Here are the logs:
GMER 1.0.14.14536 -
http://www.gmer.net
Rootkit scan 2009-01-16 20:04:51
Windows 5.1.2600 Service Pack 3
—- System - GMER 1.0.14 —-
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateKey [0xACDEC7A6]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcess [0xACDE9794]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcessEx [0xACDE9F1E]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwDeleteKey [0xACDED1F0]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwDeleteValueKey [0xACDED42A]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwRenameKey [0xACDEE12A]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwSetValueKey [0xACDED83C]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwTerminateProcess [0xACDE8D0A]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwWriteVirtualMemory [0xACDE8384]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xACB759A8]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xACB75AE5]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xACB75ACF]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xACB759E8]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xACB75B11]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xACB75A2B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xACB75930]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xACB75944]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xACB759BC]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xACB75B4D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xACB75AB9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xACB75AA3]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xACB75B39]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xACB75B25]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xACB75994]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xACB75980]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xACB75AFB]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xACB759FE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xACB759D2]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess
—- Kernel code sections - GMER 1.0.14 —-
.text ntkrnlpa.exe!ZwYieldExecution 80504AE8 7 Bytes JMP ACB759D6 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtCreateFile 80579084 5 Bytes JMP ACB759AC \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 805B2006 7 Bytes JMP ACB759EC \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805B2E14 5 Bytes JMP ACB75A02 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 805B83E6 7 Bytes JMP ACB759C0 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess 805CB408 5 Bytes JMP ACB75934 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 805CB694 5 Bytes JMP ACB75948 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetInformationProcess 805CDE52 5 Bytes JMP ACB75984 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetContextThread 805D1702 5 Bytes JMP ACB75998 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryValueKey 806219CA 7 Bytes JMP ACB75AA7 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnloadKey 80622042 7 Bytes JMP ACB75AFF \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryMultipleValueKey 806228E0 7 Bytes JMP ACB75ABD \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateKey 80623FD2 7 Bytes JMP ACB75AE9 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateValueKey 8062423C 7 Bytes JMP ACB75AD3 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwOpenKey 80624B64 5 Bytes JMP ACB75A2F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryKey 80624E8A 7 Bytes JMP ACB75B51 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRestoreKey 8062514A 5 Bytes JMP ACB75B29 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwReplaceKey 8062583E 5 Bytes JMP ACB75B3D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwNotifyChangeKey 80625958 5 Bytes JMP ACB75B15 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
? C:\WINDOWS\system32\Drivers\mchInjDrv.sys The system cannot find the file specified. !
—- User code sections - GMER 1.0.14 —-
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, BC, 83 ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, EF, F4 ]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[340] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 8E, 84 ]
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\Program Files\Java\jre6\bin\jusched.exe[396] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, F7, 84 ]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\Program Files\Google\Update\GoogleUpdate.exe[404] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2D, 5F ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 18, 5F ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 24, 5F ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0C, 5F ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 15, 5F ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 21, 5F ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0F, 5F ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 27, 5F ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[560] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 2A, 5F ]
.text C:\WINDOWS\system32\svchost.exe[560] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00A80FEF
.text C:\WINDOWS\system32\svchost.exe[560] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00A80074
.text C:\WINDOWS\system32\svchost.exe[560] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00A80F75
.text C:\WINDOWS\system32\svchost.exe[560] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00A80F86
.text C:\WINDOWS\system32\svchost.exe[560] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00A80039
.text C:\WINDOWS\system32\svchost.exe[560] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00A80014
.text C:\WINDOWS\system32\svchost.exe[560] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00A800A5
.text C:\WINDOWS\system32\svchost.exe[560] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00A80F53
.text C:\WINDOWS\system32\svchost.exe[560] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00A800C0
.text C:\WINDOWS\system32\svchost.exe[560] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00A80F27
.text C:\WINDOWS\system32\svchost.exe[560] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00A80F0C
.text C:\WINDOWS\system32\svchost.exe[560] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00A80F97
.text C:\WINDOWS\system32\svchost.exe[560] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00A80FD4
.text C:\WINDOWS\system32\svchost.exe[560] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00A80F64
.text C:\WINDOWS\system32\svchost.exe[560] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00A80FA8
.text C:\WINDOWS\system32\svchost.exe[560] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00A80FC3
.text C:\WINDOWS\system32\svchost.exe[560] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00A80F38
.text C:\WINDOWS\system32\svchost.exe[560] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00A70FCD
.text C:\WINDOWS\system32\svchost.exe[560] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00A70057
.text C:\WINDOWS\system32\svchost.exe[560] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00A70FDE
.text C:\WINDOWS\system32\svchost.exe[560] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00A70014
.text C:\WINDOWS\system32\svchost.exe[560] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00A70F90
.text C:\WINDOWS\system32\svchost.exe[560] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00A70FEF
.text C:\WINDOWS\system32\svchost.exe[560] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 00A70FA1
.text C:\WINDOWS\system32\svchost.exe[560] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [ C7, 88 ]
.text C:\WINDOWS\system32\svchost.exe[560] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00A70FB2
.text C:\WINDOWS\system32\svchost.exe[560] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F330F5A
.text C:\WINDOWS\system32\svchost.exe[560] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2F0F5A
.text C:\WINDOWS\system32\svchost.exe[560] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00A5000A
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2D, 5F ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 18, 5F ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 24, 5F ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0C, 5F ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 15, 5F ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 21, 5F ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0F, 5F ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 27, 5F ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[620] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 2A, 5F ]
.text C:\WINDOWS\system32\svchost.exe[620] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00DE0000
.text C:\WINDOWS\system32\svchost.exe[620] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00DE0078
.text C:\WINDOWS\system32\svchost.exe[620] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00DE0067
.text C:\WINDOWS\system32\svchost.exe[620] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00DE0F8D
.text C:\WINDOWS\system32\svchost.exe[620] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00DE0F9E
.text C:\WINDOWS\system32\svchost.exe[620] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00DE0FB9
.text C:\WINDOWS\system32\svchost.exe[620] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00DE00B0
.text C:\WINDOWS\system32\svchost.exe[620] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00DE0093
.text C:\WINDOWS\system32\svchost.exe[620] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00DE00E6
.text C:\WINDOWS\system32\svchost.exe[620] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00DE0F4D
.text C:\WINDOWS\system32\svchost.exe[620] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00DE00F7
.text C:\WINDOWS\system32\svchost.exe[620] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00DE0036
.text C:\WINDOWS\system32\svchost.exe[620] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00DE0FE5
.text C:\WINDOWS\system32\svchost.exe[620] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00DE0F68
.text C:\WINDOWS\system32\svchost.exe[620] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00DE0FCA
.text C:\WINDOWS\system32\svchost.exe[620] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00DE001B
.text C:\WINDOWS\system32\svchost.exe[620] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00DE00C1
.text C:\WINDOWS\system32\svchost.exe[620] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00DC0014
.text C:\WINDOWS\system32\svchost.exe[620] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00DC0F94
.text C:\WINDOWS\system32\svchost.exe[620] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00DC0FCD
.text C:\WINDOWS\system32\svchost.exe[620] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00DC0FDE
.text C:\WINDOWS\system32\svchost.exe[620] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00DC0051
.text C:\WINDOWS\system32\svchost.exe[620] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00DC0FEF
.text C:\WINDOWS\system32\svchost.exe[620] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00DC0040
.text C:\WINDOWS\system32\svchost.exe[620] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00DC002F
