GMER 1.0.12.11889 -
http://www.gmer.netRootkit scan 2006-11-25 20:02:02
Windows 5.1.2600 Service Pack 2
---- User code sections - GMER 1.0.12 ----
.text C:\Acer\eManager\anbmServ.exe[172] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 01621EC1
.text C:\Acer\eManager\anbmServ.exe[172] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 01621C62
.text C:\Acer\eManager\anbmServ.exe[172] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 01621A0B
.text C:\Acer\eManager\anbmServ.exe[172] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0162191B
.text C:\Acer\eManager\anbmServ.exe[172] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 01622C34
.text C:\Acer\eManager\anbmServ.exe[172] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 01622BA6
.text C:\Acer\eManager\anbmServ.exe[172] advapi32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 01622DA7
.text C:\Acer\eManager\anbmServ.exe[172] advapi32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 01622D16
.text C:\program files\mcafee.com\agent\mcdetect.exe[260] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 10001EC1
.text C:\program files\mcafee.com\agent\mcdetect.exe[260] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001C62
.text C:\program files\mcafee.com\agent\mcdetect.exe[260] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001A0B
.text C:\program files\mcafee.com\agent\mcdetect.exe[260] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\program files\mcafee.com\agent\mcdetect.exe[260] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10002C34
.text C:\program files\mcafee.com\agent\mcdetect.exe[260] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 10002BA6
.text C:\program files\mcafee.com\agent\mcdetect.exe[260] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 10002DA7
.text C:\program files\mcafee.com\agent\mcdetect.exe[260] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 10002D16
.text C:\PROGRA~1\mcafee.com\vso\mcshield.exe[292] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 01B61EC1
.text C:\PROGRA~1\mcafee.com\vso\mcshield.exe[292] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 01B61C62
.text C:\PROGRA~1\mcafee.com\vso\mcshield.exe[292] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 01B61A0B
.text C:\PROGRA~1\mcafee.com\vso\mcshield.exe[292] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 01B6191B
.text C:\PROGRA~1\mcafee.com\vso\mcshield.exe[292] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 01B62C34
.text C:\PROGRA~1\mcafee.com\vso\mcshield.exe[292] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 01B62BA6
.text C:\PROGRA~1\mcafee.com\vso\mcshield.exe[292] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 01B62DA7
.text C:\PROGRA~1\mcafee.com\vso\mcshield.exe[292] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 01B62D16
.text C:\PROGRA~1\mcafee.com\agent\mctskshd.exe[336] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 10001EC1
.text C:\PROGRA~1\mcafee.com\agent\mctskshd.exe[336] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001C62
.text C:\PROGRA~1\mcafee.com\agent\mctskshd.exe[336] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001A0B
.text C:\PROGRA~1\mcafee.com\agent\mctskshd.exe[336] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\PROGRA~1\mcafee.com\agent\mctskshd.exe[336] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10002C34
.text C:\PROGRA~1\mcafee.com\agent\mctskshd.exe[336] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 10002BA6
.text C:\PROGRA~1\mcafee.com\agent\mctskshd.exe[336] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 10002DA7
.text C:\PROGRA~1\mcafee.com\agent\mctskshd.exe[336] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 10002D16
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[368] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 10001EC1
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[368] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001C62
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[368] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001A0B
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[368] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[368] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10002C34
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[368] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 10002BA6
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[368] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 10002DA7
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[368] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 10002D16
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe[460] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 006D1EC1
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe[460] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 006D1C62
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe[460] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 006D1A0B
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe[460] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 006D191B
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe[460] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 006D2C34
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe[460] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 006D2BA6
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe[460] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 006D2DA7
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe[460] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 006D2D16
.text C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe[476] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 10001EC1
.text C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe[476] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001C62
.text C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe[476] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001A0B
.text C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe[476] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe[476] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10002C34
.text C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe[476] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 10002BA6
