sorry this is the entire gmer log:
GMER 1.0.15.15020 [gamer.exe] -
http://www.gmer.netRootkit scan 2009-08-13 20:11:01
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xBAD0335B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xBAD032DB]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xBAD03385]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xBAD032EF]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xBAD0331B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xBAD033AF]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xBAD032C7]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xBAD0336F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xBAD03305]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xBAD03331]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xBAD03347]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xBAD033C5]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xBAD03399]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwYieldExecution 80504AE8 7 Bytes JMP BAD0339D \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtCreateFile 80579084 5 Bytes JMP BAD0335F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!NtMapViewOfSection 805B2006 7 Bytes JMP BAD033B3 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwUnmapViewOfSection 805B2E14 5 Bytes JMP BAD033C9 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwProtectVirtualMemory 805B83E6 7 Bytes JMP BAD03373 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateProcess 805D11F8 5 Bytes JMP BAD03389 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwTerminateProcess 805D29AA 5 Bytes JMP BAD0334B \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwSetValueKey 80621D36 7 Bytes JMP BAD03335 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwRenameKey 806231D2 7 Bytes JMP BAD03309 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwCreateKey 806237B0 5 Bytes JMP BAD032DF \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteKey 80623C40 7 Bytes JMP BAD032F3 \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwDeleteValueKey 80623E10 7 Bytes JMP BAD0331F \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
PAGE ntkrnlpa.exe!ZwOpenKey 80624B82 5 Bytes JMP BAD032CB \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\Explorer.EXE[328] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00DC0FEF
.text C:\WINDOWS\Explorer.EXE[328] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00DC006A
.text C:\WINDOWS\Explorer.EXE[328] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00DC0F7F
.text C:\WINDOWS\Explorer.EXE[328] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00DC0F90
.text C:\WINDOWS\Explorer.EXE[328] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00DC004D
.text C:\WINDOWS\Explorer.EXE[328] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00DC0032
.text C:\WINDOWS\Explorer.EXE[328] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00DC0F3F
.text C:\WINDOWS\Explorer.EXE[328] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00DC0087
.text C:\WINDOWS\Explorer.EXE[328] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00DC00D8
.text C:\WINDOWS\Explorer.EXE[328] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00DC00BD
.text C:\WINDOWS\Explorer.EXE[328] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00DC00E9
.text C:\WINDOWS\Explorer.EXE[328] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00DC0FAB
.text C:\WINDOWS\Explorer.EXE[328] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00DC0FDE
.text C:\WINDOWS\Explorer.EXE[328] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00DC0F5A
.text C:\WINDOWS\Explorer.EXE[328] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00DC0FBC
.text C:\WINDOWS\Explorer.EXE[328] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00DC0FCD
.text C:\WINDOWS\Explorer.EXE[328] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00DC00A2
.text C:\WINDOWS\Explorer.EXE[328] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00CE0FCA
.text C:\WINDOWS\Explorer.EXE[328] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00CE0062
.text C:\WINDOWS\Explorer.EXE[328] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00CE001B
.text C:\WINDOWS\Explorer.EXE[328] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00CE000A
.text C:\WINDOWS\Explorer.EXE[328] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00CE0051
.text C:\WINDOWS\Explorer.EXE[328] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00CE0FEF
.text C:\WINDOWS\Explorer.EXE[328] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00CE0FAF
.text C:\WINDOWS\Explorer.EXE[328] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [EE, 88]
.text C:\WINDOWS\Explorer.EXE[328] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00CE0036
.text C:\WINDOWS\Explorer.EXE[328] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00CD0FB9
.text C:\WINDOWS\Explorer.EXE[328] msvcrt.dll!system 77C293C7 5 Bytes JMP 00CD0FD4
.text C:\WINDOWS\Explorer.EXE[328] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00CD0FEF
.text C:\WINDOWS\Explorer.EXE[328] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00CD000C
.text C:\WINDOWS\Explorer.EXE[328] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00CD003A
.text C:\WINDOWS\Explorer.EXE[328] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00CD001D
.text C:\WINDOWS\Explorer.EXE[328] WININET.dll!InternetOpenA 3D94C879 5 Bytes JMP 00CB0FEF
.text C:\WINDOWS\Explorer.EXE[328] WININET.dll!InternetOpenW 3D94CEA9 5 Bytes JMP 00CB0FD4
.text C:\WINDOWS\Explorer.EXE[328] WININET.dll!InternetOpenUrlA 3D950BD2 5 Bytes JMP 00CB0FC3
.text C:\WINDOWS\Explorer.EXE[328] WININET.dll!InternetOpenUrlW 3D99B081 5 Bytes JMP 00CB0014
.text C:\WINDOWS\Explorer.EXE[328] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00CC0FEF
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00070FE5
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 0007009A
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 0007007F
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00070062
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00070051
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00070FB9
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00070F7E
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 000700C6
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 000700FC
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00070F59
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 0007010D
