP 01600000
.text C:\Windows\System32\svchost.exe[1152] WININET.dll!InternetOpenUrlW 7763D70A 5 Bytes JMP 0160002C
.text C:\Windows\system32\svchost.exe[1192] ntdll.dll!NtCreateFile 778F4224 5 Bytes JMP 0141000A
.text C:\Windows\system32\svchost.exe[1192] ntdll.dll!NtCreateProcess 778F42E4 5 Bytes JMP 01410036
.text C:\Windows\system32\svchost.exe[1192] ntdll.dll!NtProtectVirtualMemory 778F4B84 5 Bytes JMP 0141001B
.text C:\Windows\system32\svchost.exe[1192] ntdll.dll!NtWriteVirtualMemory 778F54C4 5 Bytes JMP 00AC000A
.text C:\Windows\system32\svchost.exe[1192] ntdll.dll!KiUserExceptionDispatcher 778F5BF8 5 Bytes JMP 0098000A
.text C:\Windows\system32\svchost.exe[1192] kernel32.dll!GetStartupInfoW 76581929 5 Bytes JMP 014C0098
.text C:\Windows\system32\svchost.exe[1192] kernel32.dll!GetStartupInfoA 765819C9 5 Bytes JMP 014C0F52
.text C:\Windows\system32\svchost.exe[1192] kernel32.dll!CreateProcessW 76581BF3 5 Bytes JMP 014C0F1C
.text C:\Windows\system32\svchost.exe[1192] kernel32.dll!CreateProcessA 76581C28 5 Bytes JMP 014C00BD
.text C:\Windows\system32\svchost.exe[1192] kernel32.dll!VirtualProtect 76581DC3 5 Bytes JMP 014C0F77
.text C:\Windows\system32\svchost.exe[1192] kernel32.dll!CreateNamedPipeA 76582EF5 5 Bytes JMP 014C0FE5
.text C:\Windows\system32\svchost.exe[1192] kernel32.dll!CreateNamedPipeW 76585C0C 5 Bytes JMP 014C0FD4
.text C:\Windows\system32\svchost.exe[1192] kernel32.dll!CreatePipe 765A8F06 5 Bytes JMP 014C0087
.text C:\Windows\system32\svchost.exe[1192] kernel32.dll!LoadLibraryExW 765A927C 5 Bytes JMP 014C0F88
.text C:\Windows\system32\svchost.exe[1192] kernel32.dll!LoadLibraryW 765A9400 5 Bytes JMP 014C0040
.text C:\Windows\system32\svchost.exe[1192] kernel32.dll!LoadLibraryExA 765A9554 5 Bytes JMP 014C0051
.text C:\Windows\system32\svchost.exe[1192] kernel32.dll!LoadLibraryA 765A957C 5 Bytes JMP 014C0FC3
.text C:\Windows\system32\svchost.exe[1192] kernel32.dll!VirtualProtectEx 765ADC52 5 Bytes JMP 014C0076
.text C:\Windows\system32\svchost.exe[1192] kernel32.dll!GetProcAddress 765C925B 5 Bytes JMP 014C00D8
.text C:\Windows\system32\svchost.exe[1192] kernel32.dll!CreateFileW 765CB0EB 5 Bytes JMP 014C001B
.text C:\Windows\system32\svchost.exe[1192] kernel32.dll!CreateFileA 765CD07F 5 Bytes JMP 014C0000
.text C:\Windows\system32\svchost.exe[1192] kernel32.dll!WinExec 766160CF 5 Bytes JMP 014C0F41
.text C:\Windows\system32\svchost.exe[1192] msvcrt.dll!_wsystem 760C7F2F 5 Bytes JMP 014B001B
.text C:\Windows\system32\svchost.exe[1192] msvcrt.dll!system 760C804B 5 Bytes JMP 014B0F90
.text C:\Windows\system32\svchost.exe[1192] msvcrt.dll!_creat 760CBBE1 5 Bytes JMP 014B0000
.text C:\Windows\system32\svchost.exe[1192] msvcrt.dll!_open 760CD106 5 Bytes JMP 014B0FE3
.text C:\Windows\system32\svchost.exe[1192] msvcrt.dll!_wcreat 760CD326 5 Bytes JMP 014B0FAB
.text C:\Windows\system32\svchost.exe[1192] msvcrt.dll!_wopen 760CD501 5 Bytes JMP 014B0FD2
.text C:\Windows\system32\svchost.exe[1192] ADVAPI32.dll!RegCreateKeyExA 768039AB 5 Bytes JMP 014D0073
.text C:\Windows\system32\svchost.exe[1192] ADVAPI32.dll!RegCreateKeyA 76803BA9 5 Bytes JMP 014D0058
.text C:\Windows\system32\svchost.exe[1192] ADVAPI32.dll!RegOpenKeyA 768089C7 5 Bytes JMP 014D0000
.text C:\Windows\system32\svchost.exe[1192] ADVAPI32.dll!RegCreateKeyW 7681391E 5 Bytes JMP 014D0FD1
.text C:\Windows\system32\svchost.exe[1192] ADVAPI32.dll!RegCreateKeyExW 768141F1 5 Bytes JMP 014D008E
.text C:\Windows\system32\svchost.exe[1192] ADVAPI32.dll!RegOpenKeyExA 76817C42 5 Bytes JMP 014D002C
.text C:\Windows\system32\svchost.exe[1192] ADVAPI32.dll!RegOpenKeyW 7681E2B5 5 Bytes JMP 014D001B
.text C:\Windows\system32\svchost.exe[1192] ADVAPI32.dll!RegOpenKeyExW 76827BA1 5 Bytes JMP 014D003D
.text C:\Windows\system32\svchost.exe[1192] WS2_32.dll!socket 75FB36D1 5 Bytes JMP 01420000
.text C:\Windows\system32\svchost.exe[1192] WININET.dll!InternetOpenA 775D4E33 5 Bytes JMP 0152000A
.text C:\Windows\system32\svchost.exe[1192] WININET.dll!InternetOpenUrlA 775DBFCE 5 Bytes JMP 0152001B
.text C:\Windows\system32\svchost.exe[1192] WININET.dll!InternetOpenW 7760C02E 5 Bytes JMP 01520FE5
.text C:\Windows\system32\svchost.exe[1192] WININET.dll!InternetOpenUrlW 7763D70A 5 Bytes JMP 0152002C
.text C:\Windows\system32\svchost.exe[1308] ntdll.dll!NtCreateFile 778F4224 5 Bytes JMP 001D0FEF
.text C:\Windows\system32\svchost.exe[1308] ntdll.dll!NtCreateProcess 778F42E4 5 Bytes JMP 001D001E
.text C:\Windows\system32\svchost.exe[1308] ntdll.dll!NtProtectVirtualMemory 778F4B84 5 Bytes JMP 001D0FDE
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!GetStartupInfoW 76581929 5 Bytes JMP 00810F2B
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!GetStartupInfoA 765819C9 5 Bytes JMP 00810F46
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!CreateProcessW 76581BF3 5 Bytes JMP 008100B1
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!CreateProcessA 76581C28 5 Bytes JMP 00810096
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!VirtualProtect 76581DC3 5 Bytes JMP 00810F6B
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!CreateNamedPipeA 76582EF5 5 Bytes JMP 00810FC3
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!CreateNamedPipeW 76585C0C 5 Bytes JMP 00810FB2
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!CreatePipe 765A8F06 5 Bytes JMP 0081007B
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!LoadLibraryExW 765A927C 5 Bytes JMP 00810039
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!LoadLibraryW 765A9400 5 Bytes JMP 00810F7C
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!LoadLibraryExA 765A9554 5 Bytes JMP 0081001E
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!LoadLibraryA 765A957C 5 Bytes JMP 00810F8D
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!VirtualProtectEx 765ADC52 5 Bytes JMP 0081006A
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!GetProcAddress 765C925B 5 Bytes JMP 00810F09
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!CreateFileW 765CB0EB 5 Bytes JMP 00810FD4
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!CreateFileA 765CD07F 5 Bytes JMP 00810FEF
.text C:\Windows\system32\svchost.exe[1308] kernel32.dll!WinExec 766160CF 5 Bytes JMP 00810F1A
.text C:\Windows\system32\svchost.exe[1308] msvcrt.dll!_wsystem 760C7F2F 5 Bytes JMP 00800F89
.text C:\Windows\system32\svchost.exe[1308] msvcrt.dll!system 760C804B 5 Bytes JMP 00800F9A
.text C:\Windows\system32\svchost.exe[1308] msvcrt.dll!_creat 760CBBE1 5 Bytes JMP 00800000
.text C:\Windows\system32\svchost.exe[1308] msvcrt.dll!_open 760CD106 5 Bytes JMP 00800FE3
.text C:\Windows\system32\svchost.exe[1308] msvcrt.dll!_wcreat 760CD326 5 Bytes JMP 00800FAB
.text C:\Windows\system32\svchost.exe[1308] msvcrt.dll!_wopen 760CD501 5 Bytes JMP 00800FD2
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!RegCreateKeyExA 768039AB 5 Bytes JMP 00820FB9
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!RegCreateKeyA 76803BA9 5 Bytes JMP 00820040