.text C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe[476] advapi32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 10002DA7
.text C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe[476] advapi32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 10002D16
.text C:\WINDOWS\system32\winlogon.exe[508] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 10001EC1
.text C:\WINDOWS\system32\winlogon.exe[508] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001C62
.text C:\WINDOWS\system32\winlogon.exe[508] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001A0B
.text C:\WINDOWS\system32\winlogon.exe[508] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\winlogon.exe[508] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10002C34
.text C:\WINDOWS\system32\winlogon.exe[508] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 10002BA6
.text C:\WINDOWS\system32\winlogon.exe[508] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 10002DA7
.text C:\WINDOWS\system32\winlogon.exe[508] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 10002D16
.text C:\WINDOWS\system32\services.exe[552] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 10001EC1
.text C:\WINDOWS\system32\services.exe[552] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001C62
.text C:\WINDOWS\system32\services.exe[552] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001A0B
.text C:\WINDOWS\system32\services.exe[552] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\services.exe[552] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10002C34
.text C:\WINDOWS\system32\services.exe[552] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 10002BA6
.text C:\WINDOWS\system32\services.exe[552] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 10002DA7
.text C:\WINDOWS\system32\services.exe[552] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 10002D16
.text C:\WINDOWS\system32\lsass.exe[564] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 10001EC1
.text C:\WINDOWS\system32\lsass.exe[564] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001C62
.text C:\WINDOWS\system32\lsass.exe[564] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001A0B
.text C:\WINDOWS\system32\lsass.exe[564] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\lsass.exe[564] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10002C34
.text C:\WINDOWS\system32\lsass.exe[564] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 10002BA6
.text C:\WINDOWS\system32\lsass.exe[564] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 10002DA7
.text C:\WINDOWS\system32\lsass.exe[564] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 10002D16
.text C:\WINDOWS\system32\Ati2evxx.exe[716] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 10001EC1
.text C:\WINDOWS\system32\Ati2evxx.exe[716] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001C62
.text C:\WINDOWS\system32\Ati2evxx.exe[716] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001A0B
.text C:\WINDOWS\system32\Ati2evxx.exe[716] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\Ati2evxx.exe[716] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10002C34
.text C:\WINDOWS\system32\Ati2evxx.exe[716] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 10002BA6
.text C:\WINDOWS\system32\Ati2evxx.exe[716] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 10002DA7
.text C:\WINDOWS\system32\Ati2evxx.exe[716] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 10002D16
.text C:\WINDOWS\system32\svchost.exe[728] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 10001EC1
.text C:\WINDOWS\system32\svchost.exe[728] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001C62
.text C:\WINDOWS\system32\svchost.exe[728] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001A0B
.text C:\WINDOWS\system32\svchost.exe[728] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\svchost.exe[728] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10002C34
.text C:\WINDOWS\system32\svchost.exe[728] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 10002BA6
.text C:\WINDOWS\system32\svchost.exe[728] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 10002DA7
.text C:\WINDOWS\system32\svchost.exe[728] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 10002D16
.text C:\WINDOWS\system32\svchost.exe[784] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10002C34
.text C:\WINDOWS\system32\svchost.exe[784] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 10002BA6
.text C:\WINDOWS\system32\svchost.exe[784] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 10002DA7
.text C:\WINDOWS\system32\svchost.exe[784] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 10002D16
.text C:\WINDOWS\system32\svchost.exe[884] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 10001EC1
.text C:\WINDOWS\system32\svchost.exe[884] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001C62
.text C:\WINDOWS\system32\svchost.exe[884] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001A0B
.text C:\WINDOWS\system32\svchost.exe[884] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\svchost.exe[884] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10002C34
.text C:\WINDOWS\system32\svchost.exe[884] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 10002BA6
.text C:\WINDOWS\system32\svchost.exe[884] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 10002DA7
.text C:\WINDOWS\system32\svchost.exe[884] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 10002D16
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10002C34
.text C:\WINDOWS\system32\svchost.exe[984] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 10002BA6
.text C:\WINDOWS\system32\svchost.exe[984] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 10002DA7
.text C:\WINDOWS\system32\svchost.exe[984] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 10002D16
.text C:\WINDOWS\system32\svchost.exe[1020] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10002C34
.text C:\WINDOWS\system32\svchost.exe[1020] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 10002BA6
.text C:\WINDOWS\system32\svchost.exe[1020] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 10002DA7
