Thank you very much for your help. I will do as you instruct and will not do anything else on this PC until you resolve my issue. Here is my GMER scan. I am doing Combofix now.
GMER 1.0.15.15077 [meu7xd0k.exe] -
http://www.gmer.netRootkit scan 2009-08-23 19:11:44
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
Code 86D91128 ZwEnumerateKey
Code 863C09F0 ZwFlushInstructionCache
Code 86B9A7DE ZwSaveKey
Code 86AFA23E ZwSaveKeyEx
Code 86AF509E IofCallDriver
Code 86ADCA2E IofCompleteRequest
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!IofCallDriver 804EE130 5 Bytes JMP 86AF50A3
.text ntkrnlpa.exe!IofCompleteRequest 804EE1C0 5 Bytes JMP 86ADCA33
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 805ABEC4 5 Bytes JMP 863C09F4
PAGE ntkrnlpa.exe!ZwEnumerateKey 8061AB70 5 Bytes JMP 86D9112C
PAGE ntkrnlpa.exe!ZwSaveKey 8061BDE4 5 Bytes JMP 86B9A7E2
PAGE ntkrnlpa.exe!ZwSaveKeyEx 8061BECA 5 Bytes JMP 86AFA242
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\iPod\bin\iPodService.exe[260] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00EB2F34
.text C:\Program Files\iPod\bin\iPodService.exe[260] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00EB2EFF
.text C:\Program Files\iPod\bin\iPodService.exe[260] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00EB2C42
.text C:\Program Files\iPod\bin\iPodService.exe[260] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00EB1C5E
.text C:\Program Files\iPod\bin\iPodService.exe[260] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00EB2B78
.text C:\Program Files\iPod\bin\iPodService.exe[260] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00EB1BCD
.text C:\Program Files\iPod\bin\iPodService.exe[260] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00EB1B3C
.text C:\Program Files\iPod\bin\iPodService.exe[260] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00EB2DB4
.text C:\Program Files\iPod\bin\iPodService.exe[260] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00EB2D9A
.text C:\WINDOWS\system32\spoolsv.exe[344] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FA2F34
.text C:\WINDOWS\system32\spoolsv.exe[344] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FA2EFF
.text C:\WINDOWS\system32\spoolsv.exe[344] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00FA2C42
.text C:\WINDOWS\system32\spoolsv.exe[344] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00FA1C5E
.text C:\WINDOWS\system32\spoolsv.exe[344] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00FA2B78
.text C:\WINDOWS\system32\spoolsv.exe[344] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00FA1BCD
.text C:\WINDOWS\system32\spoolsv.exe[344] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00FA1B3C
.text C:\WINDOWS\system32\spoolsv.exe[344] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00FA2DB4
.text C:\WINDOWS\system32\spoolsv.exe[344] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00FA2D9A
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[452] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 013B2F34
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[452] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 013B2EFF
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[452] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 013B2C42
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[452] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 013B1C5E
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[452] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 013B2B78
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[452] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 013B1BCD
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[452] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 013B1B3C
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[452] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 013B2DB4
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[452] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 013B2D9A
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[528] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F32F34
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[528] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F32EFF
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[528] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00F32C42
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[528] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00F31C5E
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[528] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00F32B78
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[528] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00F31BCD
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[528] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00F31B3C
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[528] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00F32DB4
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[528] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00F32D9A
.text C:\WINDOWS\system32\svchost.exe[596] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00A12F34
.text C:\WINDOWS\system32\svchost.exe[596] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00A12EFF
.text C:\WINDOWS\system32\svchost.exe[596] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00A12C42
.text C:\WINDOWS\system32\svchost.exe[596] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00A11C5E
.text C:\WINDOWS\system32\svchost.exe[596] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00A12B78
.text C:\WINDOWS\system32\svchost.exe[596] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00A11BCD
.text C:\WINDOWS\system32\svchost.exe[596] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00A11B3C
.text C:\WINDOWS\system32\svchost.exe[596] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00A12DB4
.text C:\WINDOWS\system32\svchost.exe[596] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00A12D9A
.text D:\My Documents\Downloads\Spyware Removal\meu7xd0k.exe[788] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00152F34
.text D:\My Documents\Downloads\Spyware Removal\meu7xd0k.exe[788] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00152EFF
.text D:\My Documents\Downloads\Spyware Removal\meu7xd0k.exe[788] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00152C42
.text D:\My Documents\Downloads\Spyware Removal\meu7xd0k.exe[788] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00151C5E
.text D:\My Documents\Downloads\Spyware Removal\meu7xd0k.exe[788] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00152B78
.text D:\My Documents\Downloads\Spyware Removal\meu7xd0k.exe[788] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00151BCD
.text D:\My Documents\Downloads\Spyware Removal\meu7xd0k.exe[788] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00151B3C
.text D:\My Documents\Downloads\Spyware Removal\meu7xd0k.exe[788] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00152DB4
.text D:\My Documents\Downloads\Spyware Removal\meu7xd0k.exe[788] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00152D9A
.text C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[828] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00A12F34
.text C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[828] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00A12EFF
.text C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[828] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00A12C42
.text C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[828] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00A11C5E