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!RegOpenKeyA 768089C7 5 Bytes JMP 00820000
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!RegCreateKeyW 7681391E 5 Bytes JMP 0082005B
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!RegCreateKeyExW 768141F1 5 Bytes JMP 00820076
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!RegOpenKeyExA 76817C42 5 Bytes JMP 0082001B
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!RegOpenKeyW 7681E2B5 5 Bytes JMP 00820FE5
.text C:\Windows\system32\svchost.exe[1308] ADVAPI32.dll!RegOpenKeyExW 76827BA1 5 Bytes JMP 00820FD4
.text C:\Windows\system32\svchost.exe[1308] WS2_32.dll!socket 75FB36D1 5 Bytes JMP 00370FE5
.text C:\Windows\system32\svchost.exe[1412] ntdll.dll!NtCreateFile 778F4224 5 Bytes JMP 00190FEF
.text C:\Windows\system32\svchost.exe[1412] ntdll.dll!NtCreateProcess 778F42E4 5 Bytes JMP 00190FC3
.text C:\Windows\system32\svchost.exe[1412] ntdll.dll!NtProtectVirtualMemory 778F4B84 5 Bytes JMP 00190FDE
.text C:\Windows\system32\svchost.exe[1412] kernel32.dll!GetStartupInfoW 76581929 5 Bytes JMP 00AA00C9
.text C:\Windows\system32\svchost.exe[1412] kernel32.dll!GetStartupInfoA 765819C9 5 Bytes JMP 00AA00AE
.text C:\Windows\system32\svchost.exe[1412] kernel32.dll!CreateProcessW 76581BF3 5 Bytes JMP 00AA00EE
.text C:\Windows\system32\svchost.exe[1412] kernel32.dll!CreateProcessA 76581C28 5 Bytes JMP 00AA0F57
.text C:\Windows\system32\svchost.exe[1412] kernel32.dll!VirtualProtect 76581DC3 5 Bytes JMP 00AA0078
.text C:\Windows\system32\svchost.exe[1412] kernel32.dll!CreateNamedPipeA 76582EF5 5 Bytes JMP 00AA0FCA
.text C:\Windows\system32\svchost.exe[1412] kernel32.dll!CreateNamedPipeW 76585C0C 5 Bytes JMP 00AA001B
.text C:\Windows\system32\svchost.exe[1412] kernel32.dll!CreatePipe 765A8F06 5 Bytes JMP 00AA0093
.text C:\Windows\system32\svchost.exe[1412] kernel32.dll!LoadLibraryExW 765A927C 5 Bytes JMP 00AA0F9E
.text C:\Windows\system32\svchost.exe[1412] kernel32.dll!LoadLibraryW 765A9400 5 Bytes JMP 00AA0FAF
.text C:\Windows\system32\svchost.exe[1412] kernel32.dll!LoadLibraryExA 765A9554 5 Bytes JMP 00AA005B
.text C:\Windows\system32\svchost.exe[1412] kernel32.dll!LoadLibraryA 765A957C 5 Bytes JMP 00AA0036
.text C:\Windows\system32\svchost.exe[1412] kernel32.dll!VirtualProtectEx 765ADC52 5 Bytes JMP 00AA0F83
.text C:\Windows\system32\svchost.exe[1412] kernel32.dll!GetProcAddress 765C925B 5 Bytes JMP 00AA0F3C
.text C:\Windows\system32\svchost.exe[1412] kernel32.dll!CreateFileW 765CB0EB 5 Bytes JMP 00AA0FE5
.text C:\Windows\system32\svchost.exe[1412] kernel32.dll!CreateFileA 765CD07F 5 Bytes JMP 00AA000A
.text C:\Windows\system32\svchost.exe[1412] kernel32.dll!WinExec 766160CF 5 Bytes JMP 00AA0F68
.text C:\Windows\system32\svchost.exe[1412] msvcrt.dll!_wsystem 760C7F2F 5 Bytes JMP 00A90FBC
.text C:\Windows\system32\svchost.exe[1412] msvcrt.dll!system 760C804B 5 Bytes JMP 00A90FCD
.text C:\Windows\system32\svchost.exe[1412] msvcrt.dll!_creat 760CBBE1 5 Bytes JMP 00A90022
.text C:\Windows\system32\svchost.exe[1412] msvcrt.dll!_open 760CD106 5 Bytes JMP 00A90000
.text C:\Windows\system32\svchost.exe[1412] msvcrt.dll!_wcreat 760CD326 5 Bytes JMP 00A9003D
.text C:\Windows\system32\svchost.exe[1412] msvcrt.dll!_wopen 760CD501 5 Bytes JMP 00A90011
.text C:\Windows\system32\svchost.exe[1412] ADVAPI32.dll!RegCreateKeyExA 768039AB 5 Bytes JMP 00AF0F72
.text C:\Windows\system32\svchost.exe[1412] ADVAPI32.dll!RegCreateKeyA 76803BA9 5 Bytes JMP 00AF000A
.text C:\Windows\system32\svchost.exe[1412] ADVAPI32.dll!RegOpenKeyA 768089C7 5 Bytes JMP 00AF0FE5
.text C:\Windows\system32\svchost.exe[1412] ADVAPI32.dll!RegCreateKeyW 7681391E 5 Bytes JMP 00AF0F8D
.text C:\Windows\system32\svchost.exe[1412] ADVAPI32.dll!RegCreateKeyExW 768141F1 5 Bytes JMP 00AF0F61
.text C:\Windows\system32\svchost.exe[1412] ADVAPI32.dll!RegOpenKeyExA 76817C42 5 Bytes JMP 00AF0FB9
.text C:\Windows\system32\svchost.exe[1412] ADVAPI32.dll!RegOpenKeyW 7681E2B5 5 Bytes JMP 00AF0FD4
.text C:\Windows\system32\svchost.exe[1412] ADVAPI32.dll!RegOpenKeyExW 76827BA1 5 Bytes JMP 00AF0FA8
.text C:\Windows\system32\svchost.exe[1412] WS2_32.dll!socket 75FB36D1 5 Bytes JMP 00A80000
.text C:\Windows\system32\svchost.exe[1412] WININET.dll!InternetOpenA 775D4E33 5 Bytes JMP 00B0000A
.text C:\Windows\system32\svchost.exe[1412] WININET.dll!InternetOpenUrlA 775DBFCE 5 Bytes JMP 00B0001B
.text C:\Windows\system32\svchost.exe[1412] WININET.dll!InternetOpenW 7760C02E 5 Bytes JMP 00B00FEF
.text C:\Windows\system32\svchost.exe[1412] WININET.dll!InternetOpenUrlW 7763D70A 5 Bytes JMP 00B0002C
.text C:\Windows\system32\svchost.exe[1596] ntdll.dll!NtCreateFile 778F4224 5 Bytes JMP 0091000A
.text C:\Windows\system32\svchost.exe[1596] ntdll.dll!NtCreateProcess 778F42E4 5 Bytes JMP 00910025
.text C:\Windows\system32\svchost.exe[1596] ntdll.dll!NtProtectVirtualMemory 778F4B84 5 Bytes JMP 00910FEF
.text C:\Windows\system32\svchost.exe[1596] kernel32.dll!GetStartupInfoW 76581929 5 Bytes JMP 00980F5C
.text C:\Windows\system32\svchost.exe[1596] kernel32.dll!GetStartupInfoA 765819C9 5 Bytes JMP 009800A2
.text C:\Windows\system32\svchost.exe[1596] kernel32.dll!CreateProcessW 76581BF3 5 Bytes JMP 00980F30
.text C:\Windows\system32\svchost.exe[1596] kernel32.dll!CreateProcessA 76581C28 5 Bytes JMP 00980F41
.text C:\Windows\system32\svchost.exe[1596] kernel32.dll!VirtualProtect 76581DC3 5 Bytes JMP 00980076
.text C:\Windows\system32\svchost.exe[1596] kernel32.dll!CreateNamedPipeA 76582EF5 5 Bytes JMP 00980FCA
.text C:\Windows\system32\svchost.exe[1596] kernel32.dll!CreateNamedPipeW 76585C0C 5 Bytes JMP 00980FB9
.text C:\Windows\system32\svchost.exe[1596] kernel32.dll!CreatePipe 765A8F06 5 Bytes JMP 00980091
.text C:\Windows\system32\svchost.exe[1596] kernel32.dll!LoadLibraryExW 765A927C 5 Bytes JMP 0098005B
.text C:\Windows\system32\svchost.exe[1596] kernel32.dll!LoadLibraryW 765A9400 5 Bytes JMP 00980040
.text C:\Windows\system32\svchost.exe[1596] kernel32.dll!LoadLibraryExA 765A9554 5 Bytes JMP 00980F9E
.text C:\Windows\system32\svchost.exe[1596] kernel32.dll!LoadLibraryA 765A957C 5 Bytes JMP 00980025
.text C:\Windows\system32\svchost.exe[1596] kernel32.dll!VirtualProtectEx 765ADC52 5 Bytes JMP 00980F81
.text C:\Windows\system32\svchost.exe[1596] kernel32.dll!GetProcAddress 765C925B 5 Bytes JMP 009800E2
.text C:\Windows\system32\svchost.exe[1596] kernel32.dll!CreateFileW 765CB0EB 5 Bytes JMP 00980FDB
.text C:\Windows\system32\svchost.exe[1596] kernel32.dll!CreateFileA 765CD07F 5 Bytes JMP 00980000
.text C:\Windows\system32\svchost.exe[1596] kernel32.dll!WinExec 766160CF 5 Bytes JMP 009800BD
.text C:\Windows\system32\svchost.exe[1596] msvcrt.dll!_wsystem 760C7F2F 5 Bytes JMP 00970049
.text C:\Windows\system32\svchost.exe[1596] msvcrt.dll!system 760C804B 5 Bytes JMP 00970038
.text C:\Windows\system32\svchost.exe[1596] msvcrt.dll!_creat 760CBBE1 5 Bytes JMP 0097001D
.text C:\Windows\system32\svchost.exe[1596] msvcrt.dll!_open 760CD106 5 Bytes JMP 00970000
.text C:\Windows\system32\svchost.exe[1596] msvcrt.dll!_wcreat 760CD326 5 Bytes JMP 00970FBE