.text C:\WINDOWS\system32\svchost.exe[620] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F330F5A
.text C:\WINDOWS\system32\svchost.exe[620] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2F0F5A
.text C:\WINDOWS\system32\svchost.exe[620] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00DA000A
.text C:\WINDOWS\system32\svchost.exe[620] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 00DD0FE5
.text C:\WINDOWS\system32\svchost.exe[620] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 00DD0FD4
.text C:\WINDOWS\system32\svchost.exe[620] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00DD000A
.text C:\WINDOWS\system32\svchost.exe[620] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 00DD0025
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2D, 5F ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 18, 5F ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 24, 5F ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0C, 5F ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 15, 5F ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 21, 5F ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0F, 5F ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 27, 5F ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 2A, 5F ]
.text C:\WINDOWS\system32\svchost.exe[660] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F10000
.text C:\WINDOWS\system32\svchost.exe[660] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F10F86
.text C:\WINDOWS\system32\svchost.exe[660] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F10F97
.text C:\WINDOWS\system32\svchost.exe[660] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F10FA8
.text C:\WINDOWS\system32\svchost.exe[660] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F10FB9
.text C:\WINDOWS\system32\svchost.exe[660] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F10FE5
.text C:\WINDOWS\system32\svchost.exe[660] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F100AC
.text C:\WINDOWS\system32\svchost.exe[660] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F10F5A
.text C:\WINDOWS\system32\svchost.exe[660] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F10F1A
.text C:\WINDOWS\system32\svchost.exe[660] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F100BD
.text C:\WINDOWS\system32\svchost.exe[660] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00F100D8
.text C:\WINDOWS\system32\svchost.exe[660] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00F10FD4
.text C:\WINDOWS\system32\svchost.exe[660] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00F1001B
.text C:\WINDOWS\system32\svchost.exe[660] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00F10F75
.text C:\WINDOWS\system32\svchost.exe[660] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00F10051
.text C:\WINDOWS\system32\svchost.exe[660] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00F10040
.text C:\WINDOWS\system32\svchost.exe[660] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00F10F3F
.text C:\WINDOWS\system32\svchost.exe[660] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00F00FD4
.text C:\WINDOWS\system32\svchost.exe[660] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00F00076
.text C:\WINDOWS\system32\svchost.exe[660] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00F00FE5
.text C:\WINDOWS\system32\svchost.exe[660] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00F0001B
.text C:\WINDOWS\system32\svchost.exe[660] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00F0005B
.text C:\WINDOWS\system32\svchost.exe[660] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00F00000
.text C:\WINDOWS\system32\svchost.exe[660] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00F00040
.text C:\WINDOWS\system32\svchost.exe[660] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00F00FC3
.text C:\WINDOWS\system32\svchost.exe[660] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F330F5A
.text C:\WINDOWS\system32\svchost.exe[660] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2F0F5A
.text C:\WINDOWS\system32\svchost.exe[660] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00EE0000
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 73, 84 ]
.text C:\WINDOWS\system32\Ati2evxx.exe[692] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[692] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, F1, 83 ]
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe[872] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, F8, 83 ]
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe[888] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, BB, 83 ]
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\WINDOWS\System32\WLTRYSVC.EXE[936] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, FD, 84 ]
.text C:\WINDOWS\System32\bcmwltry.exe[948] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\WINDOWS\System32\bcmwltry.exe[948] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 2D, 88 ]
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[960] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 66, 84 ]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1088] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[1120] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\system32\csrss.exe[1120] KERNEL32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 4C, 85 ]
.text C:\WINDOWS\system32\csrss.exe[1120] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\WINDOWS\system32\csrss.exe[1120] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 4F, 85 ]
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\Program Files\Executive Software\Diskeeper\DkService.exe[1124] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[1152] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[1152] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, EF, 84 ]
.text C:\WINDOWS\system32\winlogon.exe[1152] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\WINDOWS\system32\winlogon.exe[1152] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2D, 5F ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 18, 5F ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 24, 5F ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0C, 5F ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 12, 5F ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 15, 5F ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 21, 5F ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0F, 5F ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 27, 5F ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1B, 5F ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1E, 5F ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[1196] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 2A, 5F ]
.text C:\WINDOWS\system32\services.exe[1196] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01340FE5
.text C:\WINDOWS\system32\services.exe[1196] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01340F4A
.text C:\WINDOWS\system32\services.exe[1196] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 0134003F
.text C:\WINDOWS\system32\services.exe[1196] kernel32.dll!LoadLibraryExW 7C801AF5 1 Byte [ E9 ]
.text C:\WINDOWS\system32\services.exe[1196] kernel32.dll!LoadLibraryExW + 2 7C801AF7 3 Bytes [ E5, B3, 84 ]
.text C:\WINDOWS\system32\services.exe[1196] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01340F6F
.text C:\WINDOWS\system32\services.exe[1196] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01340FA5
.text C:\WINDOWS\system32\services.exe[1196] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 0134006B
.text C:\WINDOWS\system32\services.exe[1196] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 0134005A
.text C:\WINDOWS\system32\services.exe[1196] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01340EE3
.text C:\WINDOWS\system32\services.exe[1196] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 0134007C
.text C:\WINDOWS\system32\services.exe[1196] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 01340EC8
.text C:\WINDOWS\system32\services.exe[1196] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 01340F8A
.text C:\WINDOWS\system32\services.exe[1196] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 01340000
.text C:\WINDOWS\system32\services.exe[1196] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 01340F39
.text C:\WINDOWS\system32\services.exe[1196] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 01340FC0
.text C:\WINDOWS\system32\services.exe[1196] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 01340011
.text C:\WINDOWS\system32\services.exe[1196] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 01340EFE
.text C:\WINDOWS\system32\services.exe[1196] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 0133001B
.text C:\WINDOWS\system32\services.exe[1196] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 01330062
.text C:\WINDOWS\system32\services.exe[1196] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 01330FCA
.text C:\WINDOWS\system32\services.exe[1196] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 01330000
.text C:\WINDOWS\system32\services.exe[1196] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 01330FA5
.text C:\WINDOWS\system32\services.exe[1196] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 01330FE5
.text C:\WINDOWS\system32\services.exe[1196] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 0133003D
.text C:\WINDOWS\system32\services.exe[1196] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 0133002C
.text C:\WINDOWS\system32\services.exe[1196] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F330F5A
.text C:\WINDOWS\system32\services.exe[1196] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2F0F5A
.text C:\WINDOWS\system32\services.exe[1196] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FF0000
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2D, 5F ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 18, 5F ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 24, 5F ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0C, 5F ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 12, 5F ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 15, 5F ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 21, 5F ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0F, 5F ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 27, 5F ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1B, 5F ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1E, 5F ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[1208] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 2A, 5F ]
.text C:\WINDOWS\system32\lsass.exe[1208] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00FE0000
.text C:\WINDOWS\system32\lsass.exe[1208] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00FE0075
.text C:\WINDOWS\system32\lsass.exe[1208] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00FE0064
.text C:\WINDOWS\system32\lsass.exe[1208] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00FE0F8A
.text C:\WINDOWS\system32\lsass.exe[1208] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00FE0F9B
.text C:\WINDOWS\system32\lsass.exe[1208] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00FE0FC0
.text C:\WINDOWS\system32\lsass.exe[1208] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00FE0092