.text C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[828] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00A12B78
.text C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[828] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00A11BCD
.text C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[828] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00A11B3C
.text C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[828] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00A12DB4
.text C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[828] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00A12D9A
.text C:\WINDOWS\System32\TPHDEXLG.EXE[880] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D12F34
.text C:\WINDOWS\System32\TPHDEXLG.EXE[880] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D12EFF
.text C:\WINDOWS\System32\TPHDEXLG.EXE[880] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00D12C42
.text C:\WINDOWS\System32\TPHDEXLG.EXE[880] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00D11C5E
.text C:\WINDOWS\System32\TPHDEXLG.EXE[880] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00D12B78
.text C:\WINDOWS\System32\TPHDEXLG.EXE[880] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00D11BCD
.text C:\WINDOWS\System32\TPHDEXLG.EXE[880] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00D11B3C
.text C:\WINDOWS\System32\TPHDEXLG.EXE[880] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00D12DB4
.text C:\WINDOWS\System32\TPHDEXLG.EXE[880] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00D12D9A
.text C:\WINDOWS\system32\winlogon.exe[912] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01352F34
.text C:\WINDOWS\system32\winlogon.exe[912] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01352EFF
.text C:\WINDOWS\system32\winlogon.exe[912] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 01352C42
.text C:\WINDOWS\system32\winlogon.exe[912] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 01351C5E
.text C:\WINDOWS\system32\winlogon.exe[912] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 01352B78
.text C:\WINDOWS\system32\winlogon.exe[912] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 01351BCD
.text C:\WINDOWS\system32\winlogon.exe[912] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 01351B3C
.text C:\WINDOWS\system32\winlogon.exe[912] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 01352DB4
.text C:\WINDOWS\system32\winlogon.exe[912] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 01352D9A
.text C:\WINDOWS\system32\services.exe[956] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FD2F34
.text C:\WINDOWS\system32\services.exe[956] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FD2EFF
.text C:\WINDOWS\system32\services.exe[956] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00FD2C42
.text C:\WINDOWS\system32\services.exe[956] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00FD1C5E
.text C:\WINDOWS\system32\services.exe[956] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00FD2B78
.text C:\WINDOWS\system32\services.exe[956] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00FD1BCD
.text C:\WINDOWS\system32\services.exe[956] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00FD1B3C
.text C:\WINDOWS\system32\services.exe[956] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00FD2DB4
.text C:\WINDOWS\system32\services.exe[956] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00FD2D9A
.text C:\WINDOWS\system32\lsass.exe[968] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00CF2F34
.text C:\WINDOWS\system32\lsass.exe[968] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00CF2EFF
.text C:\WINDOWS\system32\lsass.exe[968] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00CF2C42
.text C:\WINDOWS\system32\lsass.exe[968] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00CF1C5E
.text C:\WINDOWS\system32\lsass.exe[968] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00CF2B78
.text C:\WINDOWS\system32\lsass.exe[968] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00CF1BCD
.text C:\WINDOWS\system32\lsass.exe[968] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00CF1B3C
.text C:\WINDOWS\system32\lsass.exe[968] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00CF2DB4
.text C:\WINDOWS\system32\lsass.exe[968] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00CF2D9A
.text C:\WINDOWS\system32\TpKmpSVC.exe[1076] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00B02F34
.text C:\WINDOWS\system32\TpKmpSVC.exe[1076] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00B02EFF
.text C:\WINDOWS\system32\TpKmpSVC.exe[1076] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00B02C42
.text C:\WINDOWS\system32\TpKmpSVC.exe[1076] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00B01C5E
.text C:\WINDOWS\system32\TpKmpSVC.exe[1076] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00B02B78
.text C:\WINDOWS\system32\TpKmpSVC.exe[1076] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00B01BCD
.text C:\WINDOWS\system32\TpKmpSVC.exe[1076] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00B01B3C
.text C:\WINDOWS\system32\TpKmpSVC.exe[1076] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00B02DB4
.text C:\WINDOWS\system32\TpKmpSVC.exe[1076] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00B02D9A
.text C:\WINDOWS\system32\ibmpmsvc.exe[1136] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00972F34
.text C:\WINDOWS\system32\ibmpmsvc.exe[1136] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00972EFF
.text C:\WINDOWS\system32\ibmpmsvc.exe[1136] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00972C42
.text C:\WINDOWS\system32\ibmpmsvc.exe[1136] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00971C5E
.text C:\WINDOWS\system32\ibmpmsvc.exe[1136] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00972B78
.text C:\WINDOWS\system32\ibmpmsvc.exe[1136] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00971BCD
.text C:\WINDOWS\system32\ibmpmsvc.exe[1136] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00971B3C
.text C:\WINDOWS\system32\ibmpmsvc.exe[1136] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00972DB4
.text C:\WINDOWS\system32\ibmpmsvc.exe[1136] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00972D9A
.text C:\WINDOWS\system32\Ati2evxx.exe[1168] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01152F34
.text C:\WINDOWS\system32\Ati2evxx.exe[1168] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01152EFF
.text C:\WINDOWS\system32\Ati2evxx.exe[1168] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 01152C42
.text C:\WINDOWS\system32\Ati2evxx.exe[1168] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 01151C5E
.text C:\WINDOWS\system32\Ati2evxx.exe[1168] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 01152B78
.text C:\WINDOWS\system32\Ati2evxx.exe[1168] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 01151BCD
.text C:\WINDOWS\system32\Ati2evxx.exe[1168] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 01151B3C
.text C:\WINDOWS\system32\Ati2evxx.exe[1168] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 01152DB4
.text C:\WINDOWS\system32\Ati2evxx.exe[1168] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 01152D9A
.text C:\WINDOWS\system32\svchost.exe[1184] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C62F34
.text C:\WINDOWS\system32\svchost.exe[1184] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C62EFF
.text C:\WINDOWS\system32\svchost.exe[1184] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00C62C42
.text C:\WINDOWS\system32\svchost.exe[1184] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00C61C5E