.text C:\Windows\system32\svchost.exe[1596] msvcrt.dll!_wopen 760CD501 5 Bytes JMP 00970FE3
.text C:\Windows\system32\svchost.exe[1596] ADVAPI32.dll!RegCreateKeyExA 768039AB 5 Bytes JMP 00990051
.text C:\Windows\system32\svchost.exe[1596] ADVAPI32.dll!RegCreateKeyA 76803BA9 5 Bytes JMP 0099002C
.text C:\Windows\system32\svchost.exe[1596] ADVAPI32.dll!RegOpenKeyA 768089C7 5 Bytes JMP 00990FE5
.text C:\Windows\system32\svchost.exe[1596] ADVAPI32.dll!RegCreateKeyW 7681391E 5 Bytes JMP 00990FAF
.text C:\Windows\system32\svchost.exe[1596] ADVAPI32.dll!RegCreateKeyExW 768141F1 5 Bytes JMP 00990F8A
.text C:\Windows\system32\svchost.exe[1596] ADVAPI32.dll!RegOpenKeyExA 76817C42 5 Bytes JMP 0099001B
.text C:\Windows\system32\svchost.exe[1596] ADVAPI32.dll!RegOpenKeyW 7681E2B5 5 Bytes JMP 0099000A
.text C:\Windows\system32\svchost.exe[1596] ADVAPI32.dll!RegOpenKeyExW 76827BA1 5 Bytes JMP 00990FC0
.text C:\Windows\system32\svchost.exe[1596] WS2_32.dll!socket 75FB36D1 5 Bytes JMP 00920000
.text C:\Windows\system32\svchost.exe[1596] WININET.dll!InternetOpenA 775D4E33 5 Bytes JMP 009B0FEF
.text C:\Windows\system32\svchost.exe[1596] WININET.dll!InternetOpenUrlA 775DBFCE 5 Bytes JMP 009B0000
.text C:\Windows\system32\svchost.exe[1596] WININET.dll!InternetOpenW 7760C02E 5 Bytes JMP 009B0FD4
.text C:\Windows\system32\svchost.exe[1596] WININET.dll!InternetOpenUrlW 7763D70A 5 Bytes JMP 009B001B
.text C:\Windows\system32\svchost.exe[2684] ntdll.dll!NtCreateFile 778F4224 5 Bytes JMP 000D0000
.text C:\Windows\system32\svchost.exe[2684] ntdll.dll!NtCreateProcess 778F42E4 5 Bytes JMP 000D0025
.text C:\Windows\system32\svchost.exe[2684] ntdll.dll!NtProtectVirtualMemory 778F4B84 5 Bytes JMP 000D0FE5
.text C:\Windows\system32\svchost.exe[2684] kernel32.dll!GetStartupInfoW 76581929 5 Bytes JMP 00600F63
.text C:\Windows\system32\svchost.exe[2684] kernel32.dll!GetStartupInfoA 765819C9 5 Bytes JMP 006000B3
.text C:\Windows\system32\svchost.exe[2684] kernel32.dll!CreateProcessW 76581BF3 5 Bytes JMP 00600F2D
.text C:\Windows\system32\svchost.exe[2684] kernel32.dll!CreateProcessA 76581C28 5 Bytes JMP 006000C4
.text C:\Windows\system32\svchost.exe[2684] kernel32.dll!VirtualProtect 76581DC3 5 Bytes JMP 0060007D
.text C:\Windows\system32\svchost.exe[2684] kernel32.dll!CreateNamedPipeA 76582EF5 5 Bytes JMP 0060001B
.text C:\Windows\system32\svchost.exe[2684] kernel32.dll!CreateNamedPipeW 76585C0C 5 Bytes JMP 0060002C
.text C:\Windows\system32\svchost.exe[2684] kernel32.dll!CreatePipe 765A8F06 5 Bytes JMP 00600F7E
.text C:\Windows\system32\svchost.exe[2684] kernel32.dll!LoadLibraryExW 765A927C 5 Bytes JMP 00600062
.text C:\Windows\system32\svchost.exe[2684] kernel32.dll!LoadLibraryW 765A9400 5 Bytes JMP 00600FC0
.text C:\Windows\system32\svchost.exe[2684] kernel32.dll!LoadLibraryExA 765A9554 5 Bytes JMP 00600FA5
.text C:\Windows\system32\svchost.exe[2684] kernel32.dll!LoadLibraryA 765A957C 5 Bytes JMP 0060003D
.text C:\Windows\system32\svchost.exe[2684] kernel32.dll!VirtualProtectEx 765ADC52 5 Bytes JMP 00600098
.text C:\Windows\system32\svchost.exe[2684] kernel32.dll!GetProcAddress 765C925B 5 Bytes JMP 00600F1C
.text C:\Windows\system32\svchost.exe[2684] kernel32.dll!CreateFileW 765CB0EB 5 Bytes JMP 00600FDB
.text C:\Windows\system32\svchost.exe[2684] kernel32.dll!CreateFileA 765CD07F 5 Bytes JMP 00600000
.text C:\Windows\system32\svchost.exe[2684] kernel32.dll!WinExec 766160CF 5 Bytes JMP 00600F52
.text C:\Windows\system32\svchost.exe[2684] msvcrt.dll!_wsystem 760C7F2F 5 Bytes JMP 000F002E
.text C:\Windows\system32\svchost.exe[2684] msvcrt.dll!system 760C804B 5 Bytes JMP 000F0FAD
.text C:\Windows\system32\svchost.exe[2684] msvcrt.dll!_creat 760CBBE1 5 Bytes JMP 000F001D
.text C:\Windows\system32\svchost.exe[2684] msvcrt.dll!_open 760CD106 5 Bytes JMP 000F000C
.text C:\Windows\system32\svchost.exe[2684] msvcrt.dll!_wcreat 760CD326 5 Bytes JMP 000F0FC8
.text C:\Windows\system32\svchost.exe[2684] msvcrt.dll!_wopen 760CD501 5 Bytes JMP 000F0FE3
.text C:\Windows\system32\svchost.exe[2684] ADVAPI32.dll!RegCreateKeyExA 768039AB 5 Bytes JMP 0061004A
.text C:\Windows\system32\svchost.exe[2684] ADVAPI32.dll!RegCreateKeyA 76803BA9 5 Bytes JMP 00610FC3
.text C:\Windows\system32\svchost.exe[2684] ADVAPI32.dll!RegOpenKeyA 768089C7 5 Bytes JMP 00610FEF
.text C:\Windows\system32\svchost.exe[2684] ADVAPI32.dll!RegCreateKeyW 7681391E 5 Bytes JMP 00610FA8
.text C:\Windows\system32\svchost.exe[2684] ADVAPI32.dll!RegCreateKeyExW 768141F1 5 Bytes JMP 00610065
.text C:\Windows\system32\svchost.exe[2684] ADVAPI32.dll!RegOpenKeyExA 76817C42 5 Bytes JMP 00610014
.text C:\Windows\system32\svchost.exe[2684] ADVAPI32.dll!RegOpenKeyW 7681E2B5 5 Bytes JMP 00610FD4
.text C:\Windows\system32\svchost.exe[2684] ADVAPI32.dll!RegOpenKeyExW 76827BA1 5 Bytes JMP 00610025
.text C:\Windows\system32\svchost.exe[2684] WS2_32.dll!socket 75FB36D1 5 Bytes JMP 000E0FEF
.text C:\Windows\System32\svchost.exe[3088] ntdll.dll!NtCreateFile 778F4224 5 Bytes JMP 00190000
.text C:\Windows\System32\svchost.exe[3088] ntdll.dll!NtCreateProcess 778F42E4 5 Bytes JMP 0019001B
.text C:\Windows\System32\svchost.exe[3088] ntdll.dll!NtProtectVirtualMemory 778F4B84 5 Bytes JMP 00190FE5
.text C:\Windows\System32\svchost.exe[3088] kernel32.dll!GetStartupInfoW 76581929 5 Bytes JMP 002000F2
.text C:\Windows\System32\svchost.exe[3088] kernel32.dll!GetStartupInfoA 765819C9 5 Bytes JMP 002000E1
.text C:\Windows\System32\svchost.exe[3088] kernel32.dll!CreateProcessW 76581BF3 5 Bytes JMP 00200121
.text C:\Windows\System32\svchost.exe[3088] kernel32.dll!CreateProcessA 76581C28 5 Bytes JMP 00200F80
.text C:\Windows\System32\svchost.exe[3088] kernel32.dll!VirtualProtect 76581DC3 5 Bytes JMP 00200FCA
.text C:\Windows\System32\svchost.exe[3088] kernel32.dll!CreateNamedPipeA 76582EF5 5 Bytes JMP 00200FE5
.text C:\Windows\System32\svchost.exe[3088] kernel32.dll!CreateNamedPipeW 76585C0C 5 Bytes JMP 00200040
.text C:\Windows\System32\svchost.exe[3088] kernel32.dll!CreatePipe 765A8F06 5 Bytes JMP 002000C6
.text C:\Windows\System32\svchost.exe[3088] kernel32.dll!LoadLibraryExW 765A927C 5 Bytes JMP 00200098
.text C:\Windows\System32\svchost.exe[3088] kernel32.dll!LoadLibraryW 765A9400 5 Bytes JMP 0020006C
.text C:\Windows\System32\svchost.exe[3088] kernel32.dll!LoadLibraryExA 765A9554 5 Bytes JMP 00200087
.text C:\Windows\System32\svchost.exe[3088] kernel32.dll!LoadLibraryA 765A957C 5 Bytes JMP 0020005B
.text C:\Windows\System32\svchost.exe[3088] kernel32.dll!VirtualProtectEx 765ADC52 5 Bytes JMP 002000B5
.text C:\Windows\System32\svchost.exe[3088] kernel32.dll!GetProcAddress 765C925B 5 Bytes JMP 00200F6F
.text C:\Windows\System32\svchost.exe[3088] kernel32.dll!CreateFileW 765CB0EB 5 Bytes JMP 0020001B
.text C:\Windows\System32\svchost.exe[3088] kernel32.dll!CreateFileA 765CD07F 5 Bytes JMP 00200000
.text C:\Windows\System32\svchost.exe[3088] kernel32.dll!WinExec 766160CF 5 Bytes JMP 00200F9B
.text C:\Windows\System32\svchost.exe[3088] msvcrt.dll!_wsystem 760C7F2F 5 Bytes JMP 001B0FA4