.text C:\WINDOWS\system32\svchost.exe[1020] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 10002D16
.text C:\WINDOWS\system32\spoolsv.exe[1232] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 10001EC1
.text C:\WINDOWS\system32\spoolsv.exe[1232] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001C62
.text C:\WINDOWS\system32\spoolsv.exe[1232] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001A0B
.text C:\WINDOWS\system32\spoolsv.exe[1232] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\spoolsv.exe[1232] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10002C34
.text C:\WINDOWS\system32\spoolsv.exe[1232] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 10002BA6
.text C:\WINDOWS\system32\spoolsv.exe[1232] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 10002DA7
.text C:\WINDOWS\system32\spoolsv.exe[1232] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 10002D16
.text C:\WINDOWS\Explorer.EXE[1460] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 01141EC1
.text C:\WINDOWS\Explorer.EXE[1460] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 01141C62
.text C:\WINDOWS\Explorer.EXE[1460] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 01141A0B
.text C:\WINDOWS\Explorer.EXE[1460] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0114191B
.text C:\WINDOWS\Explorer.EXE[1460] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 01142C34
.text C:\WINDOWS\Explorer.EXE[1460] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 01142BA6
.text C:\WINDOWS\Explorer.EXE[1460] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 01142DA7
.text C:\WINDOWS\Explorer.EXE[1460] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 01142D16
.text C:\WINDOWS\Explorer.EXE[1460] WS2_32.dll!connect 71AB406A 5 Bytes JMP 01CF3E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\WINDOWS\system32\wdfmgr.exe[1552] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10002C34
.text C:\WINDOWS\system32\wdfmgr.exe[1552] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 10002BA6
.text C:\WINDOWS\system32\wdfmgr.exe[1552] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 10002DA7
.text C:\WINDOWS\system32\wdfmgr.exe[1552] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 10002D16
.text C:\Program Files\McAfee.com\VSO\mcvsshld.exe[1624] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 013B1EC1
.text C:\Program Files\McAfee.com\VSO\mcvsshld.exe[1624] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 013B1C62
.text C:\Program Files\McAfee.com\VSO\mcvsshld.exe[1624] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 013B1A0B
.text C:\Program Files\McAfee.com\VSO\mcvsshld.exe[1624] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 013B191B
.text C:\Program Files\McAfee.com\VSO\mcvsshld.exe[1624] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 013B2C34
.text C:\Program Files\McAfee.com\VSO\mcvsshld.exe[1624] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 013B2BA6
.text C:\Program Files\McAfee.com\VSO\mcvsshld.exe[1624] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 013B2DA7
.text C:\Program Files\McAfee.com\VSO\mcvsshld.exe[1624] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 013B2D16
.text C:\Program Files\McAfee.com\VSO\mcvsshld.exe[1624] WS2_32.dll!connect 71AB406A 3 Bytes JMP 01373E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\Program Files\McAfee.com\VSO\mcvsshld.exe[1624] WS2_32.dll!connect + 4 71AB406E 1 Byte
.text C:\Program Files\McAfee.com\VSO\oasclnt.exe[1632] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00DE1EC1
.text C:\Program Files\McAfee.com\VSO\oasclnt.exe[1632] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00DE1C62
.text C:\Program Files\McAfee.com\VSO\oasclnt.exe[1632] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00DE1A0B
.text C:\Program Files\McAfee.com\VSO\oasclnt.exe[1632] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00DE191B
.text C:\Program Files\McAfee.com\VSO\oasclnt.exe[1632] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00DE2C34
.text C:\Program Files\McAfee.com\VSO\oasclnt.exe[1632] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00DE2BA6
.text C:\Program Files\McAfee.com\VSO\oasclnt.exe[1632] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 00DE2DA7
.text C:\Program Files\McAfee.com\VSO\oasclnt.exe[1632] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 00DE2D16
.text C:\Program Files\McAfee.com\VSO\oasclnt.exe[1632] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00DB3E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\PROGRA~1\mcafee.com\agent\mcagent.exe[1640] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 01171EC1
.text C:\PROGRA~1\mcafee.com\agent\mcagent.exe[1640] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 01171C62
.text C:\PROGRA~1\mcafee.com\agent\mcagent.exe[1640] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 01171A0B
.text C:\PROGRA~1\mcafee.com\agent\mcagent.exe[1640] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0117191B
.text C:\PROGRA~1\mcafee.com\agent\mcagent.exe[1640] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 01172C34
.text C:\PROGRA~1\mcafee.com\agent\mcagent.exe[1640] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 01172BA6
.text C:\PROGRA~1\mcafee.com\agent\mcagent.exe[1640] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 01172DA7
.text C:\PROGRA~1\mcafee.com\agent\mcagent.exe[1640] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 01172D16
.text C:\PROGRA~1\mcafee.com\agent\mcagent.exe[1640] WS2_32.dll!connect 71AB406A 5 Bytes JMP 017D3E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\progra~1\mcafee.com\vso\mcvsescn.exe[1668] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 011E1EC1
.text C:\progra~1\mcafee.com\vso\mcvsescn.exe[1668] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 011E1C62
.text C:\progra~1\mcafee.com\vso\mcvsescn.exe[1668] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 011E1A0B
.text C:\progra~1\mcafee.com\vso\mcvsescn.exe[1668] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 011E191B
.text C:\progra~1\mcafee.com\vso\mcvsescn.exe[1668] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 011E2C34
.text C:\progra~1\mcafee.com\vso\mcvsescn.exe[1668] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 011E2BA6
.text C:\progra~1\mcafee.com\vso\mcvsescn.exe[1668] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 011E2DA7
.text C:\progra~1\mcafee.com\vso\mcvsescn.exe[1668] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 011E2D16
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe[1680] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 01C01EC1
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe[1680] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 01C01C62
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe[1680] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 01C01A0B
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe[1680] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 01C0191B
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe[1680] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 01C02C34
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe[1680] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 01C02BA6
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe[1680] WS2_32.dll!connect 71AB406A 5 Bytes JMP 01C23E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe[1680] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 01C02DA7
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe[1680] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 01C02D16
.text C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe[1688] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 01161EC1
.text C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe[1688] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 01161C62
.text C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe[1688] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 01161A0B
.text C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe[1688] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0116191B
.text C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe[1688] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 01162C34
.text C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe[1688] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 01162BA6
.text C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe[1688] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 01162DA7
.text C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe[1688] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 01162D16
.text C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe[1688] WS2_32.dll!connect 71AB406A 5 Bytes JMP 01113E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\windows\system32\mujdxzspt.exe[1776] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 014F1EC1
.text C:\windows\system32\mujdxzspt.exe[1776] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 014F1C62
.text C:\windows\system32\mujdxzspt.exe[1776] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 014F1A0B
.text C:\windows\system32\mujdxzspt.exe[1776] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 014F191B
.text C:\windows\system32\mujdxzspt.exe[1776] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 014F2C34
.text C:\windows\system32\mujdxzspt.exe[1776] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 014F2BA6
.text C:\windows\system32\mujdxzspt.exe[1776] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 014F2DA7
.text C:\windows\system32\mujdxzspt.exe[1776] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 014F2D16
.text C:\windows\system32\mujdxzspt.exe[1776] WS2_32.dll!connect 71AB406A 5 Bytes JMP 020B3E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\WINDOWS\system32\ctfmon.exe[1792] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00A41EC1
.text C:\WINDOWS\system32\ctfmon.exe[1792] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00A41C62
.text C:\WINDOWS\system32\ctfmon.exe[1792] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00A41A0B
.text C:\WINDOWS\system32\ctfmon.exe[1792] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00A4191B
.text C:\WINDOWS\system32\ctfmon.exe[1792] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00A42C34
.text C:\WINDOWS\system32\ctfmon.exe[1792] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00A42BA6
.text C:\WINDOWS\system32\ctfmon.exe[1792] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 00A42DA7
.text C:\WINDOWS\system32\ctfmon.exe[1792] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 00A42D16
.text C:\WINDOWS\system32\ctfmon.exe[1792] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00A13E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\Program Files\Messenger\msmsgs.exe[1800] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 00FF1EC1
.text C:\Program Files\Messenger\msmsgs.exe[1800] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 00FF1C62
.text C:\Program Files\Messenger\msmsgs.exe[1800] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00FF1A0B
.text C:\Program Files\Messenger\msmsgs.exe[1800] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 00FF191B
.text C:\Program Files\Messenger\msmsgs.exe[1800] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00FF2C34
.text C:\Program Files\Messenger\msmsgs.exe[1800] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00FF2BA6
.text C:\Program Files\Messenger\msmsgs.exe[1800] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 00FF2DA7
.text C:\Program Files\Messenger\msmsgs.exe[1800] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 00FF2D16
.text C:\Program Files\Messenger\msmsgs.exe[1800] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00CA3E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\WINDOWS\system32\svchost.exe[1908] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 10001EC1
.text C:\WINDOWS\system32\svchost.exe[1908] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001C62
.text C:\WINDOWS\system32\svchost.exe[1908] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001A0B
.text C:\WINDOWS\system32\svchost.exe[1908] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\WINDOWS\system32\svchost.exe[1908] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10002C34
.text C:\WINDOWS\system32\svchost.exe[1908] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 10002BA6
.text C:\WINDOWS\system32\svchost.exe[1908] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 10002DA7
.text C:\WINDOWS\system32\svchost.exe[1908] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 10002D16
.text C:\progra~1\mcafee.com\vso\mcvsftsn.exe[1916] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 01921EC1
.text C:\progra~1\mcafee.com\vso\mcvsftsn.exe[1916] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 01921C62
.text C:\progra~1\mcafee.com\vso\mcvsftsn.exe[1916] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 01921A0B
.text C:\progra~1\mcafee.com\vso\mcvsftsn.exe[1916] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 0192191B
.text C:\progra~1\mcafee.com\vso\mcvsftsn.exe[1916] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 01922C34
.text C:\progra~1\mcafee.com\vso\mcvsftsn.exe[1916] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 01922BA6
.text C:\progra~1\mcafee.com\vso\mcvsftsn.exe[1916] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 01922DA7
.text C:\progra~1\mcafee.com\vso\mcvsftsn.exe[1916] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 01922D16
.text C:\progra~1\mcafee.com\vso\mcvsftsn.exe[1916] WS2_32.dll!connect 71AB406A 5 Bytes JMP 017F3E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\Documents and Settings\becca\Desktop\tools\gmer\gmer.exe[2276] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 10001EC1
.text C:\Documents and Settings\becca\Desktop\tools\gmer\gmer.exe[2276] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001C62
.text C:\Documents and Settings\becca\Desktop\tools\gmer\gmer.exe[2276] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001A0B
.text C:\Documents and Settings\becca\Desktop\tools\gmer\gmer.exe[2276] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Documents and Settings\becca\Desktop\tools\gmer\gmer.exe[2276] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10002C34
.text C:\Documents and Settings\becca\Desktop\tools\gmer\gmer.exe[2276] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 10002BA6
.text C:\Documents and Settings\becca\Desktop\tools\gmer\gmer.exe[2276] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 10002DA7
.text C:\Documents and Settings\becca\Desktop\tools\gmer\gmer.exe[2276] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 10002D16
.text C:\Documents and Settings\becca\Desktop\tools\gmer\gmer.exe[2276] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00EB3E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\WINDOWS\System32\alg.exe[2892] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10002C34
.text C:\WINDOWS\System32\alg.exe[2892] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 10002BA6
.text C:\WINDOWS\System32\alg.exe[2892] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 10002DA7
.text C:\WINDOWS\System32\alg.exe[2892] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 10002D16
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe[2968] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 10001EC1
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe[2968] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001C62
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe[2968] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001A0B
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe[2968] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe[2968] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10002C34
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe[2968] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 10002BA6
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe[2968] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 10002DA7
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe[2968] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 10002D16
.text C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe[2968] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00EF3E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\Program Files\MSN Messenger\MSNMSGR.EXE[3584] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 10001EC1
.text C:\Program Files\MSN Messenger\MSNMSGR.EXE[3584] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001C62
.text C:\Program Files\MSN Messenger\MSNMSGR.EXE[3584] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001A0B
.text C:\Program Files\MSN Messenger\MSNMSGR.EXE[3584] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Program Files\MSN Messenger\MSNMSGR.EXE[3584] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10002C34
.text C:\Program Files\MSN Messenger\MSNMSGR.EXE[3584] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 10002BA6
.text C:\Program Files\MSN Messenger\MSNMSGR.EXE[3584] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 10002DA7
.text C:\Program Files\MSN Messenger\MSNMSGR.EXE[3584] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 10002D16
.text C:\Program Files\MSN Messenger\MSNMSGR.EXE[3584] WS2_32.dll!connect 71AB406A 5 Bytes JMP 016F3E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[3608] ntdll.dll!NtEnumerateKey 7C90D94C 5 Bytes JMP 10001EC1
.text C:\Program Files\Internet Explorer\iexplore.exe[3608] ntdll.dll!NtEnumerateValueKey 7C90D976 5 Bytes JMP 10001C62
.text C:\Program Files\Internet Explorer\iexplore.exe[3608] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 10001A0B
.text C:\Program Files\Internet Explorer\iexplore.exe[3608] ntdll.dll!NtQuerySystemInformation 7C90E1AA 5 Bytes JMP 1000191B
.text C:\Program Files\Internet Explorer\iexplore.exe[3608] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10002C34
.text C:\Program Files\Internet Explorer\iexplore.exe[3608] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 10002BA6
.text C:\Program Files\Internet Explorer\iexplore.exe[3608] ADVAPI32.dll!CreateProcessAsUserW 77DF7775 5 Bytes JMP 10002DA7
.text C:\Program Files\Internet Explorer\iexplore.exe[3608] ADVAPI32.dll!CreateProcessAsUserA 77E10958 5 Bytes JMP 10002D16
.text C:\Program Files\Internet Explorer\iexplore.exe[3608] WS2_32.dll!connect 71AB406A 5 Bytes JMP 02103E00 c:\progra~1\mcafee.com\vso\McVSSkt.dll
---- Processes - GMER 1.0.12 ----
Process C:\windows\system32\mujdxzspt.exe (*** hidden *** ) 1776
Library C:\windows\system32\mujdxzspt.exe (*** hidden *** ) @ C:\windows\system32\mujdxzspt.exe [1776] 0x00400000
Thanks Dan