.text C:\WINDOWS\system32\svchost.exe[1184] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00C62B78
.text C:\WINDOWS\system32\svchost.exe[1184] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00C61BCD
.text C:\WINDOWS\system32\svchost.exe[1184] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00C61B3C
.text C:\WINDOWS\system32\svchost.exe[1184] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00C62DB4
.text C:\WINDOWS\system32\svchost.exe[1184] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00C62D9A
.text C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe[1240] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C82F34
.text C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe[1240] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C82EFF
.text C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe[1240] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00C82C42
.text C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe[1240] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00C81C5E
.text C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe[1240] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00C82B78
.text C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe[1240] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00C81BCD
.text C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe[1240] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00C81B3C
.text C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe[1240] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00C82DB4
.text C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe[1240] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00C82D9A
.text C:\WINDOWS\system32\wdfmgr.exe[1292] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 005C2F34
.text C:\WINDOWS\system32\wdfmgr.exe[1292] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 005C2EFF
.text C:\WINDOWS\system32\wdfmgr.exe[1292] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 005C2C42
.text C:\WINDOWS\system32\wdfmgr.exe[1292] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 005C1C5E
.text C:\WINDOWS\system32\wdfmgr.exe[1292] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 005C2B78
.text C:\WINDOWS\system32\wdfmgr.exe[1292] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 005C1BCD
.text C:\WINDOWS\system32\wdfmgr.exe[1292] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 005C1B3C
.text C:\WINDOWS\system32\wdfmgr.exe[1292] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 005C2DB4
.text C:\WINDOWS\system32\wdfmgr.exe[1292] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 005C2D9A
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00DC2F34
.text C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00DC2EFF
.text C:\WINDOWS\system32\svchost.exe[1304] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00DC2C42
.text C:\WINDOWS\system32\svchost.exe[1304] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00DC1C5E
.text C:\WINDOWS\system32\svchost.exe[1304] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00DC2B78
.text C:\WINDOWS\system32\svchost.exe[1304] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00DC1BCD
.text C:\WINDOWS\system32\svchost.exe[1304] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00DC1B3C
.text C:\WINDOWS\system32\svchost.exe[1304] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00DC2DB4
.text C:\WINDOWS\system32\svchost.exe[1304] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00DC2D9A
.text C:\WINDOWS\System32\svchost.exe[1352] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 05232F34
.text C:\WINDOWS\System32\svchost.exe[1352] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 05232EFF
.text C:\WINDOWS\System32\svchost.exe[1352] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 05232C42
.text C:\WINDOWS\System32\svchost.exe[1352] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 05231C5E
.text C:\WINDOWS\System32\svchost.exe[1352] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 05232B78
.text C:\WINDOWS\System32\svchost.exe[1352] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 05231BCD
.text C:\WINDOWS\System32\svchost.exe[1352] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 05231B3C
.text C:\WINDOWS\System32\svchost.exe[1352] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 05232DB4
.text C:\WINDOWS\System32\svchost.exe[1352] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 05232D9A
.text C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe[1396] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01D12F34
.text C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe[1396] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01D12EFF
.text C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe[1396] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 01D12C42
.text C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe[1396] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 01D11C5E
.text C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe[1396] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 01D12B78
.text C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe[1396] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 01D11BCD
.text C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe[1396] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 01D11B3C
.text C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe[1396] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 01D12DB4
.text C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe[1396] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 01D12D9A
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1420] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FE2F34
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1420] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FE2EFF
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1420] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00FE2C42
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1420] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00FE1C5E
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1420] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00FE2B78
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1420] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00FE1BCD
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1420] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00FE1B3C
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1420] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00FE2DB4
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1420] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00FE2D9A
.text C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe[1448] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00992F34
.text C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe[1448] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00992EFF
.text C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe[1448] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00992C42
.text C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe[1448] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00991C5E
.text C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe[1448] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00992B78
.text C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe[1448] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00991BCD
.text C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe[1448] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00991B3C
.text C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe[1448] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00992DB4