.text C:\Windows\System32\svchost.exe[3088] msvcrt.dll!system 760C804B 5 Bytes JMP 001B0FB5
.text C:\Windows\System32\svchost.exe[3088] msvcrt.dll!_creat 760CBBE1 5 Bytes JMP 001B0FC6
.text C:\Windows\System32\svchost.exe[3088] msvcrt.dll!_open 760CD106 5 Bytes JMP 001B0000
.text C:\Windows\System32\svchost.exe[3088] msvcrt.dll!_wcreat 760CD326 5 Bytes JMP 001B001B
.text C:\Windows\System32\svchost.exe[3088] msvcrt.dll!_wopen 760CD501 5 Bytes JMP 001B0FD7
.text C:\Windows\System32\svchost.exe[3088] ADVAPI32.dll!RegCreateKeyExA 768039AB 5 Bytes JMP 00210FA8
.text C:\Windows\System32\svchost.exe[3088] ADVAPI32.dll!RegCreateKeyA 76803BA9 5 Bytes JMP 00210FB9
.text C:\Windows\System32\svchost.exe[3088] ADVAPI32.dll!RegOpenKeyA 768089C7 5 Bytes JMP 00210FEF
.text C:\Windows\System32\svchost.exe[3088] ADVAPI32.dll!RegCreateKeyW 7681391E 5 Bytes JMP 00210040
.text C:\Windows\System32\svchost.exe[3088] ADVAPI32.dll!RegCreateKeyExW 768141F1 5 Bytes JMP 00210F83
.text C:\Windows\System32\svchost.exe[3088] ADVAPI32.dll!RegOpenKeyExA 76817C42 5 Bytes JMP 00210014
.text C:\Windows\System32\svchost.exe[3088] ADVAPI32.dll!RegOpenKeyW 7681E2B5 5 Bytes JMP 00210FDE
.text C:\Windows\System32\svchost.exe[3088] ADVAPI32.dll!RegOpenKeyExW 76827BA1 5 Bytes JMP 00210025
.text C:\Windows\System32\svchost.exe[3088] WS2_32.dll!socket 75FB36D1 5 Bytes JMP 001A0FEF
.text C:\Windows\system32\svchost.exe[3104] ntdll.dll!NtCreateFile 778F4224 5 Bytes JMP 00E60FE5
.text C:\Windows\system32\svchost.exe[3104] ntdll.dll!NtCreateProcess 778F42E4 5 Bytes JMP 00E6000A
.text C:\Windows\system32\svchost.exe[3104] ntdll.dll!NtProtectVirtualMemory 778F4B84 5 Bytes JMP 00E60FD4
.text C:\Windows\system32\svchost.exe[3104] kernel32.dll!GetStartupInfoW 76581929 5 Bytes JMP 00E900BD
.text C:\Windows\system32\svchost.exe[3104] kernel32.dll!GetStartupInfoA 765819C9 5 Bytes JMP 00E900AC
.text C:\Windows\system32\svchost.exe[3104] kernel32.dll!CreateProcessW 76581BF3 5 Bytes JMP 00E900F0
.text C:\Windows\system32\svchost.exe[3104] kernel32.dll!CreateProcessA 76581C28 5 Bytes JMP 00E900DF
.text C:\Windows\system32\svchost.exe[3104] kernel32.dll!VirtualProtect 76581DC3 5 Bytes JMP 00E9007D
.text C:\Windows\system32\svchost.exe[3104] kernel32.dll!CreateNamedPipeA 76582EF5 5 Bytes JMP 00E90FDB
.text C:\Windows\system32\svchost.exe[3104] kernel32.dll!CreateNamedPipeW 76585C0C 5 Bytes JMP 00E90FC0
.text C:\Windows\system32\svchost.exe[3104] kernel32.dll!CreatePipe 765A8F06 5 Bytes JMP 00E90F77
.text C:\Windows\system32\svchost.exe[3104] kernel32.dll!LoadLibraryExW 765A927C 5 Bytes JMP 00E90062
.text C:\Windows\system32\svchost.exe[3104] kernel32.dll!LoadLibraryW 765A9400 5 Bytes JMP 00E90FAF
.text C:\Windows\system32\svchost.exe[3104] kernel32.dll!LoadLibraryExA 765A9554 5 Bytes JMP 00E90051
.text C:\Windows\system32\svchost.exe[3104] kernel32.dll!LoadLibraryA 765A957C 5 Bytes JMP 00E90036
.text C:\Windows\system32\svchost.exe[3104] kernel32.dll!VirtualProtectEx 765ADC52 5 Bytes JMP 00E90F88
.text C:\Windows\system32\svchost.exe[3104] kernel32.dll!GetProcAddress 765C925B 5 Bytes JMP 00E90101
.text C:\Windows\system32\svchost.exe[3104] kernel32.dll!CreateFileW 765CB0EB 5 Bytes JMP 00E90011
.text C:\Windows\system32\svchost.exe[3104] kernel32.dll!CreateFileA 765CD07F 5 Bytes JMP 00E90000
.text C:\Windows\system32\svchost.exe[3104] kernel32.dll!WinExec 766160CF 5 Bytes JMP 00E900CE
.text C:\Windows\system32\svchost.exe[3104] msvcrt.dll!_wsystem 760C7F2F 5 Bytes JMP 00E80FBE
.text C:\Windows\system32\svchost.exe[3104] msvcrt.dll!system 760C804B 5 Bytes JMP 00E80049
.text C:\Windows\system32\svchost.exe[3104] msvcrt.dll!_creat 760CBBE1 5 Bytes JMP 00E8001D
.text C:\Windows\system32\svchost.exe[3104] msvcrt.dll!_open 760CD106 5 Bytes JMP 00E80FEF
.text C:\Windows\system32\svchost.exe[3104] msvcrt.dll!_wcreat 760CD326 5 Bytes JMP 00E80038
.text C:\Windows\system32\svchost.exe[3104] msvcrt.dll!_wopen 760CD501 5 Bytes JMP 00E8000C
.text C:\Windows\system32\svchost.exe[3104] ADVAPI32.dll!RegCreateKeyExA 768039AB 5 Bytes JMP 01020047
.text C:\Windows\system32\svchost.exe[3104] ADVAPI32.dll!RegCreateKeyA 76803BA9 5 Bytes JMP 0102001B
.text C:\Windows\system32\svchost.exe[3104] ADVAPI32.dll!RegOpenKeyA 768089C7 5 Bytes JMP 01020FEF
.text C:\Windows\system32\svchost.exe[3104] ADVAPI32.dll!RegCreateKeyW 7681391E 5 Bytes JMP 01020036
.text C:\Windows\system32\svchost.exe[3104] ADVAPI32.dll!RegCreateKeyExW 768141F1 5 Bytes JMP 01020058
.text C:\Windows\system32\svchost.exe[3104] ADVAPI32.dll!RegOpenKeyExA 76817C42 5 Bytes JMP 0102000A
.text C:\Windows\system32\svchost.exe[3104] ADVAPI32.dll!RegOpenKeyW 7681E2B5 5 Bytes JMP 01020FD4
.text C:\Windows\system32\svchost.exe[3104] ADVAPI32.dll!RegOpenKeyExW 76827BA1 5 Bytes JMP 01020FAF
.text C:\Windows\system32\svchost.exe[3104] WS2_32.dll!socket 75FB36D1 5 Bytes JMP 00E7000A
.text C:\Windows\system32\svchost.exe[3104] WININET.dll!InternetOpenA 775D4E33 5 Bytes JMP 01030FEF
.text C:\Windows\system32\svchost.exe[3104] WININET.dll!InternetOpenUrlA 775DBFCE 5 Bytes JMP 01030FCD
.text C:\Windows\system32\svchost.exe[3104] WININET.dll!InternetOpenW 7760C02E 5 Bytes JMP 01030FDE
.text C:\Windows\system32\svchost.exe[3104] WININET.dll!InternetOpenUrlW 7763D70A 5 Bytes JMP 0103001E
.text C:\Windows\system32\svchost.exe[3148] ntdll.dll!NtCreateFile 778F4224 5 Bytes JMP 00860000
.text C:\Windows\system32\svchost.exe[3148] ntdll.dll!NtCreateProcess 778F42E4 5 Bytes JMP 00860FDE
.text C:\Windows\system32\svchost.exe[3148] ntdll.dll!NtProtectVirtualMemory 778F4B84 5 Bytes JMP 00860FEF
.text C:\Windows\system32\svchost.exe[3148] kernel32.dll!GetStartupInfoW 76581929 5 Bytes JMP 00A50F4B
.text C:\Windows\system32\svchost.exe[3148] kernel32.dll!GetStartupInfoA 765819C9 5 Bytes JMP 00A50F66
.text C:\Windows\system32\svchost.exe[3148] kernel32.dll!CreateProcessW 76581BF3 5 Bytes JMP 00A50F1F
.text C:\Windows\system32\svchost.exe[3148] kernel32.dll!CreateProcessA 76581C28 5 Bytes JMP 00A50F30
.text C:\Windows\system32\svchost.exe[3148] kernel32.dll!VirtualProtect 76581DC3 5 Bytes JMP 00A5006C
.text C:\Windows\system32\svchost.exe[3148] kernel32.dll!CreateNamedPipeA 76582EF5 5 Bytes JMP 00A50FC3
.text C:\Windows\system32\svchost.exe[3148] kernel32.dll!CreateNamedPipeW 76585C0C 5 Bytes JMP 00A50FB2
.text C:\Windows\system32\svchost.exe[3148] kernel32.dll!CreatePipe 765A8F06 5 Bytes JMP 00A50F77
.text C:\Windows\system32\svchost.exe[3148] kernel32.dll!LoadLibraryExW 765A927C 5 Bytes JMP 00A5005B
.text C:\Windows\system32\svchost.exe[3148] kernel32.dll!LoadLibraryW 765A9400 5 Bytes JMP 00A5002F
.text C:\Windows\system32\svchost.exe[3148] kernel32.dll!LoadLibraryExA 765A9554 5 Bytes JMP 00A5004A
.text C:\Windows\system32\svchost.exe[3148] kernel32.dll!LoadLibraryA 765A957C 5 Bytes JMP 00A5001E
.text C:\Windows\system32\svchost.exe[3148] kernel32.dll!VirtualProtectEx 765ADC52 5 Bytes JMP 00A50087
.text C:\Windows\system32\svchost.exe[3148] kernel32.dll!GetProcAddress 765C925B 5 Bytes JMP 00A50F0E