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00070036
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00070FD4
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 000700B5
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 0007001B
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 0007000A
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 000700D7
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00060014
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 0006004A
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00060FC3
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00060FD4
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00060F97
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00060FEF
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00060039
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00060FA8
.text C:\WINDOWS\system32\services.exe[752] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00050047
.text C:\WINDOWS\system32\services.exe[752] msvcrt.dll!system 77C293C7 5 Bytes JMP 00050036
.text C:\WINDOWS\system32\services.exe[752] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00050011
.text C:\WINDOWS\system32\services.exe[752] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00050FEF
.text C:\WINDOWS\system32\services.exe[752] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00050FBC
.text C:\WINDOWS\system32\services.exe[752] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00050000
.text C:\WINDOWS\system32\services.exe[752] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00040FE5
.text C:\WINDOWS\system32\lsass.exe[776] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00FF0FEF
.text C:\WINDOWS\system32\lsass.exe[776] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00FF0F44
.text C:\WINDOWS\system32\lsass.exe[776] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00FF002F
.text C:\WINDOWS\system32\lsass.exe[776] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00FF0F55
.text C:\WINDOWS\system32\lsass.exe[776] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00FF0F72
.text C:\WINDOWS\system32\lsass.exe[776] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00FF0F94
.text C:\WINDOWS\system32\lsass.exe[776] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00FF0078
.text C:\WINDOWS\system32\lsass.exe[776] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00FF0067
.text C:\WINDOWS\system32\lsass.exe[776] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00FF009A
.text C:\WINDOWS\system32\lsass.exe[776] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00FF0F0B
.text C:\WINDOWS\system32\lsass.exe[776] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00FF0EDC
.text C:\WINDOWS\system32\lsass.exe[776] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00FF0F83
.text C:\WINDOWS\system32\lsass.exe[776] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00FF0FCA
.text C:\WINDOWS\system32\lsass.exe[776] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00FF004A
.text C:\WINDOWS\system32\lsass.exe[776] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00FF0000
.text C:\WINDOWS\system32\lsass.exe[776] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00FF0FB9
.text C:\WINDOWS\system32\lsass.exe[776] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00FF0089
.text C:\WINDOWS\system32\lsass.exe[776] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00FE0FAF
.text C:\WINDOWS\system32\lsass.exe[776] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00FE0051
.text C:\WINDOWS\system32\lsass.exe[776] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00FE0FC0
.text C:\WINDOWS\system32\lsass.exe[776] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00FE0000
.text C:\WINDOWS\system32\lsass.exe[776] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00FE0036
.text C:\WINDOWS\system32\lsass.exe[776] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00FE0FEF
.text C:\WINDOWS\system32\lsass.exe[776] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00FE0F94
.text C:\WINDOWS\system32\lsass.exe[776] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [1E, 89]
.text C:\WINDOWS\system32\lsass.exe[776] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00FE0011
.text C:\WINDOWS\system32\lsass.exe[776] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00CB0FB4
.text C:\WINDOWS\system32\lsass.exe[776] msvcrt.dll!system 77C293C7 5 Bytes JMP 00CB0049
.text C:\WINDOWS\system32\lsass.exe[776] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00CB002E
.text C:\WINDOWS\system32\lsass.exe[776] msvcrt.dll!_open 77C2F566 3 Bytes JMP 00CB0000
.text C:\WINDOWS\system32\lsass.exe[776] msvcrt.dll!_open + 4 77C2F56A 1 Byte [89]
.text C:\WINDOWS\system32\lsass.exe[776] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00CB0FD9
.text C:\WINDOWS\system32\lsass.exe[776] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00CB001D
.text C:\WINDOWS\system32\lsass.exe[776] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00C60FEF
.text C:\WINDOWS\System32\svchost.exe[964] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 003A0000
.text C:\WINDOWS\System32\svchost.exe[964] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 003A0F83
.text C:\WINDOWS\System32\svchost.exe[964] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 003A006E
.text C:\WINDOWS\System32\svchost.exe[964] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 003A0F94
.text C:\WINDOWS\System32\svchost.exe[964] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 003A0051
.text C:\WINDOWS\System32\svchost.exe[964] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 003A0FC0
.text C:\WINDOWS\System32\svchost.exe[964] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 003A0F46
.text C:\WINDOWS\System32\svchost.exe[964] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 003A0F57
.text C:\WINDOWS\System32\svchost.exe[964] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 003A009F
.text C:\WINDOWS\System32\svchost.exe[964] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 003A0F10
.text C:\WINDOWS\System32\svchost.exe[964] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 003A0EEB
.text C:\WINDOWS\System32\svchost.exe[964] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 003A0FAF
.text C:\WINDOWS\System32\svchost.exe[964] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 003A0FEF
.text C:\WINDOWS\System32\svchost.exe[964] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 003A0F68
.text C:\WINDOWS\System32\svchost.exe[964] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 003A0036
.text C:\WINDOWS\System32\svchost.exe[964] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 003A001B
.text C:\WINDOWS\System32\svchost.exe[964] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 003A0F2B
.text C:\WINDOWS\System32\svchost.exe[964] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00390FA8
.text C:\WINDOWS\System32\svchost.exe[964] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00390F57
.text C:\WINDOWS\System32\svchost.exe[964] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00390FB9
.text C:\WINDOWS\System32\svchost.exe[964] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00390FCA
.text C:\WINDOWS\System32\svchost.exe[964] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00390F72
.text C:\WINDOWS\System32\svchost.exe[964] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00390FE5
.text C:\WINDOWS\System32\svchost.exe[964] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 0039001E
.text C:\WINDOWS\System32\svchost.exe[964] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00390F97
.text C:\WINDOWS\System32\svchost.exe[964] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00380051
.text C:\WINDOWS\System32\svchost.exe[964] msvcrt.dll!system 77C293C7 5 Bytes JMP 00380040
.text C:\WINDOWS\System32\svchost.exe[964] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0038000A
.text C:\WINDOWS\System32\svchost.exe[964] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00380FEF
.text C:\WINDOWS\System32\svchost.exe[964] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00380025
.text C:\WINDOWS\System32\svchost.exe[964] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00380FC6
.text C:\WINDOWS\System32\svchost.exe[964] WS2_32.dll!socket 71AB4211 3 Bytes JMP 0037000A
.text C:\WINDOWS\System32\svchost.exe[964] WS2_32.dll!socket + 4 71AB4215 1 Byte [8E]
.text C:\WINDOWS\system32\svchost.exe[1024] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02570FEF
.text C:\WINDOWS\system32\svchost.exe[1024] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 0257004A
.text C:\WINDOWS\system32\svchost.exe[1024] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 02570039
.text C:\WINDOWS\system32\svchost.exe[1024] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 02570F6B
.text C:\WINDOWS\system32\svchost.exe[1024] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 02570F7C
.text C:\WINDOWS\system32\svchost.exe[1024] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 02570FA8
.text C:\WINDOWS\system32\svchost.exe[1024] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 02570071
.text C:\WINDOWS\system32\svchost.exe[1024] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 02570F29
.text C:\WINDOWS\system32\svchost.exe[1024] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 02570EF3
.text C:\WINDOWS\system32\svchost.exe[1024] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 02570F04
.text C:\WINDOWS\system32\svchost.exe[1024] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 0257009D
.text C:\WINDOWS\system32\svchost.exe[1024] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 02570F8D
.text C:\WINDOWS\system32\svchost.exe[1024] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0257000A
.text C:\WINDOWS\system32\svchost.exe[1024] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 02570F3A
.text C:\WINDOWS\system32\svchost.exe[1024] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 02570FC3
.text C:\WINDOWS\system32\svchost.exe[1024] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 02570FD4
.text C:\WINDOWS\system32\svchost.exe[1024] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 02570082
.text C:\WINDOWS\system32\svchost.exe[1024] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 02560036
.text C:\WINDOWS\system32\svchost.exe[1024] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 02560F8A
.text C:\WINDOWS\system32\svchost.exe[1024] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 02560FE5
.text C:\WINDOWS\system32\svchost.exe[1024] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 0256001B
.text C:\WINDOWS\system32\svchost.exe[1024] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 02560FAF
.text C:\WINDOWS\system32\svchost.exe[1024] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 02560000
.text C:\WINDOWS\system32\svchost.exe[1024] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 02560FC0
.text C:\WINDOWS\system32\svchost.exe[1024] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [76, 8A] {JBE 0xffffffffffffff8c}
.text C:\WINDOWS\system32\svchost.exe[1024] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 02560047
.text C:\WINDOWS\system32\svchost.exe[1024] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 02550F9C
.text C:\WINDOWS\system32\svchost.exe[1024] msvcrt.dll!system 77C293C7 5 Bytes JMP 02550FAD
.text C:\WINDOWS\system32\svchost.exe[1024] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 02550016
.text C:\WINDOWS\system32\svchost.exe[1024] msvcrt.dll!_open 77C2F566 5 Bytes JMP 02550FEF
.text C:\WINDOWS\system32\svchost.exe[1024] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 02550027
.text C:\WINDOWS\system32\svchost.exe[1024] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 02550FD2
.text C:\WINDOWS\system32\svchost.exe[1024] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FF0000
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F80FEF
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00F80F55
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00F8004A
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00F80F70
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00F80F97
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00F8002F
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00F80F1F
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00F80F3A
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00F80EFD
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00F80F0E
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00F800B1
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00F80FA8
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00F80FD4
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00F8005B
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00F8000A
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00F80FC3
.text C:\WINDOWS\system32\svchost.exe[1100] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00F80082
.text C:\WINDOWS\system32\svchost.exe[1100] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00F70036
.text C:\WINDOWS\system32\svchost.exe[1100] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00F7005B
.text C:\WINDOWS\system32\svchost.exe[1100] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00F70FDB
.text C:\WINDOWS\system32\svchost.exe[1100] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00F7001B
.text C:\WINDOWS\system32\svchost.exe[1100] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00F70F9E
.text C:\WINDOWS\system32\svchost.exe[1100] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00F70000
.text C:\WINDOWS\system32\svchost.exe[1100] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00F70FB9
.text C:\WINDOWS\system32\svchost.exe[1100] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [17, 89]
.text C:\WINDOWS\system32\svchost.exe[1100] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00F70FCA
.text C:\WINDOWS\system32\svchost.exe[1100] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00E50F90
.text C:\WINDOWS\system32\svchost.exe[1100] msvcrt.dll!system 77C293C7 5 Bytes JMP 00E50011
.text C:\WINDOWS\system32\svchost.exe[1100] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00E50FC6
.text C:\WINDOWS\system32\svchost.exe[1100] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00E50FE3
.text C:\WINDOWS\system32\svchost.exe[1100] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00E50FAB
.text C:\WINDOWS\system32\svchost.exe[1100] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00E50000
.text C:\WINDOWS\system32\svchost.exe[1100] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00E40FE5
.text C:\WINDOWS\System32\svchost.exe[1200] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 0380000A
.text C:\WINDOWS\System32\svchost.exe[1200] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 03800F97
.text C:\WINDOWS\System32\svchost.exe[1200] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 03800096
.text C:\WINDOWS\System32\svchost.exe[1200] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 03800FB2
.text C:\WINDOWS\System32\svchost.exe[1200] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0380006F
.text C:\WINDOWS\System32\svchost.exe[1200] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 03800FD4
.text C:\WINDOWS\System32\svchost.exe[1200] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 03800F75
.text C:\WINDOWS\System32\svchost.exe[1200] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 03800F86
.text C:\WINDOWS\System32\svchost.exe[1200] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 03800F35
.text C:\WINDOWS\System32\svchost.exe[1200] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 03800F5A
.text C:\WINDOWS\System32\svchost.exe[1200] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 038000E9
.text C:\WINDOWS\System32\svchost.exe[1200] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 03800FC3
.text C:\WINDOWS\System32\svchost.exe[1200] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0380001B
.text C:\WINDOWS\System32\svchost.exe[1200] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 038000A7
.text C:\WINDOWS\System32\svchost.exe[1200] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 03800036
.text C:\WINDOWS\System32\svchost.exe[1200] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 03800FE5
.text C:\WINDOWS\System32\svchost.exe[1200] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 038000D8
.text C:\WINDOWS\System32\svchost.exe[1200] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 037F001B
.text C:\WINDOWS\System32\svchost.exe[1200] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 037F0F72
.text C:\WINDOWS\System32\svchost.exe[1200] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 037F000A
.text C:\WINDOWS\System32\svchost.exe[1200] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 037F0FCA
.text C:\WINDOWS\System32\svchost.exe[1200] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 037F0F83
.text C:\WINDOWS\System32\svchost.exe[1200] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 037F0FE5
.text C:\WINDOWS\System32\svchost.exe[1200] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 037F0FA8
.text C:\WINDOWS\System32\svchost.exe[1200] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [9F, 8B]
.text C:\WINDOWS\System32\svchost.exe[1200] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 037F0FB9
.text C:\WINDOWS\System32\svchost.exe[1200] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 037E0F7A
.text C:\WINDOWS\System32\svchost.exe[1200] msvcrt.dll!system 77C293C7 5 Bytes JMP 037E0F95
.text C:\WINDOWS\System32\svchost.exe[1200] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 037E0FC1
.text C:\WINDOWS\System32\svchost.exe[1200] msvcrt.dll!_open 77C2F566 5 Bytes JMP 037E0FEF
.text C:\WINDOWS\System32\svchost.exe[1200] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 037E0FA6
.text C:\WINDOWS\System32\svchost.exe[1200] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 037E0FDE
.text C:\WINDOWS\System32\svchost.exe[1200] WS2_32.dll!socket 71AB4211 5 Bytes JMP 037D0FEF
.text C:\WINDOWS\System32\svchost.exe[1200] WININET.dll!InternetOpenA 3D94C879 5 Bytes JMP 037C0000
.text C:\WINDOWS\System32\svchost.exe[1200] WININET.dll!InternetOpenW 3D94CEA9 5 Bytes JMP 037C0011
.text C:\WINDOWS\System32\svchost.exe[1200] WININET.dll!InternetOpenUrlA 3D950BD2 5 Bytes JMP 037C002C
.text C:\WINDOWS\System32\svchost.exe[1200] WININET.dll!InternetOpenUrlW 3D99B081 5 Bytes JMP 037C003D
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 006A0FE5
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 006A0F66
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 006A0F77
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 006A0051
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 006A0F9E
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 006A0025
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 006A0F29
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 006A0F3A
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 006A0EFD
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 006A008C
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 006A00B1
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 006A0040
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 006A0FCA
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 006A0F4B
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 006A000A
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 006A0FB9
.text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 006A0F0E
.text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 3 Bytes JMP 0069002C
.text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyExW + 4 77DD6AB3 1 Byte [88]
.text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyExW 77DD776C 3 Bytes JMP 0069006C
.text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyExW + 4 77DD7770 1 Byte [88]
.text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyExA 77DD7852 3 Bytes JMP 00690FDB
.text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyExA + 4 77DD7856 1 Byte [88]
.text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyW 77DD7946 3 Bytes JMP 00690011
.text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyW + 4 77DD794A 1 Byte [88]
.text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 3 Bytes JMP 00690FA5
.text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyExA + 4 77DDE9F8 1 Byte [88]
.text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 3 Bytes JMP 00690000
.text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegOpenKeyA + 4 77DDEFCC 1 Byte [88]
.text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 0069003D
.text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00690FB6
.text C:\WINDOWS\system32\svchost.exe[1312] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00680FA8
.text C:\WINDOWS\system32\svchost.exe[1312] msvcrt.dll!system 77C293C7 5 Bytes JMP 00680FB9
.text C:\WINDOWS\system32\svchost.exe[1312] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00680FDE
.text C:\WINDOWS\system32\svchost.exe[1312] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00680FEF
.text C:\WINDOWS\system32\svchost.exe[1312] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00680029
.text C:\WINDOWS\system32\svchost.exe[1312] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00680018
.text C:\WINDOWS\system32\svchost.exe[1312] WS2_32.dll!socket 71AB4211 5 Bytes JMP 0067000A
.text C:\WINDOWS\system32\svchost.exe[1356] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00B10000
.text C:\WINDOWS\system32\svchost.exe[1356] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00B100A9
.text C:\WINDOWS\system32\svchost.exe[1356] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00B1008E
.text C:\WINDOWS\system32\svchost.exe[1356] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00B1007D
.text C:\WINDOWS\system32\svchost.exe[1356] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00B10062
.text C:\WINDOWS\system32\svchost.exe[1356] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00B1002C
.text C:\WINDOWS\system32\svchost.exe[1356] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00B10F88
.text C:\WINDOWS\system32\svchost.exe[1356] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00B10F99
.text C:\WINDOWS\system32\svchost.exe[1356] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00B10F52
.text C:\WINDOWS\system32\svchost.exe[1356] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00B10F6D
.text C:\WINDOWS\system32\svchost.exe[1356] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00B10106
.text C:\WINDOWS\system32\svchost.exe[1356] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00B10051
.text C:\WINDOWS\system32\svchost.exe[1356] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00B1001B
.text C:\WINDOWS\system32\svchost.exe[1356] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00B100C4
.text C:\WINDOWS\system32\svchost.exe[1356] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00B10FC0
.text C:\WINDOWS\system32\svchost.exe[1356] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00B10FDB
.text C:\WINDOWS\system32\svchost.exe[1356] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00B100EB
.text C:\WINDOWS\system32\svchost.exe[1356] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00B00FCD
.text C:\WINDOWS\system32\svchost.exe[1356] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00B00F86
.text C:\WINDOWS\system32\svchost.exe[1356] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00B00FDE
.text C:\WINDOWS\system32\svchost.exe[1356] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00B00014
.text C:\WINDOWS\system32\svchost.exe[1356] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00B00043
.text C:\WINDOWS\system32\svchost.exe[1356] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00B00FEF
.text C:\WINDOWS\system32\svchost.exe[1356] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 00B00FA1
.text C:\WINDOWS\system32\svchost.exe[1356] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [D0, 88]
.text C:\WINDOWS\system32\svchost.exe[1356] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00B00FBC
.text C:\WINDOWS\system32\svchost.exe[1356] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00AF003B
.text C:\WINDOWS\system32\svchost.exe[1356] msvcrt.dll!system 77C293C7 5 Bytes JMP 00AF0FA6
.text C:\WINDOWS\system32\svchost.exe[1356] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00AF0FC1
.text C:\WINDOWS\system32\svchost.exe[1356] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00AF0FEF
.text C:\WINDOWS\system32\svchost.exe[1356] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00AF0016
.text C:\WINDOWS\system32\svchost.exe[1356] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00AF0FD2
.text C:\WINDOWS\system32\svchost.exe[1356] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00AE0FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 024B0000
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 024B006B
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 024B005A
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 024B003D
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 024B002C
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 024B0FA5
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 024B0F3E
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 024B0F5B
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 024B00B2
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 024B0097
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 024B0EFE
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 024B0F8A
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 024B0FE5
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 024B0086
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 024B0011
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 024B0FCA
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 024B0F23