.text C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe[1448] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00992D9A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1560] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D52F34
.text C:\Program Files\Bonjour\mDNSResponder.exe[1560] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D52EFF
.text C:\Program Files\Bonjour\mDNSResponder.exe[1560] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00D52C42
.text C:\Program Files\Bonjour\mDNSResponder.exe[1560] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00D51C5E
.text C:\Program Files\Bonjour\mDNSResponder.exe[1560] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00D52B78
.text C:\Program Files\Bonjour\mDNSResponder.exe[1560] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00D51BCD
.text C:\Program Files\Bonjour\mDNSResponder.exe[1560] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00D51B3C
.text C:\Program Files\Bonjour\mDNSResponder.exe[1560] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00D52DB4
.text C:\Program Files\Bonjour\mDNSResponder.exe[1560] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00D52D9A
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1576] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E72F34
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1576] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E72EFF
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1576] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00E72C42
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1576] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00E71C5E
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1576] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00E72B78
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1576] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00E71BCD
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1576] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00E71B3C
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1576] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00E72DB4
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1576] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00E72D9A
.text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1636] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01922F34
.text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1636] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01922EFF
.text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1636] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 01922C42
.text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1636] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 01921C5E
.text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1636] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 01922B78
.text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1636] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 01921BCD
.text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1636] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 01921B3C
.text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1636] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 01922DB4
.text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[1636] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 01922D9A
.text C:\WINDOWS\system32\svchost.exe[1688] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00B12F34
.text C:\WINDOWS\system32\svchost.exe[1688] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00B12EFF
.text C:\WINDOWS\system32\svchost.exe[1688] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00B12C42
.text C:\WINDOWS\system32\svchost.exe[1688] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00B11C5E
.text C:\WINDOWS\system32\svchost.exe[1688] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00B12B78
.text C:\WINDOWS\system32\svchost.exe[1688] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00B11BCD
.text C:\WINDOWS\system32\svchost.exe[1688] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00B11B3C
.text C:\WINDOWS\system32\svchost.exe[1688] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00B12DB4
.text C:\WINDOWS\system32\svchost.exe[1688] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00B12D9A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00802F34
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00802EFF
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00802C42
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00801C5E
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00802B78
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00801BCD
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00801B3C
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00802DB4
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1764] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00802D9A
.text C:\WINDOWS\system32\Ati2evxx.exe[1824] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E62F34
.text C:\WINDOWS\system32\Ati2evxx.exe[1824] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E62EFF
.text C:\WINDOWS\system32\Ati2evxx.exe[1824] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00E62C42
.text C:\WINDOWS\system32\Ati2evxx.exe[1824] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00E61C5E
.text C:\WINDOWS\system32\Ati2evxx.exe[1824] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00E62B78
.text C:\WINDOWS\system32\Ati2evxx.exe[1824] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00E61BCD
.text C:\WINDOWS\system32\Ati2evxx.exe[1824] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00E61B3C
.text C:\WINDOWS\system32\Ati2evxx.exe[1824] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00E62DB4
.text C:\WINDOWS\system32\Ati2evxx.exe[1824] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00E62D9A
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1876] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F32F34
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1876] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F32EFF
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1876] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00F32C42
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1876] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00F31C5E
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1876] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00F32B78
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1876] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00F31BCD
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1876] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00F31B3C
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1876] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00F32DB4
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1876] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00F32D9A
.text C:\WINDOWS\system32\svchost.exe[1920] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E52F34
.text C:\WINDOWS\system32\svchost.exe[1920] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E52EFF
.text C:\WINDOWS\system32\svchost.exe[1920] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00E52C42
.text C:\WINDOWS\system32\svchost.exe[1920] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00E51C5E
.text C:\WINDOWS\system32\svchost.exe[1920] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00E52B78
.text C:\WINDOWS\system32\svchost.exe[1920] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00E51BCD
.text C:\WINDOWS\system32\svchost.exe[1920] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00E51B3C
.text C:\WINDOWS\system32\svchost.exe[1920] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00E52DB4
.text C:\WINDOWS\system32\svchost.exe[1920] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00E52D9A
.text C:\WINDOWS\Explorer.EXE[1976] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00B7000A
.text C:\WINDOWS\Explorer.EXE[1976] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00E02F34
.text C:\WINDOWS\Explorer.EXE[1976] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00E02EFF
.text C:\WINDOWS\Explorer.EXE[1976] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00E02C42
.text C:\WINDOWS\Explorer.EXE[1976] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00E01C5E
.text C:\WINDOWS\Explorer.EXE[1976] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00E02B78
.text C:\WINDOWS\Explorer.EXE[1976] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00E01BCD
.text C:\WINDOWS\Explorer.EXE[1976] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00E01B3C
.text C:\WINDOWS\Explorer.EXE[1976] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00E02DB4
.text C:\WINDOWS\Explorer.EXE[1976] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00E02D9A
.text C:\Program Files\IBM ThinkVantage\Common\Logger\logmon.exe[2724] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00CF2F34
.text C:\Program Files\IBM ThinkVantage\Common\Logger\logmon.exe[2724] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00CF2EFF
.text C:\Program Files\IBM ThinkVantage\Common\Logger\logmon.exe[2724] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00CF2C42
.text C:\Program Files\IBM ThinkVantage\Common\Logger\logmon.exe[2724] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00CF1C5E
.text C:\Program Files\IBM ThinkVantage\Common\Logger\logmon.exe[2724] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00CF2B78
.text C:\Program Files\IBM ThinkVantage\Common\Logger\logmon.exe[2724] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00CF1BCD
.text C:\Program Files\IBM ThinkVantage\Common\Logger\logmon.exe[2724] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00CF1B3C
.text C:\Program Files\IBM ThinkVantage\Common\Logger\logmon.exe[2724] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00CF2DB4
.text C:\Program Files\IBM ThinkVantage\Common\Logger\logmon.exe[2724] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00CF2D9A
.text C:\WINDOWS\system32\rundll32.exe[2928] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00EE2F34
.text C:\WINDOWS\system32\rundll32.exe[2928] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00EE2EFF
.text C:\WINDOWS\system32\rundll32.exe[2928] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00EE2C42
.text C:\WINDOWS\system32\rundll32.exe[2928] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00EE1C5E
.text C:\WINDOWS\system32\rundll32.exe[2928] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00EE2B78
.text C:\WINDOWS\system32\rundll32.exe[2928] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00EE1BCD
.text C:\WINDOWS\system32\rundll32.exe[2928] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00EE1B3C
.text C:\WINDOWS\system32\rundll32.exe[2928] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00EE2DB4
.text C:\WINDOWS\system32\rundll32.exe[2928] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00EE2D9A
.text C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[2936] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01082F34
.text C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[2936] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01082EFF
.text C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[2936] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 01082C42
.text C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[2936] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 01081C5E
.text C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[2936] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 01082B78
.text C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[2936] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 01081BCD
.text C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[2936] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 01081B3C
.text C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[2936] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 01082DB4
.text C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[2936] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 01082D9A
.text C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe[2948] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 003E2F34
.text C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe[2948] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 003E2EFF
.text C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe[2948] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 003E2C42
.text C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe[2948] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 003E1C5E
.text C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe[2948] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 003E2B78
.text C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe[2948] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 003E1BCD
.text C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe[2948] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 003E1B3C
.text C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe[2948] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 003E2DB4
.text C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe[2948] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 003E2D9A
.text C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe[2980] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00DC2F34
.text C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe[2980] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00DC2EFF
.text C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe[2980] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00DC2C42
.text C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe[2980] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00DC1C5E
.text C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe[2980] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00DC2B78
.text C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe[2980] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00DC1BCD
.text C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe[2980] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00DC1B3C
.text C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe[2980] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00DC2DB4
.text C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe[2980] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00DC2D9A
.text C:\WINDOWS\system32\TpShocks.exe[2988] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00B32F34
.text C:\WINDOWS\system32\TpShocks.exe[2988] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00B32EFF
.text C:\WINDOWS\system32\TpShocks.exe[2988] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00B32C42
.text C:\WINDOWS\system32\TpShocks.exe[2988] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00B31C5E
.text C:\WINDOWS\system32\TpShocks.exe[2988] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00B32B78
.text C:\WINDOWS\system32\TpShocks.exe[2988] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00B31BCD
.text C:\WINDOWS\system32\TpShocks.exe[2988] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00B31B3C