.text C:\Windows\system32\svchost.exe[3148] kernel32.dll!CreateFileW 765CB0EB 5 Bytes JMP 00A50FDE
.text C:\Windows\system32\svchost.exe[3148] kernel32.dll!CreateFileA 765CD07F 5 Bytes JMP 00A50FEF
.text C:\Windows\system32\svchost.exe[3148] kernel32.dll!WinExec 766160CF 5 Bytes JMP 00A500AC
.text C:\Windows\system32\svchost.exe[3148] msvcrt.dll!_wsystem 760C7F2F 5 Bytes JMP 00A10F9A
.text C:\Windows\system32\svchost.exe[3148] msvcrt.dll!system 760C804B 5 Bytes JMP 00A10FAB
.text C:\Windows\system32\svchost.exe[3148] msvcrt.dll!_creat 760CBBE1 5 Bytes JMP 00A1001B
.text C:\Windows\system32\svchost.exe[3148] msvcrt.dll!_open 760CD106 5 Bytes JMP 00A10000
.text C:\Windows\system32\svchost.exe[3148] msvcrt.dll!_wcreat 760CD326 5 Bytes JMP 00A10FC6
.text C:\Windows\system32\svchost.exe[3148] msvcrt.dll!_wopen 760CD501 5 Bytes JMP 00A10FE3
.text C:\Windows\system32\svchost.exe[3148] ADVAPI32.dll!RegCreateKeyExA 768039AB 5 Bytes JMP 00AA0F8A
.text C:\Windows\system32\svchost.exe[3148] ADVAPI32.dll!RegCreateKeyA 76803BA9 5 Bytes JMP 00AA002C
.text C:\Windows\system32\svchost.exe[3148] ADVAPI32.dll!RegOpenKeyA 768089C7 5 Bytes JMP 00AA0000
.text C:\Windows\system32\svchost.exe[3148] ADVAPI32.dll!RegCreateKeyW 7681391E 5 Bytes JMP 00AA0FA5
.text C:\Windows\system32\svchost.exe[3148] ADVAPI32.dll!RegCreateKeyExW 768141F1 5 Bytes JMP 00AA0047
.text C:\Windows\system32\svchost.exe[3148] ADVAPI32.dll!RegOpenKeyExA 76817C42 5 Bytes JMP 00AA0FDB
.text C:\Windows\system32\svchost.exe[3148] ADVAPI32.dll!RegOpenKeyW 7681E2B5 5 Bytes JMP 00AA0011
.text C:\Windows\system32\svchost.exe[3148] ADVAPI32.dll!RegOpenKeyExW 76827BA1 5 Bytes JMP 00AA0FCA
.text C:\Windows\system32\svchost.exe[3148] WS2_32.dll!socket 75FB36D1 5 Bytes JMP 008B0FEF
.text C:\Windows\System32\svchost.exe[3296] ntdll.dll!NtCreateFile 778F4224 5 Bytes JMP 00050FEF
.text C:\Windows\System32\svchost.exe[3296] ntdll.dll!NtCreateProcess 778F42E4 5 Bytes JMP 00050014
.text C:\Windows\System32\svchost.exe[3296] ntdll.dll!NtProtectVirtualMemory 778F4B84 5 Bytes JMP 00050FDE
.text C:\Windows\System32\svchost.exe[3296] kernel32.dll!GetStartupInfoW 76581929 5 Bytes JMP 00070091
.text C:\Windows\System32\svchost.exe[3296] kernel32.dll!GetStartupInfoA 765819C9 5 Bytes JMP 00070F55
.text C:\Windows\System32\svchost.exe[3296] kernel32.dll!CreateProcessW 76581BF3 5 Bytes JMP 000700D8
.text C:\Windows\System32\svchost.exe[3296] kernel32.dll!CreateProcessA 76581C28 5 Bytes JMP 000700C7
.text C:\Windows\System32\svchost.exe[3296] kernel32.dll!VirtualProtect 76581DC3 5 Bytes JMP 00070F92
.text C:\Windows\System32\svchost.exe[3296] kernel32.dll!CreateNamedPipeA 76582EF5 5 Bytes JMP 0007002F
.text C:\Windows\System32\svchost.exe[3296] kernel32.dll!CreateNamedPipeW 76585C0C 5 Bytes JMP 00070FDE
.text C:\Windows\System32\svchost.exe[3296] kernel32.dll!CreatePipe 765A8F06 5 Bytes JMP 00070F70
.text C:\Windows\System32\svchost.exe[3296] kernel32.dll!LoadLibraryExW 765A927C 5 Bytes JMP 00070FAD
.text C:\Windows\System32\svchost.exe[3296] kernel32.dll!LoadLibraryW 765A9400 5 Bytes JMP 0007005B
.text C:\Windows\System32\svchost.exe[3296] kernel32.dll!LoadLibraryExA 765A9554 5 Bytes JMP 0007006C
.text C:\Windows\System32\svchost.exe[3296] kernel32.dll!LoadLibraryA 765A957C 5 Bytes JMP 0007004A
.text C:\Windows\System32\svchost.exe[3296] kernel32.dll!VirtualProtectEx 765ADC52 5 Bytes JMP 00070F81
.text C:\Windows\System32\svchost.exe[3296] kernel32.dll!GetProcAddress 765C925B 5 Bytes JMP 00070F30
.text C:\Windows\System32\svchost.exe[3296] kernel32.dll!CreateFileW 765CB0EB 5 Bytes JMP 00070014
.text C:\Windows\System32\svchost.exe[3296] kernel32.dll!CreateFileA 765CD07F 5 Bytes JMP 00070FEF
.text C:\Windows\System32\svchost.exe[3296] kernel32.dll!WinExec 766160CF 5 Bytes JMP 000700B6
.text C:\Windows\System32\svchost.exe[3296] msvcrt.dll!_wsystem 760C7F2F 5 Bytes JMP 00060042
.text C:\Windows\System32\svchost.exe[3296] msvcrt.dll!system 760C804B 5 Bytes JMP 0006001D
.text C:\Windows\System32\svchost.exe[3296] msvcrt.dll!_creat 760CBBE1 5 Bytes JMP 00060FD2
.text C:\Windows\System32\svchost.exe[3296] msvcrt.dll!_open 760CD106 5 Bytes JMP 00060FEF
.text C:\Windows\System32\svchost.exe[3296] msvcrt.dll!_wcreat 760CD326 5 Bytes JMP 00060FB7
.text C:\Windows\System32\svchost.exe[3296] msvcrt.dll!_wopen 760CD501 5 Bytes JMP 0006000C
.text C:\Windows\System32\svchost.exe[3296] ADVAPI32.dll!RegCreateKeyExA 768039AB 5 Bytes JMP 0008007D
.text C:\Windows\System32\svchost.exe[3296] ADVAPI32.dll!RegCreateKeyA 76803BA9 5 Bytes JMP 00080051
.text C:\Windows\System32\svchost.exe[3296] ADVAPI32.dll!RegOpenKeyA 768089C7 5 Bytes JMP 00080FEF
.text C:\Windows\System32\svchost.exe[3296] ADVAPI32.dll!RegCreateKeyW 7681391E 5 Bytes JMP 00080062
.text C:\Windows\System32\svchost.exe[3296] ADVAPI32.dll!RegCreateKeyExW 768141F1 5 Bytes JMP 00080FB6
.text C:\Windows\System32\svchost.exe[3296] ADVAPI32.dll!RegOpenKeyExA 76817C42 5 Bytes JMP 00080025
.text C:\Windows\System32\svchost.exe[3296] ADVAPI32.dll!RegOpenKeyW 7681E2B5 5 Bytes JMP 0008000A
.text C:\Windows\System32\svchost.exe[3296] ADVAPI32.dll!RegOpenKeyExW 76827BA1 5 Bytes JMP 00080036
.text C:\Windows\System32\svchost.exe[3296] WS2_32.dll!socket 75FB36D1 5 Bytes JMP 00130FEF
.text C:\Windows\system32\svchost.exe[3680] ntdll.dll!NtCreateFile 778F4224 5 Bytes JMP 00040FEF
.text C:\Windows\system32\svchost.exe[3680] ntdll.dll!NtCreateProcess 778F42E4 5 Bytes JMP 00040FD4
.text C:\Windows\system32\svchost.exe[3680] ntdll.dll!NtProtectVirtualMemory 778F4B84 5 Bytes JMP 00040000
.text C:\Windows\system32\svchost.exe[3680] kernel32.dll!GetStartupInfoW 76581929 5 Bytes JMP 00010F21
.text C:\Windows\system32\svchost.exe[3680] kernel32.dll!GetStartupInfoA 765819C9 5 Bytes JMP 00010F3C
.text C:\Windows\system32\svchost.exe[3680] kernel32.dll!CreateProcessW 76581BF3 5 Bytes JMP 00010EFC
.text C:\Windows\system32\svchost.exe[3680] kernel32.dll!CreateProcessA 76581C28 5 Bytes JMP 00010093
.text C:\Windows\system32\svchost.exe[3680] kernel32.dll!VirtualProtect 76581DC3 5 Bytes JMP 0001005D
.text C:\Windows\system32\svchost.exe[3680] kernel32.dll!CreateNamedPipeA 76582EF5 5 Bytes JMP 0001001B
.text C:\Windows\system32\svchost.exe[3680] kernel32.dll!CreateNamedPipeW 76585C0C 5 Bytes JMP 0001002C
.text C:\Windows\system32\svchost.exe[3680] kernel32.dll!CreatePipe 765A8F06 5 Bytes JMP 00010F4D
.text C:\Windows\system32\svchost.exe[3680] kernel32.dll!LoadLibraryExW 765A927C 5 Bytes JMP 00010F79
.text C:\Windows\system32\svchost.exe[3680] kernel32.dll!LoadLibraryW 765A9400 5 Bytes JMP 00010FA5
.text C:\Windows\system32\svchost.exe[3680] kernel32.dll!LoadLibraryExA 765A9554 5 Bytes JMP 00010F8A
.text C:\Windows\system32\svchost.exe[3680] kernel32.dll!LoadLibraryA 765A957C 5 Bytes JMP 00010FC0
.text C:\Windows\system32\svchost.exe[3680] kernel32.dll!VirtualProtectEx 765ADC52 5 Bytes JMP 00010F68
.text C:\Windows\system32\svchost.exe[3680] kernel32.dll!GetProcAddress 765C925B 5 Bytes JMP 00010EEB