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 024A0FCA
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 024A006C
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 024A001B
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 024A000A
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 024A0FAF
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 024A0FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 024A0047
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 024A0036
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E1DF4B9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E351F8F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E351F10 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E351F54 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E351E9C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E351ED6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E351FCA C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E2017EA C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 02490FB9
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] msvcrt.dll!system 77C293C7 5 Bytes JMP 02490FCA
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 02490029
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] msvcrt.dll!_open 77C2F566 5 Bytes JMP 02490FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0249003A
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 02490018
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] ole32.dll!OleLoadFromStream 77529C85 5 Bytes JMP 3E35218C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] WININET.dll!InternetOpenA 3D94C879 5 Bytes JMP 02470FEF
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] WININET.dll!InternetOpenW 3D94CEA9 5 Bytes JMP 02470FDE
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] WININET.dll!InternetOpenUrlA 3D950BD2 5 Bytes JMP 02470FCD
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] WININET.dll!InternetOpenUrlW 3D99B081 5 Bytes JMP 02470FB2
.text C:\Program Files\Internet Explorer\iexplore.exe[2732] ws2_32.dll!socket 71AB4211 5 Bytes JMP 02480FEF
.text C:\WINDOWS\system32\svchost.exe[2940] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BE0000
.text C:\WINDOWS\system32\svchost.exe[2940] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00BE0F68
.text C:\WINDOWS\system32\svchost.exe[2940] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00BE0F79
.text C:\WINDOWS\system32\svchost.exe[2940] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00BE005D
.text C:\WINDOWS\system32\svchost.exe[2940] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 00BE0F94
.text C:\WINDOWS\system32\svchost.exe[2940] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 00BE0FCA
.text C:\WINDOWS\system32\svchost.exe[2940] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 00BE00AE
.text C:\WINDOWS\system32\svchost.exe[2940] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 00BE0093
.text C:\WINDOWS\system32\svchost.exe[2940] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00BE0F30
.text C:\WINDOWS\system32\svchost.exe[2940] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00BE0F4B
.text C:\WINDOWS\system32\svchost.exe[2940] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 00BE00E4
.text C:\WINDOWS\system32\svchost.exe[2940] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00BE0FAF
.text C:\WINDOWS\system32\svchost.exe[2940] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00BE0011
.text C:\WINDOWS\system32\svchost.exe[2940] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 00BE0082
.text C:\WINDOWS\system32\svchost.exe[2940] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 00BE0FDB
.text C:\WINDOWS\system32\svchost.exe[2940] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00BE0036
.text C:\WINDOWS\system32\svchost.exe[2940] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00BE00BF
.text C:\WINDOWS\system32\svchost.exe[2940] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00660FDB
.text C:\WINDOWS\system32\svchost.exe[2940] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 0066006C
.text C:\WINDOWS\system32\svchost.exe[2940] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 0066002C
.text C:\WINDOWS\system32\svchost.exe[2940] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 0066001B
.text C:\WINDOWS\system32\svchost.exe[2940] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00660FAF
.text C:\WINDOWS\system32\svchost.exe[2940] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00660000
.text C:\WINDOWS\system32\svchost.exe[2940] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00660051
.text C:\WINDOWS\system32\svchost.exe[2940] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00660FCA
.text C:\WINDOWS\system32\svchost.exe[2940] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00650073
.text C:\WINDOWS\system32\svchost.exe[2940] msvcrt.dll!system 77C293C7 5 Bytes JMP 0065004E
.text C:\WINDOWS\system32\svchost.exe[2940] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00650022
.text C:\WINDOWS\system32\svchost.exe[2940] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00650FEF
.text C:\WINDOWS\system32\svchost.exe[2940] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00650033
.text C:\WINDOWS\system32\svchost.exe[2940] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 00650FDE
.text C:\WINDOWS\system32\svchost.exe[2940] WININET.dll!InternetOpenA 3D94C879 5 Bytes JMP 00630FEF
.text C:\WINDOWS\system32\svchost.exe[2940] WININET.dll!InternetOpenW 3D94CEA9 5 Bytes JMP 00630FD4
.text C:\WINDOWS\system32\svchost.exe[2940] WININET.dll!InternetOpenUrlA 3D950BD2 5 Bytes JMP 00630FB9
.text C:\WINDOWS\system32\svchost.exe[2940] WININET.dll!InternetOpenUrlW 3D99B081 5 Bytes JMP 0063000A
.text C:\WINDOWS\system32\svchost.exe[2940] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00640FEF
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01A90FEF
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01A90098
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01A9007D
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01A90FA3
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01A90062
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01A90036
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01A90F6D
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01A900B5
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01A90F26
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01A90F37