.text C:\WINDOWS\system32\TpShocks.exe[2988] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00B32DB4
.text C:\WINDOWS\system32\TpShocks.exe[2988] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00B32D9A
.text C:\WINDOWS\keyacc32.exe[3068] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00C02F34
.text C:\WINDOWS\keyacc32.exe[3068] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00C02EFF
.text C:\WINDOWS\keyacc32.exe[3068] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00C02C42
.text C:\WINDOWS\keyacc32.exe[3068] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00C01C5E
.text C:\WINDOWS\keyacc32.exe[3068] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00C02B78
.text C:\WINDOWS\keyacc32.exe[3068] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00C01BCD
.text C:\WINDOWS\keyacc32.exe[3068] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00C01B3C
.text C:\WINDOWS\keyacc32.exe[3068] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00C02DB4
.text C:\WINDOWS\keyacc32.exe[3068] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00C02D9A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3096] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01592F34
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3096] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01592EFF
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3096] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 01592C42
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3096] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 01591C5E
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3096] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 01592B78
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3096] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 01591BCD
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3096] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 01591B3C
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3096] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 01592DB4
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3096] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 01592D9A
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[3116] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 010A2F34
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[3116] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 010A2EFF
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[3116] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 010A2C42
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[3116] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 010A1C5E
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[3116] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 010A2B78
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[3116] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 010A1BCD
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[3116] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 010A1B3C
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[3116] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 010A2DB4
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[3116] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 010A2D9A
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe[3136] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 009A2F34
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe[3136] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 009A2EFF
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe[3136] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 009A2C42
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe[3136] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 009A1C5E
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe[3136] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 009A2B78
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe[3136] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 009A1BCD
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe[3136] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 009A1B3C
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe[3136] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 009A2DB4
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe[3136] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 009A2D9A
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe[3148] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 009F2F34
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe[3148] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 009F2EFF
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe[3148] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 009F2C42
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe[3148] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 009F1C5E
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe[3148] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 009F2B78
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe[3148] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 009F1BCD
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe[3148] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 009F1B3C
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe[3148] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 009F2DB4
.text C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe[3148] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 009F2D9A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3304] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00972F34
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3304] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00972EFF
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3304] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00972C42
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3304] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00971C5E
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3304] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00972B78
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3304] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00971BCD
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3304] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00971B3C
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3304] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00972DB4
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3304] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00972D9A
.text C:\Program Files\iTunes\iTunesHelper.exe[3340] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02002F34
.text C:\Program Files\iTunes\iTunesHelper.exe[3340] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 02002EFF
.text C:\Program Files\iTunes\iTunesHelper.exe[3340] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 02002C42
.text C:\Program Files\iTunes\iTunesHelper.exe[3340] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 02001C5E
.text C:\Program Files\iTunes\iTunesHelper.exe[3340] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 02002B78
.text C:\Program Files\iTunes\iTunesHelper.exe[3340] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 02001BCD
.text C:\Program Files\iTunes\iTunesHelper.exe[3340] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 02001B3C
.text C:\Program Files\iTunes\iTunesHelper.exe[3340] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 02002DB4
.text C:\Program Files\iTunes\iTunesHelper.exe[3340] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 02002D9A
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3436] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D22F34