.text C:\Windows\system32\svchost.exe[3680] kernel32.dll!CreateFileW 765CB0EB 5 Bytes JMP 00010FE5
.text C:\Windows\system32\svchost.exe[3680] kernel32.dll!CreateFileA 765CD07F 5 Bytes JMP 00010000
.text C:\Windows\system32\svchost.exe[3680] kernel32.dll!WinExec 766160CF 5 Bytes JMP 00010082
.text C:\Windows\system32\svchost.exe[3680] msvcrt.dll!_wsystem 760C7F2F 5 Bytes JMP 00070FA8
.text C:\Windows\system32\svchost.exe[3680] msvcrt.dll!system 760C804B 5 Bytes JMP 00070FC3
.text C:\Windows\system32\svchost.exe[3680] msvcrt.dll!_creat 760CBBE1 5 Bytes JMP 00070029
.text C:\Windows\system32\svchost.exe[3680] msvcrt.dll!_open 760CD106 5 Bytes JMP 00070FEF
.text C:\Windows\system32\svchost.exe[3680] msvcrt.dll!_wcreat 760CD326 5 Bytes JMP 00070FDE
.text C:\Windows\system32\svchost.exe[3680] msvcrt.dll!_wopen 760CD501 5 Bytes JMP 00070018
.text C:\Windows\system32\svchost.exe[3680] ADVAPI32.dll!RegCreateKeyExA 768039AB 5 Bytes JMP 00080F9E
.text C:\Windows\system32\svchost.exe[3680] ADVAPI32.dll!RegCreateKeyA 76803BA9 5 Bytes JMP 00080FAF
.text C:\Windows\system32\svchost.exe[3680] ADVAPI32.dll!RegOpenKeyA 768089C7 5 Bytes JMP 00080FEF
.text C:\Windows\system32\svchost.exe[3680] ADVAPI32.dll!RegCreateKeyW 7681391E 5 Bytes JMP 00080036
.text C:\Windows\system32\svchost.exe[3680] ADVAPI32.dll!RegCreateKeyExW 768141F1 5 Bytes JMP 00080051
.text C:\Windows\system32\svchost.exe[3680] ADVAPI32.dll!RegOpenKeyExA 76817C42 5 Bytes JMP 0008000A
.text C:\Windows\system32\svchost.exe[3680] ADVAPI32.dll!RegOpenKeyW 7681E2B5 5 Bytes JMP 00080FD4
.text C:\Windows\system32\svchost.exe[3680] ADVAPI32.dll!RegOpenKeyExW 76827BA1 5 Bytes JMP 00080025
.text C:\Windows\system32\svchost.exe[3680] WS2_32.dll!socket 75FB36D1 5 Bytes JMP 00730FE5
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[3744] kernel32.dll!LoadLibraryW 765A9400 5 Bytes JMP 6DD59A63 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe[3744] kernel32.dll!LoadLibraryA 765A957C 5 Bytes JMP 6DD599A1 C:\Program Files\Common Files\McAfee\McProxy\mcproxy.dll (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\Windows\Explorer.EXE[4052] ntdll.dll!NtCreateFile 778F4224 5 Bytes JMP 00040000
.text C:\Windows\Explorer.EXE[4052] ntdll.dll!NtCreateProcess 778F42E4 5 Bytes JMP 0004001B
.text C:\Windows\Explorer.EXE[4052] ntdll.dll!NtProtectVirtualMemory 778F4B84 5 Bytes JMP 00040FE5
.text C:\Windows\Explorer.EXE[4052] kernel32.dll!GetStartupInfoW 76581929 5 Bytes JMP 0001007D
.text C:\Windows\Explorer.EXE[4052] kernel32.dll!GetStartupInfoA 765819C9 5 Bytes JMP 00010F37
.text C:\Windows\Explorer.EXE[4052] kernel32.dll!CreateProcessW 76581BF3 5 Bytes JMP 00010EED
.text C:\Windows\Explorer.EXE[4052] kernel32.dll!CreateProcessA 76581C28 5 Bytes JMP 00010F12
.text C:\Windows\Explorer.EXE[4052] kernel32.dll!VirtualProtect 76581DC3 5 Bytes JMP 0001002C
.text C:\Windows\Explorer.EXE[4052] kernel32.dll!CreateNamedPipeA 76582EF5 5 Bytes JMP 00010FB9
.text C:\Windows\Explorer.EXE[4052] kernel32.dll!CreateNamedPipeW 76585C0C 5 Bytes JMP 0001000A
.text C:\Windows\Explorer.EXE[4052] kernel32.dll!CreatePipe 765A8F06 5 Bytes JMP 00010058
.text C:\Windows\Explorer.EXE[4052] kernel32.dll!LoadLibraryExW 765A927C 5 Bytes JMP 00010F5E
.text C:\Windows\Explorer.EXE[4052] kernel32.dll!LoadLibraryW 765A9400 5 Bytes JMP 00010F79
.text C:\Windows\Explorer.EXE[4052] kernel32.dll!LoadLibraryExA 765A9554 5 Bytes JMP 0001001B
.text C:\Windows\Explorer.EXE[4052] kernel32.dll!LoadLibraryA 765A957C 5 Bytes JMP 00010F94
.text C:\Windows\Explorer.EXE[4052] kernel32.dll!VirtualProtectEx 765ADC52 5 Bytes JMP 0001003D
.text C:\Windows\Explorer.EXE[4052] kernel32.dll!GetProcAddress 765C925B 5 Bytes JMP 0001009F
.text C:\Windows\Explorer.EXE[4052] kernel32.dll!CreateFileW 765CB0EB 5 Bytes JMP 00010FD4
.text C:\Windows\Explorer.EXE[4052] kernel32.dll!CreateFileA 765CD07F 5 Bytes JMP 00010FE5
.text C:\Windows\Explorer.EXE[4052] kernel32.dll!WinExec 766160CF 5 Bytes JMP 0001008E
.text C:\Windows\Explorer.EXE[4052] ADVAPI32.dll!RegCreateKeyExA 768039AB 5 Bytes JMP 00070F79
.text C:\Windows\Explorer.EXE[4052] ADVAPI32.dll!RegCreateKeyA 76803BA9 5 Bytes JMP 00070011
.text C:\Windows\Explorer.EXE[4052] ADVAPI32.dll!RegOpenKeyA 768089C7 5 Bytes JMP 00070FE5
.text C:\Windows\Explorer.EXE[4052] ADVAPI32.dll!RegCreateKeyW 7681391E 5 Bytes JMP 00070F8A
.text C:\Windows\Explorer.EXE[4052] ADVAPI32.dll!RegCreateKeyExW 768141F1 5 Bytes JMP 00070F54
.text C:\Windows\Explorer.EXE[4052] ADVAPI32.dll!RegOpenKeyExA 76817C42 5 Bytes JMP 00070FCA
.text C:\Windows\Explorer.EXE[4052] ADVAPI32.dll!RegOpenKeyW 7681E2B5 5 Bytes JMP 00070000
.text C:\Windows\Explorer.EXE[4052] ADVAPI32.dll!RegOpenKeyExW 76827BA1 1 Byte [E9]
.text C:\Windows\Explorer.EXE[4052] ADVAPI32.dll!RegOpenKeyExW 76827BA1 5 Bytes JMP 00070FA5
.text C:\Windows\Explorer.EXE[4052] msvcrt.dll!_wsystem 760C7F2F 5 Bytes JMP 00080031
.text C:\Windows\Explorer.EXE[4052] msvcrt.dll!system 760C804B 5 Bytes JMP 00080FB0
.text C:\Windows\Explorer.EXE[4052] msvcrt.dll!_creat 760CBBE1 5 Bytes JMP 00080FD2
.text C:\Windows\Explorer.EXE[4052] msvcrt.dll!_open 760CD106 5 Bytes JMP 00080000
.text C:\Windows\Explorer.EXE[4052] msvcrt.dll!_wcreat 760CD326 5 Bytes JMP 00080FC1
.text C:\Windows\Explorer.EXE[4052] msvcrt.dll!_wopen 760CD501 5 Bytes JMP 00080FEF
.text C:\Windows\Explorer.EXE[4052] WS2_32.dll!socket 75FB36D1 5 Bytes JMP 00170000
.text C:\Windows\Explorer.EXE[4052] WININET.dll!InternetOpenA 775D4E33 5 Bytes JMP 017F0000
.text C:\Windows\Explorer.EXE[4052] WININET.dll!InternetOpenUrlA 775DBFCE 5 Bytes JMP 017F0FE5
.text C:\Windows\Explorer.EXE[4052] WININET.dll!InternetOpenW 7760C02E 5 Bytes JMP 017F001B
.text C:\Windows\Explorer.EXE[4052] WININET.dll!InternetOpenUrlW 7763D70A 5 Bytes JMP 017F0FD4
.text C:\Windows\system32\wuauclt.exe[10624] ntdll.dll!NtCreateFile 778F4224 5 Bytes JMP 00040FEF
.text C:\Windows\system32\wuauclt.exe[10624] ntdll.dll!NtCreateProcess 778F42E4 5 Bytes JMP 00040FD4
.text C:\Windows\system32\wuauclt.exe[10624] ntdll.dll!NtProtectVirtualMemory 778F4B84 5 Bytes JMP 0004000A
.text C:\Windows\system32\wuauclt.exe[10624] kernel32.dll!GetStartupInfoW 76581929 5 Bytes JMP 00010F28
.text C:\Windows\system32\wuauclt.exe[10624] kernel32.dll!GetStartupInfoA 765819C9 5 Bytes JMP 00010F4D
.text C:\Windows\system32\wuauclt.exe[10624] kernel32.dll!CreateProcessW 76581BF3 5 Bytes JMP 00010093
.text C:\Windows\system32\wuauclt.exe[10624] kernel32.dll!CreateProcessA 76581C28 5 Bytes JMP 00010EFC
.text C:\Windows\system32\wuauclt.exe[10624] kernel32.dll!VirtualProtect 76581DC3 5 Bytes JMP 00010F79
.text C:\Windows\system32\wuauclt.exe[10624] kernel32.dll!CreateNamedPipeA 76582EF5 5 Bytes JMP 00010000
.text C:\Windows\system32\wuauclt.exe[10624] kernel32.dll!CreateNamedPipeW 76585C0C 5 Bytes JMP 00010FAF
.text C:\Windows\system32\wuauclt.exe[10624] kernel32.dll!CreatePipe 765A8F06 5 Bytes JMP 00010F5E
.text C:\Windows\system32\wuauclt.exe[10624] kernel32.dll!LoadLibraryExW 765A927C 5 Bytes JMP 0001005D