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01A90F0B
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01A90051
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01A90000
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01A90F7E
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01A90FCA
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01A9001B
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01A90F48
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01A70FBE
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] msvcrt.dll!system 77C293C7 5 Bytes JMP 01A70049
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01A7001D
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01A70FEF
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01A7002E
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01A70000
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01A80FB9
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01A8004A
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01A80FCA
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01A80000
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01A8002F
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01A80FE5
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01A80F83
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [C8, 89]
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01A80FA8
.text C:\WINDOWS\system32\inetsrv\inetinfo.exe[3096] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01A60FEF
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01E50000
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01E50F55
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01E50F70
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01E50F8D
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01E50F9E
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01E50040
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01E50F27
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01E5006F
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01E50094
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01E50EFB
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 01E50EE0
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01E50FAF
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01E50FE5
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01E50F44
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01E5001B
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01E50FCA
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01E50F16
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01E40FA8
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01E4004A
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01E40FB9
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01E40FCA
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01E40F8D
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01E40FEF
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 01E40025
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01E40014
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01E30FB5
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] msvcrt.dll!system 77C293C7 5 Bytes JMP 01E30FC6
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 01E30FD7
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01E30000
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01E30036
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01E30011
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] WS2_32.dll!socket 71AB4211 5 Bytes JMP 01E20FEF
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] WinInet.dll!InternetOpenA 3D94C879 5 Bytes JMP 01220000
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] WinInet.dll!InternetOpenW 3D94CEA9 5 Bytes JMP 01220FEF
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] WinInet.dll!InternetOpenUrlA 3D950BD2 5 Bytes JMP 01220FD4
.text C:\Program Files\McAfee\Common Framework\FrameworkService.exe[3180] WinInet.dll!InternetOpenUrlW 3D99B081 5 Bytes JMP 01220025
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 01020FEF
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 01020067
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 01020F7C
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 01020F8D
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 01020F9E
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 01020FB9
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 01020089
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 01020F41
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 0102009A
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01020F01
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 010200B5
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 01020040
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0102000A
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 01020078
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 01020FD4
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 01020025
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 01020F26
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 0101001B
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01010065
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01010FD4
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01010FEF
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 01010FA8
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 0101000A
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01010FB9
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [21, 89]
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 01010040
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01000FAD
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] msvcrt.dll!system 77C293C7 5 Bytes JMP 01000038
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0100001D
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01000000
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 01000FBE
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01000FE3
.text C:\Program Files\McAfee\Common Framework\naPrdMgr.exe[3344] WS2_32.dll!socket 71AB4211 5 Bytes JMP 00FF0000
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 eabfiltr.sys (QLB PS/2 Keyboard filter driver/Hewlett-Packard Development Company, L.P.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp mfetdik.sys (Anti-Virus Mini-Firewall Driver/McAfee, Inc.)