.text C:\WINDOWS\system32\lsass.exe[1208] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00FE0F4A
.text C:\WINDOWS\system32\lsass.exe[1208] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FE00C8
.text C:\WINDOWS\system32\lsass.exe[1208] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FE00AD
.text C:\WINDOWS\system32\lsass.exe[1208] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00FE00D9
.text C:\WINDOWS\system32\lsass.exe[1208] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00FE0047
.text C:\WINDOWS\system32\lsass.exe[1208] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00FE0FDB
.text C:\WINDOWS\system32\lsass.exe[1208] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00FE0F65
.text C:\WINDOWS\system32\lsass.exe[1208] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00FE002C
.text C:\WINDOWS\system32\lsass.exe[1208] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00FE0011
.text C:\WINDOWS\system32\lsass.exe[1208] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00FE0F2F
.text C:\WINDOWS\system32\lsass.exe[1208] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00FD0FB2
.text C:\WINDOWS\system32\lsass.exe[1208] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00FD004A
.text C:\WINDOWS\system32\lsass.exe[1208] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00FD0FC3
.text C:\WINDOWS\system32\lsass.exe[1208] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00FD0FD4
.text C:\WINDOWS\system32\lsass.exe[1208] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00FD0039
.text C:\WINDOWS\system32\lsass.exe[1208] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00FD0FE5
.text C:\WINDOWS\system32\lsass.exe[1208] ADVAPI32.dll!RegCreateKeyW 77DFBA25 5 Bytes JMP 00FD0028
.text C:\WINDOWS\system32\lsass.exe[1208] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00FD0FA1
.text C:\WINDOWS\system32\lsass.exe[1208] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F330F5A
.text C:\WINDOWS\system32\lsass.exe[1208] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2F0F5A
.text C:\WINDOWS\system32\lsass.exe[1208] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FA0000
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, AE, 84 ]
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\WINDOWS\system32\Ati2evxx.exe[1392] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2D, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 18, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 24, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0C, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 15, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 21, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0F, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 27, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 2A, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1412] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00E00FEF
.text C:\WINDOWS\system32\svchost.exe[1412] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00E00F5F
.text C:\WINDOWS\system32\svchost.exe[1412] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00E00F7A
.text C:\WINDOWS\system32\svchost.exe[1412] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00E00F97
.text C:\WINDOWS\system32\svchost.exe[1412] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00E00FA8
.text C:\WINDOWS\system32\svchost.exe[1412] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00E0002F
.text C:\WINDOWS\system32\svchost.exe[1412] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00E0008F
.text C:\WINDOWS\system32\svchost.exe[1412] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00E00F3D
.text C:\WINDOWS\system32\svchost.exe[1412] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E00F00
.text C:\WINDOWS\system32\svchost.exe[1412] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E00F11
.text C:\WINDOWS\system32\svchost.exe[1412] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00E000B4
.text C:\WINDOWS\system32\svchost.exe[1412] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00E0004A
.text C:\WINDOWS\system32\svchost.exe[1412] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00E0000A
.text C:\WINDOWS\system32\svchost.exe[1412] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00E00F4E
.text C:\WINDOWS\system32\svchost.exe[1412] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00E00FC3
.text C:\WINDOWS\system32\svchost.exe[1412] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00E00FD4
.text C:\WINDOWS\system32\svchost.exe[1412] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00E00F2C
.text C:\WINDOWS\system32\svchost.exe[1412] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00DF0047
.text C:\WINDOWS\system32\svchost.exe[1412] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00DF007D
.text C:\WINDOWS\system32\svchost.exe[1412] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00DF0036
.text C:\WINDOWS\system32\svchost.exe[1412] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00DF001B
.text C:\WINDOWS\system32\svchost.exe[1412] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00DF0062
.text C:\WINDOWS\system32\svchost.exe[1412] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00DF0000
.text C:\WINDOWS\system32\svchost.exe[1412] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 00DF0FC0
.text C:\WINDOWS\system32\svchost.exe[1412] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [ FF, 88 ]
.text C:\WINDOWS\system32\svchost.exe[1412] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00DF0FDB
.text C:\WINDOWS\system32\svchost.exe[1412] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F330F5A
.text C:\WINDOWS\system32\svchost.exe[1412] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2F0F5A
.text C:\WINDOWS\system32\svchost.exe[1412] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00D30FEF
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2D, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 18, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 24, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0C, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 15, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 21, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0F, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 27, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1E, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\svchost.exe[1480] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 2A, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1480] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01050FEF
.text C:\WINDOWS\system32\svchost.exe[1480] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01050F63
.text C:\WINDOWS\system32\svchost.exe[1480] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01050058
.text C:\WINDOWS\system32\svchost.exe[1480] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 0105003D
.text C:\WINDOWS\system32\svchost.exe[1480] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0105002C
.text C:\WINDOWS\system32\svchost.exe[1480] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01050FAF
.text C:\WINDOWS\system32\svchost.exe[1480] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01050F37
.text C:\WINDOWS\system32\svchost.exe[1480] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01050F48
.text C:\WINDOWS\system32\svchost.exe[1480] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01050EF0
.text C:\WINDOWS\system32\svchost.exe[1480] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01050F0B
.text C:\WINDOWS\system32\svchost.exe[1480] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 01050EDF
.text C:\WINDOWS\system32\svchost.exe[1480] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 01050F94
.text C:\WINDOWS\system32\svchost.exe[1480] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 0105000A
.text C:\WINDOWS\system32\svchost.exe[1480] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 01050073
.text C:\WINDOWS\system32\svchost.exe[1480] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 01050FCA
.text C:\WINDOWS\system32\svchost.exe[1480] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 0105001B
.text C:\WINDOWS\system32\svchost.exe[1480] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 01050F1C
.text C:\WINDOWS\system32\svchost.exe[1480] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00FF0FA8
.text C:\WINDOWS\system32\svchost.exe[1480] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00FF0F50
.text C:\WINDOWS\system32\svchost.exe[1480] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00FF0FC3
.text C:\WINDOWS\system32\svchost.exe[1480] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00FF0FDE
.text C:\WINDOWS\system32\svchost.exe[1480] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00FF0F61
.text C:\WINDOWS\system32\svchost.exe[1480] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00FF0FEF
.text C:\WINDOWS\system32\svchost.exe[1480] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 00FF0F7C
.text C:\WINDOWS\system32\svchost.exe[1480] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [ 1F, 89 ]
.text C:\WINDOWS\system32\svchost.exe[1480] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00FF0F8D
.text C:\WINDOWS\system32\svchost.exe[1480] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F330F5A
.text C:\WINDOWS\system32\svchost.exe[1480] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2F0F5A
.text C:\WINDOWS\system32\svchost.exe[1480] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FD0000
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2D, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 18, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 24, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0C, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 12, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 15, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 21, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0F, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 27, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1B, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1E, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 2A, 5F ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00D70000
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00D70F70
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00D70065
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00D70F8B
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00D70FA8
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00D70FC3
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00D70F3F
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00D70091
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D70F02
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D70F1D
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 00D70EE7
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 00D7004A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00D70FEF
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 00D70080
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 00D70FD4
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 00D70025
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 00D70F2E
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00D60FB9
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00D6004A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00D60FCA
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 00D6000A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00D60F97
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 00D60FE5
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 00D60FA8
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [ F6, 88 ]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00D6002F
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F340F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F300F5A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] WS2_32.dll!socket 71AB4211 5 Bytes JMP 005A0000
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, C9, 84 ]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\Program Files\Java\jre6\bin\jqs.exe[1620] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 0F, 86 ]
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe[1728] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2D, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 18, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 24, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0C, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 12, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 15, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 21, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0F, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 27, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1B, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1E, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1824] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 2A, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1824] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02C60FEF
.text C:\WINDOWS\System32\svchost.exe[1824] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 02C60F79
.text C:\WINDOWS\System32\svchost.exe[1824] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02C60078
.text C:\WINDOWS\System32\svchost.exe[1824] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02C60067
.text C:\WINDOWS\System32\svchost.exe[1824] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02C6004A
.text C:\WINDOWS\System32\svchost.exe[1824] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02C60FB2
.text C:\WINDOWS\System32\svchost.exe[1824] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02C600A4
.text C:\WINDOWS\System32\svchost.exe[1824] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02C60093
.text C:\WINDOWS\System32\svchost.exe[1824] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02C60F37
.text C:\WINDOWS\System32\svchost.exe[1824] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 02C600D0
.text C:\WINDOWS\System32\svchost.exe[1824] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 02C60F1C
.text C:\WINDOWS\System32\svchost.exe[1824] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 02C60039
.text C:\WINDOWS\System32\svchost.exe[1824] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 02C60014
.text C:\WINDOWS\System32\svchost.exe[1824] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 02C60F68
.text C:\WINDOWS\System32\svchost.exe[1824] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 02C60FC3
.text C:\WINDOWS\System32\svchost.exe[1824] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 02C60FDE
.text C:\WINDOWS\System32\svchost.exe[1824] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 02C600B5
.text C:\WINDOWS\System32\svchost.exe[1824] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 02C40FD4
.text C:\WINDOWS\System32\svchost.exe[1824] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 02C40F94
.text C:\WINDOWS\System32\svchost.exe[1824] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 02C4002F
.text C:\WINDOWS\System32\svchost.exe[1824] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 02C40014
.text C:\WINDOWS\System32\svchost.exe[1824] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 02C40051
.text C:\WINDOWS\System32\svchost.exe[1824] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 02C40FEF
.text C:\WINDOWS\System32\svchost.exe[1824] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 02C40FAF
.text C:\WINDOWS\System32\svchost.exe[1824] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [ E4, 8A ]
.text C:\WINDOWS\System32\svchost.exe[1824] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 02C40040
.text C:\WINDOWS\System32\svchost.exe[1824] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F330F5A
.text C:\WINDOWS\System32\svchost.exe[1824] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2F0F5A
.text C:\WINDOWS\System32\svchost.exe[1824] WS2_32.dll!socket 71AB4211 5 Bytes JMP 02AC0000
.text C:\WINDOWS\System32\svchost.exe[1824] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 02C5000A
.text C:\WINDOWS\System32\svchost.exe[1824] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 02C50025
.text C:\WINDOWS\System32\svchost.exe[1824] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 02C50FEF
.text C:\WINDOWS\System32\svchost.exe[1824] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 02C50036
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 79, 85 ]
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe[1912] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 73, 85 ]
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\WINDOWS\system32\LEXBCES.EXE[1980] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, C9, 85 ]
.text C:\WINDOWS\system32\spoolsv.exe[2004] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\WINDOWS\system32\spoolsv.exe[2004] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 7B, 85 ]
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\WINDOWS\system32\LEXPPS.EXE[2028] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, DA, 85 ]
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0041C340 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 0041C3C0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[2128] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 7B, 84 ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe[2180] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, D6, 84 ]
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2256] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 12, 86 ]
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\Program Files\McAfee\MPF\MPFSrv.exe[2284] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, DE, 85 ]
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\Program Files\VMware\VMware Workstation\vmware-tray.exe[2464] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, B7, 84 ]
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe[2644] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[3000] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 98, 87 ]
.text C:\Program Files\Spyware Doctor\pctsTray.exe[3000] kernel32.dll!CreateThread + 1A 7C8106E1 4 Bytes [ 37, A1, C3, 83 ]
.text C:\Program Files\Spyware Doctor\pctsTray.exe[3000] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[3000] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\snmp.exe[3212] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\System32\snmp.exe[3212] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 67, 84 ]
.text C:\WINDOWS\System32\snmp.exe[3212] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\WINDOWS\System32\snmp.exe[3212] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 68, 84 ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, EF, F4 ]
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe[3252] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 34, 5F ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 1F, 5F ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 0F, 5F ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 2B, 5F ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 13, 5F ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 19, 5F ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 1C, 5F ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 28, 5F ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 16, 5F ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 2E, 5F ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 22, 5F ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 25, 5F ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\explorer.exe[3356] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 31, 5F ]
.text C:\WINDOWS\explorer.exe[3356] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 001A0000
.text C:\WINDOWS\explorer.exe[3356] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 001A0FA8
.text C:\WINDOWS\explorer.exe[3356] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 001A009D
.text C:\WINDOWS\explorer.exe[3356] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 001A0080
.text C:\WINDOWS\explorer.exe[3356] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 001A006F
.text C:\WINDOWS\explorer.exe[3356] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 001A0FD4
.text C:\WINDOWS\explorer.exe[3356] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 001A00B8
.text C:\WINDOWS\explorer.exe[3356] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 001A0F7C
.text C:\WINDOWS\explorer.exe[3356] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 001A00FF
.text C:\WINDOWS\explorer.exe[3356] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 001A00E4
.text C:\WINDOWS\explorer.exe[3356] kernel32.dll!GetProcAddress 7C80AE30 5 Bytes JMP 001A0110
.text C:\WINDOWS\explorer.exe[3356] kernel32.dll!LoadLibraryW 7C80AEDB 5 Bytes JMP 001A0FC3
.text C:\WINDOWS\explorer.exe[3356] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 001A0FEF
.text C:\WINDOWS\explorer.exe[3356] kernel32.dll!CreatePipe 7C81D827 5 Bytes JMP 001A0F8D
.text C:\WINDOWS\explorer.exe[3356] kernel32.dll!CreateNamedPipeW 7C82F0C5 5 Bytes JMP 001A0040
.text C:\WINDOWS\explorer.exe[3356] kernel32.dll!CreateNamedPipeA 7C860B7C 5 Bytes JMP 001A0025
.text C:\WINDOWS\explorer.exe[3356] kernel32.dll!WinExec 7C8623AD 5 Bytes JMP 001A00C9
.text C:\WINDOWS\explorer.exe[3356] ADVAPI32.dll!RegOpenKeyExW 77DD6A9F 5 Bytes JMP 00290FCA
.text C:\WINDOWS\explorer.exe[3356] ADVAPI32.dll!RegCreateKeyExW 77DD775C 5 Bytes JMP 00290F72
.text C:\WINDOWS\explorer.exe[3356] ADVAPI32.dll!RegOpenKeyExA 77DD7842 5 Bytes JMP 00290FDB
.text C:\WINDOWS\explorer.exe[3356] ADVAPI32.dll!RegOpenKeyW 77DD7936 5 Bytes JMP 0029001B
.text C:\WINDOWS\explorer.exe[3356] ADVAPI32.dll!RegCreateKeyExA 77DDE9E4 5 Bytes JMP 00290F83
.text C:\WINDOWS\explorer.exe[3356] ADVAPI32.dll!RegOpenKeyA 77DDEFB8 5 Bytes JMP 0029000A
.text C:\WINDOWS\explorer.exe[3356] ADVAPI32.dll!RegCreateKeyW 77DFBA25 2 Bytes JMP 00290F9E
.text C:\WINDOWS\explorer.exe[3356] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA28 2 Bytes [ 49, 88 ]
.text C:\WINDOWS\explorer.exe[3356] ADVAPI32.dll!RegCreateKeyA 77DFBCC3 5 Bytes JMP 00290FB9
.text C:\WINDOWS\explorer.exe[3356] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F0B0F5A
.text C:\WINDOWS\explorer.exe[3356] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\explorer.exe[3356] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 002C000A
.text C:\WINDOWS\explorer.exe[3356] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 002C0FEF