.text C:\Windows\system32\wuauclt.exe[10624] kernel32.dll!LoadLibraryW 765A9400 5 Bytes JMP 00010036
.text C:\Windows\system32\wuauclt.exe[10624] kernel32.dll!LoadLibraryExA 765A9554 5 Bytes JMP 00010F94
.text C:\Windows\system32\wuauclt.exe[10624] kernel32.dll!LoadLibraryA 765A957C 5 Bytes JMP 0001001B
.text C:\Windows\system32\wuauclt.exe[10624] kernel32.dll!VirtualProtectEx 765ADC52 5 Bytes JMP 0001006E
.text C:\Windows\system32\wuauclt.exe[10624] kernel32.dll!GetProcAddress 765C925B 5 Bytes JMP 00010EE1
.text C:\Windows\system32\wuauclt.exe[10624] kernel32.dll!CreateFileW 765CB0EB 5 Bytes JMP 00010FD4
.text C:\Windows\system32\wuauclt.exe[10624] kernel32.dll!CreateFileA 765CD07F 5 Bytes JMP 00010FEF
.text C:\Windows\system32\wuauclt.exe[10624] kernel32.dll!WinExec 766160CF 5 Bytes JMP 00010F0D
.text C:\Windows\system32\wuauclt.exe[10624] msvcrt.dll!_wsystem 760C7F2F 5 Bytes JMP 00080053
.text C:\Windows\system32\wuauclt.exe[10624] msvcrt.dll!system 760C804B 5 Bytes JMP 00080FC8
.text C:\Windows\system32\wuauclt.exe[10624] msvcrt.dll!_creat 760CBBE1 5 Bytes JMP 00080FE3
.text C:\Windows\system32\wuauclt.exe[10624] msvcrt.dll!_open 760CD106 5 Bytes JMP 00080000
.text C:\Windows\system32\wuauclt.exe[10624] msvcrt.dll!_wcreat 760CD326 5 Bytes JMP 00080038
.text C:\Windows\system32\wuauclt.exe[10624] msvcrt.dll!_wopen 760CD501 5 Bytes JMP 0008001D
.text C:\Windows\system32\wuauclt.exe[10624] ADVAPI32.dll!RegCreateKeyExA 768039AB 5 Bytes JMP 00090062
.text C:\Windows\system32\wuauclt.exe[10624] ADVAPI32.dll!RegCreateKeyA 76803BA9 5 Bytes JMP 00090051
.text C:\Windows\system32\wuauclt.exe[10624] ADVAPI32.dll!RegOpenKeyA 768089C7 5 Bytes JMP 00090FEF
.text C:\Windows\system32\wuauclt.exe[10624] ADVAPI32.dll!RegCreateKeyW 7681391E 5 Bytes JMP 00090FCA
.text C:\Windows\system32\wuauclt.exe[10624] ADVAPI32.dll!RegCreateKeyExW 768141F1 5 Bytes JMP 00090FAF
.text C:\Windows\system32\wuauclt.exe[10624] ADVAPI32.dll!RegOpenKeyExA 76817C42 5 Bytes JMP 00090025
.text C:\Windows\system32\wuauclt.exe[10624] ADVAPI32.dll!RegOpenKeyW 7681E2B5 5 Bytes JMP 00090014
.text C:\Windows\system32\wuauclt.exe[10624] ADVAPI32.dll!RegOpenKeyExW 76827BA1 5 Bytes JMP 00090036
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] ntdll.dll!NtCreateFile 778F4224 5 Bytes JMP 00040FEF
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] ntdll.dll!NtCreateProcess 778F42E4 5 Bytes JMP 00040014
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] ntdll.dll!NtProtectVirtualMemory 778F4B84 5 Bytes JMP 00040FDE
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] kernel32.dll!GetStartupInfoW 76581929 5 Bytes JMP 00010F01
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] kernel32.dll!GetStartupInfoA 765819C9 5 Bytes JMP 00010F1C
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] kernel32.dll!CreateProcessW 76581BF3 5 Bytes JMP 00010ECB
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] kernel32.dll!CreateProcessA 76581C28 5 Bytes JMP 00010EF0
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] kernel32.dll!VirtualProtect 76581DC3 5 Bytes JMP 00010F5C
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] kernel32.dll!CreateNamedPipeA 76582EF5 5 Bytes JMP 00010FB9
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] kernel32.dll!CreateNamedPipeW 76585C0C 5 Bytes JMP 00010F9E
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] kernel32.dll!CreatePipe 765A8F06 5 Bytes JMP 00010F37
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] kernel32.dll!LoadLibraryExW 765A927C 5 Bytes JMP 00010036
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] kernel32.dll!LoadLibraryW 765A9400 5 Bytes JMP 00010F79
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] kernel32.dll!LoadLibraryExA 765A9554 5 Bytes JMP 00010025
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] kernel32.dll!LoadLibraryA 765A957C 5 Bytes JMP 0001000A
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] kernel32.dll!SetUnhandledExceptionFilter 765AA8C5 5 Bytes JMP 5B855465 C:\Program Files\Common Files\Microsoft Shared\office12\mso.dll (2007 Microsoft Office component/Microsoft Corporation)
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] kernel32.dll!VirtualProtectEx 765ADC52 5 Bytes JMP 00010047
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] kernel32.dll!GetProcAddress 765C925B 5 Bytes JMP 0001007D
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] kernel32.dll!CreateFileW 765CB0EB 5 Bytes JMP 00010FCA
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] kernel32.dll!CreateFileA 765CD07F 5 Bytes JMP 00010FE5
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] kernel32.dll!WinExec 766160CF 5 Bytes JMP 00010062
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] ADVAPI32.dll!RegCreateKeyExA 768039AB 5 Bytes JMP 00060FB6
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] ADVAPI32.dll!RegCreateKeyA 76803BA9 5 Bytes JMP 0006003D
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] ADVAPI32.dll!RegOpenKeyA 768089C7 5 Bytes JMP 0006000A
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] ADVAPI32.dll!RegCreateKeyW 7681391E 5 Bytes JMP 00060058
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] ADVAPI32.dll!RegCreateKeyExW 768141F1 5 Bytes JMP 00060F9B
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] ADVAPI32.dll!RegOpenKeyExA 76817C42 5 Bytes JMP 0006002C
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] ADVAPI32.dll!RegOpenKeyW 7681E2B5 5 Bytes JMP 0006001B
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] ADVAPI32.dll!RegOpenKeyExW 76827BA1 5 Bytes JMP 00060FD1
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] msvcrt.dll!_wsystem 760C7F2F 5 Bytes JMP 00070FDB
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] msvcrt.dll!system 760C804B 5 Bytes JMP 00070066
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] msvcrt.dll!_creat 760CBBE1 5 Bytes JMP 0007003A
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] msvcrt.dll!_open 760CD106 5 Bytes JMP 00070000
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] msvcrt.dll!_wcreat 760CD326 5 Bytes JMP 00070055
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] msvcrt.dll!_wopen 760CD501 5 Bytes JMP 00070029
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] ole32.dll!OleLoadFromStream 76141E80 5 Bytes JMP 5BB7B771 C:\Program Files\Common Files\Microsoft Shared\office12\mso.dll (2007 Microsoft Office component/Microsoft Corporation)
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] WS2_32.dll!socket 75FB36D1 5 Bytes JMP 03560000
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] WININET.dll!InternetOpenA 775D4E33 5 Bytes JMP 035A0000
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] WININET.dll!InternetOpenUrlA 775DBFCE 5 Bytes JMP 035A0FDB
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] WININET.dll!InternetOpenW 7760C02E 5 Bytes JMP 035A0011
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[11520] WININET.dll!InternetOpenUrlW 7763D70A 5 Bytes JMP 035A0FB6