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Roxio)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETirkcjsni@start 1
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETirkcjsni@type 1
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETirkcjsni@group file system
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETirkcjsni@imagepath \systemroot\system32\drivers\SKYNETnoecwjds.sys
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETirkcjsni\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETirkcjsni\main@aid 10096
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETirkcjsni\main@sid 0
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETirkcjsni\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETirkcjsni\main\delete@C:\DOCUME~1\devry\LOCALS~1\Temp\ytasfwlnosvrcicu.tmp
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETirkcjsni\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETirkcjsni\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETirkcjsni\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETirkcjsni\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETirkcjsni\
[email protected] \systemroot\system32\drivers\SKYNETnoecwjds.sys
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETirkcjsni\
[email protected] \systemroot\system32\SKYNETkkylvvmq.dll
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETirkcjsni\
[email protected] \systemroot\system32\SKYNETrpoddnsv.dat
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETirkcjsni\
[email protected] \systemroot\system32\SKYNETeotvtelt.dll
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETjuvgakkl@start 1
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETjuvgakkl@type 1
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETjuvgakkl@group file system
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETjuvgakkl@imagepath \systemroot\system32\drivers\SKYNETrdxgpaye.sys
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETjuvgakkl\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETjuvgakkl\main@aid 10096
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETjuvgakkl\main@sid 0
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETjuvgakkl\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETjuvgakkl\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETjuvgakkl\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETjuvgakkl\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETjuvgakkl\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETjuvgakkl\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETjuvgakkl\
[email protected] \systemroot\system32\drivers\SKYNETrdxgpaye.sys
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETjuvgakkl\
[email protected] \systemroot\system32\SKYNETpyotppph.dll
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETjuvgakkl\
[email protected] \systemroot\system32\SKYNETpquejmoe.dat
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETjuvgakkl\
[email protected] \systemroot\system32\SKYNETdareoikt.dll
Reg HKLM\SYSTEM\ControlSet001\Services\SKYNETjuvgakkl\
[email protected] \systemroot\system32\SKYNETrqlasrnh.dat
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETjuvgakkl@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETjuvgakkl@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETjuvgakkl@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETjuvgakkl@imagepath \systemroot\system32\drivers\SKYNETrdxgpaye.sys
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETjuvgakkl\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETjuvgakkl\main@aid 10096
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETjuvgakkl\main@sid 0
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETjuvgakkl\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETjuvgakkl\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETjuvgakkl\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETjuvgakkl\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETjuvgakkl\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETjuvgakkl\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETjuvgakkl\
[email protected] \systemroot\system32\drivers\SKYNETrdxgpaye.sys
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETjuvgakkl\
[email protected] \systemroot\system32\SKYNETpyotppph.dll
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETjuvgakkl\
[email protected] \systemroot\system32\SKYNETpquejmoe.dat
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETjuvgakkl\
[email protected] \systemroot\system32\SKYNETdareoikt.dll
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETjuvgakkl\
[email protected] \systemroot\system32\SKYNETrqlasrnh.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETjuvgakkl@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETjuvgakkl@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETjuvgakkl@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETjuvgakkl@imagepath \systemroot\system32\drivers\SKYNETrdxgpaye.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETjuvgakkl\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETjuvgakkl\main@aid 10096
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETjuvgakkl\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETjuvgakkl\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETjuvgakkl\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETjuvgakkl\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETjuvgakkl\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETjuvgakkl\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETjuvgakkl\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETjuvgakkl\
[email protected] \systemroot\system32\drivers\SKYNETrdxgpaye.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETjuvgakkl\
[email protected] \systemroot\system32\SKYNETpyotppph.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETjuvgakkl\
[email protected] \systemroot\system32\SKYNETpquejmoe.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETjuvgakkl\
[email protected] \systemroot\system32\SKYNETdareoikt.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETjuvgakkl\
[email protected] \systemroot\system32\SKYNETrqlasrnh.dat
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1409082233-1757981266-839522115-1003@RefCount 28
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\HFGELY2I\ftp[1].exe (size mismatch) 7914/0 bytes executable
File C:\WINDOWS\Temp\rdl65.tmp.exe (size mismatch) 7914/0 bytes executable
---- EOF - GMER 1.0.15 ----