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3436] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D22EFF
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3436] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00D22C42
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3436] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00D21C5E
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3436] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00D22B78
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3436] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00D21BCD
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3436] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00D21B3C
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3436] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00D22DB4
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3436] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00D22D9A
.text C:\Program Files\AirPort\APAgent.exe[3660] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F12F34
.text C:\Program Files\AirPort\APAgent.exe[3660] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F12EFF
.text C:\Program Files\AirPort\APAgent.exe[3660] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00F12C42
.text C:\Program Files\AirPort\APAgent.exe[3660] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00F11C5E
.text C:\Program Files\AirPort\APAgent.exe[3660] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00F12B78
.text C:\Program Files\AirPort\APAgent.exe[3660] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00F11BCD
.text C:\Program Files\AirPort\APAgent.exe[3660] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00F11B3C
.text C:\Program Files\AirPort\APAgent.exe[3660] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00F12DB4
.text C:\Program Files\AirPort\APAgent.exe[3660] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00F12D9A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3668] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00D22F34
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3668] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00D22EFF
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3668] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00D22C42
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3668] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00D21C5E
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3668] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00D22B78
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3668] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00D21BCD
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3668] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00D21B3C
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3668] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00D22DB4
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[3668] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00D22D9A
.text D:\Documents and Settings\All Users\Application Data\16838754\16838754.exe[3816] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00032F34
.text D:\Documents and Settings\All Users\Application Data\16838754\16838754.exe[3816] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00032EFF
.text D:\Documents and Settings\All Users\Application Data\16838754\16838754.exe[3816] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00032C42
.text D:\Documents and Settings\All Users\Application Data\16838754\16838754.exe[3816] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00031C5E
.text D:\Documents and Settings\All Users\Application Data\16838754\16838754.exe[3816] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00032B78
.text D:\Documents and Settings\All Users\Application Data\16838754\16838754.exe[3816] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00031BCD
.text D:\Documents and Settings\All Users\Application Data\16838754\16838754.exe[3816] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00031B3C
.text D:\Documents and Settings\All Users\Application Data\16838754\16838754.exe[3816] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00032DB4
.text D:\Documents and Settings\All Users\Application Data\16838754\16838754.exe[3816] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00032D9A
.text C:\WINDOWS\system32\ctfmon.exe[3892] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00AA2F34
.text C:\WINDOWS\system32\ctfmon.exe[3892] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00AA2EFF
.text C:\WINDOWS\system32\ctfmon.exe[3892] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00AA2C42
.text C:\WINDOWS\system32\ctfmon.exe[3892] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00AA1C5E
.text C:\WINDOWS\system32\ctfmon.exe[3892] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00AA2B78
.text C:\WINDOWS\system32\ctfmon.exe[3892] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00AA1BCD
.text C:\WINDOWS\system32\ctfmon.exe[3892] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00AA1B3C
.text C:\WINDOWS\system32\ctfmon.exe[3892] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00AA2DB4
.text C:\WINDOWS\system32\ctfmon.exe[3892] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00AA2D9A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3968] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F72F34
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3968] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F72EFF
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3968] WININET.dll!InternetReadFile 3D94654B 5 Bytes JMP 00F72C42
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3968] WININET.dll!InternetCloseHandle 3D949088 5 Bytes JMP 00F71C5E
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3968] WININET.dll!InternetQueryDataAvailable 3D94BF83 5 Bytes JMP 00F72B78
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3968] WININET.dll!HttpSendRequestW 3D94FABE 5 Bytes JMP 00F71BCD
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3968] WININET.dll!HttpSendRequestA 3D95EE81 5 Bytes JMP 00F71B3C
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3968] WININET.dll!InternetReadFileExW 3D963341 5 Bytes JMP 00F72DB4
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[3968] WININET.dll!InternetReadFileExA 3D963379 5 Bytes JMP 00F72D9A
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisDeregisterProtocol] [F79D47AC] ANCSQ.sys (IBM Rescue and Recovery- ANCSQ/IBM Corp.)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol] [F79D486E] ANCSQ.sys (IBM Rescue and Recovery- ANCSQ/IBM Corp.)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [F79D486E] ANCSQ.sys (IBM Rescue and Recovery- ANCSQ/IBM Corp.)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [F79D47AC] ANCSQ.sys (IBM Rescue and Recovery- ANCSQ/IBM Corp.)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [F79D47AC] ANCSQ.sys (IBM Rescue and Recovery- ANCSQ/IBM Corp.)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [F79D486E] ANCSQ.sys (IBM Rescue and Recovery- ANCSQ/IBM Corp.)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [F79D486E] ANCSQ.sys (IBM Rescue and Recovery- ANCSQ/IBM Corp.)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [F79D47AC] ANCSQ.sys (IBM Rescue and Recovery- ANCSQ/IBM Corp.)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [F79D486E] ANCSQ.sys (IBM Rescue and Recovery- ANCSQ/IBM Corp.)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [F79D47AC] ANCSQ.sys (IBM Rescue and Recovery- ANCSQ/IBM Corp.)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [F79D486E] ANCSQ.sys (IBM Rescue and Recovery- ANCSQ/IBM Corp.)
IAT \SystemRoot\system32\DRIVERS\irda.sys[NDIS.SYS!NdisRegisterProtocol] [F79D486E] ANCSQ.sys (IBM Rescue and Recovery- ANCSQ/IBM Corp.)
IAT \SystemRoot\system32\DRIVERS\irda.sys[NDIS.SYS!NdisDeregisterProtocol] [F79D47AC] ANCSQ.sys (IBM Rescue and Recovery- ANCSQ/IBM Corp.)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [F79D486E] ANCSQ.sys (IBM Rescue and Recovery- ANCSQ/IBM Corp.)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [F79D47AC] ANCSQ.sys (IBM Rescue and Recovery- ANCSQ/IBM Corp.)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 TPInput.sys (ThinkPad SATA Power Management Driver/Lenovo, Ltd. and IBM Corporation.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 TPInput.sys (ThinkPad SATA Power Management Driver/Lenovo, Ltd. and IBM Corporation.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
Device \FileSystem\Fastfat \Fat EE64CD20
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\drivers\kbiwkmoblrsvdy.sys (*** hidden *** ) [SYSTEM] kbiwkmyfwairft <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmyfwairft
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmyfwairft@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmyfwairft@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmyfwairft@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmyfwairft@imagepath \systemroot\system32\drivers\kbiwkmoblrsvdy.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmyfwairft\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmyfwairft\main@aid 10002
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmyfwairft\main@sid 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmyfwairft\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmyfwairft\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmyfwairft\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmyfwairft\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmyfwairft\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmyfwairft\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmyfwairft\
[email protected] \systemroot\system32\drivers\kbiwkmoblrsvdy.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmyfwairft\
[email protected] \systemroot\system32\kbiwkmuruwqjra.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmyfwairft\
[email protected] \systemroot\system32\kbiwkmxepxmybp.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmyfwairft\
[email protected] \systemroot\system32\kbiwkmthqbwghr.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmyfwairft\
[email protected] \systemroot\system32\kbiwkmqjwftypq.dat
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmyfwairft (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmyfwairft@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmyfwairft@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmyfwairft@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmyfwairft@imagepath \systemroot\system32\drivers\kbiwkmoblrsvdy.sys
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmyfwairft\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmyfwairft\main@aid 10002
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmyfwairft\main@sid 1
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmyfwairft\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmyfwairft\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmyfwairft\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmyfwairft\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmyfwairft\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmyfwairft\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmyfwairft\
[email protected] \systemroot\system32\drivers\kbiwkmoblrsvdy.sys
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmyfwairft\
[email protected] \systemroot\system32\kbiwkmuruwqjra.dll
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmyfwairft\
[email protected] \systemroot\system32\kbiwkmxepxmybp.dat
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmyfwairft\
[email protected] \systemroot\system32\kbiwkmthqbwghr.dll
Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmyfwairft\
[email protected] \systemroot\system32\kbiwkmqjwftypq.dat
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmyfwairft (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmyfwairft@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmyfwairft@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmyfwairft@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmyfwairft@imagepath \systemroot\system32\drivers\kbiwkmoblrsvdy.sys
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmyfwairft\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmyfwairft\main@aid 10002
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmyfwairft\main@sid 1
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmyfwairft\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmyfwairft\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmyfwairft\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmyfwairft\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmyfwairft\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmyfwairft\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmyfwairft\
[email protected] \systemroot\system32\drivers\kbiwkmoblrsvdy.sys
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmyfwairft\
[email protected] \systemroot\system32\kbiwkmuruwqjra.dll
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmyfwairft\
[email protected] \systemroot\system32\kbiwkmxepxmybp.dat
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmyfwairft\
[email protected] \systemroot\system32\kbiwkmthqbwghr.dll
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmyfwairft\
[email protected] \systemroot\system32\kbiwkmqjwftypq.dat
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs KATRACK.DLL
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: copy of MBR
---- EOF - GMER 1.0.15 ----