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\tdx \Device\Tcp mfewfpk.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\tdx \Device\Udp mfewfpk.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat mfehidk.sys (McAfee Link Driver/McAfee, Inc.)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002556d4bc86
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002556d4bc86@e8e5d693a93f 0x63 0x89 0xFE 0xD6 …
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002556d4bc86 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002556d4bc86@e8e5d693a93f 0x63 0x89 0xFE 0xD6 …

—- EOF - GMER 1.0.15 —-
Hi Squid555,

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Dear Jeff, I have run ComboFix and have a couple things to report. Periodically the program told me that it could not find the file 'NIRKMD'. I just said OK every time. In addition after the scan was completed and the computer had restarted a Logitech executable was using up all of my CPU. I ended the process and ComboFix could finish its report, which is attached. –David

Attachments:

Hi squid555,

**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

It seems as though we are dealing with the ZeroAccess Rootkit. It can be cleanable but sometimes it takes some time to remove. There may be a time where you might lose internet access as well until we have it neutralized.

If you would like to format and reinstall your Operating System please let me know and I can assist you with that.

If you would like to continue with the cleaning, please continue with the following instructions and I will be more than happy to help. :)
———-

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Right-click and Run as Administrator TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-
Dear Jeff, TDSSKiller came back clean. I should also note that ComboFix did identify the ZeroAccessRootkit and I assume attempted to remove it. –David
Hi squid555,

I should also note that ComboFix did identify the ZeroAccessRootkit and I assume attempted to remove it.

Yes it looks like we probably got a part of it. :) We have plenty to do still so stick with me.
——————

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    DDS::
    uInternet Settings,ProxyServer = http=127.0.0.1:54263
    uRun: [msraator] rundll32 "c:\users\david\appdata\local\temp\dns-conf.dll",DllGetVersion
    uRun: [Gpilohahozewujo] rundll32.exe "c:\users\david\appdata\local\eapcap.dll",Startup
    uRun: [Privacy Protection] c:\users\david\appdata\roaming\privacy.exe
    
    Registry::
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "Gpilohahozewujo"=-
    "{DD40DAC1-F6CC-372F-9344-54F8E0149012}"=-
    
    RegLock::
    [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
    
    DirLook::
    c:\users\David\AppData\Roaming\EFBF5
    c:\users\David\AppData\Roaming\82CEF
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
Hi Squid555,

Please download Malwarebytes' Anti-Malware to your desktop.

  • Right-click and Run as Administrator mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.


The log can also be found here:
C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
———-

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



As a Vista/Win7 user you will need to right click your browser icon and select "Run as Administrator" in order to run this scan.
  • Do not use this instance of your browser for anything besides doing this scan
  • When the scan is complete and the results saved, close that instance of your browser
  • Open a new one the usual way and post the results in this topic.


  • Right-click and Run as Administartor on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/
———-

In your next reply please post the logs created by Malwarebytes and ESET online scanner. :)
Hi Squid555,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    File::
    C:\Documents and Settings\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\55d743c0-3ee58abe	
    C:\Documents and Settings\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\6582a14a-7cb51c49	
    C:\Documents and Settings\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\3b51d80d-374d5f5a	
    C:\Documents and Settings\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\5416a4d0-55ad23fe	
    C:\Documents and Settings\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\67e22353-7d5a2d57	
    C:\Documents and Settings\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\12879fc2-36a54aee	
    C:\Documents and Settings\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\393a8716-2037938f	
    C:\Documents and Settings\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\5eab9fd7-331efae4	
    C:\Documents and Settings\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\78fe4718-5ea03ec5	
    C:\Documents and Settings\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\a11d45f-7359c641	
    C:\Documents and Settings\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\290a52e3-71dfe1ab	
    C:\Documents and Settings\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\5bb7d9e3-54635296	
    C:\Documents and Settings\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\cba3b24-391f4914	
    C:\Documents and Settings\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\72802a69-60c19f7c	
    C:\Documents and Settings\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\465f12ac-67874b85	
    C:\Documents and Settings\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\629cc8ec-4efa6cc7	
    C:\Documents and Settings\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\1e7854b0-18fec3ef	
    C:\Documents and Settings\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\224df3f9-4d674ee4	
    C:\Users\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\55d743c0-3ee58abe	
    C:\Users\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10\6582a14a-7cb51c49	
    C:\Users\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\3b51d80d-374d5f5a	
    C:\Users\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\5416a4d0-55ad23fe	
    C:\Users\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\67e22353-7d5a2d57	
    C:\Users\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\12879fc2-36a54aee	
    C:\Users\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\393a8716-2037938f	
    C:\Users\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\5eab9fd7-331efae4	
    C:\Users\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\78fe4718-5ea03ec5	
    C:\Users\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\a11d45f-7359c641	
    C:\Users\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\290a52e3-71dfe1ab	
    C:\Users\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\5bb7d9e3-54635296	
    C:\Users\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\cba3b24-391f4914	
    C:\Users\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\72802a69-60c19f7c	
    C:\Users\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\465f12ac-67874b85	
    C:\Users\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44\629cc8ec-4efa6cc7	
    C:\Users\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\1e7854b0-18fec3ef	
    C:\Users\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\224df3f9-4d674ee4
    
    Folder::
    c:\users\David\AppData\Roaming\82CEF
    c:\users\David\AppData\Roaming\EFBF5
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-

How is your system running? :)
Dear Jeff, My system is running quite well. The first time we ran ComboFix my computer restarted and it loaded up with quite a bit fewer processes than in the past and it seems to be running pretty quickly. The newest log is attached. –David

Attachments:

Hi,

My system is running quite well.

Great! That is good to hear. :)

When you ran DDS the first time there were two logs that were created and you posted one of those. Take a look and see if you have the other log named Attach.txt and post that into your next reply.

If you don't have it please re-run DDS and post both of the new logs into your next reply. Please just copy/paste the logs into the reply…it makes it easier for me to read. Thanks. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI