GMER 1.0.14.14536 -
http://www.gmer.netRootkit scan 2008-08-16 13:42:31
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.14 ----
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xF58429AA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xF5842A41]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xF5842958]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xF584296C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xF5842A55]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xF5842A81]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xF5842AEF]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xF5842AD9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xF58429EA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xF5842B1B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xF5842A2D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xF5842930]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xF5842944]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xF58429BE]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xF5842B57]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xF5842AC3]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xF5842AAD]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xF5842A6B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xF5842B43]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xF5842B2F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xF5842996]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xF5842982]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xF5842A97]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xF5842A19]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xF5842B05]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xF5842A00]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xF58429D4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess
---- Kernel code sections - GMER 1.0.14 ----
.text ntkrnlpa.exe!ZwYieldExecution 8050189C 7 Bytes JMP F58429D8 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtCreateFile 8056D3CA 2 Bytes JMP F58429AE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtCreateFile + 3 8056D3CD 2 Bytes [ 2D, 75 ]
PAGE ntkrnlpa.exe!NtMapViewOfSection 805A6206 7 Bytes JMP F58429EE \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805A701C 5 Bytes JMP F5842A04 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 805AC78E 7 Bytes JMP F58429C2 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenProcess 805BFE1E 5 Bytes JMP F5842934 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtOpenThread 805C00AA 5 Bytes JMP F5842948 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtSetInformationProcess 805C28DC 5 Bytes JMP F5842986 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805C5ED8 7 Bytes JMP F5842970 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcess 805C5F8E 5 Bytes JMP F584295C \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetContextThread 805C64B0 5 Bytes JMP F584299A \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805C776C 5 Bytes JMP F5842A1D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryValueKey 80616F40 7 Bytes JMP F5842AB1 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRestoreKey 8061728E 5 Bytes JMP F5842B33 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetValueKey 80617546 7 Bytes JMP F5842A9B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnloadKey 8061780E 7 Bytes JMP F5842B09 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryMultipleValueKey 80618054 7 Bytes JMP F5842AC7 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRenameKey 806188AC 7 Bytes JMP F5842A6F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateKey 80618E86 5 Bytes JMP F5842A45 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteKey 80619316 7 Bytes JMP F5842A59 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteValueKey 806194E6 7 Bytes JMP F5842A85 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateKey 806196C6 7 Bytes JMP F5842AF3 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateValueKey 80619930 7 Bytes JMP F5842ADD \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwOpenKey 8061A21C 5 Bytes JMP F5842A31 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwQueryKey 8061A540 7 Bytes JMP F5842B5B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwReplaceKey 8061AA66 5 Bytes JMP F5842B47 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwNotifyChangeKey 8061AB80 5 Bytes JMP F5842B1F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
---- User code sections - GMER 1.0.14 ----
.text C:\WINDOWS\system32\services.exe[552] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 01160000
.text C:\WINDOWS\system32\services.exe[552] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 01160F9E
.text C:\WINDOWS\system32\services.exe[552] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 01160FAF
.text C:\WINDOWS\system32\services.exe[552] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 01160089
.text C:\WINDOWS\system32\services.exe[552] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 0116006C
.text C:\WINDOWS\system32\services.exe[552] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 01160047
.text C:\WINDOWS\system32\services.exe[552] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 01160F5C
.text C:\WINDOWS\system32\services.exe[552] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 011600AE
.text C:\WINDOWS\system32\services.exe[552] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 01160F29
.text C:\WINDOWS\system32\services.exe[552] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 01160F3A
.text C:\WINDOWS\system32\services.exe[552] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 011600DD
.text C:\WINDOWS\system32\services.exe[552] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 01160FCA
.text C:\WINDOWS\system32\services.exe[552] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 0116001B
.text C:\WINDOWS\system32\services.exe[552] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 01160F8D
.text C:\WINDOWS\system32\services.exe[552] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 01160036
.text C:\WINDOWS\system32\services.exe[552] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 01160FE5
.text C:\WINDOWS\system32\services.exe[552] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 01160F4B
.text C:\WINDOWS\system32\services.exe[552] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00980FB9
.text C:\WINDOWS\system32\services.exe[552] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00980F72
.text C:\WINDOWS\system32\services.exe[552] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00980FCA
.text C:\WINDOWS\system32\services.exe[552] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00980000
.text C:\WINDOWS\system32\services.exe[552] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00980F8D
.text C:\WINDOWS\system32\services.exe[552] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00980025
.text C:\WINDOWS\system32\services.exe[552] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00980FEF
.text C:\WINDOWS\system32\services.exe[552] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00980FA8
.text C:\WINDOWS\system32\services.exe[552] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00950000
.text C:\WINDOWS\system32\lsass.exe[564] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00C70000
.text C:\WINDOWS\system32\lsass.exe[564] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00C70F4B
.text C:\WINDOWS\system32\lsass.exe[564] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00C70F5C
.text C:\WINDOWS\system32\lsass.exe[564] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00C70040
.text C:\WINDOWS\system32\lsass.exe[564] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00C70F83
.text C:\WINDOWS\system32\lsass.exe[564] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00C70FAF
.text C:\WINDOWS\system32\lsass.exe[564] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00C70F09
.text C:\WINDOWS\system32\lsass.exe[564] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00C70F24
.text C:\WINDOWS\system32\lsass.exe[564] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00C70080
.text C:\WINDOWS\system32\lsass.exe[564] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00C70EDD
.text C:\WINDOWS\system32\lsass.exe[564] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00C70091
.text C:\WINDOWS\system32\lsass.exe[564] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00C70F94
.text C:\WINDOWS\system32\lsass.exe[564] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00C70FE5
.text C:\WINDOWS\system32\lsass.exe[564] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00C70051
.text C:\WINDOWS\system32\lsass.exe[564] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00C70FC0
.text C:\WINDOWS\system32\lsass.exe[564] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00C7001B
.text C:\WINDOWS\system32\lsass.exe[564] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00C70EF8
.text C:\WINDOWS\system32\lsass.exe[564] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00C60FCD
.text C:\WINDOWS\system32\lsass.exe[564] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00C60054
.text C:\WINDOWS\system32\lsass.exe[564] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00C60FDE
.text C:\WINDOWS\system32\lsass.exe[564] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00C60FEF
.text C:\WINDOWS\system32\lsass.exe[564] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00C60FA1
.text C:\WINDOWS\system32\lsass.exe[564] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00C60043
.text C:\WINDOWS\system32\lsass.exe[564] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00C60000
.text C:\WINDOWS\system32\lsass.exe[564] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00C60FB2
.text C:\WINDOWS\system32\lsass.exe[564] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00C40000
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[680] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 0041C340 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe[680] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 0041C3C0 c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe (McAfee Proxy Service Module/McAfee, Inc.)
.text C:\WINDOWS\system32\svchost.exe[720] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00AF0000
.text C:\WINDOWS\system32\svchost.exe[720] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00AF0F97
.text C:\WINDOWS\system32\svchost.exe[720] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00AF008C
.text C:\WINDOWS\system32\svchost.exe[720] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00AF0071
.text C:\WINDOWS\system32\svchost.exe[720] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00AF004A
.text C:\WINDOWS\system32\svchost.exe[720] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00AF002F
.text C:\WINDOWS\system32\svchost.exe[720] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00AF0F72
.text C:\WINDOWS\system32\svchost.exe[720] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00AF00C4
.text C:\WINDOWS\system32\svchost.exe[720] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00AF00F0
.text C:\WINDOWS\system32\svchost.exe[720] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00AF00DF
.text C:\WINDOWS\system32\svchost.exe[720] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00AF010B
.text C:\WINDOWS\system32\svchost.exe[720] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00AF0FA8
.text C:\WINDOWS\system32\svchost.exe[720] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00AF0FDB
.text C:\WINDOWS\system32\svchost.exe[720] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00AF00A7
.text C:\WINDOWS\system32\svchost.exe[720] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00AF0FB9
.text C:\WINDOWS\system32\svchost.exe[720] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00AF0FCA
.text C:\WINDOWS\system32\svchost.exe[720] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00AF0F61
.text C:\WINDOWS\system32\svchost.exe[720] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00AE001B
.text C:\WINDOWS\system32\svchost.exe[720] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00AE0F9B
.text C:\WINDOWS\system32\svchost.exe[720] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00AE0FD4
.text C:\WINDOWS\system32\svchost.exe[720] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00AE000A
.text C:\WINDOWS\system32\svchost.exe[720] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00AE004E
.text C:\WINDOWS\system32\svchost.exe[720] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00AE003D
.text C:\WINDOWS\system32\svchost.exe[720] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00AE0FEF
.text C:\WINDOWS\system32\svchost.exe[720] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00AE002C
.text C:\WINDOWS\system32\svchost.exe[720] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00AA000A
.text C:\WINDOWS\system32\svchost.exe[768] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00CE0FE5
.text C:\WINDOWS\system32\svchost.exe[768] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00CE0064
.text C:\WINDOWS\system32\svchost.exe[768] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00CE0049
.text C:\WINDOWS\system32\svchost.exe[768] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00CE0038
.text C:\WINDOWS\system32\svchost.exe[768] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00CE0F6F
.text C:\WINDOWS\system32\svchost.exe[768] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00CE0F94
.text C:\WINDOWS\system32\svchost.exe[768] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00CE007F
.text C:\WINDOWS\system32\svchost.exe[768] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00CE0F43
.text C:\WINDOWS\system32\svchost.exe[768] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00CE0F01
.text C:\WINDOWS\system32\svchost.exe[768] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00CE0F12
.text C:\WINDOWS\system32\svchost.exe[768] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00CE00B5
.text C:\WINDOWS\system32\svchost.exe[768] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00CE001B
.text C:\WINDOWS\system32\svchost.exe[768] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00CE0FCA
.text C:\WINDOWS\system32\svchost.exe[768] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00CE0F54
.text C:\WINDOWS\system32\svchost.exe[768] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00CE0FAF
.text C:\WINDOWS\system32\svchost.exe[768] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00CE0000
.text C:\WINDOWS\system32\svchost.exe[768] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00CE0090
.text C:\WINDOWS\system32\svchost.exe[768] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00CD0051
.text C:\WINDOWS\system32\svchost.exe[768] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00CD0F8A
.text C:\WINDOWS\system32\svchost.exe[768] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00CD0040
.text C:\WINDOWS\system32\svchost.exe[768] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00CD0025
.text C:\WINDOWS\system32\svchost.exe[768] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00CD0FA5
.text C:\WINDOWS\system32\svchost.exe[768] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00CD0FC0
.text C:\WINDOWS\system32\svchost.exe[768] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00CD0000
.text C:\WINDOWS\system32\svchost.exe[768] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00CD0FDB
.text C:\WINDOWS\system32\svchost.exe[768] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00CB0FE5
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 01740000
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 01740067
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 01740F7C
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 01740056
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 01740F8D
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 01740FAF
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 01740093
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 01740078
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 01740F30
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 017400BF
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 01740F1F
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 01740F9E
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 01740FEF
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 01740F57
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 01740FCA
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 01740025
.text C:\WINDOWS\System32\svchost.exe[832] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 017400AE
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 011B0FA8
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 011B0F6B
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 011B0FC3
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 011B0FDE
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 011B0F86
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 011B0028
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 011B0FEF
.text C:\WINDOWS\System32\svchost.exe[832] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 011B0F97
.text C:\WINDOWS\System32\svchost.exe[832] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 01190FEF
.text C:\WINDOWS\System32\svchost.exe[832] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 011C0000
.text C:\WINDOWS\System32\svchost.exe[832] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 011C001B
.text C:\WINDOWS\System32\svchost.exe[832] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 011C0FDB
.text C:\WINDOWS\System32\svchost.exe[832] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 011C0036
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 0087000A
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00870089
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00870F94
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00870FAF
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 0087006C
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 0087004A
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00870F57
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00870F68
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00870F10
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00870F2B
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 008700C4
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 0087005B
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 0087001B
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00870F79
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00870FD4
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00870FE5
.text C:\WINDOWS\system32\svchost.exe[888] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00870F46
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00860FB9
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00860F68
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00860FD4
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00860FEF
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00860025
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00860F8D
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 0086000A
.text C:\WINDOWS\system32\svchost.exe[888] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00860FA8
.text C:\WINDOWS\system32\svchost.exe[888] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 007B0000
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00A50FEF
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00A50F6B
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00A50F7C
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00A5004A
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00A50F8D
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00A5001B
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00A50F2E
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00A50F3F
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00A50EF1
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00A50F0C
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00A50ED6
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00A50F9E
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00A5000A
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00A50F50
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00A50FAF
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00A50FD4
.text C:\WINDOWS\system32\svchost.exe[1008] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00A50F1D
.text C:\WINDOWS\system32\svchost.exe[1008] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 007F0036
.text C:\WINDOWS\system32\svchost.exe[1008] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 007F005B
.text C:\WINDOWS\system32\svchost.exe[1008] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 007F0FE5
.text C:\WINDOWS\system32\svchost.exe[1008] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 007F0025
.text C:\WINDOWS\system32\svchost.exe[1008] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 007F0FA8
.text C:\WINDOWS\system32\svchost.exe[1008] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 007F0FB9
.text C:\WINDOWS\system32\svchost.exe[1008] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 007F0000
.text C:\WINDOWS\system32\svchost.exe[1008] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 007F0FD4
.text C:\WINDOWS\system32\svchost.exe[1008] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 007D000A
.text C:\WINDOWS\system32\svchost.exe[1008] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 00800FE5
.text C:\WINDOWS\system32\svchost.exe[1008] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 00800000
.text C:\WINDOWS\system32\svchost.exe[1008] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00800FCA
.text C:\WINDOWS\system32\svchost.exe[1008] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 00800025
.text C:\WINDOWS\Explorer.EXE[1316] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 01E60FE5
.text C:\WINDOWS\Explorer.EXE[1316] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 01E60F5F
.text C:\WINDOWS\Explorer.EXE[1316] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 01E60F70
.text C:\WINDOWS\Explorer.EXE[1316] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 01E60F81
.text C:\WINDOWS\Explorer.EXE[1316] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 01E6004A
.text C:\WINDOWS\Explorer.EXE[1316] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 01E60039
.text C:\WINDOWS\Explorer.EXE[1316] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 01E60083
.text C:\WINDOWS\Explorer.EXE[1316] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 01E60F31
.text C:\WINDOWS\Explorer.EXE[1316] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 01E60094
.text C:\WINDOWS\Explorer.EXE[1316] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 01E60F05
.text C:\WINDOWS\Explorer.EXE[1316] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 01E60EE0
.text C:\WINDOWS\Explorer.EXE[1316] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 01E60FB2
.text C:\WINDOWS\Explorer.EXE[1316] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 01E6000A
.text C:\WINDOWS\Explorer.EXE[1316] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 01E60F4E
.text C:\WINDOWS\Explorer.EXE[1316] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 01E60FC3
.text C:\WINDOWS\Explorer.EXE[1316] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 01E60FD4
.text C:\WINDOWS\Explorer.EXE[1316] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 01E60F16
.text C:\WINDOWS\Explorer.EXE[1316] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 01770036
.text C:\WINDOWS\Explorer.EXE[1316] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 01770F8A
.text C:\WINDOWS\Explorer.EXE[1316] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 01770025
.text C:\WINDOWS\Explorer.EXE[1316] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 01770FEF
.text C:\WINDOWS\Explorer.EXE[1316] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 01770FA5
.text C:\WINDOWS\Explorer.EXE[1316] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 01770047
.text C:\WINDOWS\Explorer.EXE[1316] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 0177000A
.text C:\WINDOWS\Explorer.EXE[1316] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 01770FC0
.text C:\WINDOWS\Explorer.EXE[1316] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 018E0FE5
.text C:\WINDOWS\Explorer.EXE[1316] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 018E000A
.text C:\WINDOWS\Explorer.EXE[1316] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 018E0FCA
.text C:\WINDOWS\Explorer.EXE[1316] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 018E0025
.text C:\WINDOWS\Explorer.EXE[1316] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 01470000
.text C:\Program Files\Messenger\msmsgs.exe[1676] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00E70000
.text C:\Program Files\Messenger\msmsgs.exe[1676] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00E7006C
.text C:\Program Files\Messenger\msmsgs.exe[1676] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00E70F77
.text C:\Program Files\Messenger\msmsgs.exe[1676] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00E70051
.text C:\Program Files\Messenger\msmsgs.exe[1676] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00E70F9E
.text C:\Program Files\Messenger\msmsgs.exe[1676] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00E70036
.text C:\Program Files\Messenger\msmsgs.exe[1676] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 00E70087
.text C:\Program Files\Messenger\msmsgs.exe[1676] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00E70F3F
.text C:\Program Files\Messenger\msmsgs.exe[1676] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 00E70F02
.text C:\Program Files\Messenger\msmsgs.exe[1676] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00E70F13
.text C:\Program Files\Messenger\msmsgs.exe[1676] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00E70EF1
.text C:\Program Files\Messenger\msmsgs.exe[1676] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00E70FAF
.text C:\Program Files\Messenger\msmsgs.exe[1676] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00E7001B
.text C:\Program Files\Messenger\msmsgs.exe[1676] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00E70F5C
.text C:\Program Files\Messenger\msmsgs.exe[1676] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 00E70FCA
.text C:\Program Files\Messenger\msmsgs.exe[1676] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 00E70FE5
.text C:\Program Files\Messenger\msmsgs.exe[1676] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00E70F24
.text C:\Program Files\Messenger\msmsgs.exe[1676] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00E50022
.text C:\Program Files\Messenger\msmsgs.exe[1676] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 00E50047
.text C:\Program Files\Messenger\msmsgs.exe[1676] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00E50011
.text C:\Program Files\Messenger\msmsgs.exe[1676] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00E50FDB
.text C:\Program Files\Messenger\msmsgs.exe[1676] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00E50F8A
.text C:\Program Files\Messenger\msmsgs.exe[1676] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00E50F9B
.text C:\Program Files\Messenger\msmsgs.exe[1676] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00E50000
.text C:\Program Files\Messenger\msmsgs.exe[1676] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00E50FC0
.text C:\Program Files\Messenger\msmsgs.exe[1676] WS2_32.dll!socket 71AB3B91 5 Bytes JMP 00E30000
.text C:\Program Files\Messenger\msmsgs.exe[1676] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 00E60FE5
.text C:\Program Files\Messenger\msmsgs.exe[1676] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 00E60000
.text C:\Program Files\Messenger\msmsgs.exe[1676] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 00E60011
.text C:\Program Files\Messenger\msmsgs.exe[1676] WININET.dll!InternetOpenUrlW 780BAEB9 5 Bytes JMP 00E60022
.text C:\WINDOWS\system32\svchost.exe[2228] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 001A0000
.text C:\WINDOWS\system32\svchost.exe[2228] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 001A0F9C
.text C:\WINDOWS\system32\svchost.exe[2228] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 001A0FB7
.text C:\WINDOWS\system32\svchost.exe[2228] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 001A0FC8
.text C:\WINDOWS\system32\svchost.exe[2228] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 001A0091
.text C:\WINDOWS\system32\svchost.exe[2228] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 001A005B
.text C:\WINDOWS\system32\svchost.exe[2228] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 001A0F5D
.text C:\WINDOWS\system32\svchost.exe[2228] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 001A0F6E
.text C:\WINDOWS\system32\svchost.exe[2228] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 001A0F16
.text C:\WINDOWS\system32\svchost.exe[2228] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 001A0F31
.text C:\WINDOWS\system32\svchost.exe[2228] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 001A00CA
.text C:\WINDOWS\system32\svchost.exe[2228] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 001A0080
.text C:\WINDOWS\system32\svchost.exe[2228] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 001A0025
.text C:\WINDOWS\system32\svchost.exe[2228] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 001A0F8B
.text C:\WINDOWS\system32\svchost.exe[2228] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 001A0FEF
.text C:\WINDOWS\system32\svchost.exe[2228] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 001A0040
.text C:\WINDOWS\system32\svchost.exe[2228] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 001A0F42
.text C:\WINDOWS\system32\svchost.exe[2228] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 0028001B
.text C:\WINDOWS\system32\svchost.exe[2228] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 0028005B
.text C:\WINDOWS\system32\svchost.exe[2228] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00280000
.text C:\WINDOWS\system32\svchost.exe[2228] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00280FD4
.text C:\WINDOWS\system32\svchost.exe[2228] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00280F9E
.text C:\WINDOWS\system32\svchost.exe[2228] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00280FAF
.text C:\WINDOWS\system32\svchost.exe[2228] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00280FE5
.text C:\WINDOWS\system32\svchost.exe[2228] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 0028002C
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] kernel32.dll!CreateFileA 7C801A24 5 Bytes JMP 00260000
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] kernel32.dll!VirtualProtectEx 7C801A5D 5 Bytes JMP 00260073
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] kernel32.dll!VirtualProtect 7C801AD0 5 Bytes JMP 00260062
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] kernel32.dll!LoadLibraryExW 7C801AF1 5 Bytes JMP 00260F94
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] kernel32.dll!LoadLibraryExA 7C801D4F 5 Bytes JMP 00260FA5
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] kernel32.dll!LoadLibraryA 7C801D77 5 Bytes JMP 00260FC0
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] kernel32.dll!GetStartupInfoW 7C801E50 5 Bytes JMP 002600B5
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] kernel32.dll!GetStartupInfoA 7C801EEE 5 Bytes JMP 00260F6D
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 002600E4
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] kernel32.dll!CreateProcessA 7C802367 5 Bytes JMP 00260F41
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] kernel32.dll!GetProcAddress 7C80ADA0 5 Bytes JMP 00260F26
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] kernel32.dll!LoadLibraryW 7C80AE4B 5 Bytes JMP 00260047
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] kernel32.dll!CreateFileW 7C810760 5 Bytes JMP 00260FE5
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] kernel32.dll!CreatePipe 7C81E0C7 5 Bytes JMP 00260098
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] kernel32.dll!CreateNamedPipeW 7C82F0D4 5 Bytes JMP 0026002C
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] kernel32.dll!CreateNamedPipeA 7C85FC74 5 Bytes JMP 0026001B
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] kernel32.dll!WinExec 7C86136D 5 Bytes JMP 00260F52
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] ADVAPI32.dll!RegOpenKeyExW 77DD6A78 5 Bytes JMP 00340FA5
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] ADVAPI32.dll!RegCreateKeyExW 77DD7535 5 Bytes JMP 0034002C
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] ADVAPI32.dll!RegOpenKeyExA 77DD761B 5 Bytes JMP 00340FC0
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] ADVAPI32.dll!RegOpenKeyW 77DD770F 5 Bytes JMP 00340FE5
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] ADVAPI32.dll!RegCreateKeyExA 77DDEAF4 5 Bytes JMP 00340F6F
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] ADVAPI32.dll!RegCreateKeyW 77DF8F7D 5 Bytes JMP 00340011
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] ADVAPI32.dll!RegOpenKeyA 77DFC41B 5 Bytes JMP 00340000
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] ADVAPI32.dll!RegCreateKeyA 77DFD5BB 5 Bytes JMP 00340F94
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] USER32.dll!DialogBoxParamW 7E42555F 5 Bytes JMP 42F0F301 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] USER32.dll!DialogBoxIndirectParamW 7E432032 5 Bytes JMP 430A1667 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] USER32.dll!MessageBoxIndirectA 7E43A04A 5 Bytes JMP 430A15E8 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] USER32.dll!DialogBoxParamA 7E43B10C 5 Bytes JMP 430A162C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] USER32.dll!MessageBoxExW 7E4505D8 5 Bytes JMP 430A1574 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] USER32.dll!MessageBoxExA 7E4505FC 5 Bytes JMP 430A15AE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] USER32.dll!DialogBoxIndirectParamA 7E456B50 5 Bytes JMP 430A16A2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 42F316B6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] WININET.dll!InternetOpenA 7806C865 5 Bytes JMP 01460FEF
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] WININET.dll!InternetOpenW 7806CE99 5 Bytes JMP 01460FCA
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3224] WININET.dll!InternetOpenUrlA 78070BCA 5 Bytes JMP 0146