.text C:\WINDOWS\explorer.exe[3356] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 002C0FDE
.text C:\WINDOWS\explorer.exe[3356] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 002C0039
.text C:\WINDOWS\explorer.exe[3356] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01BA0FE5
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 0F, 84 ]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[3408] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\Program Files\Spyware Doctor\pctsSvc.exe[3420] kernel32.dll!CreateThread + 1A 7C8106E1 4 Bytes [ 23, A1, C3, 83 ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\rundll32.exe[3544] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\system32\rundll32.exe[3544] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 16, 84 ]
.text C:\WINDOWS\system32\rundll32.exe[3544] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, EF, F4 ]
.text C:\WINDOWS\system32\rundll32.exe[3544] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\WINDOWS\system32\rundll32.exe[3544] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, FB, 83 ]
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[3624] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, BB, 83 ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, EF, F4 ]
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\Documents and Settings\Meaghan\Desktop\gmer.exe[3644] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 42, 84 ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, EF, F4 ]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3768] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, BC, 83 ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, EF, F4 ]
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe[4140] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 0C, 84 ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, EF, F4 ]
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe[4488] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 2F, 84 ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, EF, F4 ]
.text C:\WINDOWS\system32\ctfmon.exe[4548] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\WINDOWS\system32\ctfmon.exe[4548] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 09, 84 ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, EF, F4 ]
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\WINDOWS\system32\vmnetdhcp.exe[4728] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\alg.exe[4928] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\System32\alg.exe[4928] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, ED, 83 ]
.text C:\WINDOWS\System32\alg.exe[4928] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, EF, F4 ]
.text C:\WINDOWS\System32\alg.exe[4928] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\WINDOWS\System32\alg.exe[4928] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 1C, 84 ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, EF, F4 ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe[5416] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, FA, 83 ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, EF, F4 ]
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe[5660] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtClose 7C90CFD0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtClose + 4 7C90CFD4 2 Bytes [ 2C, 5F ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtCreateFile 7C90D090 1 Byte [ FF ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtCreateFile + 2 7C90D092 1 Byte [ 1E ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtCreateFile + 4 7C90D094 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtCreateKey 7C90D0D0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtCreateKey + 4 7C90D0D4 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtDeleteKey 7C90D230 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtDeleteKey + 4 7C90D234 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtDeleteValueKey 7C90D250 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtDeleteValueKey + 4 7C90D254 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtRenameKey 7C90DA40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtRenameKey + 4 7C90DA44 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtSetInformationFile 7C90DC40 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtSetInformationFile + 4 7C90DC44 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtSetValueKey 7C90DDB0 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtSetValueKey + 4 7C90DDB4 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtWriteFile 7C90DF60 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtWriteFile + 4 7C90DF64 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtWriteFileGather 7C90DF70 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtWriteFileGather + 4 7C90DF74 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\vmnat.exe[6052] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\system32\vmnat.exe[6052] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes [ 43, E4, 09, 84 ]
.text C:\WINDOWS\system32\vmnat.exe[6052] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes [ B5, 53, EF, F4 ]
.text C:\WINDOWS\system32\vmnat.exe[6052] USER32.dll!SetWindowsHookExW 7E42820F 6 Bytes JMP 5F320F5A
.text C:\WINDOWS\system32\vmnat.exe[6052] USER32.dll!SetWindowsHookExA 7E431211 6 Bytes JMP 5F2E0F5A
—- User IAT/EAT - GMER 1.0.14 —-
IAT C:\WINDOWS\system32\svchost.exe[560] @ C:\WINDOWS\system32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[560] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[560] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[560] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[560] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[560] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[560] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[620] @ C:\WINDOWS\system32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[620] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[620] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[620] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[620] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[620] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[620] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[620] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[660] @ C:\WINDOWS\system32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[660] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[660] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[660] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[660] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[660] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[660] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[660] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\services.exe[1196] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\services.exe[1196] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\services.exe[1196] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\services.exe[1196] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\services.exe[1196] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\services.exe[1196] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\lsass.exe[1208] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\lsass.exe[1208] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\lsass.exe[1208] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\lsass.exe[1208] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\lsass.exe[1208] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\lsass.exe[1208] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\lsass.exe[1208] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[1412] @ C:\WINDOWS\system32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[1412] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[1412] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[1412] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[1412] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[1412] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[1412] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[1412] @ c:\windows\system32\rpcss.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[1480] @ C:\WINDOWS\system32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[1480] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[1480] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[1480] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[1480] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[1480] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[1480] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\svchost.exe[1480] @ c:\windows\system32\rpcss.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\system32\inetsrv\inetinfo.exe[1576] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[1824] @ C:\WINDOWS\System32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[1824] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[1824] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[1824] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[1824] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[1824] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[1824] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[1824] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\System32\svchost.exe[1824] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\explorer.exe[3356] @ C:\WINDOWS\explorer.exe [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\explorer.exe[3356] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\explorer.exe[3356] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\explorer.exe[3356] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\explorer.exe[3356] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\explorer.exe[3356] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\explorer.exe[3356] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\explorer.exe[3356] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
IAT C:\WINDOWS\explorer.exe[3356] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 5F080000
—- Devices - GMER 1.0.14 —-
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 VMkbd.sys (VMware keyboard filter driver (32-bit)/VMware, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 tdrpman.sys (Acronis Try&Decide and Restore Points Volume Filter Driver/Acronis)
Device \Driver\usbhub \Device\00000090 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbhub \Device\00000092 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbhub \Device\00000094 hcmon.sys (VMware USB monitor/VMware, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
Device \Driver\usbhub \Device\00000096 hcmon.sys (VMware USB monitor/VMware, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
Device \Driver\usbhub \Device\00000098 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbohci \Device\USBFDO-0 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbohci \Device\USBFDO-1 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbohci \Device\USBFDO-2 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbohci \Device\USBFDO-3 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbohci \Device\USBFDO-4 hcmon.sys (VMware USB monitor/VMware, Inc.)
Device \Driver\usbehci \Device\USBFDO-5 hcmon.sys (VMware USB monitor/VMware, Inc.)
—- Registry - GMER 1.0.14 —-
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{11C308BA-18B2-3E44-C771-766DC101B05F}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{11C308BA-18B2-3E44-C771-766DC101B05F}@maalnlhimjdcajmmbcoclnnfic 0x6B 0x61 0x6A 0x70 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{11C308BA-18B2-3E44-C771-766DC101B05F}@naokljnlffjadnbolggoacneeohb 0x6B 0x61 0x6A 0x70 …
—- EOF - GMER 1.0.14 —-
GMER 1.0.14.14536 -
http://www.gmer.net
Autostart scan 2009-01-16 20:06:36
Windows 5.1.2600 Service Pack 3
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = C:\WINDOWS\system32\userinit.exe,
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
AtiExtEvent@DLLName = Ati2evxx.dll
dimsntfy@DLLName = %SystemRoot%\System32\dimsntfy.dll
WgaLogon@DLLName = WgaLogon.dll
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs = ypeplq.dll c:\windows\system32\tavimoba.dll,C:\WINDOWS\system32\yovukuyo.dll,C:\WINDOWS\system32\wiwirira.dll,C:\WINDOWS\system32\pimimoso.dll ssmasq.dll c:\windows\system32\ruvesuye.dll
HKLM\SYSTEM\CurrentControlSet\Services\ >>>
aawservice@ = "C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe"
AcrSch2Svc@ = "C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe"
AdobeActiveFileMonitor7.0@ = C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
Ati HotKey Poller@ = %SystemRoot%\system32\Ati2evxx.exe
Bonjour Service@ = "C:\Program Files\Bonjour\mDNSResponder.exe"
Diskeeper@ = "C:\Program Files\Executive Software\Diskeeper\DkService.exe"
gupdate1c93d1796586d5c@ = "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc
IISADMIN@ = C:\WINDOWS\system32\inetsrv\inetinfo.exe
JavaQuickStarterService@ = "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"
LexBceS@ = C:\WINDOWS\system32\LEXBCES.EXE
mcmscsvc@ = C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
McNASvc@ = "c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe"
McProxy@ = c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
McShield@ = C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
MDM@ = "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
MpfService@ = "C:\Program Files\McAfee\MPF\MPFSrv.exe"
MySQL@ = "C:\Program Files\MySQL\MySQL Server\bin\mysqld" –defaults-file="C:\Program Files\MySQL\MySQL Server\my.ini" MySQL
Roxio Upnp Server 10@ = "C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe"
RoxLiveShare10@ = "C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe"
RoxWatch10@ = "C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe"
ScsiPort@ = %SystemRoot%\system32\drivers\scsiport.sys
sdAuxService@ = C:\Program Files\Spyware Doctor\pctsAuxs.exe
sdCoreService@ = C:\Program Files\Spyware Doctor\pctsSvc.exe
SessionLauncher@ = C:\DOCUME~1\Meaghan\LOCALS~1\Temp\DX9\SessionLauncher.exe /*file not found*/
SNMP@ = %SystemRoot%\System32\snmp.exe
TryAndDecideService@ = "C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe"
VMAuthdService@ = C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
VMnetDHCP@ = C:\WINDOWS\system32\vmnetdhcp.exe
vmount2@ = "C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe"
VMware NAT Service@ = C:\WINDOWS\system32\vmnat.exe
W3SVC@ = %SystemRoot%\system32\inetsrv\inetinfo.exe
wltrysvc@ = %SystemRoot%\System32\WLTRYSVC.EXE %SystemRoot%\System32\bcmwltry.exe
XAudioService@ = %SystemRoot%\system32\DRIVERS\xaudio.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@SigmatelSysTrayAppstsystra.exe = stsystra.exe
@Broadcom Wireless Manager UIC:\WINDOWS\system32\WLTRAY.exe = C:\WINDOWS\system32\WLTRAY.exe
@ITSecMng%ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START /*file not found*/ = %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START /*file not found*/
@SunJavaUpdateSched"C:\Program Files\Java\jre6\bin\jusched.exe" = "C:\Program Files\Java\jre6\bin\jusched.exe"
@TrueImageMonitor.exeC:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe = C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
@AcronisTimounterMonitorC:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe = C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
@Acronis Scheduler2 Service"C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" = "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
@OSSelectorReinstallC:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe = C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe
@DiskeeperSystray"C:\Program Files\Executive Software\Diskeeper\DkIcon.exe" = "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
@PWRISOVM.EXEC:\Program Files\PowerISO\PWRISOVM.EXE = C:\Program Files\PowerISO\PWRISOVM.EXE
@QuickTime Task"C:\Program Files\QuickTime\QTTask.exe" -atboottime = "C:\Program Files\QuickTime\QTTask.exe" -atboottime
@vmware-trayC:\Program Files\VMware\VMware Workstation\vmware-tray.exe = C:\Program Files\VMware\VMware Workstation\vmware-tray.exe
@VMware hqtray"C:\Program Files\VMware\VMware Workstation\hqtray.exe" = "C:\Program Files\VMware\VMware Workstation\hqtray.exe"
@BrStsWndC:\Program Files\Brownie\BrstsWnd.exe Autorun /*file not found*/ = C:\Program Files\Brownie\BrstsWnd.exe Autorun /*file not found*/
@Lexmark X1100 Series"C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" = "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
@Acrobat Assistant 8.0"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" = "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
@Adobe_ID0EYTHMC:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE = C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
@RoxWatchTray"C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe" = "C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe"
@DMXLauncher"C:\Program Files\Roxio\CinePlayer\DMXLauncher.exe" = "C:\Program Files\Roxio\CinePlayer\DMXLauncher.exe"
@Adobe Reader Speed Launcher"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" = "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
@mcagent_exeC:\Program Files\McAfee.com\Agent\mcagent.exe /runkey /*file not found*/ = C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey /*file not found*/
@McAfee BackupC:\Program Files\McAfee\MBK\McAfeeDataBackup.exe = C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
@MBkLogOnHookC:\Program Files\McAfee\MBK\LogOnHook.exe = C:\Program Files\McAfee\MBK\LogOnHook.exe
@CanonSolutionMenuC:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon /*file not found*/ = C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon /*file not found*/
@CanonMyPrinterC:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon /*file not found*/ = C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon /*file not found*/
@IJNetworkScanUtilityC:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE = C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
@ISTray"C:\Program Files\Spyware Doctor\pctsTray.exe" = "C:\Program Files\Spyware Doctor\pctsTray.exe"
@gemewenamuRundll32.exe "C:\WINDOWS\system32\bilezefa.dll",s = Rundll32.exe "C:\WINDOWS\system32\bilezefa.dll",s
HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@ctfmon.exeC:\WINDOWS\system32\ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
@swgC:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe = C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
@MSMSGS"C:\Program Files\Messenger\msmsgs.exe" /background = "C:\Program Files\Messenger\msmsgs.exe" /background
@Google Update"C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c = "C:\Documents and Settings\Meaghan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
@AdobeUpdaterC:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe = C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
@gemewenamuRundll32.exe "C:\WINDOWS\system32\bilezefa.dll",s = Rundll32.exe "C:\WINDOWS\system32\bilezefa.dll",s
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad >>>
@WPDShServiceObjC:\WINDOWS\system32\WPDShServiceObj.dll = C:\WINDOWS\system32\WPDShServiceObj.dll
@SSODL(null) =
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler@{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} =
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Display Panning CPL Extension*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{5a61f7a0-cde1-11cf-9113-00aa00425c62} /*IIS Shell Extension*/C:\WINDOWS\system32\inetsrv\w3ext.dll = C:\WINDOWS\system32\inetsrv\w3ext.dll
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/C:\WINDOWS\system32\twext.dll = C:\WINDOWS\system32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/C:\WINDOWS\system32\twext.dll = C:\WINDOWS\system32\twext.dll
@{30D02401-6A81-11d0-8274-00C04FD5AE38} /*IE Search Band*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} /*Shell DocObject Viewer*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FBF23B40-E3F0-101B-8488-00AA003E56F8} /*InternetShortcut*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3C374A40-BAE4-11CF-BF7D-00AA006946EE} /*Microsoft Url History Service*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FF393560-C2A7-11CF-BFF4-444553540000} /*History*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{7BD29E00-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{7BD29E01-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{CFBFAE00-17A6-11D0-99CB-00C04FD64497} /*Microsoft Url Search Hook*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3DC7A020-0ACD-11CF-A9BB-00AA004AE837} /*The Internet*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{871C5380-42A0-1069-A2EA-08002B30309D} /*Internet Name Space*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/C:\WINDOWS\system32\extmgr.dll = C:\WINDOWS\system32\extmgr.dll
@{e82a2d71-5b2f-43a0-97b8-81be15854de8} /*ShellLink for Application References*/c:\WINDOWS\system32\dfshim.dll = c:\WINDOWS\system32\dfshim.dll
@{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} /*Shell Icon Handler for Application References*/c:\WINDOWS\system32\dfshim.dll = c:\WINDOWS\system32\dfshim.dll
@{45670FA8-ED97-4F44-BC93-305082590BFB} /*Microsoft.XPS.Shell.Metadata.1*/%SystemRoot%\System32\XPSSHHDR.DLL = %SystemRoot%\System32\XPSSHHDR.DLL
@{44121072-A222-48f2-A58A-6D9AD51EBBE9} /*Microsoft.XPS.Shell.Thumbnail.1*/%SystemRoot%\System32\XPSSHHDR.DLL = %SystemRoot%\System32\XPSSHHDR.DLL
@{07C45BB1-4A8C-4642-A1F5-237E7215FF66} /*IE Microsoft BrowserBand*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{1C1EDB47-CE22-4bbb-B608-77B48F83C823} /*IE Fade Task*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{205D7A97-F16D-4691-86EF-F3075DCCA57D} /*IE Menu Desk Bar*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3028902F-6374-48b2-8DC6-9725E775B926} /*IE AutoComplete*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{43886CD5-6529-41c4-A707-7B3C92C05E68} /*IE Navigation Bar*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{44C76ECD-F7FA-411c-9929-1B77BA77F524} /*IE Menu Site*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{4B78D326-D922-44f9-AF2A-07805C2A3560} /*IE Menu Band*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6038EF75-ABFC-4e59-AB6F-12D397F6568D} /*IE Microsoft History AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE} /*IE Tracking Shell Menu*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6CF48EF8-44CD-45d2-8832-A16EA016311B} /*IE IShellFolderBand*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{73CFD649-CD48-4fd8-A272-2070EA56526B} /*IE BandProxy*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8} /*IE MRU AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E} /*IE RSS Feeder Folder*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{9D958C62-3954-4b44-8FAB-C4670C1DB4C2} /*IE Microsoft Shell Folder AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{B31C5FAE-961F-415b-BAF0-E697A5178B94} /*IE Microsoft Multiple AutoComplete List Container*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{BC476F4C-D9D7-4100-8D4E-E043F6DEC409} /*Microsoft Browser Architecture*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A} /*IE Shell Rebar BandSite*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{E6EE9AAC-F76B-4947-8260-A9F136138E11} /*IE Shell Band Site Menu*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{F2CF5485-4E02-4f68-819C-B92DE9277049} /*&Links*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E} /*IE Registry Tree Options Utility*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} /*IE User Assist*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FDE7673D-2E19-4145-8376-BBD58C4BC7BA} /*IE Custom MRU AutoCompleted List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{C539A15A-3AF9-4c92-B771-50CB78F5C751} /*Acronis True Image Shell Context Menu Extension*/C:\Program Files\Acronis\TrueImageHome\tishell.dll = C:\Program Files\Acronis\TrueImageHome\tishell.dll
@{C539A15B-3AF9-4c92-B771-50CB78F5C751} /*Acronis True Image Shell Extension*/C:\Program Files\Acronis\TrueImageHome\tishell.dll = C:\Program Files\Acronis\TrueImageHome\tishell.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Web Folders*/C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{00020D75-0000-0000-C000-000000000046} /*Microsoft Office Outlook Desktop Icon Handler*/C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL = C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL
@{0006F045-0000-0000-C000-000000000046} /*Microsoft Office Outlook Custom Icon Handler*/C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL = C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Program Files\Microsoft Office\OFFICE11\msohev.dll = C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
@{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} /*Adobe.Acrobat.ContextMenu*/C:\Program Files\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.dll = C:\Program Files\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.dll
@{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} /*DropboxExt*/C:\Program Files\Dropbox\DropboxExt.dll = C:\Program Files\Dropbox\DropboxExt.dll
@{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} /*DropboxExt*/C:\Program Files\Dropbox\DropboxExt.dll = C:\Program Files\Dropbox\DropboxExt.dll
@{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} /*DropboxExt*/C:\Program Files\Dropbox\DropboxExt.dll = C:\Program Files\Dropbox\DropboxExt.dll
@{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} /*Microsoft Office Metadata Handler*/C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll = C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
@{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} /*Microsoft Office Thumbnail Handler*/C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll = C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
@{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} /*OpenOffice.org Column Handler*/"C:\Program Files\OpenOffice.org 2.4\program\shlxthdl.dll" = "C:\Program Files\OpenOffice.org 2.4\program\shlxthdl.dll"
@{087B3AE3-E237-4467-B8DB-5A38AB959AC9} /*OpenOffice.org Infotip Handler*/"C:\Program Files\OpenOffice.org 2.4\program\shlxthdl.dll" = "C:\Program Files\OpenOffice.org 2.4\program\shlxthdl.dll"
@{63542C48-9552-494A-84F7-73AA6A7C99C1} /*OpenOffice.org Property Sheet Handler*/"C:\Program Files\OpenOffice.org 2.4\program\shlxthdl.dll" = "C:\Program Files\OpenOffice.org 2.4\program\shlxthdl.dll"
@{3B092F0C-7696-40E3-A80F-68D74DA84210} /*OpenOffice.org Thumbnail Viewer*/"C:\Program Files\OpenOffice.org 2.4\program\shlxthdl.dll" = "C:\Program Files\OpenOffice.org 2.4\program\shlxthdl.dll"
@{35786D3C-B075-49b9-88DD-029876E11C01} /*Portable Devices*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} /*Portable Devices Menu*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/C:\Program Files\WinRAR\rarext.dll = C:\Program Files\WinRAR\rarext.dll
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
Adobe.Acrobat.ContextMenu@{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} = C:\Program Files\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.dll
DropboxExt@{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} = C:\Program Files\Dropbox\DropboxExt.dll
McCtxMenu@{01576F39-90DE-4D6E-A068-5B20C22BAAEE} = c:\PROGRA~1\mcafee\VIRUSS~1\mcctxmnu.dll
PowerISO@{967B2D40-8B7D-4127-9049-61EA0C2C6DCE} =
RXDCExtSvr@{70D0238E-E029-4a94-B68D-182018B6C4FF} = C:\Program Files\Roxio\Virtual Drive 10\DC_ShellExt.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll
HKLM\Software\Classes\*\shellex\ContextMenuHandlers@{C539A15A-3AF9-4c92-B771-50CB78F5C751} = C:\Program Files\Acronis\TrueImageHome\tishell.dll
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
DropboxExt@{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} = C:\Program Files\Dropbox\DropboxExt.dll
PowerISO@{967B2D40-8B7D-4127-9049-61EA0C2C6DCE} =
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
Adobe.Acrobat.ContextMenu@{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} = C:\Program Files\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.dll
McCtxMenu@{01576F39-90DE-4D6E-A068-5B20C22BAAEE} = c:\PROGRA~1\mcafee\VIRUSS~1\mcctxmnu.dll
PowerISO@{967B2D40-8B7D-4127-9049-61EA0C2C6DCE} =
RXDCExtSvr@{70D0238E-E029-4a94-B68D-182018B6C4FF} = C:\Program Files\Roxio\Virtual Drive 10\DC_ShellExt.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers@{C539A15A-3AF9-4c92-B771-50CB78F5C751} = C:\Program Files\Acronis\TrueImageHome\tishell.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{0c2dd263-42c8-4b2f-aa2d-142c1c37544a}C:\WINDOWS\system32\jihakera.dll /*file not found*/ = C:\WINDOWS\system32\jihakera.dll /*file not found*/
@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}C:\Program Files\Java\jre6\bin\ssv.dll = C:\Program Files\Java\jre6\bin\ssv.dll
@{AA58ED58-01DD-4d91-8333-CF10577473F7}C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll = C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
@{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll = C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
@{DBC80044-A445-435b-BC74-9C25C1C588A9}C:\Program Files\Java\jre6\bin\jp2ssv.dll = C:\Program Files\Java\jre6\bin\jp2ssv.dll
HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://go.microsoft.com/fwlink/?LinkId=69157 = http://go.microsoft.com/fwlink/?LinkId=69157
@Start Pagehttp://go.microsoft.com/fwlink/?LinkId=69157 = http://go.microsoft.com/fwlink/?LinkId=69157
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://go.microsoft.com/fwlink/?LinkId=69157 = http://go.microsoft.com/fwlink/?LinkId=69157
@Local PageC:\WINDOWS\system32\blank.htm = C:\WINDOWS\system32\blank.htm
HKLM\Software\Classes\PROTOCOLS\Filter\text/xml@CLSID = C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
its@CLSID = C:\WINDOWS\system32\itss.dll
mhtml@CLSID = %SystemRoot%\system32\inetcomm.dll
ms-its@CLSID = C:\WINDOWS\system32\itss.dll
ms-itss@CLSID = C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
mso-offdap@CLSID = C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
mso-offdap11@CLSID = C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
wia@CLSID = C:\WINDOWS\system32\wiascr.dll
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{323C3A17-922C-46E8-88A9-03FCDA1701BC} /*VMware Network Adapter VMnet1*/ >>>
@IPAddress192.168.139.1 = 192.168.139.1
@NameServer =
@DefaultGateway =
@Domain =
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8CCD0759-B683-4A0D-85F0-7E6826F82AA1} /*VMware Network Adapter VMnet8*/ >>>
@IPAddress192.168.190.1 = 192.168.190.1
@NameServer =
@DefaultGateway =
@Domain =
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004@LibraryPath = C:\Program Files\Bonjour\mdnsNSP.dll
—- EOF - GMER 1.0.14 —-